locked
Can't create Outlook message from other apps. RRS feed

  • Question

  • I have a new computer running Windows 10 1803.  To save money (this is County government, afterall), we moved the Office 2013 Home & Business license from the old computer to this one.  Office in general works fine.  However, the user has an business application that will allow her to e-mail a document image from the application itself.  The user reported that this doesn't work on the new computer.  In the course of troubleshooting, we discovered that we have the same issue in Adobe Reader.  When we run Excel and try to e-mail a spreadsheet as an attachment, we get the message "Mail system failure.  Check your mail installation."  I made sure that I could e-mail the same spreadsheet from with Outlook.  That works.

    I have uninstalled and reinstalled Office multiple times, but it hasn't eliminated the issue.  It shouldn't be the combination of 1803 and Office 2013 as I have the same setup on my computer, though I have different hardware.  At first, there seemed to be an issue with Office 365 running instead of the 2013 apps.  (It wasn't preinstalled and we don't use 365 at all, so I'm not sure how this happened.)  I believe that's cleared up, but it didn't eliminate my issue.

    I would appreciate any solutions you may have to offer.

    Tuesday, July 10, 2018 11:49 PM

Answers

All replies

  • Hi,

    >>When we run Excel and try to e-mail a spreadsheet as an attachment, we get the message "Mail system failure.  Check your mail installation." 

    Please first check if you have set Outlook as the default mail app in windows.

    Besides, we can try repairing Office to check the result. To do this, please go to Control Pane > Programs and Features. Right click your Office suit. Click Change and then click Repair.

     

    If the steps above don't help, you could repair Msmapi32.dll to see if there are any improvements. Please refer to the steps below:

    1. Exit Outlook

    2. Delete Msmapi32.dll which may be located C:\Program Files\Common Files\system\MSMAPI\1033

    3. Search fixmapi.exe from C:\Windows and run it to repair Msmapi32.dll.

    4. Open Outlook (Outlook will replace & register the Msmapi32.dll and then open).

    Hope this helps.

    Regards,

    Perry


    Please remember to mark the replies as answers if they helped. If you have feedback for TechNet Subscriber Support, contact tnsf@microsoft.com.


    Click here to learn more. Visit the dedicated forum to share, explore and talk to experts about Microsoft Teams.

    Wednesday, July 11, 2018 5:24 AM
  • Thank you for the response.

    I scanned and found C:\Program Files\Microsoft Office 15\root\vfs\ProgramFilesCommonX86\System\MSMAPI\1033\msmapi32.dll.  Renamed it to .old.  Ran fixmapi.  Never saw anything appear on the screen from the program and didn't see where a new msmapi32.dll was created.  Started Outlook.  Try to e-mail the spreadsheet from Excel.  Outlook gives error "This action is not supported while an older version of Outlook is running."  I confirmed the version in File|Office Account is Outlook Home & Business 2013.  Excel then says "General mail failure.  Quit Microsoft Excel, restart the mail system, and try again."

    I found more copies of msmapi32.dll under Program Files\WindowsApps and Windows\InfusedApps but don't have access to those.

    Any more ideas?

    Wednesday, July 11, 2018 5:26 PM
  • Hi,

    From the error message, it seems that you have an earlier version of Outlook running on your computer. Please refer to the details in this article to see if it works for you.

    Regards,

    Perry


    Please remember to mark the replies as answers if they helped. If you have feedback for TechNet Subscriber Support, contact tnsf@microsoft.com.


    Click here to learn more. Visit the dedicated forum to share, explore and talk to experts about Microsoft Teams.


    • Edited by Perry-Pan Friday, July 13, 2018 8:25 AM
    • Proposed as answer by Perry-Pan Monday, July 16, 2018 1:38 AM
    Friday, July 13, 2018 8:24 AM
  • When I look at the installed programs, only Office Home & Business 2013 is listed.  Now, there was a point, in the beginning, at which Excel would prompt for an activation for 365, even though 2013 was installed.  I uninstalled/reinstalled Office 2013 and was careful to make sure that the activation with done correctly as a Click and Run.  Is it possible that that is the source of the issue?  Wouldn't reinstalling Office have corrected it if it was?
    Monday, July 16, 2018 11:23 PM
  • What's the detailed version of Office 2013?

    How do you activate Office? Email address or produce key? Please refer to the details in this link. When you move the Office 2013 Home & Business license from the old computer to this one, please uninstall the Office 2013 from old computer to check the results.

    Regards,

    Perry


    Please remember to mark the replies as answers if they helped. If you have feedback for TechNet Subscriber Support, contact tnsf@microsoft.com.


