Edit C:\Windows\SysWOW64\evntagnt.dll
MZ? ÿÿ ¸ @ è º ´ Í!¸LÍ!This program cannot be run in DOS mode. $ w£?3ÂêG3ÂêG3ÂêGî='G2ÂêGî=$G>ÂêG3ÂëGmÂêGî=!G:ÂêGî=%G5ÂêGî= G2ÂêGî=9G7ÂêGî=#G2ÂêGî=&G2ÂêGRich3ÂêG PE L p?R à ! h ?! 0 ° /¿ @ - § ?a d p ? ? ? H£ \ ` ? .text § `.data ü) 0 " @ À.idata ` $ @ @.rsrc ? p 0 @ @.reloc ª ? N @ B G+ ? p?R % ¤£ ¤? ´?'à?0à0£'ParameterMessageFile ResetGlobals: Entering extension agent ResetGlobals routine . StrToOid: Entering routine to convert string to OID StrToOid: String to convert is %s StrToOid: No strings found. Exiting with FALSE StrToOid: BaseOID will not be appended to this OID StrToOid: BaseOID %s will be appended to this OID StrToOid: strtoul overflow or underflow. Exiting with FALSE StrToOid: String contains a non-numeric value. Exiting with FALSE StrToOid: %lu tokens found StrToOid: Allocating storage for OID StrToOid: Unable to allocate integer array for OID structure. Exiting with FALSE StrToOid: OID integer array storage allocated at %08X StrToOid: OID[%lu] is %lu StrToOid: Exiting routine with TRUE StrToOid: Unable to do strcat. Exiting with FALSE CloseStopAll: Closing handle to service shutdown event %08X CloseStopAll: Error closing handle for service shutdown event %08X; code %lu CloseEventNotify: Closing handle to event notify event %08X CloseEventNotify: Error closing handle for StopLog event %08X; code %lu CloseRegNotify: Closing handle to registry key changed notify event %08X CloseRegNotify: Error closing handle for registry key changed event %08X; code %lu CloseRegParmKey: Closing Parameter key in registry CloseRegParmKey: Error closing handle for Parameters registry key %08X; code %lu CloseLogs: Closing event logs CloseLogs: Closing event log %s, handle %lu at %08X CloseLogs: Freeing PrimaryModule for event log %s, handle %lu at %08X CloseLogs: Freeing memory for event log handles at address %08X CloseLogs: Freeing memory for PrimaryModule handles at address %08X CloseLogs: Freeing memory for event log names at address %08X Position_to_Log_End: Entering position to end of log routine Position_to_Log_End: Handle is %08X Position_to_Log_End: Handle for end of log is invalid - %08X Position_to_Log_End: Log position to end failed Position_to_Log_End: Allocating log buffer Position_to_Log_End: Position to end of log for handle %08X failed Position_to_Log_End: Buffer memory allocation failed Position_to_Log_End: Log buffer memory allocated at %08X Position_to_Log_End: Positioning to last record Position_to_Log_End: Getting oldest event log record Position_to_Log_End: Freeing log event record buffer %08X Position_to_Log_End: GetOldestEventLogRecord for log handle %08X failed with code %lu Position_to_Log_End: Oldest event log record is %lu Position_to_Log_End: Getting number of event log records Position_to_Log_End: Freeing log event record buffer Position_to_Log_End: GetNumberOfEventLogRecords for log handle %08X failed with code %lu Position_to_Log_End: Number of event log records is %lu Position_to_Log_End: Positioning to record #%lu Position_to_Log_End: Handle %08X positioned at EOF Position_to_Log_End: Returning from position to end of log function Position_to_Log_End: SEEK to record in event log %08X failed with code %lu Position_to_Log_End: BytesRead is %lu Position_to_Log_End: MinNumberofBytesNeeded is %lu Position_to_Log_End: Reading any residual records Position_to_Log_End: Number of bytes read for residual read is %lu Position_to_Log_End: Checking for EOF return Position_to_Log_End: Freeing event log buffer memory %08X Position_to_Log_End: Handle %08X positioned at EOF; record #%lu Position_to_Log_End: Read for handle %08X failed with code %lu Position_to_Log_End: Log not positioned to end Read_Registry_Parameters: Entering routine Read_Registry_Parameters: Routined entered due to threshold performance parameters reached and modified. Read_Registry_Parameters: Notification of registry key changes was successful. Read_Registry_Parameters: Notification of registry key changes failed with code of %lu Read_Registry_Parameters: Initialization continues, but registry changes will require a restart of SNMP Read_Registry_Parameters: Exiting Read_Registry_Parameters routine with TRUE. SOFTWARE\Microsoft\SNMP_EVENTS\EventLog\Parameters Read_Registry_Parameters: Opening %s Read_Registry_Parameters: Error in RegOpenKeyEx for Parameters = %lu Read_Registry_Parameters: Creating event for registry change notification Read_Registry_Parameters: Error creating registry change notification event; code %lu Read_Registry_Parameters: No registry notification will be performed. Continuing with initialization. Read_Registry_Parameters: Registry key changed event handle is %08X Read_Registry_Parameters: Error reading registry value is %lu for index %lu (Parameters) Read_Registry_Parameters: Parameter