Event Viewer Error 4201

How to Fix the Event Viewer 4201 Error in Vista

information   Information
This will show you how to fix the Event viewer if you are getting this error :

ERROR_WMI_INSTANCE_NOT_FOUND
4201 The instance name passed was not recognized as valid by a WMI data provider

warning   Warning
This may only work if you did a clean install of Vista and not a upgrade from XP. Instead, use this method for a upgrade verion of Vista to have it install as a clean install: How to Do a Clean Install of Vista with a Upgrade Version


Note   Note
One usual cause of this error is a corrupted Repository file.




Here's How:
1. Restart the computer into Safe Mode (without networking).​
2. In Safe Mode, open a elevated command prompt.​
3. In the elevated command prompt, type net stop winmgmt and press Enter.​
NOTE: This is to make certain the wmi service is not running.
4. Wait until the successful message appears, then close the elevated command prompt.​
5. Open Windows Explorer and navigate to C:\Windows\System32\wbem.​
6. Right click on the Repository folder and click on Rename.​
7. Type in RepositoryOld and press Enter.​
NOTE: This is to make this a backup of the original Repository folder.
8. Restart the computer back into normal mode to an administrator account.​
9. When it is done starting up, open a elevated command prompt.​
10. In the elevated command prompt, type net stop winmgmt and press Enter.​
NOTE: This is to make certain the wmi service is not running.
11. Wait until successful message appears, and then type winmgmt /resetRepository in the elevated command prompt and press Enter.​
12. Wait until the successful message appears and then close the elevated command prompt.​
13. Take ownership of these two files:​
  • C:\windows\logs
  • C:\windows\system32\logfiles
14. Restart the computer.​
15. Test the Event Viewer. It should be working now.​
16. If it is working again, then go back and delete the RepositoryOld folder. (See step 7)​
17. If it is still not working for you, then do a System Restore using a restore point dated before the problem.​
That's it,
Shawn



 

Attachments

  • thumb_Event_Viewer.jpg
    thumb_Event_Viewer.jpg
    2.8 KB · Views: 488
Last edited by a moderator:
I tried your suggestion but the system security will not allow me to rename the repository folder. I tried changing ownership and adding my specific user to the folder and contents with full control but no such luck.

Attached is a screen print of "Access Denied" error message.

By the way I did this with the "Administrator" user.

Now what? :cry:

Access Denied.jpg
 

My Computer

System One

  • CPU
    Core 2 Duo E6550
    Motherboard
    ASUS P5N-E SLI
    Memory
    2048MB Corsair™ DDR2 PC6400 DDR2-800
    Graphics Card(s)
    NVIDIA® GeForce™ 8600 GTS
    Hard Drives
    400GB 7200RPM SATA (OS)
    160GB 7200RPM ATA
Hi Rocky, and welcome to Vista Forums.

I updated the steps a little to help. Try again and see what you get this time.

Hope this helps,
Shawn
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro 64-bit
    Manufacturer/Model
    Custom
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G7 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO PRO M.2,
    8TB WD MyCloudEX2Ultra NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3
    Cooling
    Corsair Hydro H115i
    Keyboard
    Logitech wireless K800
    Mouse
    Logitech MX Master 3
    Internet Speed
    1 Gb/s Download and 35 Mb/s Upload
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    APC SMART-UPS RT 1000 XL - SURT1000XLI,
    Galaxy S23 Plus phone
  • Operating System
    Windows 10 Pro
    Manufacturer/Model
    HP Envy Y0F94AV
    CPU
    i7-7500U @ 2.70 GHz
    Memory
    16 GB DDR4-2133
    Graphics card(s)
    NVIDIA GeForce 940MX
    Sound Card
    Conexant ISST Audio
    Monitor(s) Displays
    17.3" UHD IPS touch
    Screen Resolution
    3480 x 2160
    Hard Drives
    512 GB M.2 SSD
Hi Shawn,

I have been trying this approach to getting my event viewer running so that i can install vista sp1 and have religiously followed these steps. All the confirmations have worked and the repository folder has been reset yet I still get the same error message when i try and manually start the event viewer service. I would restore to a point before the problem but it seems the problem has always been there as I reinstalled vista only about a month ago. I am worried about doing a repair install as I have several software's on this machine worth a fortune and no install files for them. Are there any other ways to get the event viewer running or sp1 installed without having to take those steps?

