Microsoft-Windows-NtfsLog_c2df6c7f2eb93a240df3cc4d073d362f
708 events across 1 channel
Event ID 10 — NtfsLookupRealAllocation: Vcn A10_Vcn!
Description
NtfsLookupRealAllocation: Vcn A10_Vcn!I64x!, LowestVcn A11_AttributeFormNonresidentLowestVcn!I64x!, HighestVcn A12_AttributeFormNonresidentHighestVcn!I64x!, AllocationClusters A13_AllocationClusters!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcn HexInt64 | — |
A11_AttributeFormNonresidentLowestVcn HexInt64 | — |
A12_AttributeFormNonresidentHighestVcn HexInt64 | — |
A13_AllocationClusters HexInt64 | — |
Event ID 11 — NtfsAllocateAttribute MaxAlloc for Mft's AttrList IC:A10_IrpContext, Scb:A11_Scb.
Event ID 12 — FileObject: A10_FileObject, Scb: A11_Scb, StaringVcn: A12_StartingVcn!
Description
FileObject: A10_FileObject, Scb: A11_Scb, StaringVcn: A12_StartingVcn!I64x!, ClusterCount: A13_ClusterCount!I64x!, Flags: A14_Flags!08x!, CcbForWriteExtend: A15_CcbForWriteExtend.
Message #
Fields #
| Name | Description |
|---|---|
A10_FileObject Pointer | — |
A11_Scb Pointer | — |
A12_StartingVcn HexInt64 | — |
A13_ClusterCount HexInt64 | — |
A14_Flags HexInt32 | — |
A15_CcbForWriteExtend Pointer | — |
Event ID 13 — NtfsAddAllocation IC:A10_IrpContext, FileObject:A11_FileObject, Scb:A12_Scb, StaringVcn:A13_StartingVcn!
Description
NtfsAddAllocation IC:A10_IrpContext, FileObject:A11_FileObject, Scb:A12_Scb, StaringVcn:A13_StartingVcn!I64x!, ClusterCount:A14_ClusterCount!I64x!, Flags:A15_Flags!08x!, CcbForWriteExtend:A16_CcbForWriteExtend.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_FileObject Pointer | — |
A12_Scb Pointer | — |
A13_StartingVcn HexInt64 | — |
A14_ClusterCount HexInt64 | — |
A15_Flags HexInt32 | — |
A16_CcbForWriteExtend Pointer | — |
Event ID 14 — Purge failed: Scb: A10_Scb, PurgeOffset: 0xA11_PurgeOffset!
Event ID 15 — Purge failed: Scb: A10_Scb, PurgeOffset: 0xA11_PurgeOffset!
Event ID 16 — NtfsGetLastVcnForNewMappingPairSize IC:A10_IrpContext, Using LastVcn:A11_LastVcn!
Event ID 17 — Can't find StdInfo in FileRef A10_NtfsFullFileRefNumber_FcbFileReference!
Event ID 18 — Can't find StdInfo in FileRef A10_NtfsFullFileRefNumber_FcbFileReference!
Event ID 19 — NtfsCreateNonresidentWithValue Create Mft's NonResident Attribute List IC:A10_IrpContextValueLength:A11_ValueLength, AttrFlags=A12_AttributeFlags.
Event ID 20 — NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!I64x!, LastVcn A14_LastVcn!I64x!, NewHighestVcn A15_NewHighestVcn!I64x!, PassCount A16_PassCount - step 6.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_LastVcn HexInt64 | — |
A15_NewHighestVcn HexInt64 | — |
A16_PassCount HexInt32 | — |
Event ID 21 — NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
NtfsAddAttributeAllocation(!p!,!p!): Scb !p!, FileRef !I64x!, LowestVcn !I64x!, HighestVcn !I64x!, ALE.LowestVcn !I64x! - try to merge backward.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_ContextFoundAttributeAttributeFormNonresidentLowestVcn HexInt64 | — |
A15_ContextFoundAttributeAttributeFormNonresidentHighestVcn HexInt64 | — |
A16_ContextAttributeListEntryLowestVcn HexInt64 | — |
Event ID 22 — NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
NtfsAddAttributeAllocation(!p!,!p!): Scb !p!, FileRef !I64x!, LowestVcn !I64x!, HighestVcn !I64x!, ALE.LowestVcn !I64x! - after merge backward.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_ContextFoundAttributeAttributeFormNonresidentLowestVcn HexInt64 | — |
A15_ContextFoundAttributeAttributeFormNonresidentHighestVcn HexInt64 | — |
A16_ContextAttributeListEntryLowestVcn HexInt64 | — |
Event ID 23 — NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
NtfsAddAttributeAllocation(!p!,!p!): Scb !p!, FileRef !I64x!, LowestVcn !I64x!, HighestVcn !I64x!, ALE.LowestVcn !I64x!, PassCount !x! - before last merge after step 6.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_ContextFoundAttributeAttributeFormNonresidentLowestVcn HexInt64 | — |
A15_ContextFoundAttributeAttributeFormNonresidentHighestVcn HexInt64 | — |
A16_ContextAttributeListEntryLowestVcn HexInt64 | — |
A17_PassCount HexInt32 | — |
Event ID 24 — NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
NtfsAddAttributeAllocation(!p!,!p!): Scb !p!, FileRef !I64x!, LowestVcn !I64x!, HighestVcn !I64x!, ALE.LowestVcn !I64x! - after last merge after step 6.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_ContextFoundAttributeAttributeFormNonresidentLowestVcn HexInt64 | — |
A15_ContextFoundAttributeAttributeFormNonresidentHighestVcn HexInt64 | — |
A16_ContextAttributeListEntryLowestVcn HexInt64 | — |
Event ID 25 — NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!I64x!, MergeSkipCt A14_NtfsFrsConsolidationStatisticsMergeSkipCount - done.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_NtfsFrsConsolidationStatisticsMergeSkipCount HexInt32 | — |
Event ID 26 — NtfsRestartRemoveAttribute FileRef:0xA10_FileRecordSegmentNumberHighPart!
Description
NtfsRestartRemoveAttribute FileRef:0xA10_FileRecordSegmentNumberHighPart!04x!_A11_FileRecordSegmentNumberLowPart!08x!, BaseFRS:0xA12_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment!012I64x!, Attrib:0xA13_AttributeTypeCode.
Message #
Fields #
| Name | Description |
|---|---|
A10_FileRecordSegmentNumberHighPart HexInt32 | — |
A11_FileRecordSegmentNumberLowPart HexInt32 | — |
A12_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment HexInt64 | — |
A13_AttributeTypeCode HexInt32 | — |
Event ID 27 — NtfsRestartChangeValue FileRef:0xA10_FileRecordSegmentNumberHighPart!
Description
NtfsRestartChangeValue FileRef:0xA10_FileRecordSegmentNumberHighPart!04x!_A11_FileRecordSegmentNumberLowPart!08x!, BaseFRS:0xA12_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment!012I64x!, Attrib:0xA13_AttributeTypeCode.
Message #
Fields #
| Name | Description |
|---|---|
A10_FileRecordSegmentNumberHighPart HexInt32 | — |
A11_FileRecordSegmentNumberLowPart HexInt32 | — |
A12_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment HexInt64 | — |
A13_AttributeTypeCode HexInt32 | — |
Event ID 28 — AddToAttributeList(A10_FcbVcb,A11_IrpContext): FRef A12_PULONGLONG_FcbFileReference!
Description
AddToAttributeList(A10_FcbVcb,A11_IrpContext): FRef A12_PULONGLONG_FcbFileReference!I64x!, OldSig A13_StdInfoAttrListEntrySignature, OldLCS A14_StdInfoAttrListEntryLastCompactedSize, NewLCS A15_CurrentAttributeListSize.
Message #
Fields #
| Name | Description |
|---|---|
A10_FcbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_PULONGLONG_FcbFileReference HexInt64 | — |
A13_StdInfoAttrListEntrySignature HexInt32 | — |
A14_StdInfoAttrListEntryLastCompactedSize HexInt32 | — |
A15_CurrentAttributeListSize HexInt32 | — |
Event ID 29 — DeleteFromAttributeList(A10_FcbVcb,A11_IrpContext): FRef A12_PULONGLONG_FcbFileReference!
Description
DeleteFromAttributeList(A10_FcbVcb,A11_IrpContext): FRef A12_PULONGLONG_FcbFileReference!I64x!, OldSig A13_StdInfoAttrListEntrySignature, OldLCS A14_StdInfoAttrListEntryLastCompactedSize, NewLCS A15_NewStdInfoAttrListEntryLastCompactedSize.
Message #
Fields #
| Name | Description |
|---|---|
A10_FcbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_PULONGLONG_FcbFileReference HexInt64 | — |
A13_StdInfoAttrListEntrySignature HexInt32 | — |
A14_StdInfoAttrListEntryLastCompactedSize HexInt32 | — |
A15_NewStdInfoAttrListEntryLastCompactedSize HexInt32 | — |
Event ID 30 — MakeRoomForAttribute Moving Mft's attribute IC:A10_IrpContext, Moving Attrib A11_i/A12_MAX_MOVEABLE_ATTRIBUTES, Type=A13_AttributeTypeCode, RecLengh=A14_AttributeRecordLength, Instance:A15_Attribut...
Description
MakeRoomForAttribute Moving Mft's attribute IC:A10_IrpContext, Moving Attrib A11_i/A12_MAX_MOVEABLE_ATTRIBUTES, Type=A13_AttributeTypeCode, RecLengh=A14_AttributeRecordLength, Instance:A15_AttributeInstance.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_i HexInt32 | — |
A12_MAX_MOVEABLE_ATTRIBUTES HexInt32 | — |
A13_AttributeTypeCode HexInt32 | — |
A14_AttributeRecordLength HexInt32 | — |
A15_AttributeInstance HexInt32 | — |
Event ID 31 — MoveAttributeToOwnRecord Moving Mft's $BITMAP IC:A10_IrpContext, SizeNeeded:A11_SizeNeeded, TypeCode:A12_AttributeTypeCode, RecLen:A13_AttributeRecordLength, Form:A14_AttributeFormCode, Instance:A1...