read is %s, length is %Iu Read_Registry_Parameters: Parameter type is REG_SZ BaseEnterpriseOID Read_Registry_Parameters: BaseEnterpriseOID parameter matched TraceFileName Read_Registry_Parameters: TraceFileName parameter matched SupportedView Read_Registry_Parameters: SupportedView parameter matched Read_Registry_Parameters: Unknown Registry value name: %s Read_Registry_Parameters: Unknown Registry value contents %s Read_Registry_Parameters: Parameter type is REG_DWORD TraceLevel Read_Registry_Parameters: TraceLevel parameter matched TrimMessage Read_Registry_Parameters: Global TrimMessage parameter matched MaxTrapSize Read_Registry_Parameters: Maximum Trap Size parameter matched TrimFlag Read_Registry_Parameters: Global trap trimming flag TrimFlag parameter matched ThresholdEnabled Read_Registry_Parameters: Global threshold checking flag ThresholdEnabled parameter matched Threshold Read_Registry_Parameters: Global preformance threshold flag Threshold parameter matched ThresholdCount Read_Registry_Parameters: Global preformance threshold count ThresholdCount parameter matched ThresholdTime Read_Registry_Parameters: Global preformance threshold time ThresholdTime parameter matched LastBootTime Read_Registry_Parameters: Initialization last boot time parameter matched EventLogPollTime Read_Registry_Parameters: Global Event Log poll time EventLogPollTime parameter matched Read_Registry_Parameters: EventLogPollTime parameter found in registry of %lu. Read_Registry_Parameters: reset EventLogPollTime parameter to %lu. VarBindPrefixSubId Read_Registry_Parameters: Global VarBindPrefixSubId parameter matched Read_Registry_Parameters: VarBindPrefixSubId parameter found in registry of %lu. Read_Registry_Parameters: reset VarBindPrefixSubId parameter to %lu. Read_Registry_Parameters: Unknown Registry value contents: %lu Read_Registry_Parameters: Unknown Registry value contents not displayed Read_Registry_Parameters: Checking BaseEnterpriseOID read from registry Read_Registry_Parameters: BaseEnterpriseOID parameter not found in registry Read_Registry_Parameters: Checking SupportedView read from registry Read_Registry_Parameters: SupportedView parameter not found in registry Read_Registry_Parameters: Checking TraceFileName read from registry Read_Registry_Parameters: TraceFileName parameter not found in registry, defaulting to %s. Read_Registry_Parameters: TraceFileName parameter found in registry of %s. Read_Registry_Parameters: Checking TraceLevel read from registry Read_Registry_Parameters: TraceLevel parameter not found in registry, defaulting to %lu. Read_Registry_Parameters: TraceLevel parameter found in registry of %lu. Read_Registry_Parameters: Checking MaxTrapSize read from registry Read_Registry_Parameters: MaxTrapSize parameter not found in registry, defaulting to %lu. Read_Registry_Parameters: MaxTrapSize parameter found in registry of %lu. Read_Registry_Parameters: Checking TrimFlag read from registry Read_Registry_Parameters: TrimFlag parameter not found in registry, defaulting to %lu. Read_Registry_Parameters: TrimFlag parameter found in registry of %lu. Read_Registry_Parameters: TrimMessage parameter not found in registry, defaulting to %lu. Read_Registry_Parameters: TrimMessage parameter found in registry of %lu. Read_Registry_Parameters: Checking ThresholdEnabled parameter read from registry Read_Registry_Parameters: ThresholdEnabled parameter not found in registry, defaulting to 1. Read_Registry_Parameters: ThresholdEnabled parameter found in registry of %lu. Read_Registry_Parameters: Checking Threshold parameter read from registry Read_Registry_Parameters: Threshold parameter not found in registry, defaulting to 0. Read_Registry_Parameters: Threshold parameter found in registry of %lu. Read_Registry_Parameters: Checking ThresholdCount parameter read from registry Read_Registry_Parameters: ThresholdCount parameter not found in registry, defaulting to %lu. Read_Registry_Parameters: ThresholdCount parameter found in registry of %lu. Read_Registry_Parameters: ThresholdCount is an invalid value -- a minimum of 2 is used. Read_Registry_Parameters: Checking ThresholdTime parameter read from registry Read_Registry_Parameters: ThresholdTime parameter not found in registry, defaulting to %lu. Read_Registry_Parameters: ThresholdTime parameter found in registry of %lu. Read_Registry_Parameters: ThresholdTime is an invalid value -- a minimum of 1 is used. Read_Registry_Parameters: Threshold values have been reset. Trap processing resumed. Read_Registry_Parameters: Threshold values have been set. Trap processing will not be done. Read_Registry_Parameters: BaseEnterpriseOID is %s Read_Registry_Parameters: SupportedView is %s Read_Registry_Parameters: Global TrimFlag value is %lu (trim yes/no) Read_Registry_Parameters: Global TrimMessage value