Windows 10: Need Thoughts on These Event 4688 and WMI Event 5861 Instances

Discus and support Need Thoughts on These Event 4688 and WMI Event 5861 Instances in Windows 10 Software and Apps to solve the problem; so my PC has a little bit of a kink to it where sometimes, during boot, the VGA light on the motherboard will hang and fast startup will fail;... Discussion in 'Windows 10 Software and Apps' started by JamesBacon620, Oct 24, 2023.

  1. Need Thoughts on These Event 4688 and WMI Event 5861 Instances


    so my PC has a little bit of a kink to it where sometimes, during boot, the VGA light on the motherboard will hang and fast startup will fail; eventually, the monitor and Windows will come up as normal and everything will function perfectly fine. it's done this since I got the computer, not really an issue, not trying to fix it eitherwhen this happens, various Event 4688 Process Creations will log in Event Viewer > Security; typically, if I restart the computer, the same 4688 events will be logged again. if I restart one more time, nothing happens and I'll just continue about my day since t

    :)
     
    JamesBacon620, Oct 24, 2023
    #1
  2. Sonya L Win User

    WMI activity Event ID 5861

    Opened the WMI-Activity%4Operational log and found thousands of this one event. I do not have the event on the laptop just the desktop. Operating system Windows 10 PRO. WMI runs all of the with at least 2 instances open then there's server one that runs
    and that reverse thing that also runs. Below I have pasted both general and details hopefully someone can tell me what this is?

    Namespace = //./root/subscription; Eventfilter = SCM Event Log Filter (refer to its activate eventid:5859); Consumer = NTEventLogEventConsumer="SCM Event Log Consumer"; PossibleCause = Binding EventFilter:

    instance of __EventFilter

    {

    CreatorSID = {1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0};

    EventNamespace = "root\\cimv2";

    Name = "SCM Event Log Filter";

    Query = "select * from MSFT_SCMEventLogEvent";

    QueryLanguage = "WQL";

    };

    Perm. Consumer:

    instance of NTEventLogEventConsumer

    {

    Category = 0;

    CreatorSID = {1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0};

    EventType = 1;

    Name = "SCM Event Log Consumer";

    NameOfUserSIDProperty = "sid";

    SourceName = "Service Control Manager";

    };

    System

    - Provider

    [ Name] Microsoft-Windows-WMI-Activity

    [ Guid] {1418EF04-B0B4-4623-BF7E-D74AB47BBDAA}



    EventID 5861



    Version 0



    Level 0



    Task 0



    Opcode 0



    Keywords 0x4000000000000000



    - TimeCreated

    [ SystemTime] 2017-09-23T07:20:08.309942800Z



    EventRecordID 7613



    Correlation



    - Execution

    [ ProcessID] 4520

    [ ThreadID] 720



    Channel Microsoft-Windows-WMI-Activity/Operational



    Computer DESKTOP-L2LHDAJ



    - Security

    [ UserID] S-1-5-18



    - UserData

    - Operation_ESStoConsumerBinding

    Namespace //./root/subscription



    ESS SCM Event Log Filter



    CONSUMER NTEventLogEventConsumer="SCM Event Log Consumer"



    PossibleCause Binding EventFilter: instance of __EventFilter { CreatorSID = {1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0}; EventNamespace = "root\\cimv2"; Name = "SCM Event Log Filter"; Query = "select * from MSFT_SCMEventLogEvent"; QueryLanguage =
    "WQL"; }; Perm. Consumer: instance of NTEventLogEventConsumer { Category = 0; CreatorSID = {1, 2, 0, 0, 0, 0, 0, 5, 32, 0, 0, 0, 32, 2, 0, 0}; EventType = 1; Name = "SCM Event Log Consumer"; NameOfUserSIDProperty = "sid"; SourceName = "Service Control Manager";
    };
     
    Sonya L, Oct 24, 2023
    #2
  3. Igor Leyko, Oct 24, 2023
    #3
  4. Sonya L Win User

    Need Thoughts on These Event 4688 and WMI Event 5861 Instances

    WMI activity Event ID 5861

    Okay well thank you, posted there but nothing yet. In the meantime I have just wiped the HD and reinstalled Windows 10 Pro with nothing but security software to see if I still get these events. If so, is there anyway that I can actually disable WMI? I have
    tried several times in the past but it never works.

