Solved Strange event logs

Jackal

New member
Local time
10:37 PM
Messages
46
Strange Events and BSOD

Hi guys
i dont really look into my event logs because usually, i dont have the need too.

i randomly decided to look into my event log (while doing some maintenance on my setup)
and found some strange events.

two distinct event logs which are somewhat related.

Problem 1. I can cause the following event by removing my iPod from my pc via iTunes (remove virtually not physically)

Following events have
Log name: Microsoft-Windows-WMI-Activity/Operational
Event ID: 5858
Level: Error

Event 1:
Id = {00000000-0000-0000-0000-000000000000}; ClientMachine = SHADY-PC; User = NT AUTHORITY\SYSTEM; ClientProcessId = 2992; Component = Unknown; Operation = Start IWbemServices::ExecQuery - root\wmi : select * from WDMClassesOfDriver where ClassName = "MSStorageDriver_ClassErrorLogEntry"; ResultCode = 0x80041032; PossibleCause = Unknown

Event 2:
Id = {00000000-0000-0000-0000-000000000000}; ClientMachine = SHADY-PC; User = NT AUTHORITY\SYSTEM; ClientProcessId = 2992; Component = Unknown; Operation = Start IWbemServices::ExecQuery - root\wmi : select * from WDMClassesOfDriver where ClassName = "MSStorageDriver_ClassErrorLog"; ResultCode = 0x80041032; PossibleCause = Unknown

Event 3:
Id = {00000000-0000-0000-0000-000000000000}; ClientMachine = SHADY-PC; User = NT AUTHORITY\SYSTEM; ClientProcessId = 2992; Component = Unknown; Operation = Start IWbemServices::ExecQuery - root\wmi : select * from WMIBinaryMofResource where Name = "IDE\\DiskOCZ-VERTEX3_____________________________2.22____\\5&2b5975fc&0&0.0.0_0-{05901221-D566-11d1-B2F0-00A0C9062910}"; ResultCode = 0x80041032; PossibleCause = Unknown

Event 4:
Id = {00000000-0000-0000-0000-000000000000}; ClientMachine = SHADY-PC; User = NT AUTHORITY\SYSTEM; ClientProcessId = 2992; Component = Unknown; Operation = Start IWbemServices::ExecQuery - root\wmi : select * from WMIBinaryMofResource where Name = "IDE\\DiskWDC_WD2002FAEX-007BA0___________________05.01D05\\5&2785c9a&0&1.0.0_0-{05901221-D566-11d1-B2F0-00A0C9062910}"; ResultCode = 0x80041032; PossibleCause = Unknown

Event 5:
Id = {00000000-0000-0000-0000-000000000000}; ClientMachine = SHADY-PC; User = NT AUTHORITY\SYSTEM; ClientProcessId = 2992; Component = Unknown; Operation = Start IWbemServices::ExecQuery - root\wmi : select * from WDMClassesOfDriver where ClassName = "MSStorageDriver_SenseData"; ResultCode = 0x80041032; PossibleCause = Unknown

Event 6:
Id = {00000000-0000-0000-0000-000000000000}; ClientMachine = SHADY-PC; User = NT AUTHORITY\SYSTEM; ClientProcessId = 2992; Component = Unknown; Operation = Start IWbemServices::ExecQuery - root\wmi : select * from WDMClassesOfDriver where ClassName = "MSStorageDriver_ScsiRequestBlock"; ResultCode = 0x80041032; PossibleCause = Unknown



Problem 2:
the following errors occur when i insert a USB in my PC

Event 1:
The driver detected a controller error on \Device\Harddisk4\DR5.
*Note Hard disk 4 is the actual USB

Event 2 to 6 are the same as Problem 1: Events 1-6


I ran driver verifier with no apparent problems

uninstalled/reinstalled USB drivers
im stumped as to the cause of this problem.


thanks for any help in advance.