Thanks a million

Evan
 

My Computer

System One

  • Manufacturer/Model
    Lenovo
Hi Evan, and welcome to Vista Forums.

Have you already tried setting this Event Viewer service to just Automatic and restart the computer to allow it to start that way? You might also double check to make sure that all of it's Dependencies (other required services) are started to.

If you had to, a Repair install will not delete any installed software. It may remove the shortcuts for some of them in the Start menu, but you can easily recreate those from the program's exe file if needed.

Hope this helps,
Shawn
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro 64-bit
    Manufacturer/Model
    Custom
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G7 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO PRO M.2,
    8TB WD MyCloudEX2Ultra NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3
    Cooling
    Corsair Hydro H115i
    Keyboard
    Logitech wireless K800
    Mouse
    Logitech MX Master 3
    Internet Speed
    1 Gb/s Download and 35 Mb/s Upload
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    APC SMART-UPS RT 1000 XL - SURT1000XLI,
    Galaxy S23 Plus phone
  • Operating System
    Windows 10 Pro
    Manufacturer/Model
    HP Envy Y0F94AV
    CPU
    i7-7500U @ 2.70 GHz
    Memory
    16 GB DDR4-2133
    Graphics card(s)
    NVIDIA GeForce 940MX
    Sound Card
    Conexant ISST Audio
    Monitor(s) Displays
    17.3" UHD IPS touch
    Screen Resolution
    3480 x 2160
    Hard Drives
    512 GB M.2 SSD
Hi Shawn,

Thank you for replying to my post. I had tried that to no avail but after some persistance I managed to follow some instructions on a post which solved the issue about an hour ago.

Thanks once again for your suggestions

Evan
 

My Computer

System One

  • Manufacturer/Model
    Lenovo
I'm happy to hear that you got it sorted out Evan. Could you post the link to that post so that others with the same problem may be able solve their problem as well.

Thank you,
Shawn
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro 64-bit
    Manufacturer/Model
    Custom
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G7 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO PRO M.2,
    8TB WD MyCloudEX2Ultra NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3
    Cooling
    Corsair Hydro H115i
    Keyboard
    Logitech wireless K800
    Mouse
    Logitech MX Master 3
    Internet Speed
    1 Gb/s Download and 35 Mb/s Upload
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    APC SMART-UPS RT 1000 XL - SURT1000XLI,
    Galaxy S23 Plus phone
  • Operating System
    Windows 10 Pro
    Manufacturer/Model
    HP Envy Y0F94AV
    CPU
    i7-7500U @ 2.70 GHz
    Memory
    16 GB DDR4-2133
    Graphics card(s)
    NVIDIA GeForce 940MX
    Sound Card
    Conexant ISST Audio
    Monitor(s) Displays
    17.3" UHD IPS touch
    Screen Resolution
    3480 x 2160
    Hard Drives
    512 GB M.2 SSD
Hi All,

After trying a few things after having started with the process at the top of this page I ended up following the steps at the following link and it has solved the problem:

Re: Serious security concern: event log error 4201 - MSDN Forums

It all started when I couldn't install vista SP1 and then traced back to the eventlog and viewer services being unable to start - it seems a few folk have been having the issue and I'm pleased to announce that this has worked (well so far - I'm only an hour and a half in :) ). The services now run and so far as I can tell there are no other deleterious effects. Vista sp1 has also now finally installed without difficulty. It all looked way too complicated at the beginning but if a simple plant breeder can pull it off - hopefully so can you. I hope this helps.

Evan
 

My Computer

System One

  • Manufacturer/Model
    Lenovo
Thank you Evan for posting this link so that it can help others.