    Well I have confirmed this is still happening after format and reinstall. Only things I have installed are MBAM, Spybot, and Superantispyware. 259 events so far. Previous install had 10x as many in just 4 days.
     
    Sonya L, Oct 24, 2023
    #4
Thema:

Need Thoughts on These Event 4688 and WMI Event 5861 Instances

Loading...
  1. Need Thoughts on These Event 4688 and WMI Event 5861 Instances - Similar Threads - Need Thoughts Event

  2. WMI Warning Event 63

    in Windows 10 Gaming
    WMI Warning Event 63: Hello,PC Freezes and have to hard reboot.Getting error in eventvwr: A provider, IntelMEProv, has been registered in the Windows Management Instrumentation namespace root\Intel_ME to use the LocalSystem account. This account is privileged and the provider may cause a security...
  3. WMI Warning Event 63

    in Windows 10 Software and Apps
    WMI Warning Event 63: Hello,PC Freezes and have to hard reboot.Getting error in eventvwr: A provider, IntelMEProv, has been registered in the Windows Management Instrumentation namespace root\Intel_ME to use the LocalSystem account. This account is privileged and the provider may cause a security...
  4. WMI Event ID 63 Warning in Event Viewer

    in Windows 10 Gaming
    WMI Event ID 63 Warning in Event Viewer: Hello i getting the warning right before my pc freeze it mostly freeze in the game Satisfactory but saw it freeze in FiveM too Specs:4070 I7-14700KF the rma one after bios update64gb ddr4 ram 3200mobo Z690 Pro A Wifi DDR4 Msiand i running the game from Samsung 980 pro nvme...
  5. WMI Event ID 63 Warning in Event Viewer

    in Windows 10 Software and Apps
    WMI Event ID 63 Warning in Event Viewer: Hello i getting the warning right before my pc freeze it mostly freeze in the game Satisfactory but saw it freeze in FiveM too Specs:4070 I7-14700KF the rma one after bios update64gb ddr4 ram 3200mobo Z690 Pro A Wifi DDR4 Msiand i running the game from Samsung 980 pro nvme...
  6. Need Thoughts on These Event 4688 and WMI Event 5861 Instances

    in Windows 10 Gaming
    Need Thoughts on These Event 4688 and WMI Event 5861 Instances: so my PC has a little bit of a kink to it where sometimes, during boot, the VGA light on the motherboard will hang and fast startup will fail; eventually, the monitor and Windows will come up as normal and everything will function perfectly fine. it's done this since I got...
  7. Need Thoughts on These Event 4688 and WMI Event 5861 Instances

    in AntiVirus, Firewalls and System Security
    Need Thoughts on These Event 4688 and WMI Event 5861 Instances: so my PC has a little bit of a kink to it where sometimes, during boot, the VGA light on the motherboard will hang and fast startup will fail; eventually, the monitor and Windows will come up as normal and everything will function perfectly fine. it's done this since I got...
  8. Event 1108 due to Event 4688

    in Windows 10 Gaming
    Event 1108 due to Event 4688: The event logging service encountered an error while processing an incoming event published from Microsoft-Windows-Security-Auditing.None of my process creation event is being logged. All these logs are thrown as event 1108 with error code 15003 and 15005. Don't know what to...
  9. Event 1108 due to Event 4688

    in Windows 10 Software and Apps
    Event 1108 due to Event 4688: The event logging service encountered an error while processing an incoming event published from Microsoft-Windows-Security-Auditing.None of my process creation event is being logged. All these logs are thrown as event 1108 with error code 15003 and 15005. Don't know what to...
  10. Event viewer - Event id 4688

    in Windows 10 Customization
    Event viewer - Event id 4688: I tried to create a custom view, with àwindows as the event log, and 4688 as the event ID. I had no other changed settings, and I expected this to give me a stream of events showing whenever I opened an application. Instead I only got events related to Microsoft processes....