Motherboard is ASUSTeK Computer Inc. -Support- Drivers and Download Maximus IV Extreme

Windows 7 64bit
 
Last edited:

My Computer

OS
WIN 7 HP 64bit
CPU
i7 920
Motherboard
EX58-EXtreme
Memory
6GB Corsair Dominator
Graphics Card(s)
GTX480
Monitor(s) Displays
22" BenQ
Screen Resolution
1080p
Hard Drives
4TB - caviar black
PSU
770W XT ZM
Case
armor+mx
Cooling
thermalright ultra black
Keyboard
G15
Mouse
G9x
Internet Speed
http://www.speedtest.net/result/911749129.png
anyone?

these errors only occur when removing a USB device.
 

My Computer

OS
WIN 7 HP 64bit
CPU
i7 920
Motherboard
EX58-EXtreme
Memory
6GB Corsair Dominator
Graphics Card(s)
GTX480
Monitor(s) Displays
22" BenQ
Screen Resolution
1080p
Hard Drives
4TB - caviar black
PSU
770W XT ZM
Case
armor+mx
Cooling
thermalright ultra black
Keyboard
G15
Mouse
G9x
Internet Speed
http://www.speedtest.net/result/911749129.png
found the process id for the errors
it seems to be pointing at WmiPrvSE.exe
 

My Computer

OS
WIN 7 HP 64bit
CPU
i7 920
Motherboard
EX58-EXtreme
Memory
6GB Corsair Dominator
Graphics Card(s)
GTX480
Monitor(s) Displays
22" BenQ
Screen Resolution
1080p
Hard Drives
4TB - caviar black
PSU
770W XT ZM
Case
armor+mx
Cooling
thermalright ultra black
Keyboard
G15
Mouse
G9x
Internet Speed
http://www.speedtest.net/result/911749129.png

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
home built
OS
Multi-Boot W7_Pro_x64 W8.1_Pro_x64 W10_Pro_x64 +Linux_VMs +Chromium_VM
CPU
AMD Athlon II x4 620
Motherboard
Gigabyte GA-MA785G-UD3H
Memory
6GB GSkill DDR2 800
Graphics Card(s)
AMD 4670 GPU + AMD 4200 IGP
Sound Card
on board Realtek ALC889A
Monitor(s) Displays
RCA 40" LCD TV, Insignia 32" LCD TV, HP 15" LCD monitor
Screen Resolution
1680 x 1050
Hard Drives
OCZ Vertex 3 120GB,
Samsung F3 1TB (3),
Several others - WD, Seagate, Hitachi, ...
PSU
Corsair 500 W
Case
Rosewill mid tower
Cooling
CM 90mm rifle
Keyboard
Gyration wireless, Logitech wireless, Dell USB wired
Mouse
Gyration wireless, Logitech wireless, V7 USB wired
Internet Speed
Spectrum - 100Mbps D / 10Mbps U
Antivirus
Avast, MBAM3, EMET, WinPatrol
Browser
Pale Moon, Firefox, IE
Other Info
2 multi-boot PC's
Mainly HTPC/Office/Gen purpose (no gaming).
Trendnet USB KVM.
LG DVD burner/Blue Ray Player.
Tray system for removable SATA backup drives.

Not currently OCd, under-volted.
I use Hybrid sleep, rarely re-boot or shutdown.

Hauppauge HD-PVR, Avermedia PCIe TV Tuner, Hauppauge PCI TV Tuner.
You would have to check the process-ID at about the time the event is logged but I'd guess it's iTunes polling for devices or objects through IWBEM services (Windows Management Instrumentation). The result code 0x80041032 indicates a "WBEM_E_CALL_CANCELLED". This would indicate a driver or program problem. If you can create these events by removing the iPod from iTunes, there's most likely a programming error in iTunes.