Description
MoveAttributeToOwnRecord Moving Mft's $BITMAP IC:A10_IrpContext, SizeNeeded:A11_SizeNeeded, TypeCode:A12_AttributeTypeCode, RecLen:A13_AttributeRecordLength, Form:A14_AttributeFormCode, Instance:A15_AttributeInstance.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_SizeNeeded HexInt32 | — |
A12_AttributeTypeCode HexInt32 | — |
A13_AttributeRecordLength HexInt32 | — |
A14_AttributeFormCode HexInt32 | — |
A15_AttributeInstance HexInt32 | — |
Event ID 32 — MoveAttributeToOwnRecord IC:A10_IrpContext, SizeNeeded:A11_SizeNeeded, Bytes2Free:A12_BytesToFree, OldMappingSize:A13_MappingPairSize, NewMappingSize:A14_NewMappingPairSize.
Description
MoveAttributeToOwnRecord IC:A10_IrpContext, SizeNeeded:A11_SizeNeeded, Bytes2Free:A12_BytesToFree, OldMappingSize:A13_MappingPairSize, NewMappingSize:A14_NewMappingPairSize.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_SizeNeeded HexInt32 | — |
A12_BytesToFree HexInt32 | — |
A13_MappingPairSize HexInt32 | — |
A14_NewMappingPairSize HexInt32 | — |
Event ID 33 — NtfsRestartZeroEndOfFileRecord FileRef:0xA10_FileRecordSegmentNumberHighPart!
Description
NtfsRestartZeroEndOfFileRecord FileRef:0xA10_FileRecordSegmentNumberHighPart!04x!_A11_FileRecordSegmentNumberLowPart!08x!, BaseFRS:0xA12_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment!012I64x!, Start:0xA13_StartZero, Len:0xA14_ZeroLength.
Message #
Fields #
| Name | Description |
|---|---|
A10_FileRecordSegmentNumberHighPart HexInt32 | — |
A11_FileRecordSegmentNumberLowPart HexInt32 | — |
A12_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment HexInt64 | — |
A13_StartZero HexInt32 | — |
A14_ZeroLength HexInt32 | — |
Event ID 34 — MergeFRS2(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
MergeFRS2(!p!,!p!): Scb !p!, FileRef !I64x!, TypeCode !x!, AttrName !S!, LowVcn !I64x!, HalfWayVcn !I64x!, FinalVcn !I64x!, PackedMode !x!, TryPrior !x! - about to merge.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_ScbAttributeTypeCode HexInt32 | — |
A15__ScbAttributeName CountedUtf16String | — |
A16_NewStartVcn HexInt64 | — |
A17_NewHalfWayVcn HexInt64 | — |
A18_NewFinalVcn HexInt64 | — |
A19_PackedMode HexInt32 | — |
A20_TryPrior HexInt32 | — |
Event ID 35 — MergeFRS2(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
MergeFRS2(!p!,!p!): Scb !p!, FileRef !I64x!, TypeCode !x!, AttrName !S!, DeleteFileRef !x!0000!08x!, LowVcn !I64x!, LastVcn !I64x!, FinalVcn !I64x! - all fit in one so get rid of the second one.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_ScbAttributeTypeCode HexInt32 | — |
A15__ScbAttributeName CountedUtf16String | — |
A16_FileRecordSequenceNumber HexInt32 | — |
A17_FileRecordSegmentNumberLowPart HexInt32 | — |
A18_NewStartVcn HexInt64 | — |
A19_LastVcn HexInt64 | — |
A20_NewFinalVcn HexInt64 | — |
Event ID 36 — MergeFRS2.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_ScbAttributeTypeCode HexInt32 | — |
A15__ScbAttributeName CountedUtf16String | — |
A16_FileRecordSequenceNumber HexInt32 | — |
A17_FileRecordSegmentNumberLowPart HexInt32 | — |
A18_NewStartVcn HexInt64 | — |
A19_LastVcn HexInt64 | — |
A20_NewFinalVcn HexInt64 | — |
Event ID 37 — MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!I64x!, Vcn A14_NewFinalVcn!I64x! - initial RangePtr query.
Message #
Fields #
| Name | Description |
|---|---|
A10_ScbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_NewFinalVcn HexInt64 | — |
Event ID 38 — MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!I64x!, Vcn A14_NewHalfWayVcn!I64x!, Rptr A15_RangePtr - secondary RangePtr query.
Message #
Fields #
| Name | Description |
|---|---|
A10_ScbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_NewHalfWayVcn HexInt64 | — |
A15_RangePtr Pointer | — |
Event ID 39 — MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!I64x!, Vcn A14_NewHalfWayVcn!I64x!, Rptr A15_RangePtr - calling lookup runs range.
Message #
Fields #
| Name | Description |
|---|---|
A10_ScbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_NewHalfWayVcn HexInt64 | — |
A15_RangePtr Pointer | — |
Event ID 40 — MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!I64x!, McbArray A14_NtfsMcbArray (A15_NtfsMcbArrayStartingVcn!I64x!, A16_NtfsMcbArrayEndingVcn!I64x!) - current McbArray.
Message #
Fields #
| Name | Description |
|---|---|
A10_ScbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_NtfsMcbArray Pointer | — |
A15_NtfsMcbArrayStartingVcn HexInt64 | — |
A16_NtfsMcbArrayEndingVcn HexInt64 | — |
Event ID 41 — MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!I64x!, McbArray A14_NtfsMcbArray (A15_NtfsMcbArrayStartingVcn!I64x!, A16_NtfsMcbArrayEndingVcn!I64x!) - previous McbArray.
Message #
Fields #
| Name | Description |
|---|---|
A10_ScbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_NtfsMcbArray Pointer | — |
A15_NtfsMcbArrayStartingVcn HexInt64 | — |
A16_NtfsMcbArrayEndingVcn HexInt64 | — |
Event ID 42 — MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!I64x!, McbArray A14_NtfsMcbArray (A15_NtfsMcbArrayStartingVcn!I64x!, A16_NtfsMcbArrayEndingVcn!I64x!) - prev prev McbArray.
Message #
Fields #
| Name | Description |
|---|---|
A10_ScbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_NtfsMcbArray Pointer | — |
A15_NtfsMcbArrayStartingVcn HexInt64 | — |
A16_NtfsMcbArrayEndingVcn HexInt64 | — |
Event ID 43 — MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!I64x!, McbArray A14_NtfsMcbArray (A15_NtfsMcbArrayStartingVcn!I64x!, A16_NtfsMcbArrayEndingVcn!I64x!) - next McbArray.
Message #
Fields #
| Name | Description |
|---|---|
A10_ScbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_NtfsMcbArray Pointer | — |
A15_NtfsMcbArrayStartingVcn HexInt64 | — |
A16_NtfsMcbArrayEndingVcn HexInt64 | — |
Event ID 44 — MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!I64x!, NewFinalVcnInMcb A14_NewFinalVcnInMcb!I64x! > NewFinalVcn A15_NewFinalVcn!I64x! - NewFinalVcn is smaller.
Message #
Fields #
| Name | Description |
|---|---|
A10_ScbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_NewFinalVcnInMcb HexInt64 | — |
A15_NewFinalVcn HexInt64 | — |
Event ID 45 — MergeFRS2.
Message #
Fields #
| Name | Description |
|---|---|
A10_ScbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_NewStartVcn HexInt64 | — |
A15_LastVcn HexInt64 | — |
A16_NewFinalVcn HexInt64 | — |
A17_NewFinalVcnInMcb HexInt64 | — |
A18_NumberOfRanges HexInt32 | — |
A19_DeletedNextAttribute HexInt32 | — |
A20_Mcb1StartWithNewStartVcn HexInt32 | — |
A21_Mcb1HoldNewStartVcn HexInt32 | — |
A22_Mcb2StartWithNewStartVcn HexInt32 | — |
A23_Mcb2HoldNewStartVcn HexInt32 | — |
A24_McbArraySizeInUseChange Int32 | — |
Event ID 46 — MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!I64x!, StartingVcn A14_NewStartVcn!I64x!, EndingVcn A15_DeletedNextAttributeNewFinalVcnInMcbLastVcn1!I64x! - redefined mcb range1.
Message #
Fields #
| Name | Description |
|---|---|
A10_ScbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_NewStartVcn HexInt64 | — |
A15_DeletedNextAttributeNewFinalVcnInMcbLastVcn1 HexInt64 | — |
Event ID 47 — MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
MergeFRS2(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!I64x!, StartingVcn A14_LastVcn!I64x!, EndingVcn A15_NewFinalVcnInMcb!I64x! - redefined mcb range2.
Message #
Fields #
| Name | Description |
|---|---|
A10_ScbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_LastVcn HexInt64 | — |
A15_NewFinalVcnInMcb HexInt64 | — |
Event ID 48 — RedoAttribute(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
RedoAttribute(!p!,!p!): Scb !p!, FileRef !I64x!, TypeCode !x!, AttrName !S!, FileRef !I64x!, OldLowVcn !I64x!, NewLowVcn !I64x!, Instance !x! - updating LowestVcn in attribute list entry.
Message #
Fields #
| Name | Description |
|---|---|
A10_ScbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_ScbAttributeTypeCode HexInt32 | — |
A15__ScbAttributeName CountedUtf16String | — |
A16_PULONGLONG_ContextAttributeListEntrySegmentReference HexInt64 | — |
A17_OldLowestVcn HexInt64 | — |
A18_StartVcn HexInt64 | — |
A19_NewAttributeInstance HexInt32 | — |
Event ID 49 — RedoAttribute(A10_ScbVcb,A11_IrpContext): Scb A12_Scb, FileRef A13_PULONGLONG_ScbFcbFileReference!
Description
RedoAttribute(!p!,!p!): Scb !p!, FileRef !I64x!, TypeCode !x!, AttrName !S!, OldLowVcn !I64x!, NewLowVcn !I64x!, OldHighVcn !I64x!, NewHighVcn !I64x!, ChildRef !x!0000!08x! - done.
Message #
Fields #
| Name | Description |
|---|---|
A10_ScbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A14_ScbAttributeTypeCode HexInt32 | — |
A15__ScbAttributeName CountedUtf16String | — |
A16_OldLowestVcn HexInt64 | — |
A17_StartVcn HexInt64 | — |
A18_OldHighestVcn HexInt64 | — |
A19_LastVcn HexInt64 | — |
A20_FileRecordSequenceNumber HexInt32 | — |
A21_FileRecordSegmentNumberLowPart HexInt32 | — |
Event ID 50 — NtfsConsolidateAllFileRecords: Invalid Vcb.
Event ID 51 — NtfsConsolidateAllFileRecords: Volume is locked.
