Solved Event 3 on boot: NT Kernel Log full, error 0xC000000D

This morning I found the etl file at 5MB. I rebooted and the size didn't change (except for the date and time). When I try to open it with Event Viewer, it says the file is corrupt. I wonder if something is writing to it. And today, in the Performance Monitor, Event Trace Sessions, the NT Kernel Logger is not there. I have a number 3 Event, "Session 'NT Kernel Logger' stopped due to the following error: 0xC000000D
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Win7 Ultimate x64
CPU
Intel i5-3450 3.10GHz
Motherboard
ASUS P8H61-M LE BIOS 4601 x64 9/8/2013 (UEFI)
Memory
8GB
Graphics Card(s)
Radeon HD6670, 1GB DDR3, On-Board: Intel HD 2500Graphics
Hard Drives
SanDisk Extreme SSD 120 GB SATA3 6Gps
Western Digital Blue 500GB SATA
Antivirus
Avira
Browser
Firefox x64

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built using existing case
OS
Windows 7 Home Premium 64 bit sp1
CPU
Intel i5 3570 3.4Ghz Ivy Bridge SKT 1155 quad core
Motherboard
Gigabyte Z77-HD3 SKT 1155 2xSata 3, 4x USB 3.0
Memory
G-Skill Rip Jaws 16Gb (8x2) DDR3 -1600 PC3 12800 CL 10 red
Graphics Card(s)
Gigabyte NVIDIA GT610 1Gb DDR3 810/1200 PCI-E 2.0 Silent
Sound Card
NVIDIA High Definition & Realtech High Definition Audio
Monitor(s) Displays
2 x Philips 226V4L 16:9 aspect ratio
Screen Resolution
1920 x 1080 HD
Hard Drives
Samsung 840 Pro 256gb SSD, SATA 3.
Hitachi Touro Portable 1tb, USB 3.0 HDD used for image b/ups.
PSU
Corsair VS450
Case
Codeng
Cooling
PSU fan & CPU fan
Keyboard
Logitech
Mouse
Logitech Wireless trackball M570
Internet Speed
Wireless 3G. 3mg down & 550kb up.
Antivirus
Bitdefender Internet Security 2020
Browser
Opera (Current Version) & Firefox
Other Info
MS Office 2013 Pro. Davis weather station software. MGE Nova 600 avr UPS.
Dear Ranger 4. Well, that solution is indirectly applicable to my situation; I do not have a difficulty with EppOobe.etl I will continue to monitor NT Kernel Logger.etl Perhaps I'll discover the program or service which is actually triggering it.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Win7 Ultimate x64
CPU
Intel i5-3450 3.10GHz
Motherboard
ASUS P8H61-M LE BIOS 4601 x64 9/8/2013 (UEFI)
Memory
8GB
Graphics Card(s)
Radeon HD6670, 1GB DDR3, On-Board: Intel HD 2500Graphics
Hard Drives
SanDisk Extreme SSD 120 GB SATA3 6Gps
Western Digital Blue 500GB SATA
Antivirus
Avira
Browser
Firefox x64
This morning I do not have an Event 2 or 3. The NT Kernel Logger.etl file is 51 MB and is readable (full of Event 0, Op Code 5, 10(mostly) and 14). In the Performance Monitor> Data Collector Sets > Event Trace Sessions, NT Kernel Logger is present and running. It's Properties > File > Log Mode > is set to "Append". This is different than the Circular, the last time I had access to it. I would still like to know how to control this Logger.
I did a Scan Disk with no errors.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Win7 Ultimate x64
CPU
Intel i5-3450 3.10GHz
Motherboard
ASUS P8H61-M LE BIOS 4601 x64 9/8/2013 (UEFI)
Memory
8GB
Graphics Card(s)
Radeon HD6670, 1GB DDR3, On-Board: Intel HD 2500Graphics
Hard Drives
SanDisk Extreme SSD 120 GB SATA3 6Gps
Western Digital Blue 500GB SATA
Antivirus
Avira
Browser
Firefox x64