In addition to what DavidE suggests, check to see if there's an update for iTunes. They're getting better. It used to cause numerous BSODs so you're lucky. ;)

REF: https://support.microsoft.com/en-us/kb/295821

REF: https://msdn.microsoft.com/en-us/library/windows/desktop/aa392107(v=vs.85).aspx

Oh yes, Problem 2 might be a bad USB drive (thumb drive) if that's what you're inserting. They do wear out.
 
Last edited:

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
You would have to check the process-ID at about the time the event is logged but I'd guess it's iTunes polling for devices or objects through IWBEM services (Windows Management Instrumentation). The result code 0x80041032 indicates a "WBEM_E_CALL_CANCELLED". This would indicate a driver or program problem. If you can create these events by removing the iPod from iTunes, there's most likely a programming error in iTunes.

The issue can be recreated by 'safely removing' a USB from the PC too so its not restricted to iTunes.

Also i am checking process ID at the time of event and it always comes back with wmiprvse.exe.






i have done SFC scannow, also rebuilt WMI repository still nothing.
 

My Computer

OS
WIN 7 HP 64bit
CPU
i7 920
Motherboard
EX58-EXtreme
Memory
6GB Corsair Dominator
Graphics Card(s)
GTX480
Monitor(s) Displays
22" BenQ
Screen Resolution
1080p
Hard Drives
4TB - caviar black
PSU
770W XT ZM
Case
armor+mx
Cooling
thermalright ultra black
Keyboard
G15
Mouse
G9x
Internet Speed
http://www.speedtest.net/result/911749129.png
i inserted my USB and removed it a few times with the errors coming up and i received a BSOD
minidump is attached if anyone can help.
 

Attachments

My Computer

OS
WIN 7 HP 64bit
CPU
i7 920
Motherboard
EX58-EXtreme
Memory
6GB Corsair Dominator
Graphics Card(s)
GTX480
Monitor(s) Displays
22" BenQ
Screen Resolution
1080p
Hard Drives
4TB - caviar black
PSU
770W XT ZM
Case
armor+mx
Cooling
thermalright ultra black
Keyboard
G15
Mouse
G9x
Internet Speed
http://www.speedtest.net/result/911749129.png
Code:
fffff880`0d1514c8  00000000`000007ff
fffff880`0d1514d0  00000000`0000000c
fffff880`0d1514d8  fffff800`02fa0300 nt!ObpQueryNameString
fffff880`0d1514e0  fffff880`02676a22Unable to load image \SystemRoot\system32\DRIVERS\tdrpm251.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for tdrpm251.sys
*** ERROR: Module load completed but symbols could not be loaded for [B][COLOR="Red"]tdrpm251.sys[/COLOR][/B]
 tdrpm251+0x53a22
fffff880`0d1514e8  fffff800`02c57000 nt!KiSelectNextThread <PERF> (nt+0x0)
fffff880`0d1514f0  fffff800`02ef02ec nt!BBTBuffer <PERF> (nt+0x2992ec)
fffff880`0d1514f8  fffff800`02c57000 nt!KiSelectNextThread <PERF> (nt+0x0)
fffff880`0d151500  fffff800`02ef0580 nt!BBTBuffer <PERF> (nt+0x299580)
fffff880`0d151508  fffff880`02623000 tdrpm251
fffff880`0d151510  fffff880`027729f8 tdrpm251+0x14f9f8
fffff880`0d151518  fffff880`02623000 tdrpm251
At first glance, the issue appears to be a Acronis driver issue, but I think Norton is screwing you over as evidenced below:
Code:
fffff880`0d151910  00000000`00000000
fffff880`0d151918  00000000`00000004
fffff880`0d151920  fffff880`0457b940Unable to load image \??\C:\Windows\system32\Drivers\SYMEVENT64x86.SYS, Win32 error 0n2
*** WARNING: Unable to verify timestamp for [B][COLOR="red"]SYMEVENT64x86.SYS[/COLOR][/B]
*** ERROR: Module load completed but symbols could not be loaded for SYMEVENT64x86.SYS
 SYMEVENT64x86+0x22940
fffff880`0d151928  fffff880`04572d33 SYMEVENT64x86+0x19d33
fffff880`0d151930  00000000`00000000
fffff880`0d151938  fffff880`0d1519a0
Code:
fffff880`0d1510e8  00000000`00000000
fffff880`0d1510f0  00000000`019701c0
fffff880`0d1510f8  00000000`77a0e12a
fffff880`0d151100  fffff880`04f73758Unable to load image \??\C:\Program Files (x86)\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150408.001\BHDrvx64.sys, Win32 error 0n2
*** WARNING: Unable to verify timestamp for [B][COLOR="red"]BHDrvx64.sys[/COLOR][/B]
*** ERROR: Module load completed but symbols could not be loaded for BHDrvx64.sys
 BHDrvx64+0x151758
fffff880`0d151108  fffff8a0`047c9458
fffff880`0d151110  00000000`00000000
fffff880`0d151118  00000000`00001f80
fffff880`0d151120  fffffa80`0ca38b30
Recommend replacing Norton with soemthing less instrusive, and checking to see if Acronis can be updated.