Description
NtfsConsolidateAllFileRecords: Volume is locked. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Volume Id: A14__VolumeId, Vcb State: 0xA15_VcbVcbState!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14__VolumeId CountedUtf16String | — |
A15_VcbVcbState HexInt32 | — |
Event ID 52 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_PULONGLONG_FcbFileReference!
Description
NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_PULONGLONG_FcbFileReference!I64x!, FirstRequest A14_AllFlagsFirstRequest - opened fcb.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Fcb Pointer | — |
A13_PULONGLONG_FcbFileReference HexInt64 | — |
A14_AllFlagsFirstRequest HexInt32 | — |
Event ID 53 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_PULONGLONG_FcbFileReference!
Event ID 54 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_PULONGLONG_FcbFileReference!
Event ID 55 — NtfsConsolidateAllFileRecords.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Fcb Pointer | — |
A13_PULONGLONG_FcbFileReference HexInt64 | — |
A14_FrsConsolidationContextRestartAttributeTypeCode HexInt32 | — |
A15__FrsConsolidationContextRestartAttributeName CountedUtf16String | — |
A16_FrsConsolidationContextRestartVcn HexInt64 | — |
A17_FrsConsolidationContextRestartAttributeListEntryOffset HexInt32 | — |
A18_AttributeListEntryOffset HexInt32 | — |
A19_AttrContextAttributeListAttributeListFormNonresidentValidDataLength HexInt64 | — |
A20_AttributeListGrowBy HexInt32 | — |
A21_AttributeListGrowBy Int32 | — |
Event ID 56 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_PULONGLONG_FcbFileReference!
Description
NtfsConsolidateAllFileRecords(!p!,!p!): Fcb !p!, FileRef !I64x!, TypeCode !x!, AttrName !S!, Vcn !I64x!, Instance !x!, RstrAttrListEntryOffset !x!, AttrListLength !I64x! - breaking up 1.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Fcb Pointer | — |
A13_PULONGLONG_FcbFileReference HexInt64 | — |
A14_FrsConsolidationContextRestartAttributeTypeCode HexInt32 | — |
A15__FrsConsolidationContextRestartAttributeName CountedUtf16String | — |
A16_FrsConsolidationContextRestartVcn HexInt64 | — |
A17_FrsConsolidationContextInstance HexInt32 | — |
A18_FrsConsolidationContextRestartAttributeListEntryOffset HexInt32 | — |
A19_AttrContextAttributeListAttributeListFormNonresidentValidDataLength HexInt64 | — |
Event ID 57 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_PULONGLONG_FcbFileReference!
Description
NtfsConsolidateAllFileRecords(!p!,!p!): Fcb !p!, FileRef !I64x!, TypeCode !x!, AttrName !S!, Vcn !I64x!, Instance !x!, RstrAttrListEntryOffset !x!, AttrListLength !I64x! - breaking up 2.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Fcb Pointer | — |
A13_PULONGLONG_FcbFileReference HexInt64 | — |
A14_FrsConsolidationContextRestartAttributeTypeCode HexInt32 | — |
A15__FrsConsolidationContextRestartAttributeName CountedUtf16String | — |
A16_FrsConsolidationContextRestartVcn HexInt64 | — |
A17_FrsConsolidationContextInstance HexInt32 | — |
A18_FrsConsolidationContextRestartAttributeListEntryOffset HexInt32 | — |
A19_AttrContextAttributeListAttributeListFormNonresidentValidDataLength HexInt64 | — |
Event ID 58 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_PULONGLONG_FcbFileReference!
Description
NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_PULONGLONG_FcbFileReference!I64x!, Scb A14_Scb - completed this Scb.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Fcb Pointer | — |
A13_PULONGLONG_FcbFileReference HexInt64 | — |
A14_Scb Pointer | — |
Event ID 59 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_PULONGLONG_FcbFileReference!
Event ID 60 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): FileRef A12_PULONGLONG_FrsConsolidationContextFileReference!
Description
NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): FileRef A12_PULONGLONG_FrsConsolidationContextFileReference!I64x!, Status A13_IrpContextExceptionStatus - Abnormal Termination.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_PULONGLONG_FrsConsolidationContextFileReference HexInt64 | — |
A13_IrpContextExceptionStatus HexInt32 | — |
Event ID 61 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_PULONGLONG_FcbFileReference!
Event ID 62 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_PULONGLONG_FcbFileReference!
Event ID 63 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_FileRef!
Event ID 64 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_FileRef!
Description
NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_FileRef!I64x!, RemovedFcb A14_RemovedFcb, AllFlags.FcbAcquired A15_AllFlagsFcbAcquired, TransId A16_IrpContextTransactionId - no release.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Fcb Pointer | — |
A13_FileRef HexInt64 | — |
A14_RemovedFcb HexInt32 | — |
A15_AllFlagsFcbAcquired HexInt32 | — |
A16_IrpContextTransactionId HexInt32 | — |
Event ID 65 — NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): DeltaTime A12_EndTimeQuadPart1000NtfsPerformanceFrequencyQuadPart!
Description
NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): DeltaTime A12_EndTimeQuadPart1000NtfsPerformanceFrequencyQuadPart!I64d! (ms), TotalTime A13_FrsConsolidationContextTotalTime1000NtfsPerformanceFrequencyQuadPart!I64d! (ms).
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_EndTimeQuadPart1000NtfsPerformanceFrequencyQuadPart Int64 | — |
A13_FrsConsolidationContextTotalTime1000NtfsPerformanceFrequencyQuadPart Int64 | — |
Event ID 66 — UpdateLCS: Vcb A10_FcbVcb, IC A11_IrpContext, FRef A12_PULONGLONG_FcbFileReference!
Description
UpdateLCS: Vcb A10_FcbVcb, IC A11_IrpContext, FRef A12_PULONGLONG_FcbFileReference!I64x!, OldSig A13_StdInfoAttrListEntrySignature, OldLCS A14_StdInfoAttrListEntryLastCompactedSize, NewLCS A15_AttributeListSize.
Message #
Fields #
| Name | Description |
|---|---|
A10_FcbVcb Pointer | — |
A11_IrpContext Pointer | — |
A12_PULONGLONG_FcbFileReference HexInt64 | — |
A13_StdInfoAttrListEntrySignature HexInt32 | — |
A14_StdInfoAttrListEntryLastCompactedSize HexInt32 | — |
A15_AttributeListSize HexInt32 | — |
Event ID 67 — NtfsAllocateClustersPriv IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: A13__ScbMcb, Vcn: 0xA14_OriginalStartingVcn!
Description
NtfsAllocateClustersPriv IC: !p!, Vcb: !p!, Scb: !p!, Mcb: !p!, Vcn: 0x!I64x!, Length: 0x!I64x!, AllocateAll: !S!, TargetLcn: 0x!I64x!, PreAllocated: !S!, DelayedAllocation: !S!
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_Vcb Pointer | — |
A12_Scb Pointer | — |
A13__ScbMcb Pointer | — |
A14_OriginalStartingVcn HexInt64 | — |
A15_ClusterCount HexInt64 | — |
A16_AllocateAll UInt32 | — |
A17_TargetLcnNULLTargetLcnULONGLONG1 HexInt64 | — |
A18_PreAllocated UInt32 | — |
A19_UseDelayedAllocation UInt32 | — |
Event ID 68 — NtfsAllocateClustersPriv IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: A13__ScbMcb, Vcn: 0xA14_OriginalStartingVcn!
Description
NtfsAllocateClustersPriv IC: !p!, Vcb: !p!, Scb: !p!, Mcb: !p!, Vcn: 0x!I64x!, Length: 0x!I64x!, AllocateAll: !S!, TargetLcn: 0x!I64x!, PreAllocated: !S!, DelayedAllocation: !S!
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_Vcb Pointer | — |
A12_Scb Pointer | — |
A13__ScbMcb Pointer | — |
A14_OriginalStartingVcn HexInt64 | — |
A15_ClusterCount HexInt64 | — |
A16_AllocateAll UInt32 | — |
A17_TargetLcnNULLTargetLcnULONGLONG1 HexInt64 | — |
A18_PreAllocated UInt32 | — |
A19_UseDelayedAllocation UInt32 | — |
Event ID 69 — NtfsAllocateClustersPriv: Incremented TotalAllocated by 0xA10_FoundClusterCount!
Event ID 70 — NtfsAllocateClustersPriv: Skipped incrementing TotalAllocated by 0xA10_FoundClusterCount!
Description
NtfsAllocateClustersPriv: Skipped incrementing TotalAllocated by 0xA10_FoundClusterCount!I64x! clusters, Scb: A11_Scb, TotalAllocated: 0xA12_ScbTotalAllocated!I64x!ScbState: A13_ScbState!08x!, IrpContextState2: A14_IrpContextState2!08x!, AllocateWithNoHole: A15_AllocateWithNoHole.
Message #
Fields #
| Name | Description |
|---|---|
A10_FoundClusterCount HexInt64 | — |
A11_Scb Pointer | — |
A12_ScbTotalAllocated HexInt64 | — |
A13_ScbState HexInt32 | — |
A14_IrpContextState2 HexInt32 | — |
A15_AllocateWithNoHole Int32 | — |
Event ID 71 — NtfsAllocateClustersPriv IC: A10_IrpContext, ClustersAllocated: A11_ClustersAllocated.
Event ID 72 — NtfsAllocateClustersPriv IC: A10_IrpContext, ClustersAllocated: A11_ClustersAllocated.
Event ID 73 — NtfsDeallocateClusters IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: A13__ScbMcb, StartVcn: 0xA14_StartingVcn!
Description
NtfsDeallocateClusters IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: A13__ScbMcb, StartVcn: 0xA14_StartingVcn!I64x!, EndVcn: 0xA15_EndingVcn!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_Vcb Pointer | — |
A12_Scb Pointer | — |
A13__ScbMcb Pointer | — |
A14_StartingVcn HexInt64 | — |
A15_EndingVcn HexInt64 | — |
Event ID 74 — NtfsDeallocateClusters: Vcb A10_Vcb - deleting FR A11_PULONGLONG_ScbFcbFileReference!
Description
NtfsDeallocateClusters: Vcb A10_Vcb - deleting FR A11_PULONGLONG_ScbFcbFileReference!I64x! from clusters A12_StartingVcn!I64x! to A13_EndingVcn!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A12_StartingVcn HexInt64 | — |
A13_EndingVcn HexInt64 | — |
Event ID 75 — NtfsDeallocateClusters IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: A13__ScbMcb, StartVcn: 0xA14_StartingVcn!