    Click here to learn more. Visit the dedicated forum to share, explore and talk to experts about Microsoft Teams.

    Thursday, July 19, 2018 4:35 AM
  • Office has been uninstalled from the old computer.  To install it on the new computer, I used office.com/myaccount, then selected the appropriate entry.  (The computer was ordered without Office preinstalled.)  So, technically, none of the options in your link were used to install Office.  HOWEVER, at some point after the user had the computer for a few days, they were prompted with the Activation Wizard, but for Office 365, not the Home and Business 2013 I had installed.  I suspect they must have clicked on something related to 365, but I don't know what.  After uninstalling/reinstall Office (once again, through office.com/myaccount), we are not being prompted for activation.  Unfortunately, though, the mapi problem remains.
    Monday, July 23, 2018 3:47 PM
  • Are there any log recorded in Event Viewer?
    Thursday, July 26, 2018 8:37 AM
  • The System log has 10010 and 10016 DCOM errors.
    Thursday, August 2, 2018 3:54 PM
  • Would you mind pasting the detailed error log here?

    Regards,

    Perry


    Please remember to mark the replies as answers if they helped. If you have feedback for TechNet Subscriber Support, contact tnsf@microsoft.com.


    Click here to learn more. Visit the dedicated forum to share, explore and talk to experts about Microsoft Teams.

    Tuesday, August 7, 2018 1:30 AM
  • Here are the entries in the System log during the time I tested this.  During that time I tried to send a message from Excel and one from Adobe Reader.

