Event ID 10016, Source DistributedCOM

invisiblebond

Journeyman
I had to perform a hard reboot and check the Computer Management console under Windows Logs - System.

Three warning-level entries:

'The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID* and APPID* to the user NT AUTHORITY\LOCAL SERVICE (SID S-1-5-19) from address LocalHost (using LRPC) running in the application container Unavailable (SID Unavailable). This security permission can be modified using the Component Services administrative tool.

*
XML:
- <Event xmlns="*schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  <EventID Qualifiers="0">10016</EventID>
  <Version>0</Version>
  <Level>3</Level>
  <Task>0</Task>
  <Opcode>0</Opcode>
  <Keywords>0x8080000000000000</Keywords>
  <TimeCreated SystemTime="2024-08-11T06:10:52.5785338Z" />
  <EventRecordID>73517</EventRecordID>
  <Correlation ActivityID="{e8a1cfb8-aa46-40a5-acc6-b542edc906e5}" />
  <Execution ProcessID="560" ThreadID="996" />
  <Channel>System</Channel>
  <Computer>DESKTOP-AHIS6G5</Computer>
  <Security UserID="S-1-5-19" />
  </System>
- <EventData>
  <Data Name="param1">application-specific</Data>
  <Data Name="param2">Local</Data>
  <Data Name="param3">Activation</Data>
  <Data Name="param4">{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}</Data>
  <Data Name="param5">{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}</Data>
  <Data Name="param6">NT AUTHORITY</Data>
  <Data Name="param7">LOCAL SERVICE</Data>
  <Data Name="param8">S-1-5-19</Data>
  <Data Name="param9">LocalHost (Using LRPC)</Data>
  <Data Name="param10">Unavailable</Data>
  <Data Name="param11">Unavailable</Data>
  </EventData>
  </Event>

*
XML:
- <Event xmlns="*schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  <EventID Qualifiers="0">10016</EventID>
  <Version>0</Version>
  <Level>3</Level>
  <Task>0</Task>
  <Opcode>0</Opcode>
  <Keywords>0x8080000000000000</Keywords>
  <TimeCreated SystemTime="2024-08-11T06:10:52.6097808Z" />
  <EventRecordID>73518</EventRecordID>
  <Correlation ActivityID="{b7a614ea-8ad5-477e-80b6-56c680f0da90}" />
  <Execution ProcessID="560" ThreadID="7500" />
  <Channel>System</Channel>
  <Computer>DESKTOP-AHIS6G5</Computer>
  <Security UserID="S-1-5-19" />
  </System>
- <EventData>
  <Data Name="param1">application-specific</Data>
  <Data Name="param2">Local</Data>
  <Data Name="param3">Activation</Data>
  <Data Name="param4">{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}</Data>
  <Data Name="param5">{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}</Data>
  <Data Name="param6">NT AUTHORITY</Data>
  <Data Name="param7">LOCAL SERVICE</Data>
  <Data Name="param8">S-1-5-19</Data>
  <Data Name="param9">LocalHost (Using LRPC)</Data>
  <Data Name="param10">Unavailable</Data>
  <Data Name="param11">Unavailable</Data>
  </EventData>
  </Event>

*
XML:
- <Event xmlns="*schemas.microsoft.com/win/2004/08/events/event">
- <System>
  <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
  <EventID Qualifiers="0">10016</EventID>
  <Version>0</Version>
  <Level>3</Level>
  <Task>0</Task>
  <Opcode>0</Opcode>
  <Keywords>0x8080000000000000</Keywords>
  <TimeCreated SystemTime="2024-08-11T06:22:54.9053296Z" />
  <EventRecordID>73519</EventRecordID>
  <Correlation ActivityID="{1823c43f-a368-4afd-82d7-a7514192ea96}" />
  <Execution ProcessID="560" ThreadID="10368" />
  <Channel>System</Channel>
  <Computer>DESKTOP-AHIS6G5</Computer>
  <Security UserID="S-1-5-21-3053808206-3889450725-3740017451-1001" />
  </System>
- <EventData>
  <Data Name="param1">application-specific</Data>
  <Data Name="param2">Local</Data>
  <Data Name="param3">Activation</Data>
  <Data Name="param4">{2593F8B9-4EAF-457C-B68A-50F6B8EA6B54}</Data>
  <Data Name="param5">{15C20B67-12E7-4BB6-92BB-7AFF07997402}</Data>
  <Data Name="param6">DESKTOP-AHIS6G5</Data>
  <Data Name="param7">lenovo</Data>
  <Data Name="param8">S-1-5-21-3053808206-3889450725-3740017451-1001</Data>
  <Data Name="param9">LocalHost (Using LRPC)</Data>
  <Data Name="param10">Unavailable</Data>
  <Data Name="param11">Unavailable</Data>
  </EventData>
  </Event>
 
Top Bottom