is %lu (trim msg/ins str first) Read_Registry_Parameters: Reread of registry parameters is complete Read_Registry_Parameters: Exiting Read_Registry_Parameters with TRUE SYSTEM\CurrentControlSet\Services\EventLog\ Read_Registry_Parameters: Error in RegOpenKeyEx for EventLog = %lu Read_Registry_Parameters: Error reading registry value is %lu for index %lu (EventLogFiles) Read_Registry_Parameters: Error in EventLogOpen = %lu Read_Registry_Parameters: Log file name: %s Read_Registry_Parameters: Unable to position to end of log. DLL terminated. Read_Registry_Parameters: uNumEventLogs (%lu) greater than USHRT_MAX. Read_Registry_Parameters: Unable to reallocate log event array Read_Registry_Parameters: Event log array reallocated at %08X Read_Registry_Parameters: iLogNameSize (%lu) greater than allowed MAX_LOGSIZE Read_Registry_Parameters: Integer overflow. Read_Registry_Parameters: Unable to reallocate log name array Read_Registry_Parameters: Event log name array reallocated at %p Read_Registry_Parameters: Unable to reallocate PrimaryModule handle array Read_Registry_Parameters: PrimaryModule handle array reallocated at %08X Read_Registry_Parameters: Opening registry for PrimaryModule for %s Read_Registry_Parameters: Unable to open EventLog service registry key %s; RegOpenKeyEx returned %lu Read_Registry_Parameters: Exiting Read_Registry_Parameters with FALSE PrimaryModule Read_Registry_Parameters: No PrimaryModule registry key for %s; RegQueryValueEx returned %lu Read_Registry_Parameters: LoadPrimaryModuleParams failed with errCode = %lu Read_Registry_Parameters: Log file name is %s Read_Registry_Parameters: Log handle #%lu is %08X Read_Registry_Parameters: PrimaryModule handle #%lu is %08X Read_Registry_Parameters: Number of handles acquired is %lu Read_Registry_Parameters: Handle # %lu %08X %s Read_Registry_Parameters: Registry contains no log file entries to process Read_Registry_Parameters: Unable to do strcat to %s. CloseSourceHandles: Error freeing message dll is %lu. SNMPEventLogDllMain: Entering SNMPEventLogDllMain routine..... SNMPEventLogDllMain: Reason code indicates process attach SNMPEventLogDllMain: Reason code indicates process detach SNMPEventLogDllMain: Reason code indicates thread attach SNMPEventLogDllMain: Reason code indicates thread detach SNMPEventLogDllMain: Unknown reason code indicated in SNMPEventLogDllMain SNMPEventLogDllMain: Exiting SNMPEventLogDllMain routine with TRUE SnmpExtensionInit: Entering extension agent SnmpExtensionInit routine SnmpExtensionInit: SNMP Event Log Extension Agent DLL is starting EvntAgnt SnmpExtensionInit: Unable to log application events; code is %lu SnmpExtensionInit: SNMP Event Log Extension Agent DLL initialization abnormal termination SnmpExtensionInit: Exiting SnmpExtensionInit routine with FALSE SnmpExtensionInit: Creating event for extension DLL shutdown SnmpExtensionInit: Error creating stop extension DLL event; code %lu SnmpExtensionInit: SNMPELEA DLL abnormal initialization SnmpExtensionInit: Extension DLL shutdown event handle is %08X SnmpExtensionInit: Error during registry initialization processing SnmpExtensionInit: SNMP Event Log Extension Agent DLL abnormal initialization SnmpExtensionInit: Exiting extension agent SnmpExtensionInit routine with FALSE SnmpExtensionInit: Creating event for manager agent trap event notification SnmpExtensionInit: Error creating EventNotify event; code %lu SnmpExtensionInit: Manager agent trap event notification handle is %08X SnmpExtensionInit: Creating thread for event log processing routine SnmpExtensionInit: Error creating event log processing thread; code %lu SnmpExtensionInit: Handle to event log processing routine thread is %08X SnmpExtensionInit: Unable to convert supported view string to OID SnmpExtensionInit: Exiting extension agent SnmpExtensionInit routine with TRUE SnmpExtensionClose: Entering extension agent SnmpExtensionClose routine. SnmpExtensionClose: Error setting dll termination event %08X in process detach; code %lu SnmpExtensionClose: Shutdown event %08X is now complete SnmpExtensionClose: Waiting for event log processing thread %08X to terminate SnmpExtensionClose: Checking for thread exit code value SnmpExtensionClose: Thread exit code value is %lu SnmpExtensionClose: GetExitCodeThread returned FALSE, reason code %lu SnmpExtensionClose: Thread exit code indicates still active. Will wait... SnmpExtensionClose: About to wait... SnmpExtensionClose: Finished wait... SnmpExtensionClose: Error on WaitForSingleObject/log processing thread %08X; code %lu SnmpExtensionClose: Event log processing thread %08X has terminated! SnmpExtensionClose: Event log processing thread %08X has not terminated within 30 seconds; terminating thread SnmpExtensionClose: Unknown result from WaitForSingleObject waiting on log processing