Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 16-02-2010, 12:25 PM   #1 (permalink)
Apprentice
 
ritesh.techie's Avatar
 
Join Date: Jul 2009
Location: Bhopal, India
Posts: 99
Default Check Your PC for Shutdown and Startup Log - Forensic Way


Originally Posted at Source

Before we begin its better to know what an Event Viewer is, Event Viewer is a Microsoft Management Console (MMC) snap-in that enables you to browse and manage event logs. It is an indispensable tool for monitoring the health of systems and troubleshooting issues when they arise.

Event Viewer enables you to perform the following tasks:
  1. View events from multiple event logs
  2. Save useful event filters as custom views that can be reused
  3. Schedule a task to run in response to an event
  4. Create and manage event subscriptions
  5. Now most important thing where to use it, well if I rely on my source than by using the following procedures Forensic Department knows when you started your PC and when you shut it down.

So in order to view the exact shutdown time and start-up time follow the below steps -

1. Open Run Dialog box by pressing WIN +R

2. In Run dilog box type eventvwr.msc and press Enter



3. Click on System left navigation pane

4. Now look for the following Event code, At the far right pane click on find, and enter the following event code to look for them.

6005 – System start up

6006 -System shutdown



A detailed note on Event ID’s that may interests you -

Quote:
  • Event 6005 is logged at boot time noting that the Event Log service was started. It gives the message “The Event log service was started”.
  • Event 6006 is logged as a clean shutdown. It gives the message “The Event log service was stopped”.
  • Event 6008 is logged as a dirty shutdown. It gives the message “The previous system shutdown at time on date was unexpected”.
  • Event 6009 is logged during every boot and indicates the operating system version, build number, service pack level, and other pertinent information about the system. Depending on your current configuration, it gives a message similar to: “Microsoft (R) Windows NT 4.0 1381 Service Pack 6 Multiprocessor free”.

And now you have just made your way to Forensic department
__________________
Get all latest tips and tricks at http://beingpc.com/
ritesh.techie is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 16-02-2010, 07:30 PM   #2 (permalink)
http://eitwebguru.com
 
maxmk's Avatar
 
Join Date: Sep 2006
Location: Nashik
Posts: 118
Default Re: Check Your PC for Shutdown and Startup Log - Forensic Way

hey.. thanks for the post it's really informative...but I think it should be in Tutorial section (I might be incorrect)..
__________________
Regards,
Milind_Koyande_a_K_a_MaxMK

Fully Managed Datacenter | Windows & Linux Tweaks
Indian Social Bookmarking | HQ Wallpapers
maxmk is offline  
Old 16-02-2010, 07:43 PM   #3 (permalink)
live life king like...
 
hot zubs's Avatar
 
Join Date: Aug 2008
Location: Bangalore
Posts: 219
Default Re: Check Your PC for Shutdown and Startup Log - Forensic Way

interesting info mate... Forensic science is really great...
__________________
Core i5 2400, Intel DH67BL-B3, 2GB Corsair DDR3, Geforce 8600GT, Seagate 1TB, LG 20x , BenQ E2220 HD, Creative M4500 , CM extreme 600W, CM 690, APC BackUPS -ES650VA
hot zubs is offline  
Old 16-02-2010, 08:52 PM   #4 (permalink)
Apprentice
 
ritesh.techie's Avatar
 
Join Date: Jul 2009
Location: Bhopal, India
Posts: 99
Default Re: Check Your PC for Shutdown and Startup Log - Forensic Way

Yeah thanks for comment.

Mods: Please move it to tutorial section.
__________________
Get all latest tips and tricks at http://beingpc.com/
ritesh.techie is offline  
Old 19-02-2010, 09:32 PM   #5 (permalink)
Apprentice
 
Join Date: Mar 2004
Posts: 99
Default Re: Check Your PC for Shutdown and Startup Log - Forensic Way

good info...thanks
__________________
Vicky Advani
---------------------------------------------------------------------------------------
I said "no" to drugs, but they just wouldn't listen.
vickyadvani is offline  
Old 21-02-2010, 10:11 AM   #6 (permalink)
In The Zone
 
ruturaj3's Avatar
 
Join Date: Feb 2007
Location: Mumbai
Posts: 214
Default Re: Check Your PC for Shutdown and Startup Log - Forensic Way

Hey ritesh, event ID of windows startup is 12 and for shutdown it is 13.
Plz check tat it gives info about time of startup. And u can create custom log to keep track of it.
ruturaj3 is offline  
Old 25-02-2010, 07:24 PM   #7 (permalink)
Right Off the Assembly Line
 
Join Date: Feb 2010
Location: butwal,nepal
Posts: 5
Default Re: Check Your PC for Shutdown and Startup Log - Forensic Way

yeha its interesting to know thkx for info..
bishwash is offline  
Old 26-02-2010, 05:50 PM   #8 (permalink)
I M A *STAR*
 
saqib_khan's Avatar
 
Join Date: Nov 2007
Location: Planet Earth
Posts: 855
Default Re: Check Your PC for Shutdown and Startup Log - Forensic Way

Quote:
Originally Posted by ritesh.techie View Post
Mods: Please move it to tutorial section.
Yes, this is a good article, Mods should move this to Tutorials section. But wait, are there any ACTIVE mods here.
__________________
Blogging at:
Technostarry
saqib_khan is offline  
Old 26-02-2010, 06:23 PM   #9 (permalink)
Right Off the Assembly Line
 
Join Date: Feb 2010
Posts: 1
Default Re: Check Your PC for Shutdown and Startup Log - Forensic Way

Thanks dude
zebediah is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Deleting startup items of other user Devrath_ND Software Q&A 1 12-02-2010 03:40 PM
Error at Startup...plz help !! bajaj151 Software Q&A 15 06-02-2010 11:03 PM
Due Kernel I/O error, system refuses to boot randomly gary4gar Open Source 33 04-05-2008 10:22 AM
plz check out this hijackthis log ssk_the_gr8 Software Q&A 6 09-05-2007 09:08 PM
My Hijack This log file --- please check pradipudhaya QnA (read only) 14 05-09-2005 02:26 PM

 
Latest Threads
- by Tenida
- by chris
- by Who
- by abhidev
- by clmlbx

Advertisement




All times are GMT +5.5. The time now is 10:39 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2