Description
NtfsDeallocateClusters IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: A13__ScbMcb, StartVcn: 0xA14_StartingVcn!I64x!, EndVcn: 0xA15_EndingVcn!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_Vcb Pointer | — |
A12_Scb Pointer | — |
A13__ScbMcb Pointer | — |
A14_StartingVcn HexInt64 | — |
A15_EndingVcn HexInt64 | — |
Event ID 76 — NtfsDeallocateClusters: Vcb A10_Vcb - deleting FR A11_PULONGLONG_ScbFcbFileReference!
Description
NtfsDeallocateClusters: Vcb A10_Vcb - deleting FR A11_PULONGLONG_ScbFcbFileReference!I64x! starting at A12_AdjLcn!I64x! for A13_AdjClusterCount!I64x! clusters.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_PULONGLONG_ScbFcbFileReference HexInt64 | — |
A12_AdjLcn HexInt64 | — |
A13_AdjClusterCount HexInt64 | — |
Event ID 77 — NtfsDeallocateClusters: Vcb A10_Vcb - raising logfile full.
Event ID 78 — NtfsDeallocateClusters: Vcb A10_Vcb - adding clusters to DeallocatedClusters: A11_DeallocatedClusters ==> Lsn: A12_DeallocatedClustersLsnQuadPart!
Description
NtfsDeallocateClusters: Vcb !p! - adding clusters to DeallocatedClusters: !p! ==> Lsn: !I64x!, ClusterCount: !I64x!, Flags: !08x!; Vcb's DeallocatedClustersCount old: !I64x! new: !I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_DeallocatedClusters Pointer | — |
A12_DeallocatedClustersLsnQuadPart HexInt64 | — |
A13_DeallocatedClustersClusterCount HexInt64 | — |
A14_DeallocatedClustersFlags HexInt32 | — |
A15_VcbDeallocatedClusters HexInt64 | — |
A16_VcbDeallocatedClustersAdjClusterCount HexInt64 | — |
Event ID 79 — NtfsDeallocateClusters: Decremented TotalAllocated by 0xA10_ClusterCount!
Description
NtfsDeallocateClusters: Decremented TotalAllocated by 0xA10_ClusterCount!I64x! clusters, Scb: A11_Scb, TotalAllocated: 0xA12_TotalAllocated!I64x!Addr(TotalAllocated): A13_TotalAllocated.
Message #
Fields #
| Name | Description |
|---|---|
A10_ClusterCount HexInt64 | — |
A11_Scb Pointer | — |
A12_TotalAllocated HexInt64 | — |
A13_TotalAllocated Pointer | — |
Event ID 80 — NtfsDeallocateClusters: Skipped decrementing TotalAllocated by 0xA10_ClusterCount!
Description
NtfsDeallocateClusters: Skipped decrementing TotalAllocated by 0xA10_ClusterCount!I64x! clusters, Scb: A11_ScbAddr(TotalAllocated): A12_TotalAllocated, ScbState: A13_ScbState!08x!, IrpContextState2: A14_IrpContextState2!08x!
Message #
Fields #
| Name | Description |
|---|---|
A10_ClusterCount HexInt64 | — |
A11_Scb Pointer | — |
A12_TotalAllocated Pointer | — |
A13_ScbState HexInt32 | — |
A14_IrpContextState2 HexInt32 | — |
Event ID 81 — NtfsDeallocateClusters: Vcb A10_Vcb - Undoing some changes to DeallocatedClustersCount from A11_VcbDeallocatedClusters!
Description
NtfsDeallocateClusters: Vcb A10_Vcb - Undoing some changes to DeallocatedClustersCount from A11_VcbDeallocatedClusters!I64x! to A12_VcbDeallocatedClustersClustersRemoved!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_VcbDeallocatedClusters HexInt64 | — |
A12_VcbDeallocatedClustersClustersRemoved HexInt64 | — |
Event ID 82 — NtfsDeallocateClusters IC: A10_IrpContext, ClustersDeallocated: A11_ClustersDeallocated.
Event ID 83 — NtfsDeallocateClusters IC: A10_IrpContext, ClustersDeallocated: A11_ClustersDeallocated.
Event ID 84 — NtfsModifyBitsInBitmap IC: A10_IrpContext, Vcb: A11_Vcb, FirstBit: 0xA12_FirstBit!
Description
NtfsModifyBitsInBitmap IC: A10_IrpContext, Vcb: A11_Vcb, FirstBit: 0xA12_FirstBit!I64x!, BeyondLastBit: 0xA13_BeyondFinalBit!I64x!, Redo: 0xA14_RedoOperation, Undo: 0xA15_UndoOperation.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_Vcb Pointer | — |
A12_FirstBit HexInt64 | — |
A13_BeyondFinalBit HexInt64 | — |
A14_RedoOperation HexInt32 | — |
A15_UndoOperation HexInt32 | — |
Event ID 85 — NtfsModifyBitsInBitmap IC: A10_IrpContext, Bitmap: A11__Bitmap, BaseLcn: 0xA12_BaseLcn!
Event ID 86 — NtfsAllocateBitmapRun IC: A10_IrpContext, Vcb: A11_Vcb, StartingLcn: 0xA12_StartingLcn!
Event ID 87 — NtfsAllocateBitmapRun IC: A10_IrpContext, Bitmap: A11__Bitmap, BaseLcn: 0xA12_BaseLcn!
Event ID 88 — NtfsRestartSetBitsInBitMap IC: A10_IrpContext, Bitmap: A11_Bitmap, BitMapOffset: 0xA12_BitMapOffset!
Event ID 89 — NtfsFreeBitmapRun IC: A10_IrpContext, Vcb: A11_Vcb, StartingLcn: 0xA12_StartingLcn!
Event ID 90 — NtfsFreeBitmapRun IC: A10_IrpContext, Bitmap: A11__Bitmap, BaseLcn: 0xA12_BaseLcn!
Event ID 91 — NtfsRestartClearBitsInBitMap IC: A10_IrpContext, Bitmap: A11_Bitmap, BitMapOffset: 0xA12_BitMapOffset!
Event ID 92 — NtfsSetOrClearBitsUsingBaseMcb IC: A10_IrpContext, Vcb: A11_Vcb, Bitmap: A12_Bitmap, StartingBitmapLcn: 0xA13_StartingBitmapLcn!
Description
NtfsSetOrClearBitsUsingBaseMcb IC: A10_IrpContext, Vcb: A11_Vcb, Bitmap: A12_Bitmap, StartingBitmapLcn: 0xA13_StartingBitmapLcn!I64x!, SetBits: A14_SetBits.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_Vcb Pointer | — |
A12_Bitmap Pointer | — |
A13_StartingBitmapLcn HexInt64 | — |
A14_SetBits UInt32 | — |
Event ID 93 — NtfsSetOrClearBitsUsingBaseMcb IC: A10_IrpContext, Bitmap: A11_Bitmap, StartLcn: 0xA12_StartingBit!
Event ID 94 — NtfsSetOrClearBitsUsingBaseMcb IC: A10_IrpContext, Result: A11_Results.
Event ID 95 — System files not marked as in use in the MFT bitmap.
Event ID 96 — Length: 0 --> BinIndex : 0 - Unexpected length
Description
Length: 0 --> BinIndex : 0 - Unexpected length.
Message #
Event ID 97 — Length: A10_Length!
Description
Length: A10_Length!8I64d! --> BinIndex : A11_BinIndex!8u! - Key: A12_Key, BitPosition: A13_BitPosition, GroupIndex: A14_GroupIndex, GroupShiftFactor: A15_GroupShiftFactor.
Message #
Fields #
| Name | Description |
|---|---|
A10_Length Int64 | — |
A11_BinIndex UInt32 | — |
A12_Key UInt32 | — |
A13_BitPosition Int32 | — |
A14_GroupIndex Int32 | — |
A15_GroupShiftFactor Int32 | — |
Event ID 98 — Length: A10_Length!
Event ID 99 — BinIndex: A10_BinIndex!
Event ID 100 — BinIndex: A10_BinIndex!
Description
BinIndex: A10_BinIndex!8u! --> MaxLength: A11_MaxLength!8I64d! - GroupIndex: A12_GroupIndex, RelativeBinIndex: A13_RelativeBinIndex, MaxKey: A14_MaxKey.
Message #
Fields #
| Name | Description |
|---|---|
A10_BinIndex UInt32 | — |
A11_MaxLength Int64 | — |
A12_GroupIndex Int32 | — |
A13_RelativeBinIndex Int32 | — |
A14_MaxKey UInt32 | — |
Event ID 101 — BinGroupShift: A10_NtfsCachedRunBinGroupShift!
Description
BinGroupShift: A10_NtfsCachedRunBinGroupShift!8ld!, BinGroupSize: A11_NtfsCachedRunBinGroupSize!8u!, BinGroupMask: A12_NtfsCachedRunBinGroupMask!8x!
Message #
Fields #
| Name | Description |
|---|---|
A10_NtfsCachedRunBinGroupShift Int32 | — |
A11_NtfsCachedRunBinGroupSize UInt32 | — |
A12_NtfsCachedRunBinGroupMask HexInt32 | — |
Event ID 102 — BinIndex: A10_BinIndex!
Event ID 103 — Searched committed allocations but didnt find enough free space.
Description
Searched committed allocations but didnt find enough free space. StartingCluster A10_StartingCluster!I64x!, ClusterCount A11_ClusterCount!I64x!, Committed A12_VcbTotalClustersCommitted!I64x!, Total A13_VcbTotalClusters!I64x!, Free A14_VcbFreeClusters!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_StartingCluster HexInt64 | — |
A11_ClusterCount HexInt64 | — |
A12_VcbTotalClustersCommitted HexInt64 | — |
A13_VcbTotalClusters HexInt64 | — |
A14_VcbFreeClusters HexInt64 | — |
Event ID 104 — NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): first bit 0xA11_FirstBitToClear, last bit 0xA12_BeyondLastBitToClear1.
Event ID 105 — NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): no leading partial slab.
Event ID 106 — NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): leading partial slab returned - LCN A11_FreeClusterBase1!
Event ID 107 — NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): no trailing partial slab.
Event ID 108 — NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): trailing partial slab returned - lcn A11_FreeClusterBase2!