    Log Name:      System
    Source:        Microsoft-Windows-DistributedCOM
    Date:          8/2/2018 9:49:33 AM
    Event ID:      10001
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          SYSTEM
    Computer:      CLK23.eddycountynm.local
    Description:
    Unable to start a DCOM Server: {995C996E-D918-4A8C-A302-45719A6F4EA7} as Unavailable/Unavailable. The error:
    "2"
    Happened while starting this command:
    C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
        <EventID Qualifiers="0">10001</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8080000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:49:33.546322800Z" />
        <EventRecordID>8068</EventRecordID>
        <Correlation />
        <Execution ProcessID="684" ThreadID="14972" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="param1">C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding</Data>
        <Data Name="param2">2</Data>
        <Data Name="param3">{995C996E-D918-4A8C-A302-45719A6F4EA7}</Data>
        <Data Name="param4">Unavailable</Data>
        <Data Name="param5">Unavailable</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-DistributedCOM
    Date:          8/2/2018 9:49:09 AM
    Event ID:      10001
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          SYSTEM
    Computer:      CLK23.eddycountynm.local
    Description:
    Unable to start a DCOM Server: {995C996E-D918-4A8C-A302-45719A6F4EA7} as Unavailable/Unavailable. The error:
    "2"
    Happened while starting this command:
    C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
        <EventID Qualifiers="0">10001</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8080000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:49:09.200755100Z" />
        <EventRecordID>8067</EventRecordID>
        <Correlation />
        <Execution ProcessID="684" ThreadID="10940" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="param1">C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding</Data>
        <Data Name="param2">2</Data>
        <Data Name="param3">{995C996E-D918-4A8C-A302-45719A6F4EA7}</Data>
        <Data Name="param4">Unavailable</Data>
        <Data Name="param5">Unavailable</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-DistributedCOM
    Date:          8/2/2018 9:49:06 AM
    Event ID:      10001
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          SYSTEM
    Computer:      CLK23.eddycountynm.local
    Description:
    Unable to start a DCOM Server: {995C996E-D918-4A8C-A302-45719A6F4EA7} as Unavailable/Unavailable. The error:
    "1008"
    Happened while starting this command:
    C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
        <EventID Qualifiers="0">10001</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8080000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:49:06.954342500Z" />
        <EventRecordID>8066</EventRecordID>
        <Correlation />
        <Execution ProcessID="684" ThreadID="10940" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="param1">C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding</Data>
        <Data Name="param2">1008</Data>
        <Data Name="param3">{995C996E-D918-4A8C-A302-45719A6F4EA7}</Data>
        <Data Name="param4">Unavailable</Data>
        <Data Name="param5">Unavailable</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Winlogon
    Date:          8/2/2018 9:49:06 AM
    Event ID:      7002
    Task Category: (1102)
    Level:         Information
    Keywords:      (35184372088832)
    User:          SYSTEM
    Computer:      CLK23.eddycountynm.local
    Description:
    User Logoff Notification for Customer Experience Improvement Program
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Winlogon" Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" />
        <EventID>7002</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>1102</Task>
        <Opcode>0</Opcode>
        <Keywords>0x2000200000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:49:06.568410700Z" />
        <EventRecordID>8065</EventRecordID>
        <Correlation />
        <Execution ProcessID="2176" ThreadID="5160" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="TSId">2</Data>
        <Data Name="UserSid">S-1-5-21-275593300-1636143335-3899451950-1826</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-DistributedCOM
    Date:          8/2/2018 9:46:07 AM
    Event ID:      10010
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          EDDYCOUNTYNM\amy
    Computer:      CLK23.eddycountynm.local
    Description:
    The server {0006F03A-0000-0000-C000-000000000046} did not register with DCOM within the required timeout.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
        <EventID Qualifiers="0">10010</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8080000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:46:07.095231700Z" />
        <EventRecordID>8064</EventRecordID>
        <Correlation />
        <Execution ProcessID="1076" ThreadID="6724" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-21-275593300-1636143335-3899451950-2154" />
      </System>
      <EventData>
        <Data Name="param1">{0006F03A-0000-0000-C000-000000000046}</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:42:24 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          EDDYCOUNTYNM\ken-admin
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.Desktop_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:42:24.573731800Z" />
        <EventRecordID>8063</EventRecordID>
        <Correlation />
        <Execution ProcessID="13608" ThreadID="6096" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-21-275593300-1636143335-3899451950-1826" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">106</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.Desktop_8wekyb3d8bbwe\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">1</Data>
        <Data Name="DirtyPages">1</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:42:23 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          EDDYCOUNTYNM\ken-admin
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.Desktop.Word_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:42:23.910755300Z" />
        <EventRecordID>8062</EventRecordID>
        <Correlation />
        <Execution ProcessID="13608" ThreadID="6096" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-21-275593300-1636143335-3899451950-1826" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">111</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.Desktop.Word_8wekyb3d8bbwe\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">1</Data>
        <Data Name="DirtyPages">1</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:42:23 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          EDDYCOUNTYNM\ken-admin
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.Desktop.Publisher_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:42:23.709247800Z" />
        <EventRecordID>8061</EventRecordID>
        <Correlation />
        <Execution ProcessID="13608" ThreadID="6096" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-21-275593300-1636143335-3899451950-1826" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">116</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.Desktop.Publisher_8wekyb3d8bbwe\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">1</Data>
        <Data Name="DirtyPages">1</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:42:23 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          EDDYCOUNTYNM\ken-admin
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.Desktop.PowerPoint_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:42:23.464753400Z" />
        <EventRecordID>8060</EventRecordID>
        <Correlation />
        <Execution ProcessID="13608" ThreadID="6096" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-21-275593300-1636143335-3899451950-1826" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">117</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.Desktop.PowerPoint_8wekyb3d8bbwe\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">1</Data>
        <Data Name="DirtyPages">1</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:42:23 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          EDDYCOUNTYNM\ken-admin
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.Desktop.Outlook_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:42:23.271956100Z" />
        <EventRecordID>8059</EventRecordID>
        <Correlation />
        <Execution ProcessID="13608" ThreadID="6096" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-21-275593300-1636143335-3899451950-1826" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">114</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.Desktop.Outlook_8wekyb3d8bbwe\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">1</Data>
        <Data Name="DirtyPages">1</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:42:23 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          EDDYCOUNTYNM\ken-admin
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.Desktop.Excel_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:42:23.106738200Z" />
        <EventRecordID>8058</EventRecordID>
        <Correlation />
        <Execution ProcessID="13608" ThreadID="6096" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-21-275593300-1636143335-3899451950-1826" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">112</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.Desktop.Excel_8wekyb3d8bbwe\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">1</Data>
        <Data Name="DirtyPages">1</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:42:22 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          EDDYCOUNTYNM\ken-admin
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.Desktop.Access_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:42:22.905276400Z" />
        <EventRecordID>8057</EventRecordID>
        <Correlation />
        <Execution ProcessID="13608" ThreadID="6096" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-21-275593300-1636143335-3899451950-1826" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">113</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.Desktop.Access_8wekyb3d8bbwe\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">1</Data>
        <Data Name="DirtyPages">1</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:42:16 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          EDDYCOUNTYNM\ken-admin
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:42:16.746842000Z" />
        <EventRecordID>8056</EventRecordID>
        <Correlation />
