G
Guest
Hopefully someone can help. I can open the event viewer but when I try to
open a catagory like Application or Security, etc. I get a red M&M icon with
an X in it and it says:
Unable to open this log or view. Access is denied (5)
I get this with all the catagories.
Ive gone to Windows\System32\Logfiles\WMI\RtBackup and the files in there
wont let me take ownership or anything. I figure these might be related but
not sure. They are:
EtwRTDiagLog.etl
EtwRTEventLog-Application.etl
EtwRTEventLog-ForwardedEvents.etl
EtwRTEventlog-Security.etl
EtwRTEventLog-System.etl
The only reason that I noticed these at all was that theyre the only files
in the sytem32 folder that I couldnt take ownership of. Actually there was
one other but cant remember which one. Didnt seem related though.
Ive tried using an elevated cmd prompt and doing some things described
elsewhere to get a more full control but theses particular files and the
Event Viewer itself seem to be totally locked.
On the Owner tab of these files it says You do not have permission to view
this objects owner etc. The permissions tab as well as all the other tabs say
something similar. They dont even let me see the permissions for the various
accounts or the different potential owners either. Ive never seen this before.
I have Full Control of the eventvwr.msc and eventvwr.exe. Or so it says. Ive
switched the owner around but it still wont let me see events. Run as
administrator doesnt do it either. Is ther a more,sort of, brute force way to
get control of these files and/or the Event Viewer? Or some kind of God
command to giveth dominion over absolutely everything.
--
(¯`·._.·Ecat·._.·´¯)
HP a1230n
Athlon 64 Processor 3800+
1 Gig RAM
Radeon X700
open a catagory like Application or Security, etc. I get a red M&M icon with
an X in it and it says:
Unable to open this log or view. Access is denied (5)
I get this with all the catagories.
Ive gone to Windows\System32\Logfiles\WMI\RtBackup and the files in there
wont let me take ownership or anything. I figure these might be related but
not sure. They are:
EtwRTDiagLog.etl
EtwRTEventLog-Application.etl
EtwRTEventLog-ForwardedEvents.etl
EtwRTEventlog-Security.etl
EtwRTEventLog-System.etl
The only reason that I noticed these at all was that theyre the only files
in the sytem32 folder that I couldnt take ownership of. Actually there was
one other but cant remember which one. Didnt seem related though.
Ive tried using an elevated cmd prompt and doing some things described
elsewhere to get a more full control but theses particular files and the
Event Viewer itself seem to be totally locked.
On the Owner tab of these files it says You do not have permission to view
this objects owner etc. The permissions tab as well as all the other tabs say
something similar. They dont even let me see the permissions for the various
accounts or the different potential owners either. Ive never seen this before.
I have Full Control of the eventvwr.msc and eventvwr.exe. Or so it says. Ive
switched the owner around but it still wont let me see events. Run as
administrator doesnt do it either. Is ther a more,sort of, brute force way to
get control of these files and/or the Event Viewer? Or some kind of God
command to giveth dominion over absolutely everything.
--
(¯`·._.·Ecat·._.·´¯)
HP a1230n
Athlon 64 Processor 3800+
1 Gig RAM
Radeon X700