Event ID 109 — NtfsValidateTotalClustersCommitted(A10_Vcb,A11_PsGetCurrentThread): TCC A12_VcbTotalClustersCommitted!
Description
NtfsValidateTotalClustersCommitted(A10_Vcb,A11_PsGetCurrentThread): TCC A12_VcbTotalClustersCommitted!I64x!, TC A13_VcbTotalClusters!I64x!, BMSize A14_VcbTPMapSizeOfBitMap.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_PsGetCurrentThread Pointer | — |
A12_VcbTotalClustersCommitted HexInt64 | — |
A13_VcbTotalClusters HexInt64 | — |
A14_VcbTPMapSizeOfBitMap HexInt32 | — |
Event ID 110 — Illegal MDL Complete for major code A10_IrpContextMajorFunction.
Event ID 111 — Entering: Scb: A10_Scb, StartingZero: 0xA11_StartingZero!
Description
Entering: Scb: !p!, StartingZero: 0x!016I64x!, ByteCount: 0x!016I64x!, ExtentsDescriptor: !p!, ExtentsDescriptorIndex: !d!, ExtentsDescriptorStartOffset: 0x!016I64x!, Offset: 0x!016I64x!, MaxRuns: !d!
Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer | — |
A11_StartingZero HexInt64 | — |
A12_ByteCount HexInt64 | — |
A13_ExtentsDescriptor Pointer | — |
A14_ExtentsDescriptorIndex Int32 | — |
A15_ExtentsDescriptorStartOffset HexInt64 | — |
A16_Offset HexInt64 | — |
A17_MaxRuns Int32 | — |
Event ID 112 — RunEntry ==> A10_RunIndex!
Description
RunEntry ==> A10_RunIndex!4d!: [0xA11_ExtentsDescriptorRunRunIndexBasePage!016I64x!, 0xA12_ExtentsDescriptorRunRunIndexPageCount!016I64x!], ExtentLength: 0xA13_ExtentLength!016I64x!, Offset: 0xA14_Offset!016I64x!, RunIndexStartOffset: 0xA15_RunIndexStartOffset!016I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_RunIndex Int32 | — |
A11_ExtentsDescriptorRunRunIndexBasePage HexInt64 | — |
A12_ExtentsDescriptorRunRunIndexPageCount HexInt64 | — |
A13_ExtentLength HexInt64 | — |
A14_Offset HexInt64 | — |
A15_RunIndexStartOffset HexInt64 | — |
Event ID 113 — Offset is beyond this extent skipping the extent.
Description
Offset is beyond this extent skipping the extent.
Message #
Event ID 114 — Shrinking LengthInExtent.
Event ID 115 — Zeroing: StartingPhysicalAddr: 0xA10_StartingPhysicalAddrQuadPart!
Event ID 116 — Exiting: ExtentsDescriptorIndex: A10_ExtentsDescriptorIndex ExtentsDescriptorStartOffset: 0xA11_ExtentsDescriptorStartOffset!
Event ID 117 — Entering: Scb: A10_Scb, StartingZero: 0xA11_StartingOffset!
Event ID 118 — Dsm Ranges[A10_DataSetRangeIndex]: StartingOffset: 0xA11_DsmBufferDataSetRangesDataSetRangeIndexStartingOffset!
Description
Dsm Ranges[A10_DataSetRangeIndex]: StartingOffset: 0xA11_DsmBufferDataSetRangesDataSetRangeIndexStartingOffset!016I64x!, LengthInBytes: 0xA12_DsmBufferDataSetRangesDataSetRangeIndexLengthInBytes!016I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_DataSetRangeIndex Int32 | — |
A11_DsmBufferDataSetRangesDataSetRangeIndexStartingOffset HexInt64 | — |
A12_DsmBufferDataSetRangesDataSetRangeIndexLengthInBytes HexInt64 | — |
Event ID 119 — RemainingClusterCount: 0xA10_RemainingClusterCount!
Event ID 120 — Dsm: TotalNumberOfRanges: A10_DsmByteAddressRangesTotalNumberOfRanges, NumberOfRangesReturned: A11_DsmByteAddressRangesNumberOfRangesReturned.
Event ID 121 — DsmOut Ranges[A10_Index]: StartingAddress: 0xA11_DsmByteAddressRangesRangesIndexStartAddress!
Description
DsmOut Ranges[A10_Index]: StartingAddress: 0xA11_DsmByteAddressRangesRangesIndexStartAddress!016I64x!, LengthInBytes: 0xA12_DsmByteAddressRangesRangesIndexLengthInBytes!016I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Index Int32 | — |
A11_DsmByteAddressRangesRangesIndexStartAddress HexInt64 | — |
A12_DsmByteAddressRangesRangesIndexLengthInBytes HexInt64 | — |
Event ID 122 — Zeroing: StartingPhysicalAddr: 0xA10_StartingPhysicalAddrQuadPart!
Event ID 123 — Updating ExtentsDescriptor Index and StartOffset from Locals: ExtentsDescriptorIndex: A10_ExtentsDescriptorIndex, ExtentsDescriptorStartOffset: 0xA11_ExtentsDescriptorStartOffset!
Description
Updating ExtentsDescriptor Index and StartOffset from Locals: ExtentsDescriptorIndex: A10_ExtentsDescriptorIndex, ExtentsDescriptorStartOffset: 0xA11_ExtentsDescriptorStartOffset!016I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_ExtentsDescriptorIndex Int32 | — |
A11_ExtentsDescriptorStartOffset HexInt64 | — |
Event ID 124 — Entering: Scb: A10_Scb, StartingZero: 0xA11_StartingZero!
Description
Entering: Scb: !p!, StartingZero: 0x!016I64x!, BeyondEndOffset: 0x!016I64x!, ByteCount: 0x!016I64x!, ExtentsDescriptor: !p!, ExtentsDescriptorIndex: !d!, ExtentsDescriptorStartOffset: 0x!016I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer | — |
A11_StartingZero HexInt64 | — |
A12_BeyondEndOffset HexInt64 | — |
A13_ByteCount HexInt64 | — |
A14_ExtentsDescriptor Pointer | — |
A15_ExtentsDescriptorIndexExtentsDescriptorIndex0 Int32 | — |
A16_ExtentsDescriptorStartOffsetExtentsDescriptorStartOffset0 HexInt64 | — |
Event ID 125 — Updating ExtentsDescriptor Index and StartOffset from Locals: ExtentsDescriptorIndex: A10_ExtentsDescriptorIndex, ExtentsDescriptorStartOffset: 0xA11_ExtentsDescriptorStartOffset!
Description
Updating ExtentsDescriptor Index and StartOffset from Locals: ExtentsDescriptorIndex: A10_ExtentsDescriptorIndex, ExtentsDescriptorStartOffset: 0xA11_ExtentsDescriptorStartOffset!016I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_ExtentsDescriptorIndex Int32 | — |
A11_ExtentsDescriptorStartOffset HexInt64 | — |
Event ID 126 — IrpContext: A10_IrpContext; Scb: A11_Scb; StartOffset: 0xA12_StartOffset!
Event ID 127 — Return.
Event ID 128 — Unexpected open type received: A10_TypeOfOpen.
Event ID 129 — Raising STATUS_SUCCESS from NtfsCommonCleanup: A10_Status.
Event ID 130 — Raising STATUS_SUCCESS from NtfsCommonCleanup: 0xA10_Status.
Event ID 131 — Raising STATUS_SUCCESS from NtfsCommonCleanup: 0xA10_Status.
Event ID 132 — Irp: A10_Irp, IC: A11_IrpContext, Vcb: A12_Vcb, FileObject: A13_CreateContextFileObject, RelatedFileObject: A14_CreateContextFileObjectRelatedFileObject, FileIdBuffer: A15__CreateContextFileObjectF...
Description
Irp: !p!, IC: !p!, Vcb: !p!, FileObject: !p!, RelatedFileObject: !p!, FileIdBuffer: !S!, Options: 0x!08x!, FileAttributes: 0x!04x!, DesiredAccess: 0x!08x!, ShareAccess: 0x!04x!, EaLength: 0x!08x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Irp Pointer | — |
A11_IrpContext Pointer | — |
A12_Vcb Pointer | — |
A13_CreateContextFileObject Pointer | — |
A14_CreateContextFileObjectRelatedFileObject Pointer | — |
A15__CreateContextFileObjectFileName 25 | — |
A16_CreateContextIrpSpParametersCreateOptions HexInt32 | — |
A17_CreateContextIrpSpParametersCreateFileAttributes HexInt32 | — |
A18_CreateContextDesiredAccess HexInt32 | — |
A19_CreateContextIrpSpParametersCreateShareAccess HexInt32 | — |
A20_CreateContextIrpSpParametersCreateEaLength HexInt32 | — |
Event ID 133 — Irp: A10_Irp, IC: A11_IrpContext, Vcb: A12_Vcb, FileObject: A13_CreateContextFileObject, RelatedFileObject: A14_CreateContextFileObjectRelatedFileObject, Path: A15__CreateContextFileObjectFileName,...
Description
Irp: !p!, IC: !p!, Vcb: !p!, FileObject: !p!, RelatedFileObject: !p!, Path: !S!, Options: 0x!08x!, FileAttributes: 0x!04x!, DesiredAccess: 0x!08x!, ShareAccess: 0x!04x!, EaLength: 0x!08x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Irp Pointer | — |
A11_IrpContext Pointer | — |
A12_Vcb Pointer | — |
A13_CreateContextFileObject Pointer | — |
A14_CreateContextFileObjectRelatedFileObject Pointer | — |
A15__CreateContextFileObjectFileName CountedUtf16String | — |
A16_CreateContextIrpSpParametersCreateOptions HexInt32 | — |
A17_CreateContextIrpSpParametersCreateFileAttributes HexInt32 | — |
A18_CreateContextDesiredAccess HexInt32 | — |
A19_CreateContextIrpSpParametersCreateShareAccess HexInt32 | — |
A20_CreateContextIrpSpParametersCreateEaLength HexInt32 | — |
Event ID 134 — NtfsCommonCreate: Volume is locked.
Description
NtfsCommonCreate: Volume is locked. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Vcb State: A14_VcbVcbState.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_VcbVcbState HexInt32 | — |
Event ID 135 — NtfsCommonVolumeOpen: Invalid create disposition for volume open.
Event ID 136 — NtfsCommonVolumeOpen: Volume is locked or we have performed a dismount.