        <Execution ProcessID="13608" ThreadID="6096" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-21-275593300-1636143335-3899451950-1826" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">106</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Office.OneNote_8wekyb3d8bbwe\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">1</Data>
        <Data Name="DirtyPages">1</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:42:14 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          EDDYCOUNTYNM\ken-admin
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:42:14.438585600Z" />
        <EventRecordID>8055</EventRecordID>
        <Correlation />
        <Execution ProcessID="13608" ThreadID="6096" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-21-275593300-1636143335-3899451950-1826" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">106</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Windows.Photos_8wekyb3d8bbwe\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">1</Data>
        <Data Name="DirtyPages">1</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:42:12 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          EDDYCOUNTYNM\ken-admin
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 1 keys and creating 1 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:42:12.267000800Z" />
        <EventRecordID>8054</EventRecordID>
        <Correlation />
        <Execution ProcessID="13608" ThreadID="6096" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-21-275593300-1636143335-3899451950-1826" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">104</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.WindowsStore_8wekyb3d8bbwe\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">1</Data>
        <Data Name="DirtyPages">1</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:42:10 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          EDDYCOUNTYNM\ken-admin
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat was cleared updating 2 keys and creating 1 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:42:10.077316800Z" />
        <EventRecordID>8053</EventRecordID>
        <Correlation />
        <Execution ProcessID="13608" ThreadID="6096" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-21-275593300-1636143335-3899451950-1826" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">100</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.SkypeApp_kzf8qxf38zg5c\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">2</Data>
        <Data Name="DirtyPages">1</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:42:07 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          EDDYCOUNTYNM\ken-admin
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 54 keys and creating 9 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:42:07.531160700Z" />
        <EventRecordID>8052</EventRecordID>
        <Correlation />
        <Execution ProcessID="13608" ThreadID="6096" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-21-275593300-1636143335-3899451950-1826" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">117</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\microsoft.windowscommunicationsapps_8wekyb3d8bbwe\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">54</Data>
        <Data Name="DirtyPages">9</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:41:36 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          SYSTEM
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat was cleared updating 4 keys and creating 1 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:41:36.932664800Z" />
        <EventRecordID>8051</EventRecordID>
        <Correlation />
        <Execution ProcessID="15120" ThreadID="15216" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">105</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.MicrosoftEdge_8wekyb3d8bbwe\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">4</Data>
        <Data Name="DirtyPages">1</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:41:35 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          SYSTEM
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat was cleared updating 41 keys and creating 9 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:41:35.618340000Z" />
        <EventRecordID>8050</EventRecordID>
        <Correlation />
        <Execution ProcessID="3400" ThreadID="14308" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">107</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Windows.Cortana_cw5n1h2txyewy\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">41</Data>
        <Data Name="DirtyPages">9</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:41:35 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          SYSTEM
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat was cleared updating 3 keys and creating 1 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:41:35.554476400Z" />
        <EventRecordID>8049</EventRecordID>
        <Correlation />
        <Execution ProcessID="9904" ThreadID="1788" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">119</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Windows.ShellExperienceHost_cw5n1h2txyewy\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">3</Data>
        <Data Name="DirtyPages">1</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:41:35 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          SYSTEM
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat was cleared updating 246 keys and creating 28 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:41:35.516437100Z" />
        <EventRecordID>8048</EventRecordID>
        <Correlation />
        <Execution ProcessID="1948" ThreadID="13056" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">122</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">246</Data>
        <Data Name="DirtyPages">28</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-DistributedCOM
    Date:          8/2/2018 9:41:33 AM
    Event ID:      10016
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          LOCAL SERVICE
    Computer:      CLK23.eddycountynm.local
    Description:
    The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
    {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
     and APPID 
    {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
     to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
        <EventID Qualifiers="0">10016</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8080000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:41:33.985582900Z" />
        <EventRecordID>8047</EventRecordID>
        <Correlation />
        <Execution ProcessID="1076" ThreadID="13592" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-19" />
      </System>
      <EventData>
        <Data Name="param1">application-specific</Data>
        <Data Name="param2">Local</Data>
        <Data Name="param3">Activation</Data>
        <Data Name="param4">{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}</Data>
        <Data Name="param5">{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}</Data>
        <Data Name="param6">NT AUTHORITY</Data>
        <Data Name="param7">LOCAL SERVICE</Data>
        <Data Name="param8">S-1-5-19</Data>
        <Data Name="param9">LocalHost (Using LRPC)</Data>
        <Data Name="param10">Unavailable</Data>
        <Data Name="param11">Unavailable</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-DistributedCOM
    Date:          8/2/2018 9:41:33 AM
    Event ID:      10016
    Task Category: None
    Level:         Error
    Keywords:      Classic
    User:          LOCAL SERVICE
    Computer:      CLK23.eddycountynm.local
    Description:
    The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID 
    {6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}
     and APPID 
    {4839DDB7-58C2-48F5-8283-E1D1807D0D7D}
     to the user NT AUTHORITY\LOCAL SERVICE SID (S-1-5-19) from address LocalHost (Using LRPC) running in the application container Unavailable SID (Unavailable). This security permission can be modified using the Component Services administrative tool.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-DistributedCOM" Guid="{1B562E86-B7AA-4131-BADC-B6F3A001407E}" EventSourceName="DCOM" />
        <EventID Qualifiers="0">10016</EventID>
        <Version>0</Version>
        <Level>2</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8080000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:41:33.983485800Z" />
        <EventRecordID>8046</EventRecordID>
        <Correlation />
        <Execution ProcessID="1076" ThreadID="9052" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-19" />
      </System>
      <EventData>
        <Data Name="param1">application-specific</Data>
        <Data Name="param2">Local</Data>
        <Data Name="param3">Activation</Data>
        <Data Name="param4">{6B3B8D23-FA8D-40B9-8DBD-B950333E2C52}</Data>
        <Data Name="param5">{4839DDB7-58C2-48F5-8283-E1D1807D0D7D}</Data>
        <Data Name="param6">NT AUTHORITY</Data>
        <Data Name="param7">LOCAL SERVICE</Data>
        <Data Name="param8">S-1-5-19</Data>
        <Data Name="param9">LocalHost (Using LRPC)</Data>
        <Data Name="param10">Unavailable</Data>
        <Data Name="param11">Unavailable</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:41:33 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          SYSTEM
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\ken-admin\ntuser.dat was cleared updating 54 keys and creating 32 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:41:33.655894700Z" />
        <EventRecordID>8045</EventRecordID>
        <Correlation />
        <Execution ProcessID="1780" ThreadID="6708" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">33</Data>
        <Data Name="HiveName">\??\C:\Users\ken-admin\ntuser.dat</Data>
        <Data Name="KeysUpdated">54</Data>
        <Data Name="DirtyPages">32</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Winlogon
    Date:          8/2/2018 9:41:33 AM
    Event ID:      7001
    Task Category: (1101)
    Level:         Information
    Keywords:      (35184372088832)
    User:          SYSTEM
    Computer:      CLK23.eddycountynm.local
    Description:
    User Logon Notification for Customer Experience Improvement Program
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Winlogon" Guid="{DBE9B383-7CF3-4331-91CC-A3CB16A3B538}" />
        <EventID>7001</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>1101</Task>
        <Opcode>0</Opcode>
        <Keywords>0x2000200000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:41:33.636227900Z" />
        <EventRecordID>8044</EventRecordID>
        <Correlation />
        <Execution ProcessID="2176" ThreadID="5160" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="TSId">2</Data>
        <Data Name="UserSid">S-1-5-21-275593300-1636143335-3899451950-1826</Data>
      </EventData>
    </Event>
    