   Note
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
i will uninstall and report back asap.
 

My Computer

OS
WIN 7 HP 64bit
CPU
i7 920
Motherboard
EX58-EXtreme
Memory
6GB Corsair Dominator
Graphics Card(s)
GTX480
Monitor(s) Displays
22" BenQ
Screen Resolution
1080p
Hard Drives
4TB - caviar black
PSU
770W XT ZM
Case
armor+mx
Cooling
thermalright ultra black
Keyboard
G15
Mouse
G9x
Internet Speed
http://www.speedtest.net/result/911749129.png
also @Golden
for future reference debugging
how did you pull those troubled drivers

windbg analyze v only brings up the ntkrnlpl.exe
and third party software shows fastfat.sys as a likely cause
 

My Computer

OS
WIN 7 HP 64bit
CPU
i7 920
Motherboard
EX58-EXtreme
Memory
6GB Corsair Dominator
Graphics Card(s)
GTX480
Monitor(s) Displays
22" BenQ
Screen Resolution
1080p
Hard Drives
4TB - caviar black
PSU
770W XT ZM
Case
armor+mx
Cooling
thermalright ultra black
Keyboard
G15
Mouse
G9x
Internet Speed
http://www.speedtest.net/result/911749129.png
good news! i no longer get BSOD's now that ive uninstalled norton
my USB works as it should, i also get no more controller error logs in my event log.

however the only problem i have now are the incoherent event logs when i "safely remove" a USB device.
i have attached a copy of the event log errors i receive once i remove my USB device.
 

Attachments

My Computer

OS
WIN 7 HP 64bit
CPU
i7 920
Motherboard
EX58-EXtreme
Memory
6GB Corsair Dominator
Graphics Card(s)
GTX480
Monitor(s) Displays
22" BenQ
Screen Resolution
1080p
Hard Drives
4TB - caviar black
PSU
770W XT ZM
Case
armor+mx
Cooling
thermalright ultra black
Keyboard
G15
Mouse
G9x
Internet Speed
http://www.speedtest.net/result/911749129.png
any ideas what that eventlog could be referencing?
 

My Computer

OS
WIN 7 HP 64bit
CPU
i7 920
Motherboard
EX58-EXtreme
Memory
6GB Corsair Dominator
Graphics Card(s)
GTX480
Monitor(s) Displays
22" BenQ
Screen Resolution
1080p
Hard Drives
4TB - caviar black
PSU
770W XT ZM
Case
armor+mx
Cooling
thermalright ultra black
Keyboard
G15
Mouse
G9x
Internet Speed
http://www.speedtest.net/result/911749129.png
Sorry no idea at this stage.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Sorry no idea at this stage.

only thing i know is that its related to WMI.
i take it that this error is by design since it only happens when removing a USB device
 