Shawn
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro 64-bit
    Manufacturer/Model
    Custom
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G7 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO PRO M.2,
    8TB WD MyCloudEX2Ultra NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3
    Cooling
    Corsair Hydro H115i
    Keyboard
    Logitech wireless K800
    Mouse
    Logitech MX Master 3
    Internet Speed
    1 Gb/s Download and 35 Mb/s Upload
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    APC SMART-UPS RT 1000 XL - SURT1000XLI,
    Galaxy S23 Plus phone
  • Operating System
    Windows 10 Pro
    Manufacturer/Model
    HP Envy Y0F94AV
    CPU
    i7-7500U @ 2.70 GHz
    Memory
    16 GB DDR4-2133
    Graphics card(s)
    NVIDIA GeForce 940MX
    Sound Card
    Conexant ISST Audio
    Monitor(s) Displays
    17.3" UHD IPS touch
    Screen Resolution
    3480 x 2160
    Hard Drives
    512 GB M.2 SSD
In my case taking ownership of c:\windows\logs and c:\windows\system32\logfiles\ resolved the issue.
 

My Computer

System One

  • Manufacturer/Model
    Self built
    CPU
    Intel E8400 3GHz
    Motherboard
    Intel DX48BT2
    Memory
    Kingston PC3-10666 4Gb
    Graphics Card(s)
    XFX 9800 GTX XXX
    Sound Card
    Soundblaster X-Fi XtremeMusic
    Monitor(s) Displays
    2x Samsung SM-T220HD 22"
    Screen Resolution
    1680x1050 on two monitors
    Hard Drives
    WD Raptor X/150Gb in RAID0
    WD Raptor 36gb
    3x Samsung F1 1Tb
    PSU
    Thermaltake ToughPower 850w
    Case
    Thermaltake Armor
    Cooling
    Tuniq Tower 120
    Keyboard
    Dell Multimedia Enhanced USB
    Mouse
    Razer Diamondback 3G
    Internet Speed
    8128/832
    Other Info
    Thermaltake Muse esata caddy
Thank you Swarfega. It has been included in the tutorial to helps others.

Shawn
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro 64-bit
    Manufacturer/Model
    Custom
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G7 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO PRO M.2,
    8TB WD MyCloudEX2Ultra NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3
    Cooling
    Corsair Hydro H115i
    Keyboard
    Logitech wireless K800
    Mouse
    Logitech MX Master 3
    Internet Speed
    1 Gb/s Download and 35 Mb/s Upload
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    APC SMART-UPS RT 1000 XL - SURT1000XLI,
    Galaxy S23 Plus phone
  • Operating System
    Windows 10 Pro
    Manufacturer/Model
    HP Envy Y0F94AV
    CPU
    i7-7500U @ 2.70 GHz
    Memory
    16 GB DDR4-2133
    Graphics card(s)
    NVIDIA GeForce 940MX
    Sound Card
    Conexant ISST Audio
    Monitor(s) Displays
    17.3" UHD IPS touch
    Screen Resolution
    3480 x 2160
    Hard Drives
    512 GB M.2 SSD
Fixed Event Viewer Error 4201

I researched several forums and none of the suggestions worked. So I compared the folder permissions to c:\windows\system32\logfiles\wmi\rtbackup to a working machine. Navigate to rtbackup properties and check security settings. It requires SYSTEM - full control. I added this permission and rebooted PC to fix the issue. I can now access my event viewer.
 

My Computer

I got to the point of taking ownership of the LOG files / folder and it gave me an error saying the files were in use. I'm thinking about installing Unlokr and forcing an unlock on the files and then trying it. What do you think?
-dennis
 

My Computer

Hello Dennis, and welcome to Vista Forums.

Do you have them open or Event Viewer open? Were you able to do all of the other steps above without getting any errors?