Description
NtfsCommonVolumeOpen: Volume is locked or we have performed a dismount. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Vcb State: 0xA14_VcbVcbState!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_VcbVcbState HexInt32 | — |
Event ID 137 — NtfsCommonVolumeOpen: Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Requested ...
Description
NtfsCommonVolumeOpen: Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Requested ShareAccess: 0x!08x!, Vcb->CleanupCount: !d!, BiasedCleanupCount: !d!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_IrpSpParametersCreateShareAccess HexInt32 | — |
A15_ReadULongNoFence_VcbCleanupCount Int32 | — |
A16_BiasedCleanupCount Int32 | — |
Event ID 138 — NtfsCommonVolumeOpen: Volume is locked or we have performed a dismount.
Description
NtfsCommonVolumeOpen: Volume is locked or we have performed a dismount.Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Vcb State: 0xA14_VcbVcbState!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_VcbVcbState HexInt32 | — |
Event ID 139 — NtfsCommonVolumeOpen: Conlicting file objects.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_IrpSpParametersCreateShareAccess HexInt32 | — |
A15_VcbReadOnlyCloseCount Int32 | — |
A16_VcbCloseCount Int32 | — |
A17_VcbSystemFileCloseCount Int32 | — |
Event ID 140 — NtfsHandlePagingFile: Paging file already open, paging files can only be opened once.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_FcbVcb Pointer | — |
A12__FcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_FcbCleanupCount Int32 | — |
A17_FcbFcbState HexInt32 | — |
A18_IrpSpFlags HexInt32 | — |
Event ID 141 — NtfsHandlePagingFile: Cannot open system file as paging file.
Description
NtfsHandlePagingFile: Cannot open system file as paging file. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, Fcb->FcbState: 0x!08x!, IrpSp->Flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_FcbVcb Pointer | — |
A12__FcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_FcbFcbState HexInt32 | — |
A17_IrpSpFlags HexInt32 | — |
Event ID 142 — NtfsHandlePagingFile: Persisted paging file already exists.
Description
NtfsHandlePagingFile: Persisted paging file already exists. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, IrpContext->State: 0x!08x!, IrpSp->Flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_FcbVcb Pointer | — |
A12__FcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_IrpContextState HexInt32 | — |
A17_IrpSpFlags HexInt32 | — |
Event ID 143 — NtfsOpenFcbById: Invalid system file access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_ThisFcbFcbState HexInt32 | — |
A17_CreateContextIrpSpParametersCreateOptions24_0x000000ff HexInt32 | — |
A18_CreateContextIrpSpParametersCreateSecurityContextDesiredAccess HexInt32 | — |
Event ID 144 — NtfsOpenExistingPrefixFcb: Can not directly open txf directory.
Description
NtfsOpenExistingPrefixFcb: Can not directly open txf directory. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, FileAttributes: 0x!08x!, Rmstate: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_CreateContextCurrentFcbVcb Pointer | — |
A12__CreateContextCurrentFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWCreateContextCurrentFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHCreateContextCurrentFcbVcbVpb CountedUtf16String | — |
A14_CreateContextCurrentFcb Pointer | — |
A15_NtfsFullFileRefNumber_CreateContextCurrentFcbFileReference HexInt64 | — |
A16_CreateContextCurrentFcbInfoFileAttributes HexInt32 | — |
A17_CreateContextCurrentFcbTxfRmcbRmState HexInt32 | — |
Event ID 145 — NtfsOpenExistingPrefixFcb: Invalid system file access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_CreateContextCurrentFcbVcb Pointer | — |
A12__CreateContextCurrentFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWCreateContextCurrentFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHCreateContextCurrentFcbVcbVpb CountedUtf16String | — |
A14_CreateContextCurrentFcb Pointer | — |
A15_NtfsFullFileRefNumber_CreateContextCurrentFcbFileReference HexInt64 | — |
A16_CreateContextCurrentFcbFcbState HexInt32 | — |
A17_CreateContextIrpSpParametersCreateOptions24_0x000000ff HexInt32 | — |
A18_CreateContextIrpSpParametersCreateSecurityContextDesiredAccess HexInt32 | — |
Event ID 146 — NtfsOpenFile: Unsafe to acquire parent directory after acquiring a txf-system file.
Description
NtfsOpenFile: Unsafe to acquire parent directory after acquiring a txf-system file. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, FcbState: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_ThisFcbFcbState HexInt32 | — |
Event ID 147 — NtfsOpenFile: Invalid system file access.
Description
NtfsOpenFile: Invalid system file access. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, FcbState: 0x!08x!, CreateDisposition: 0x!08x!, DesiredAccess: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_ThisFcbFcbState HexInt32 | — |
A17_CreateContextIrpSpParametersCreateOptions24_0x000000ff HexInt32 | — |
A18_CreateContextIrpSpParametersCreateSecurityContextDesiredAccess HexInt32 | — |
Event ID 148 — NtfsOpenFile: Deny open when txf rm is active.
Description
NtfsOpenFile: Deny open when txf rm is active. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, TxfRmcb Rmstate: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_ThisFcbTxfRmcbRmState HexInt32 | — |
Event ID 149 — NtfsCreateNewFile: Deny creation in system directory (except root).
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ParentScbFcbVcb Pointer | — |
A12__ParentScbFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWParentScbFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHParentScbFcbVcbVpb CountedUtf16String | — |
A14_ParentScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ParentScbFcbFileReference HexInt64 | — |
A16_ParentScbFcbFcbState HexInt32 | — |
A17_ParentScbFcbTxfRmcbRmState HexInt32 | — |
A18_AttrTypeCode HexInt32 | — |
Event ID 150 — NtfsCreateNewFile: Unable to create Ea for the file.
Description
NtfsCreateNewFile: Unable to create Ea for the file. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, Create options: 0x!08x!, Ccb flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_CreateContextIrpSpParametersCreateOptions HexInt32 | — |
A17_CcbFlags HexInt32 | — |
Event ID 151 — NtfsCreateNewFile: Unable to create in the $txf directory.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ParentScbVcb Pointer | — |
A12__ParentScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWParentScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHParentScbVcbVpb CountedUtf16String | — |
A14_ParentScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ParentScbFcbFileReference HexInt64 | — |
A16_ParentScbFcbFcbState HexInt32 | — |
A17_ParentScbFcbTxfRmcbRmState HexInt32 | — |
Event ID 152 — NtfsOpenSubdirectory: Denying access to $Txf file when the RM is active.
Description
NtfsOpenSubdirectory: Denying access to $Txf file when the RM is active. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, TxfRmcb state: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_ThisFcbTxfRmcbRmState HexInt32 | — |
Event ID 153 — NtfsOpenAttributeInExistingFile: Denying access due to caller being Ea blind.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_ThisEaInformationNeedEaCount Int32 | — |
A17_CreateContextIrpSpParametersCreateOptions HexInt32 | — |
A18_CcbFlags HexInt32 | — |
Event ID 154 — NtfsOpenAttributeInExistingFile: Fail to find $INDEX_ROOT attribute.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_AttrTypeCode HexInt32 | — |
A17_CreateDisposition HexInt32 | — |
Event ID 155 — NtfsOpenAttributeInExistingFile: Denying access for volume root directory.
Description
NtfsOpenAttributeInExistingFile: Denying access for volume root directory. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, CreateDisposition: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_CreateDisposition HexInt32 | — |
Event ID 156 — NtfsCreateNewFile: Not allowed to create streams on system files.
Description
NtfsCreateNewFile: Not allowed to create streams on system files. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, FcbState: 0x!08x!, AttrTypeCode: 0x!x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_ThisFcbFcbState HexInt32 | — |
A17_AttrTypeCode HexInt32 | — |
Event ID 157 — NtfsOverwriteAttr: Cannot overwrite hidden or system attribute for a non-paging file.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_ThisFcbInfoFileAttributes HexInt32 | — |
A17_FileAttributes HexInt32 | — |
Event ID 158 — NtfsOverwriteAttr: Denying access due to user being Ea blind.
Description
NtfsOverwriteAttr: Denying access due to user being Ea blind. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: !I64x!, Create options: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_CreateContextIrpSpParametersCreateOptions HexInt32 | — |
Event ID 159 — NtfsOverwriteAttr: Deny access due to encryption happening on the stream.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_CreateContextThisScbAttributeTypeCode HexInt32 | — |
A17_CreateContextThisScbState HexInt32 | — |
A18_CreateContextThisScbScbTypeDataHighWaterMark Int64 | — |
Event ID 160 — NtfsCheckValidAttributeAccess: Supersede or overwrite is not allowed on this type of named attribute.
Event ID 161 — NtfsCheckValidAttributeAccess: Only read attributes access is supported on this attribute.
Description
NtfsCheckValidAttributeAccess: Only read attributes access is supported on this attribute. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, AttributeTypeCode: 0x!x!, DesiredAccess: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_AttrCode HexInt32 | — |
A15_IrpSpParametersCreateSecurityContextAccessStateOriginalDesiredAccess HexInt32 | — |
Event ID 162 — NtfsCheckValidAttributeAccess: Deny access for protected system attributes.