My Computer

OS
WIN 7 HP 64bit
CPU
i7 920
Motherboard
EX58-EXtreme
Memory
6GB Corsair Dominator
Graphics Card(s)
GTX480
Monitor(s) Displays
22" BenQ
Screen Resolution
1080p
Hard Drives
4TB - caviar black
PSU
770W XT ZM
Case
armor+mx
Cooling
thermalright ultra black
Keyboard
G15
Mouse
G9x
Internet Speed
http://www.speedtest.net/result/911749129.png
WMI is just the servicing agent. It's doing what its told.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
WMI is just the servicing agent. It's doing what its told.

so the errors i receive by WMI are by design?
if so i shouldnt need to worry.
 

My Computer

OS
WIN 7 HP 64bit
CPU
i7 920
Motherboard
EX58-EXtreme
Memory
6GB Corsair Dominator
Graphics Card(s)
GTX480
Monitor(s) Displays
22" BenQ
Screen Resolution
1080p
Hard Drives
4TB - caviar black
PSU
770W XT ZM
Case
armor+mx
Cooling
thermalright ultra black
Keyboard
G15
Mouse
G9x
Internet Speed
http://www.speedtest.net/result/911749129.png
Yes, of course, error handling is by design. Otherwise, you'd get a blue screen. An error is an error. Whether it's serious depends on what the software was trying to do. I've already suggested that it might be iTunes. I have one of my own I'm trying to track down and it bugs me. While not serious or affecting the system, it's still an error and shouldn't be there. (Mine)

I would suggest you do a Clean Start and see if your errors continue. If they disappear, add back ONE of the startups at a time until you locate the offender.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Built 2/11/2011
OS
Windows 7 Pro-x64
CPU
i7-2600 3.4GHz - 3.8GHz Turbo
Motherboard
Intel DH67BL-B3
Memory
8Gb - 2x4GB, Muskin 991770 PC3-1333
Graphics Card(s)
Integrated Intel HD 2000
Sound Card
Integrated Intel 10.1 HD, RealTek ALC892
Monitor(s) Displays
Asus LCD VH222H, Haier HL24XSL2a
Screen Resolution
1920x1080, 1920x1080
Hard Drives
Crucial SSD C300-128Gb,
Western Digital WD5002AALX - 500Gb,
Western Digital WD7501AALS - 750Gb
PSU
Seasonic 650W 80+ Gold Modular
Case
Rosewill Defender
Cooling
Stock CPU, Four 120mm case fans, PCH fan added
Keyboard
Logitech EX100 Y-RBH94 Wireless
Mouse
Logitech EX100 M-RCE95 Wireless
Internet Speed
3.0/1.5 Mbs
Antivirus
Microsoft Security Essentials
Browser
Microsoft Internet Explorer 11
Other Info
Antec Veris Premier-Multimedia IR Station,
Cyber Accoustics-3602 Speakers,
AFT XM-5U Card Reader,
Hauppauge TV-HVR-2250,
Sony LX300 USB Turntable
Yes, of course, error handling is by design. Otherwise, you'd get a blue screen. An error is an error. Whether it's serious depends on what the software was trying to do. I've already suggested that it might be iTunes. I have one of my own I'm trying to track down and it bugs me. While not serious or affecting the system, it's still an error and shouldn't be there. (Mine)

I would suggest you do a Clean Start and see if your errors continue. If they disappear, add back ONE of the startups at a time until you locate the offender.

thanks
ill mark this as solved as the BSOD are no longer happening.
 

My Computer

OS
WIN 7 HP 64bit
CPU
i7 920
Motherboard
EX58-EXtreme
Memory
6GB Corsair Dominator
Graphics Card(s)
GTX480
Monitor(s) Displays
22" BenQ
Screen Resolution
1080p
Hard Drives
4TB - caviar black
PSU
770W XT ZM
Case
armor+mx
Cooling
thermalright ultra black
Keyboard
G15
Mouse
G9x
Internet Speed
http://www.speedtest.net/result/911749129.png
Back
Top