thread %08X termination is %lu SnmpExtensionClose: Checking for thread exit code again SnmpExtensionClose: Closing handle to log processing thread %08X SnmpExtensionClose: Error closing handle for log processing thread %08X; code %lu SnmpExtensionClose: SNMPELEA Event Log Extension Agent DLL has terminated BuildThresholdTrap: Building static variable bindings for threshold trap BuildThresholdTrap: &thresholdVarBind is at %08X BuildThresholdTrap: thresholdVarBind is %08X BuildThresholdTrap: BaseEnterpriseOID value read is %s BuildThresholdTrap: Unable to convert OID from BaseEnterpriseOID .1.0 BuildThresholdTrap: Unable to allocate storage for varbind BuildThresholdTrap: Storage allocated for varbind entry at address at %08X BuildThresholdTrap: Number of varbinds present set to %lu BuildThresholdTrap: Unable to allocate tempthreshmsg BuildThresholdTrap: Varbind entry length is %lu BuildThresholdTrap: Varbind entry string is %s BuildThresholdTrap: Varbind OID length is %lu BuildThresholdTrap: Varbind OID[%lu] is %lu BuildThresholdTrap: &thresholdOID is at %08X BuildThresholdTrap: thresholdOID is %08X BuildThresholdTrap: Variable bindings for threshold trap have been built BuildThresholdTrap: Unable to append .1.0 to %s SnmpExtensionTrap: Entering SnmpExtensionTrap routine SnmpExtensionTrap: Varbind list upon entry is %08X SnmpExtensionTrap: Varbind queue upon entry is %08X SnmpExtensionTrap: Handle to Mutex object is %08X SnmpExtensionTrap: Waiting for Mutex object to become available SnmpExtensionTrap: WaitForMulitpleObjects returned a value of %lu SnmpExtensionTrap: Error waiting for mutex event array is %lu SnmpExtensionTrap: Exiting SnmpExtensionTrap routine with FALSE SnmpExtensionTrap: Mutex object not available yet. Wait will continue. SnmpExtensionTrap: Mutex object has been abandoned. SnmpExtensionTrap: DLL shutdown detected. Wait abandoned. SnmpExtensionTrap: Mutex object acquired. SnmpExtensionTrap: Undefined error encountered in WaitForMultipleObjects. Wait abandoned. SnmpExtensionTrap: Varbind queue pointer indicates no more data to process SnmpExtensionTrap: Releasing mutex object %08X SnmpExtensionTrap: Unable to release mutex object for reason code %lu SnmpExtensionTrap: Current queue pointer indicates processed trap SnmpExtensionTrap: Freeing processed trap storage SnmpExtensionTrap: Freeing enterprise OID %08X SnmpExtensionTrap: Saving forward buffer pointer %08X SnmpExtensionTrap: Freeing varbind list pointer %08X SnmpExtensionTrap: Freeing varbind queue entry storage %08X SnmpExtensionTrap: Setting current buffer pointer to %08X SnmpExtensionTrap: Reentering process loop for next buffer entry SnmpExtensionTrap: Sending trap to indicate performance threshold has been reached. SnmpExtensionTrap: Delete all varbind entries SnmpExtensionTrap: Deleted all entries, releasing mutex object %08X SnmpExtensionTrap: *enterprise is %08X SnmpExtensionTrap: &thresholdOID is %08X SnmpExtensionTrap: *timeStamp is %08X SnmpExtensionTrap: *variableBindings is %08X SnmpExtensionTrap: &thresholdVarBind is %08X SnmpExtensionTrap: *specificTrap is %08X SnmpExtensionTrap: SNMPELEA_THRESHOLD_REACHED is %08X SnmpExtensionTrap: Number of entries in enterprise OID is %lu SnmpExtensionTrap: Enterprise OID[%lu] is %lu SnmpExtensionTrap: Variable binding %lu is %s, length %lu SnmpExtensionTrap: OID for this binding is (number of %lu): SnmpExtensionTrap: %lu. SnmpExtensionTrap: Exiting SnmpExtensionTrap routine with TRUE SnmpExtensionTrap: *(lpVarBindQueue->enterprise) is %08X SnmpExtensionTrap: *(lpVarBindQueue->VariableBindings) is %08X SnmpExtensionTrap: Threshold time has been exceeded. Resetting threshold values. SnmpExtensionTrap: Threshold count has been reached within defined performance parameters. SnmpExtensionTrap: Further traps will not be sent without operator intervention. SnmpExtensionTrap: Unable to set registry key for threshold reached; RegSetValueEx returned %lu SnmpExtensionTrap: Threshold reached flag has been set in the registry SnmpExtensionTrap: Threshold count is %lu; time elapsed is %08X SnmpExtensionQuery: Entering SnmpExtensionQuery routine SnmpExtensionQuery: Exiting SnmpExtensionQuery routine SeSecurityPrivilege EnablePrivilege: AdjustTokenPrivileges GetLastError %lu SNMP EventLog Extension Agent is quiescing trap processing due to performance threshold parameters. bad allocation TidyCountTimeTable: Entering TidyCountTimeTable routine TidyCountTimeTable: Empty table, exiting TidyCountTimeTable TidyCountTimeTable: Checking entry %08X TidyCountTimeTable: Entry not found TidyCountTimeTable: Freeing first entry in lpCountTable at %08X TidyCountTimeTable: Freeing entry in lpCountTable at %08X TidyCountTimeTable: Exiting TidyCountTimeTable CheckCountTime: Entering CheckCountTime routine CheckCountTime: Count/Time table is