Event ID 163 — NtfsOpenAttributeCheck: File already has user writable references.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisScbVcb Pointer | — |
A12__ThisScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb CountedUtf16String | — |
A14_ThisScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference HexInt64 | — |
A16_ThisScb Pointer | — |
A17_ThisScbAttributeTypeCode HexInt32 | — |
A18__ThisScbAttributeName CountedUtf16String | — |
A19_IrpSpParametersCreateShareAccess HexInt32 | — |
A20_IrpSpParametersCreateSecurityContextAccessStatePreviouslyGrantedAccess HexInt32 | — |
Event ID 164 — NtfsOpenAttributeCheck: Deny access for online encryption backup data stream.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisScbVcb Pointer | — |
A12__ThisScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb CountedUtf16String | — |
A14_ThisScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference HexInt64 | — |
A16_ThisScb Pointer | — |
A17_ThisScbAttributeTypeCode HexInt32 | — |
A18__ThisScbAttributeName CountedUtf16String | — |
Event ID 165 — NtfsOpenAttributeCheck: File was granted write access but has image section.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisScbVcb Pointer | — |
A12__ThisScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb CountedUtf16String | — |
A14_ThisScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference HexInt64 | — |
A16_ThisScb Pointer | — |
A17_ThisScbAttributeTypeCode HexInt32 | — |
A18__ThisScbAttributeName CountedUtf16String | — |
A19_IrpSpParametersCreateSecurityContextAccessStatePreviouslyGrantedAccess HexInt32 | — |
Event ID 166 — NtfsOpenAttribute: Denying write access on disallowed writes.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisScbVcb Pointer | — |
A12__ThisScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb CountedUtf16String | — |
A14_ThisScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference HexInt64 | — |
A16_ThisScb Pointer | — |
A17_ThisScbMarkHandleDisallowWritesCount Int32 | — |
A18_IrpSpParametersCreateSecurityContextDesiredAccess HexInt32 | — |
Event ID 167 — NtfsOpenAttribute: File already has user writable references.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisScbVcb Pointer | — |
A12__ThisScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb CountedUtf16String | — |
A14_ThisScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference HexInt64 | — |
A16_ThisScb Pointer | — |
A17_ThisScbAttributeTypeCode HexInt32 | — |
A18__ThisScbAttributeName CountedUtf16String | — |
A19_IrpSpParametersCreateShareAccess HexInt32 | — |
A20_GrantedAccess HexInt32 | — |
Event ID 168 — NtfsOpenAttribute: Open for exclusive read access is not allowed.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisScbVcb Pointer | — |
A12__ThisScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb CountedUtf16String | — |
A14_ThisScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference HexInt64 | — |
A16_IrpSpParametersCreateShareAccess HexInt32 | — |
A17_IrpSpFileObjectFlags HexInt32 | — |
Event ID 169 — NtfsOpenAttribute: File already has user writable references.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisScbVcb Pointer | — |
A12__ThisScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb CountedUtf16String | — |
A14_ThisScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference HexInt64 | — |
A16_ThisScb Pointer | — |
A17_ThisScbAttributeTypeCode HexInt32 | — |
A18__ThisScbAttributeName CountedUtf16String | — |
A19_IrpSpParametersCreateShareAccess HexInt32 | — |
A20_GrantedAccess HexInt32 | — |
Event ID 170 — NtfsOpenAttribute: Open for exclusive read access is not allowed.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_IrpSpParametersCreateShareAccess HexInt32 | — |
A17_IrpSpFileObjectFlags HexInt32 | — |
Event ID 171 — NtfsCheckExistingFile: Desired access conflicts with read-only state.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_IrpSpParametersCreateSecurityContextDesiredAccess HexInt32 | — |
A17_ThisFcbInfoFileAttributes HexInt32 | — |
A18_IrpSpFlags HexInt32 | — |
Event ID 172 — NtfsOpenExistingEncryptedStream: No encryption driver found.
Description
NtfsOpenExistingEncryptedStream: No encryption driver found. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, FileAttributes: 0x!08x!, NtfsData flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_CurrentFcbVcb Pointer | — |
A12__CurrentFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWCurrentFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHCurrentFcbVcbVpb CountedUtf16String | — |
A14_CurrentFcb Pointer | — |
A15_NtfsFullFileRefNumber_CurrentFcbFileReference HexInt64 | — |
A16_CurrentFcbInfoFileAttributes HexInt32 | — |
A17_NtfsDataFlags HexInt32 | — |
Event ID 173 — NtfsOpenExistingEncryptedStream: Opening for read/write access not allowed on compressed file.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_CurrentFcbVcb Pointer | — |
A12__CurrentFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWCurrentFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHCurrentFcbVcbVpb CountedUtf16String | — |
A14_CurrentFcb Pointer | — |
A15_NtfsFullFileRefNumber_CurrentFcbFileReference HexInt64 | — |
A16_CurrentFcbInfoFileAttributes HexInt32 | — |
A17_ThisScbAttributeFlags HexInt32 | — |
Event ID 174 — NtfsEncryptionCreateCallback: Encrytion engine fail to encrypt all streams for file with open handle.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisScbVcb Pointer | — |
A12__ThisScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisScbVcbVpb CountedUtf16String | — |
A14_ThisScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisScbFcbFileReference HexInt64 | — |
A16_CreateContextCurrentFcbCleanupCount Int32 | — |
A17_NtfsDataEncryptionCallBackTableImplementationFlags HexInt32 | — |
Event ID 175 — NtfsFindStartingNode: Opening not allowed for txf name when RM is active.
Description
NtfsFindStartingNode: Opening not allowed for txf name when RM is active. Thread: A10_PsGetCurrentThread, Fcb: A11_CurrentFcb, FileRef: 0xA12_NtfsFullFileRefNumber_CurrentFcbFileReference!I64x!, TxfRmcb RM state: A13_CurrentFcbTxfRmcbRmState.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_CurrentFcb Pointer | — |
A12_NtfsFullFileRefNumber_CurrentFcbFileReference HexInt64 | — |
A13_CurrentFcbTxfRmcbRmState HexInt32 | — |
Event ID 176 — NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_LcbFcbVcb Pointer | — |
A12__LcbFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWLcbFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHLcbFcbVcbVpb CountedUtf16String | — |
A14_LcbFcb Pointer | — |
A15_NtfsFullFileRefNumber_LcbFcbFileReference HexInt64 | — |
A16_WppCountedStringWLcbFileNameAttrFileNameUSHORTLcbFileNameAttrFileNameLength CountedUtf16String | — |
A17_DesiredAccess HexInt32 | — |
A18_DesiredShareAccess HexInt32 | — |
A19_IoShareAccessFlags HexInt32 | — |
A20_LinkShareAccessOpenCount Int32 | — |
A21_LinkShareAccessDeleters Int32 | — |
A22_LinkShareAccessSharedDelete Int32 | — |
Event ID 177 — NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_ScbAttributeTypeCode HexInt32 | — |
A17__ScbAttributeName CountedUtf16String | — |
A18_DesiredAccess HexInt32 | — |
A19_DesiredShareAccess HexInt32 | — |
A20_IoShareAccessFlags HexInt32 | — |
A21_ShareAccessOpenCount Int32 | — |
A22_ShareAccessReaders Int32 | — |
A23_ShareAccessWriters Int32 | — |
A24_ShareAccessDeleters Int32 | — |
A25_ShareAccessSharedRead Int32 | — |
A26_ShareAccessSharedWrite Int32 | — |
A27_ShareAccessSharedDelete Int32 | — |
Event ID 178 — NtfsCheckShareAccess: IoCheckLinkShareAccess failed with sharing violation.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_ScbAttributeTypeCode HexInt32 | — |
A17__ScbAttributeName CountedUtf16String | — |
A18_WppCountedStringWLcbFileNameAttrFileNameUSHORTLcbFileNameAttrFileNameLength CountedUtf16String | — |
A19_DesiredAccess HexInt32 | — |
A20_DesiredShareAccess HexInt32 | — |
A21_IoShareAccessFlags HexInt32 | — |
A22_ShareAccessOpenCount Int32 | — |
A23_ShareAccessReaders Int32 | — |
A24_ShareAccessWriters Int32 | — |
A25_ShareAccessDeleters Int32 | — |
A26_ShareAccessSharedRead Int32 | — |
A27_ShareAccessSharedWrite Int32 | — |
A28_ShareAccessSharedDelete Int32 | — |
A29_LinkShareAccessOpenCount Int32 | — |
A30_LinkShareAccessDeleters Int32 | — |
A31_LinkShareAccessSharedDelete Int32 | — |
Event ID 179 — NtfsReCheckShareAccess: Does not meet allow open requirement.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_ScbAttributeTypeCode HexInt32 | — |
A17__ScbAttributeName CountedUtf16String | — |
A18_ARGUMENT_PRESENTLcbWppCountedStringWLcbFileNameAttrFileNameUSHORTLcbFileNameAttrFileNameLengthWppCountedStringWNULL0 CountedUtf16String | — |
A19_AccessStatePreviouslyGrantedAccess HexInt32 | — |
A20_AccessStateFlags HexInt32 | — |
A21_DesiredShareAccess HexInt32 | — |
A22_CreateDisposition HexInt32 | — |
A23_ScbShareAccessOpenCount Int32 | — |
A24_ScbShareAccessReaders Int32 | — |
A25_ScbShareAccessWriters Int32 | — |
A26_ScbShareAccessDeleters Int32 | — |
A27_ScbShareAccessSharedRead Int32 | — |
A28_ARGUMENT_PRESENTLcbLcbLinkShareAccessDeleters0 Int32 | — |
Event ID 180 — A10_FILEID_FROM_SOURCEFileNLine:A11_LINENUM_FROM_SOURCEFileNLine Status: A12_Status ProcessName: A13__ProcessName.
Event ID 181 — A10_FILEID_FROM_SOURCEFileNLine:A11_LINENUM_FROM_SOURCEFileNLine Status: A12_Status ProcessName: A13__ProcessName.
Event ID 182 — A10_FILEID_FROM_SOURCEFileNLine:A11_LINENUM_FROM_SOURCEFileNLine Status: A12_Status ProcessName: A13__ProcessName.
Event ID 183 — A10_FILEID_FROM_SOURCEFileNLine:A11_LINENUM_FROM_SOURCEFileNLine Status: A12_Status ProcessName: A13__ProcessName.
Event ID 184 — NtfsSendUnusedClustersHint: Vcb A10_Vcb - Will tell storage we are freeing at A11_StartingCluster!
Event ID 185 — NtfsSendUnusedClustersHint: Vcb A10_Vcb - Flush requested.
Event ID 186 — NtfsSendUnusedClustersHint: Vcb A10_Vcb - Created new MarkUnusedContext A11_MarkUnusedContext, DEALLOCATED_CLUSTERS A12_MarkUnusedContextDeallocatedClusters, MCB A13__MarkUnusedContextDeallocatedCl...
Description
NtfsSendUnusedClustersHint: Vcb A10_Vcb - Created new MarkUnusedContext A11_MarkUnusedContext, DEALLOCATED_CLUSTERS A12_MarkUnusedContextDeallocatedClusters, MCB A13__MarkUnusedContextDeallocatedClustersMcb.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_MarkUnusedContext Pointer | — |
A12_MarkUnusedContextDeallocatedClusters Pointer | — |
A13__MarkUnusedContextDeallocatedClustersMcb Pointer | — |
Event ID 187 — NtfsSendUnusedClustersHint: Vcb A10_Vcb - Successfully added clusters starting at A11_StartingCluster!