    Log Name:      System
    Source:        Microsoft-Windows-Kernel-General
    Date:          8/2/2018 9:40:45 AM
    Event ID:      16
    Task Category: None
    Level:         Information
    Keywords:      
    User:          SYSTEM
    Computer:      CLK23.eddycountynm.local
    Description:
    The access history in hive \??\C:\Users\amy\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat was cleared updating 5 keys and creating 1 modified pages.
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Kernel-General" Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
        <EventID>16</EventID>
        <Version>0</Version>
        <Level>4</Level>
        <Task>0</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8000000000000000</Keywords>
        <TimeCreated SystemTime="2018-08-02T15:40:45.533314100Z" />
        <EventRecordID>8043</EventRecordID>
        <Correlation />
        <Execution ProcessID="2088" ThreadID="4576" />
        <Channel>System</Channel>
        <Computer>CLK23.eddycountynm.local</Computer>
        <Security UserID="S-1-5-18" />
      </System>
      <EventData>
        <Data Name="HiveNameLength">102</Data>
        <Data Name="HiveName">\??\C:\Users\amy\AppData\Local\Packages\Microsoft.AAD.BrokerPlugin_cw5n1h2txyewy\Settings\settings.dat</Data>
        <Data Name="KeysUpdated">5</Data>
        <Data Name="DirtyPages">1</Data>
      </EventData>
    </Event>

    Wednesday, August 8, 2018 11:23 PM
  • I found the problem.  I had to uninstall Microsoft Office Desktop Apps from Settings|Apps.  I originally encountered this solution in https://www.slipstick.com/problems/the-stationery-and-font-button-doesnt-work/ while working on a problem involving Outlook 2013 signatures.  It tried it on this problem and solved it as well.

    Thank you to all who provided suggestions.

    Wednesday, August 15, 2018 11:46 PM