currently empty. Adding entry. CheckCountTime: Unable to acquire storage for Count/Time table entry. CheckCountTime: New table entry is %08X CheckCountTime: Checking entry %08X CheckCountTime: Entry information located in table at %08X CheckCountTime: Entry count value is %lu CheckCountTime: Entry last time value is %08X CheckCountTime: Entry current time value is %08X CheckCountTime: Time difference is %lu CheckCountTime: Registry count is %lu, time is %lu CheckCountTime: Time value is being checked CheckCountTime: Specified time parameters exceeded for entry. Resetting table information. CheckCountTime: Exiting CheckCountTime with FALSE CheckCountTime: Count field has been satisfied for entry CheckCountTime: Exiting CheckCountTime with TRUE CheckCountTime: Count field not satisfied for entry CheckCountTime: New table entry added at %08X GetRegistryValue: Entering GetRegistryValue function GetRegistryValue: Performance threshold flag is on. No data will be processed. GetRegistryValue: Exiting GetRegistryValue function with FALSE GetRegistryValue: Unable to allocate registry source key storage. Trap not sent. GetRegistryValue: Unable to allocate registry event key storage. Trap not sent. SOFTWARE\Microsoft\SNMP_EVENTS\EventLog\Sources\ \ GetRegistryValue: Opening registry key for %s GetRegistryValue: No registry entry exists for %s. RegOpenKeyEx returned %lu Count GetRegistryValue: Count field is %lu GetRegistryValue: Using default of global trim message flag of %lu GetRegistryValue: Local message trim field is %lu Time GetRegistryValue: Time field is %lu EnterpriseOID GetRegistryValue: EnterpriseOID field is %s Append GetRegistryValue: Append field is %lu GetRegistryValue: Appended enterprise OID is %s GetRegistryValue: Values found for Count and/or Time for this entry GetRegistryValue: Count/Time values not met for this entry GetRegistryValue: Exiting ReadRegistryValue with FALSE GetRegistryValue: Exiting ReadRegistryValue with TRUE StopAll: Signaling DLL shutdown event %08X from Event Log Processing thread. StopAll: Error signaling DLL shutdown event %08X in SNMPELPT; code %lu DoExitLogEv: SnmpEvLogProc has encountered an error. DoExitLogEv: Count/Time table has storage allocated. Freeing table. DoExitLogEv: Freeing Count/Time table entry at %08X DoExitLogEv: Exiting SnmpEvLogProc routine..... CloseEvents: Closing handle for wait event %lu - %08X CloseEvents: Error closing event handle %08X is %lu CloseEvents: Freeing memory for wait event list %08X ReopenLog: Log file %s has been cleared; reopening log ReopenLog: Error in EventLogOpen for %s = %lu ReopenLog: New handle for %s is %08X ReopenLog: Reissuing NotifyChangeEventLog for log ReopenLog: NotifyChangeEventLog failed with code %lu ReopenLog: ChangeNotify was successful DisplayLogRecord: Values from ReadEventLog follow: DisplayLogRecord: EventSize = %lu EventNeeded = %lu DisplayLogRecord: Event Log Buffer contents follow: DisplayLogRecord: Length = %lu Record Number = %lu DisplayLogRecord: Time generated = %08X Time written = %08X DisplayLogRecord: Event ID = %lu (%08X) Event Type = %04X DisplayLogRecord: Num Strings = %lu EventCategory = %04X DisplayLogRecord: String Offset = %lu Data Length = %lu DisplayLogRecord: Data Offset = %lu DisplayLogRecord: EventBuffer address is %08X DisplayLogRecord: EVENTRECSIZE is %lu DisplayLogRecord: String pointer is assigned address %08X DisplayLogRecord: SourceName[] = %s DisplayLogRecord: Computername[] = %s DisplayLogRecord: String #%lu ->%s AddBufferToQueue: Entering AddBufferToQueue function AddBufferToQueue: Performance threshold flag is on. No data will be processed. AddBufferToQueue: Exiting AddBufferToQueue function with FALSE AddBufferToQueue: Current buffer pointer is %08X AddBufferToQueue: Adding buffer address %08X to queue AddBufferToQueue: Handle to Mutex object is %08X AddBufferToQueue: Waiting for Mutex object to become available AddBufferToQueue: WaitForMulitpleObjects returned a value of %lu AddBufferToQueue: DLL shutdown detected. Wait abandoned. AddBufferToQueue: Exiting AddBufferToQueue routine with FALSE AddBufferToQueue: Error waiting for mutex event array is %lu AddBufferToQueue: Mutex object not available yet. Wait will continue. AddBufferToQueue: Mutex object has been abandoned. AddBufferToQueue: Mutex object acquired. AddBufferToQueue: Undefined error encountered in WaitForMultipleObjects. Wait abandoned. AddBufferToQueue: queue too big -- posting notification event %08X AddBufferToQueue: Unable to post event %08X; reason is %lu AddBufferToQueue: Unable to release mutex object for reason code %lu AddBufferToQueue: Current queue is empty. Adding %08X as first queue entry AddBufferToQueue: Releasing mutex object %08X AddBufferToQueue: Exiting AddBufferToQueue function with TRUE AddBufferToQueue: Queue is not