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built using existing case
OS
Windows 7 Home Premium 64 bit sp1
CPU
Intel i5 3570 3.4Ghz Ivy Bridge SKT 1155 quad core
Motherboard
Gigabyte Z77-HD3 SKT 1155 2xSata 3, 4x USB 3.0
Memory
G-Skill Rip Jaws 16Gb (8x2) DDR3 -1600 PC3 12800 CL 10 red
Graphics Card(s)
Gigabyte NVIDIA GT610 1Gb DDR3 810/1200 PCI-E 2.0 Silent
Sound Card
NVIDIA High Definition & Realtech High Definition Audio
Monitor(s) Displays
2 x Philips 226V4L 16:9 aspect ratio
Screen Resolution
1920 x 1080 HD
Hard Drives
Samsung 840 Pro 256gb SSD, SATA 3.
Hitachi Touro Portable 1tb, USB 3.0 HDD used for image b/ups.
PSU
Corsair VS450
Case
Codeng
Cooling
PSU fan & CPU fan
Keyboard
Logitech
Mouse
Logitech Wireless trackball M570
Internet Speed
Wireless 3G. 3mg down & 550kb up.
Antivirus
Bitdefender Internet Security 2020
Browser
Opera (Current Version) & Firefox
Other Info
MS Office 2013 Pro. Davis weather station software. MGE Nova 600 avr UPS.
Thanks very much Ranger 4. I took care of Intel's QueenCreek etl generator last month, so the first 2 suggestions don't apply. The last 2 are very useful though. So, it looks like the Global Logger is what starts the NT Kernel Logger (I guess they're actually the same). In HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\GlobalLogger, Log File Mode. The current value of this is 5 which seems to be 1 + 4 (Ref: Logging Mode Constants https://msdn.microsoft.com/en-us/library/windows/desktop/aa364080(v=vs.85).aspx) sequential + append. I think I'd like to set it to 2, Circular. I'll try to set it the LogFileMode to 2 and Start to 1.
Thanks a lot. I wonder why I didn't find these in my web crawling. I appreciate your time in finding these for me.
 
Last edited:

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Win7 Ultimate x64
CPU
Intel i5-3450 3.10GHz
Motherboard
ASUS P8H61-M LE BIOS 4601 x64 9/8/2013 (UEFI)
Memory
8GB
Graphics Card(s)
Radeon HD6670, 1GB DDR3, On-Board: Intel HD 2500Graphics
Hard Drives
SanDisk Extreme SSD 120 GB SATA3 6Gps
Western Digital Blue 500GB SATA
Antivirus
Avira
Browser
Firefox x64
You are welcome & thanks for getting back. Glad to have been of some help & thanks for marking the thread as solved.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built using existing case
OS
Windows 7 Home Premium 64 bit sp1
CPU
Intel i5 3570 3.4Ghz Ivy Bridge SKT 1155 quad core
Motherboard
Gigabyte Z77-HD3 SKT 1155 2xSata 3, 4x USB 3.0
Memory
G-Skill Rip Jaws 16Gb (8x2) DDR3 -1600 PC3 12800 CL 10 red
Graphics Card(s)
Gigabyte NVIDIA GT610 1Gb DDR3 810/1200 PCI-E 2.0 Silent
Sound Card
NVIDIA High Definition & Realtech High Definition Audio
Monitor(s) Displays
2 x Philips 226V4L 16:9 aspect ratio
Screen Resolution
1920 x 1080 HD
Hard Drives
Samsung 840 Pro 256gb SSD, SATA 3.
Hitachi Touro Portable 1tb, USB 3.0 HDD used for image b/ups.
PSU
Corsair VS450
Case
Codeng
Cooling
PSU fan & CPU fan
Keyboard
Logitech
Mouse
Logitech Wireless trackball M570
Internet Speed
Wireless 3G. 3mg down & 550kb up.
Antivirus
Bitdefender Internet Security 2020
Browser
Opera (Current Version) & Firefox
Other Info
MS Office 2013 Pro. Davis weather station software. MGE Nova 600 avr UPS.
This morning on boot I find that the NT Kernel Logger.etl file size is 0 bytes. The NTKL is running. The log file mode is set to circular and the max file size is 100 MB. I think that the logger should be logging something as it did before.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Win7 Ultimate x64
CPU
Intel i5-3450 3.10GHz
Motherboard
ASUS P8H61-M LE BIOS 4601 x64 9/8/2013 (UEFI)
Memory
8GB
Graphics Card(s)
Radeon HD6670, 1GB DDR3, On-Board: Intel HD 2500Graphics
Hard Drives
SanDisk Extreme SSD 120 GB SATA3 6Gps
Western Digital Blue 500GB SATA
Antivirus
Avira
Browser
Firefox x64
Lets see what happens with everything as it is. At least with it showing zero you shouldn't receive the constant warning you were getting before.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built using existing case
OS
Windows 7 Home Premium 64 bit sp1
CPU
Intel i5 3570 3.4Ghz Ivy Bridge SKT 1155 quad core
Motherboard
Gigabyte Z77-HD3 SKT 1155 2xSata 3, 4x USB 3.0
Memory
G-Skill Rip Jaws 16Gb (8x2) DDR3 -1600 PC3 12800 CL 10 red
Graphics Card(s)
Gigabyte NVIDIA GT610 1Gb DDR3 810/1200 PCI-E 2.0 Silent
Sound Card
NVIDIA High Definition & Realtech High Definition Audio
Monitor(s) Displays
2 x Philips 226V4L 16:9 aspect ratio
Screen Resolution
1920 x 1080 HD
Hard Drives
Samsung 840 Pro 256gb SSD, SATA 3.
Hitachi Touro Portable 1tb, USB 3.0 HDD used for image b/ups.
PSU
Corsair VS450
Case
Codeng
Cooling
PSU fan & CPU fan
Keyboard
Logitech
Mouse
Logitech Wireless trackball M570
Internet Speed
Wireless 3G. 3mg down & 550kb up.
Antivirus
Bitdefender Internet Security 2020
Browser
Opera (Current Version) & Firefox
Other Info
MS Office 2013 Pro. Davis weather station software. MGE Nova 600 avr UPS.
Another day of no error and no logging. I could use a little expertise in choosing an appropriate logging mode constant. Reference post #26.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
custom build
OS
Win7 Ultimate x64
CPU
Intel i5-3450 3.10GHz
Motherboard
ASUS P8H61-M LE BIOS 4601 x64 9/8/2013 (UEFI)
Memory
8GB
Graphics Card(s)
Radeon HD6670, 1GB DDR3, On-Board: Intel HD 2500Graphics
Hard Drives
SanDisk Extreme SSD 120 GB SATA3 6Gps
Western Digital Blue 500GB SATA
Antivirus
Avira
Browser
Firefox x64
I can't offer any help on an appropriate logging mode as I have never experienced this problem, but as it seems to working well I would just leave it as it is & not get too concerned about it.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Self built using existing case
OS
Windows 7 Home Premium 64 bit sp1
CPU
Intel i5 3570 3.4Ghz Ivy Bridge SKT 1155 quad core
Motherboard
Gigabyte Z77-HD3 SKT 1155 2xSata 3, 4x USB 3.0
Memory
G-Skill Rip Jaws 16Gb (8x2) DDR3 -1600 PC3 12800 CL 10 red
Graphics Card(s)
Gigabyte NVIDIA GT610 1Gb DDR3 810/1200 PCI-E 2.0 Silent
Sound Card
NVIDIA High Definition & Realtech High Definition Audio
Monitor(s) Displays
2 x Philips 226V4L 16:9 aspect ratio
Screen Resolution
1920 x 1080 HD
Hard Drives
Samsung 840 Pro 256gb SSD, SATA 3.
Hitachi Touro Portable 1tb, USB 3.0 HDD used for image b/ups.
PSU
Corsair VS450
Case
Codeng
Cooling
PSU fan & CPU fan
Keyboard
Logitech
Mouse
Logitech Wireless trackball M570
Internet Speed
Wireless 3G. 3mg down & 550kb up.
Antivirus
Bitdefender Internet Security 2020
Browser
Opera (Current Version) & Firefox
Other Info
MS Office 2013 Pro. Davis weather station software. MGE Nova 600 avr UPS.
Back
Top