If not, you might see if you may be able to do it after restarting the computer or in Safe Mode first.
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro 64-bit
    Manufacturer/Model
    Custom
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G7 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO PRO M.2,
    8TB WD MyCloudEX2Ultra NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3
    Cooling
    Corsair Hydro H115i
    Keyboard
    Logitech wireless K800
    Mouse
    Logitech MX Master 3
    Internet Speed
    1 Gb/s Download and 35 Mb/s Upload
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    APC SMART-UPS RT 1000 XL - SURT1000XLI,
    Galaxy S23 Plus phone
  • Operating System
    Windows 10 Pro
    Manufacturer/Model
    HP Envy Y0F94AV
    CPU
    i7-7500U @ 2.70 GHz
    Memory
    16 GB DDR4-2133
    Graphics card(s)
    NVIDIA GeForce 940MX
    Sound Card
    Conexant ISST Audio
    Monitor(s) Displays
    17.3" UHD IPS touch
    Screen Resolution
    3480 x 2160
    Hard Drives
    512 GB M.2 SSD
I was able to do the above steps and reboot in safe mode.
I had to mess with it a bit to get the repository folder to rename (it was in use too). But when I tried to take ownership / change permissions. That's when I got the "in use" error. I was rebooted in safe mode too.
Should I use unlokr? It seems like the taking ownership is a critical step in fixing this problem.
 

My Computer

Yes, go ahead and try unlocker to see if it will allow you to afterwards.
 

My Computers

System One System Two

  • Operating System
    Windows 10 Pro 64-bit
    Manufacturer/Model
    Custom
    CPU
    Intel i7-8700K 5 GHz
    Motherboard
    ASUS ROG Maximus XI Formula Z390
    Memory
    64 GB (4x16GB) G.SKILL TridentZ RGB DDR4 3600 MHz (F4-3600C18D-32GTZR)
    Graphics Card(s)
    ASUS ROG-STRIX-GTX1080TI-O11G-GAMING
    Sound Card
    Integrated Digital Audio (S/PDIF)
    Monitor(s) Displays
    2 x Samsung Odyssey G7 27"
    Screen Resolution
    2560x1440
    Hard Drives
    1TB Samsung 990 PRO M.2,
    4TB Samsung 990 PRO PRO M.2,
    8TB WD MyCloudEX2Ultra NAS
    PSU
    Seasonic Prime Titanium 850W
    Case
    Thermaltake Core P3
    Cooling
    Corsair Hydro H115i
    Keyboard
    Logitech wireless K800
    Mouse
    Logitech MX Master 3
    Internet Speed
    1 Gb/s Download and 35 Mb/s Upload
    Other Info
    Logitech Z625 speaker system,
    Logitech BRIO 4K Pro webcam,
    HP Color LaserJet Pro MFP M477fdn,
    APC SMART-UPS RT 1000 XL - SURT1000XLI,
    Galaxy S23 Plus phone
  • Operating System
    Windows 10 Pro
    Manufacturer/Model
    HP Envy Y0F94AV
    CPU
    i7-7500U @ 2.70 GHz
    Memory
    16 GB DDR4-2133
    Graphics card(s)
    NVIDIA GeForce 940MX
    Sound Card
    Conexant ISST Audio
    Monitor(s) Displays
    17.3" UHD IPS touch
    Screen Resolution
    3480 x 2160
    Hard Drives
    512 GB M.2 SSD
This method work great for this:

Boot Vista DVD

choose language>>repair computer>>WinRE>>command prompt
and type:

RD /S C:\Windows\System32\LogFiles\WMI\RtBackup

gone :)
 

My Computer

:cool: worked sweet as for win7. cheers bud
 

My Computer

System One

  • Manufacturer/Model
    xfx custom
    CPU
    QuadCore Intel Core 2 Extreme QX9650, 3000 MHz (9 x
    Motherboard
    XFX MB-N780-ISH9
    Memory
    4096 MB (DDR2-800 DDR2 SDRAM)
    Graphics Card(s)
    NVIDIA GeForce 9800 GTX/9800 GTX+ (512 MB)
    Sound Card
    Realtek ALC888/1200
    Monitor(s) Displays
    Philips 180P
Back
Top