empty. Scanning for end of queue. AddBufferToQueue: This buffer address is %08X, next buffer pointer is %08X AddBufferToQueue: Adding buffer address %08X as next buffer pointer in %08X AddSourceHandle: Unable to acquire storage for source/handle entry. AddSourceHandle: Unable to load message module %s; LoadLibraryEx returned %lu AddSourceHandle: Exiting AddSourceHandle with NULL. ScanParameters: Entering ScanParameters routine ScanParameters: Size of original insertion strings is %lu ScanParameters: Opening registry for parameter module for %s ScanParameters: Unable to open EventLog service registry key %s; RegOpenKeyEx returned %lu ScanParameters: Exiting ScanParameters ScanParameters: No ParameterMessageFile registry key for %s; RegQueryValueEx returned %lu ScanParameters: ParameterMessageFile value read was %s ScanParameters: Unable to expand parameter module %s; expanded size required is %lu bytes ScanParameters: ParameterMessageFile expanded to %s ScanParameters: Closing registry key for parameter module ScanParameters: Scanning insertion string %lu: %s %% ScanParameters: No secondary substitution parameters found ScanParameters: %% found, but remainder of string is null ScanParameters: %% found, but following characters were not numeric ScanParameters: Looking up secondary substitution string %lu in ParameterMessageFile %s ScanParameters: ParameterMessageFile did not locate parameter - error %lu ScanParameters: Searching PrimaryModule for parameter ScanParameters: PrimaryModule did not locate parameter - error %lu ScanParameters: Original string length is %lu, new string length is %lu ScanParameters: Unable to reallocate storage for insertion strings. Scanning terminated. ScanParameters: Size of new insertion strings is %lu ScanParameters: Insertion string reallocated to %08X ScanParameters: Old size of all insertion strings was %lu, new size is %lu ScanParameters: New size of string is <= old size of string ScanParameters: Integer Overflow. Scanning terminated. ScanParameters: New insertion string is %s ScanParameters: Exiting ScanParameters routine FreeArrays: Freeing storage for strings and string length arrays FreeArrays: Freeing string storage at address %08X FreeArrays: Freeing storage for string array %08X FreeArrays: Freeing storage for string length array only FreeArrays: Freeing storage for string length array %08X FreeVarBind: Entering FreeVarBind routine FreeVarBind: Varbind list is %08X FreeVarBind: varBind->list is %08X FreeVarBind: Freeing OID #%lu ids at %08X FreeVarBind: Freeing varbind stream #%lu at %08X FreeVarBind: Exiting FreeVarBind routine TrimTrap: Entering TrimTrap routine TrimTrap: Trimming %lu bytes TrimTrap: Trap size is %lu bytes TrimTrap: Registry values indicate EventLog text to be trimmed first TrimTrap: EventLog text size is greater than amount to trim. Trimming EventLog text only TrimTrap: EventLog text size is %lu, trim amount is %lu TrimTrap: New EventLog text is %s TrimTrap: Exiting TrimTrap routine TrimTrap: EventLog text size is less than or equal to the amount to trim. Zeroing varbinds. TrimTrap: Zeroing EventLog text. TrimTrap: Trimming off %lu bytes from EventLog text. TrimTrap: New size is now %lu bytes. TrimTrap: Trap size is %lu, max size is %lu. Zeroing varbind entry %lu of size %lu. TrimTrap: Trap size is now %lu. TrimTrap: All varbinds have been zeroed, but trap still too large. TrimTrap: Registry values indicate varbind insertion strings to be trimmed first TrimTrap: All insertion strings removed. Only EventLog text remains of size %lu. TrimTrap: Need to trim %lu bytes from Event Log text. TrimTrap: Data to be trimmed exceeds data in trap. TrimTrap: EventLog text string length is now %lu BuildTrapBuffer: Entering BuildTrapBuffer BuildTrapBuffer: Performance threshold flag is on. No data will be processed. BuildTrapBuffer: Exiting BuildTrapBuffer function with FALSE BuildTrapBuffer: Notify event handle is %08X BuildTrapBuffer: Source name is %s, length is %Iu BuildTrapBuffer: Computer name is %s, length is %Iu BuildTrapBuffer: Pointer to User SID is %08X BuildTrapBuffer: First inserted string is %s BuildTrapBuffer: Opening registry for message module for %s BuildTrapBuffer: Unable to open EventLog service registry key %s; RegOpenKeyEx returned %lu BuildTrapBuffer: Exiting BuildTrapBuffer with FALSE EventMessageFile BuildTrapBuffer: No EventMessageFile registry key for %s; RegQueryValueEx returned %lu BuildTrapBuffer: Unable to expand message module %s; expanded size required is %lu bytes BuildTrapBuffer: Unable to allocate storage for string array BuildTrapBuffer: String array allocated at %08X BuildTrapBuffer: Unable to allocate storage for string length array BuildTrapBuffer: String length array allocated at %08X BuildTrapBuffer: String %lu is %s, size of %lu BuildTrapBuffer: Unable to allocate storage for insertion string BuildTrapBuffer: Insertion string %lu address at %08X BuildTrapBuffer: Scanned string %lu is %s BuildTrapBuffer: Request to trap extension agent log event ignored. BuildTrapBuffer: Error formatting message number %lu (%08X) is %lu BuildTrapBuffer: Formatted message: %s BuildTrapBuffer: Insertion string 0 address at %08X BuildTrapBuffer: Error freeing FormatMessage buffer is %lu BuildTrapBuffer: Unable to acquire account name for event, reason %lu. Unknown is used. Unknown BuildTrapBuffer: UserSidLength was 0. No SID is present. Unknown is used. BuildTrapBuffer: Insertion string 1 address at %08X BuildTrapBuffer: Unable to allocate storage for computer name string. Trap not sent. BuildTrapBuffer: Insertion string 2 address at %08X BuildTrapBuffer: Unable to allocate storage for event type string. Trap not sent. BuildTrapBuffer: Insertion string 3 address at %08X BuildTrapBuffer: Unable to allocate storage for event category string. Trap not sent. BuildTrapBuffer: Insertion string 4 address at %08X BuildTrapBuffer: Unable to allocate storage for varbind queue entry. Trap not sent. BuildTrapBuffer: Storage allocated for varbind queue entry at address at %08X BuildTrapBuffer: Unable to allocate storage for varbind list. Trap not sent. BuildTrapBuffer: Storage allocated for varbind list at address at %08X BuildTrapBuffer: Unable to allocate storage for varbind. Trap not sent. BuildTrapBuffer: Storage allocated for varbind array at address at %08X BuildTrapBuffer: Number of varbinds present set to %lu BuildTrapBuffer: Unable to allocate storage for enterprise OID. Trap not sent. BuildTrapBuffer: Storage allocated for enterprise OID at address at %08X BuildTrapBuffer: Unable to convert OID from buffer. Trap not sent. BuildTrapBuffer: String %lu is %s .0 BuildTrapBuffer: Current OID name is %s BuildTrapBuffer: Unable to convert appended OID for variable binding %lu. Trap not sent. BuildTrapBuffer: Freeing storage for string array %08X BuildTrapBuffer: Current OID address is %08X BuildTrapBuffer: All variable bindings have been built, size of %lu BuildTrapBuffer: TrimTrap returned new size of %lu BuildTrapBuffer: TrimTrap could not trim buffer. Trap not sent BuildTrapBuffer: Unable to add trap buffer to queue. Trap not sent. BuildTrapBuffer: Freeing storage for string length array %08X BuildTrapBuffer: Exiting BuildTrapBuffer with TRUE BuildTrapBuffer: WRAP_STRCAT_A failed on variable binding %lu. Trap not sent. Position_LogfilesToBootTime: Error allocating memory for log event record Position_LogfilesToBootTime: Alert will not be processed Position_LogfilesToBootTime: Log event buffer is at address %08X Position_LogfilesToBootTime: Reading log event for handle %08X Position_LogfilesToBootTime: Error reallocating memory for log event record Position_LogfilesToBootTime: END OF FILE of event log is reached Position_LogfilesToBootTime: Error reading event log %08X record is %lu Position_LogfilesToBootTime: Freeing log event buffer %08X SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\009 Counter System System Up Time SnmpEvLogProc: Entering SnmpEvLogProc routine.... SnmpEvLogProc: Value of hStopAll is %08X SnmpEvLogProc: Value of phEventLogs is %08X SnmpEvLogProc: Event log %s(%lu) has handle of %08X SnmpEvLogProc: Unable to allocate memory for wait event array SnmpEvLogProc: SnmpEvLogProc abnormal initialization SnmpEvLogProc: Unable to allocate memory for boolean array SnmpEvLogProc: Unable to allocate memory for record ID array SnmpEvLogProc: CreateEvent/ChangeNotify loop pass %lu SnmpEvLogProc: Error creating event for log notify is %lu SnmpEvLogProc: CreateEvent returned handle of %08X SnmpEvLogProc: Handle address is %08X SnmpEvLogProc: Handle contents by pointer is %08X SnmpEvLogProc: ChangeNotify on log handle %08X SnmpEvLogProc: Address of log handle %08X SnmpEvLogProc: NotifyChangeEventLog failed with code %lu SnmpEvLogProc: ChangeNotify was successful SnmpEvLogProc: Termination event is set to %08X SnmpEvLogProc: Address of termination event is %08X SnmpEvLogProc: On entry, handle value is %08X SnmpEvLogProc: Registry notification event is set to %08X SnmpEvLogProc: Address of registry notification event is %08X SnmpEvLogProc: CreateMutex returned handle of %08X and reason code of %lu SnmpEvLogProc: Unable to create Mutex object, reason code %lu SnmpEvLogProc: Created mutex object handle is %08X SnmpEvLogProc: Releasing mutex object %08X SnmpEvLogProc: Unable to release mutex object for reason code %lu SnmpEvLogProc: Allocating memory for log event record SnmpEvLogProc: Error allocating memory for log event record SnmpEvLogProc: Waiting for event to occur SnmpEvLogProc: Normal event wait in progress SnmpEvLogProc: Event handle %lu is %08X SnmpEvLogProc: EventOccur value: %lu SnmpEvLogProc: Error waiting for event array is %lu SnmpEvLogProc: Event detected DLL shutdown SnmpEvLogProc: Event detected registry key change. Rereading registry parameters. SnmpEvLogProc: Error reading registry information. DLL is terminating. SnmpEvLogProc: Registry parameters have been refreshed. SnmpEvLogProc: Event detected log record written for %s - %lu - %08X SnmpEvLogProc: Performance threshold flag is on. No data will be processed. SnmpEvLogProc: Log event buffer is at address %08X SnmpEvLogProc: Reading log event for handle %08X SnmpEvLogProc: Error reallocating memory for log event record SnmpEvLogProc: Alert will not be processed SnmpEvLogProc: END OF FILE of event log is reached SnmpEvLogProc: Error reading event log %08X record is %lu SnmpEvLogProc: Preparing to read config file values SnmpEvLogProc: Event ID converted to ASCII SnmpEvLogProc: Source is %s. Event ID is %s. SnmpEvLogProc: This event is being tracked -- formatting trap buffer SnmpEvLogProc: Unable to build trap buffer. Trap not sent. SnmpEvLogProc: Notify event handle is %08X SnmpEvLogProc: A new trap buffer was added -- posting notification event %08X SnmpEvLogProc: Unable to post event %08X; reason is %lu SnmpEvLogProc: Closing mutex handle %08X SnmpEvLogProc: Freeing event log record buffer %08X SnmpEvLogProc: Exiting SnmpEvLogProc via abnormal shutdown SnmpEvLogProc: Exiting SnmpEvLogProc via normal shutdown a %02i/%02i/%02i %02i:%02i:%02i SYSTEM\CurrentControlSet\Services\EventLog\Application\EvntAgnt LoadMessageDLL: Unable to open EventLog service registry key; RegOpenKeyEx returned %lu LoadMessageDLL: Unable to open EventMessageFile registry key; RegQueryValueEx returned %lu LoadMessageDLL: Unable to expand message module %s; expanded size required is %lu bytes LoadMessageDLL: Unable to load message module %s; LoadLibraryEx returned %lu FormatTrace: Error formatting message number %08X is %lu FormatTrace: Error freeing FormatMessage buffer is %lu FormatTrace: Unable to format message number %08X; message DLL handle is null. WriteLog: Error writing to system event log is %lu WriteLog: Unable to write to system event log; handle is null WriteLog: Error allocating memory for system event log write \ 0࣠RSDSú Ò L dóGØÿS evntagnt.pdb Z* M+ ?ÿU?ì?ì ¡03Å?EüS?ÙV3öWö?ú?? ??èýÿÿÇ?èýÿÿ P??ôþÿÿÆEø P??äýÿÿPVhp ÿ7ÿT`?ð?öu^h ??ìýÿÿP??ôþÿÿPÿÌ`?Àt9= w2jV??ìýÿÿPÿÄ`?C?Àu#ÿÈ`?ð??ôþÿÿV¹ Àè§u ëÿÈ`?ðÿ7ÿL`?Mü?Æ_^3Í[è¼ ?å]ÃÌÌÌÌÌ?ÿU?ì3À?Òt?úÿÿÿv¸W ??ÀxQÿuQèy ë?ÒtÆ ] ÌÌÌÌÌ?ÿU?ìS3À?ÙV?ð?Òt?úÿÿÿv¾W ??öx8?Ê?ðW?û?Òt8tGIuø?Ét?Â+Áë¾W ?_?öxQÿu+ÐQ?è ?ð?Æ^[] ÌÌÌÌÌ?ÿU?ìW3ÿ?Òt$?ESV¾þÿÿ+Á?öt??Ût?ANJuî^[?ÒuI¿z ??ÇÆ _] ÌÌÌÌÌh? j è/w ? 0ÿ3ÀYY3ÉÇØ3ô @? 06? ¬3? 6? (6? è3? 6? ð3? °3? D6? $6? 6? 5£0£0? <6? H6? L6? 46? à3? @6? ä3£0? 6? 5? 86? Ô3ÇÈ3, ? ,6? ¸3? 5? ´3? ¼3? ì3? d7? `6? \6? X6? Ü3? P6ÃÌÌÌÌÌ?ÿU?ì?ì, ¡03Å?EüSVWj.X3Û??ØûÿÿhÌ j ?ñf??àûÿÿ?]ø??ìýÿÿèåu Vh SèÙu ?Î?Ä?û?Q?A?Àuù+Êu h( é® ?>.t&hX j è©u YY» ??ðýÿÿV?Óèuýÿÿé¢ »5Sh? j è}u YYSQ» ??ðýÿÿ?Óèçýÿÿ??ðýÿÿ?Q?A?Àuù+Ê?A= ?6 hÈ ?Ó??ðýÿÿèNýÿÿ??ðýÿÿ?J?B?Àuù+Ñ?Î?A??Üûÿÿ?A?Àuù+?Üûÿÿ?AÂ= ?ê V?Ó??ðýÿÿèýÿÿQ??ðýÿÿ?ÓPQ??äûÿÿèWýÿÿ??àûÿÿP??ðýÿÿPÿda?ðYY?ö?óþÿÿ?µÔûÿÿÿè`j ? ??ÔûÿÿPVÿà`?Äÿè`?8"?e ??Ôûÿÿ;ð?? ?8 ?6 ??àûÿÿGPj ?½Üûÿÿÿda?ðYY?öu??ÿ??þÿÿWhD Pè=t h` j è1t ?Ä?ÇÁàPÿ|a?µØûÿÿ?F?Àuh? jè t YY¹? ?è¶n éõ PhÜ j èës ?Ä?>??äûÿÿ?ÓPQ??ðýÿÿèQüÿÿ?da??àûÿÿP??ðýÿÿPÿÓYY?Àt9?½Øûÿÿ3öj ??ÔûÿÿQPÿà`?O???àûÿÿPj ?vÿÓ?Ä?ÀuÕ?½Üûÿÿ?=$0 u'3ö?ÿt!??Øûÿÿ?@ÿ4°Vh j èTs ?ÄF;÷rßh0 j è@s Y3ÀY@ë8h jè-s YY¹? ?éÿÿÿÿè`hÀ ? ëhX jès YY3À?Mü_^3Í[è?z ?å]ÃÌÌÌÌÌ¡5?ÀtXPh° j èÕr ?Äÿ55ÿ?`?Àu1VÿÈ`?ðVÿ55h jè¦r ?5?Ä¹Ø ?Vè¬n ^?%5 ÃÌÌÌÌÌ?=ð3 tPVhT j ènr YYÿ5ð3ÿL`?ð?öt'Vÿ5ð3h? jèGr ?ð3?Ĺ٠?VèMn ?%ð3 ^ÃÌÌÌÌÌ?ÿSVhÜ j èr 3Û?óYY9(6vW?û¡¬3?Àt-9°t(ÿ4°¡06VÇPhü Sèßq ¡¬3?Äÿ4°ÿ`¡6?Àt-9°t(ÿ4°¡06VÇPh8 Sè©q ¡6?Äÿ4°ÿÀ`F?Ç ;5(6r?_ÿ5¬3h? j èvq ?5pa?Äÿ5¬3ÿÖÿ56?¬3hÈ j èMq ?Äÿ56ÿÖÿ506?6h j è*q ?Äÿ506ÿÖ^?06[ÃÌÌÌÌÌ?ÿU?ì?ìVWhP j ?ùèùp Wh? 3öVèëp ?Ä?ÿu9Vh¸ jè×p hø jèËp ?Ä3Ò¹¸ Àèæk ¹¹ ?èkk 3Àéü Sh, j è?p YYh ÿ|a?Ø?Ûu-WhX jè~p h? jèrp ?Ä?×¹º Àè?k é~ ShÔ VèRp h j èFp hD j è:p ?Ä?EðPWÿ4`?Àu:ÿÈ`Sh| j ?ðèp ?ÄSÿpaVWh¸ jèûo ?Ĺ» Àé ÿuðh Vèào hH VèÕo ?Ä?EôPWÿ,`?Àu8ÿÈ`h? j ?ðè¯o YYSÿpaVWhÀ jè?o ?Ĺ¼ Àé£ ÿuôh Vè}o ?uðNuôVhX j ?uìèfo ?Ä?EøP?EüPh SVjWÿ`?À?? ÿÈ`Sh| j ?ðè.o ?ÄSÿpa?þ&u!Wh? j èo hÀ j èo ?ÄéK VWh jèðn ?Ä?×¹½ ÀVèúj ¹¹ ?è?i ÿuühT j èÇn ÿuøh| j è¸n ?ÄéÚ h° j è¤n ?eü ?EøYYP?Eü?óPh ?uèSë9?Eüë Phè j èwn ?C?Ä?Eì?Eü+?Eü?ÀuÜ?Eø?ÞP?EüPh Vj jWÿ`?Àu¸ÿÈ`h, j ?ðè-n ?]èSh\ j èn ?ÄSÿpa?þ&t<?öt8VWhà jèüm h jèðm ?Ĺ¾ ?V?×èúi ¹¹ ?è?h 3Àë"ÿuìWh? j èÂm hÀ j è¶m ?Ä3À@[_^?å]ÃÌÌÌÌÌ?ÿU?ì?ìl ¡03Å?EüS3ÛVWhP j ??¤üÿÿ??¨üÿÿ?? üÿÿ??°üÿÿ??¬üÿÿ??Èüÿÿ??Ìüÿÿ??Ðüÿÿ??´üÿÿ???üÿÿèBm YY??ìþÿÿ?]ô??äýÿÿ9ä3?? h? j èm ¡5CYY?Àt]SPjSÿ5ð3ÿ(`?ð?öuhð j èêl YY?46ë0Vh@ j_WèÑl ?Ä?Ö¹Ô @èìg h? Wè·l YYèÅùÿÿh j è¤l ?Ãé ¿X Wh? j è?l 3ö?ÄF9@6t?µØüÿÿ90u??Øüÿÿ9ð3u@hð3h SWh ?ÿP`?ø?ÿt#Wh¸ jè7l ?×¹è ??ÄèRg 3Àé? j_9L6ukh ! j è l YYSSSS?5L6ÿ¬`£5?Àu5ÿÈ`?ðVhP! WèÛk ?Ä?Ö¹Ó ?èöf h¨! WèÁk Y3öYFëPh"