Description
NtfsSendUnusedClustersHint: Vcb A10_Vcb - Successfully added clusters starting at A11_StartingCluster!I64x! for A12_RunLength into MCB A13__MarkUnusedContextDeallocatedClustersMcb.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_StartingCluster HexInt64 | — |
A12_RunLength HexInt32 | — |
A13__MarkUnusedContextDeallocatedClustersMcb Pointer | — |
Event ID 188 — NtfsSendUnusedClustersHint: Vcb A10_Vcb - MCB A11__MarkUnusedContextDeallocatedClustersMcb is full.
Event ID 189 — NtfsSendUnusedClustersHint: Vcb A10_Vcb - Queuing request to IC pre-trim list, MUC A11_MarkUnusedContext, IC A12_IrpContext.
Event ID 190 — NtfsSendUnusedClustersHint: Vcb A10_Vcb - Failed to allocate/initial MarkUnusedContext.
Event ID 191 — NtfsTransferMaxDataSetRanges: Src A10_Src, Dst A11_Dst, SrcRemainClusCt A12_SrcClustersCount!
Description
NtfsTransferMaxDataSetRanges: Src A10_Src, Dst A11_Dst, SrcRemainClusCt A12_SrcClustersCount!I64x!, SrcOrigClusCt A13_SrcDeallocatedClustersClusterCount!I64x!, SrcDSRL A14_SrcDsmAttrDataSetRangesLength - Entering.
Message #
Fields #
| Name | Description |
|---|---|
A10_Src Pointer | — |
A11_Dst Pointer | — |
A12_SrcClustersCount HexInt64 | — |
A13_SrcDeallocatedClustersClusterCount HexInt64 | — |
A14_SrcDsmAttrDataSetRangesLength HexInt32 | — |
Event ID 192 — NtfsTransferMaxDataSetRanges: Src A10_Src, Dst A11_Dst, SrcRemainClusCt A12_SrcClustersCount!
Description
NtfsTransferMaxDataSetRanges: Src !p!, Dst !p!, SrcRemainClusCt !I64x!, DstClusCt !I64x!, DstDSRL !x!, DstLIB !I64x!, DstSOff !I64x! - Leaving.
Message #
Fields #
| Name | Description |
|---|---|
A10_Src Pointer | — |
A11_Dst Pointer | — |
A12_SrcClustersCount HexInt64 | — |
A13_DstClustersCount HexInt64 | — |
A14_DstDsmAttrDataSetRangesLength HexInt32 | — |
A15_DstFirstDataSetRangePtrLengthInBytes HexInt64 | — |
A16_DstFirstDataSetRangePtrStartingOffset HexInt64 | — |
Event ID 193 — NtfsMarkUnusedContextPostTrimProcessing: Entering
Description
NtfsMarkUnusedContextPostTrimProcessing: Entering.
Message #
Event ID 194 — NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext - DC A12_VcbDeallocatedClusters!
Description
NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext - DC A12_VcbDeallocatedClusters!I64x!, DCIT A13_VcbDeallocatedClustersListLengthInTrim, DCTD A14_VcbDeallocatedClustersListLengthToDrain, CC A15_ClustersClusterCount!I64x!, IR A16_InitialRanges.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_MarkUnusedContext Pointer | — |
A12_VcbDeallocatedClusters HexInt64 | — |
A13_VcbDeallocatedClustersListLengthInTrim HexInt32 | — |
A14_VcbDeallocatedClustersListLengthToDrain HexInt32 | — |
A15_ClustersClusterCount HexInt64 | — |
A16_InitialRanges HexInt32 | — |
Event ID 195 — NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext - Removed interior slab(s) from TP map - [LCN A12_StartingLcn!
Description
NtfsMarkUnusedContextPostTrimProcessing: Vcb !p!, MUC !p! - Removed interior slab(s) from TP map - [LCN !I64X!, len !I64X!] => [LCN !I64X!, len !I64X!], [LCN !I64X!, len !I64X!].
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_MarkUnusedContext Pointer | — |
A12_StartingLcn HexInt64 | — |
A13_ClusterCount HexInt64 | — |
A14_FreeClusterBase1 HexInt64 | — |
A15_FreeClusterCount1 HexInt64 | — |
A16_FreeClusterBase2 HexInt64 | — |
A17_FreeClusterCount2 HexInt64 | — |
Event ID 196 — NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb - Releasing bitmap.
Event ID 197 — NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb - CloseCount A11_VcbCloseCount.
Event ID 198 — NtfsMarkUnusedContextPostTrimProcessing: Leaving
Description
NtfsMarkUnusedContextPostTrimProcessing: Leaving.
Message #
Event ID 199 — NtfsAsyncSendUnusedClustersHintCompletionRoutine: Irp A10_Irp.
Event ID 200 — NtfsMarkUnusedContextPreTrimProcessing: Vcb A10_Vcb, IC A11_IrpContext - Entering.
Event ID 201 — NtfsMarkUnusedContextPreTrimProcessing: Vcb A10_Vcb - Kicked off DelayedWorkQueue.
Event ID 202 — NtfsMarkUnusedContextPreTrimProcessing: Vcb A10_Vcb - Leaving.
Event ID 203 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Entering Vcb A10_Vcb.
Event ID 204 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Small MUC A11_SmallMarkUnusedContext instead of MUC A12_MarkUnusedContext.
Event ID 205 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Failed to allocate small MUC so use MUC A11_MarkUnusedContext.
Event ID 206 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Sending storage ioctl down.
Event ID 207 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext - [A12_TrimEntryCount] Offset A13_DataSetRangePtrStartingOffset!
Description
NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext - [A12_TrimEntryCount] Offset A13_DataSetRangePtrStartingOffset!I64x!, Length A14_DataSetRangePtrLengthInBytes!I64x! - trim entry.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_MarkUnusedContext Pointer | — |
A12_TrimEntryCount HexInt32 | — |
A13_DataSetRangePtrStartingOffset HexInt64 | — |
A14_DataSetRangePtrLengthInBytes HexInt64 | — |
Event ID 208 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext, Irp A12_IrpUsed - Completed.
Event ID 209 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext - A12_Status - failed to send.
Event ID 210 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Add MUC A11_MarkUnusedContext to post trim list.
Event ID 211 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Free small MUC A11_MarkUnusedContext.
Event ID 212 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Sending storage ioctl down failed with A11_Status.
Description
NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Sending storage ioctl down failed with A11_Status. MUC A12_MarkUnusedContext, Count A13_MarkUnusedContextNULL__MarkUnusedContextDeallocatedClustersNULLMarkUnusedContextDeallocatedClustersClusterCount1LL!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_Status HexInt32 | — |
A12_MarkUnusedContext Pointer | — |
A13_MarkUnusedContextNULL__MarkUnusedContextDeallocatedClustersNULLMarkUnusedContextDeallocatedClustersClusterCount1LL HexInt64 | — |
Event ID 213 — NtfsMarkUnusedContextPreTrimWorkItemProcessing: Leaving
Description
NtfsMarkUnusedContextPreTrimWorkItemProcessing: Leaving.
Message #
Event ID 214 — NtfsWakeupDeallocatedClustersWaiters: Vcb A10_Vcb - There are waiters for DC A11_DeallocatedClusters.
Event ID 215 — NtfsWakeupDeallocatedClustersWaiters: Vcb A10_Vcb - Waking up waiter for DC A11_DeallocatedClusters.
Event ID 216 — NtfsWakeupDeallocatedClustersWaiters: Vcb A10_Vcb - Done waking up DC A11_DeallocatedClusters.
Event ID 217 — NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb, All A11_All - Entering.
Event ID 218 — NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Waiting to drain.
Event ID 219 — NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Waiting for partial drain.
Event ID 220 — NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Leaving.
Event ID 221 — NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Entering.
Event ID 222 — NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Inserted A11_DeallocatedClustersToWaitForDeallocatedClusters.
Event ID 223 — NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Leaving.
Event ID 224 — NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Vcb A10_IrpContextVcb - Wait for DC A11_DeallocatedClustersToWaitForDeallocatedClusters.
Event ID 225 — NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Waited for A10_WaitInSeconds (s), Exceeded by A11_CurrentTimeQuadPartDeallocatedClustersToWaitForEndTimeQuadPartULONGCurrentTimeQuadPartDeallocate...
Description
NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Waited for !d! (s), Exceeded by !d! (s), IC !p!, Vcb !p!, DC !p!
Message #
Fields #
| Name | Description |
|---|---|
A10_WaitInSeconds Int32 | — |
A11_CurrentTimeQuadPartDeallocatedClustersToWaitForEndTimeQuadPartULONGCurrentTimeQuadPartDeallocatedClustersToWaitForEndTimeQuadPartNtfsDataSystemTimeIncrementINTERVAL_ONE_SECOND0 Int32 | — |
A12_IrpContext Pointer | — |
A13_IrpContextVcb Pointer | — |
A14_DeallocatedClusters Pointer | — |
Event ID 226 — NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Waited for A10_WaitInSeconds (s), Exceeded by A11_CurrentTimeQuadPartDeallocatedClustersToWaitForEndTimeQuadPartULONGCurrentTimeQuadPartDeallocate...
Description
NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Waited for !d! (s), Exceeded by !d! (s), IC !p!, Vcb !p!, DC !p!
Message #
Fields #
| Name | Description |
|---|---|
A10_WaitInSeconds Int32 | — |
A11_CurrentTimeQuadPartDeallocatedClustersToWaitForEndTimeQuadPartULONGCurrentTimeQuadPartDeallocatedClustersToWaitForEndTimeQuadPartNtfsDataSystemTimeIncrementINTERVAL_ONE_SECOND0 Int32 | — |
A12_IrpContext Pointer | — |
A13_IrpContextVcb Pointer | — |
A14_DeallocatedClusters Pointer | — |
Event ID 227 — NtfsCheckForTrimThrottling: Vcb A10_Vcb - hitting trim threshold A11_VcbDeallocatedClustersListLengthInTrim.
Event ID 228 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - Entering.
Event ID 229 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - Precondition checks failed.
Event ID 230 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - Precondition checks failed; AcquiredSyncResource A11_AcquiredVcb.
Event ID 231 — NtfsUpdateSmartTrimState: Vcb A10_Vcb, MUC A11_MarkUnusedContext - Skipping deallocated clusters gen'd by smart trim.
Event ID 232 — NtfsUpdateSmartTrimState: Vcb A10_Vcb, MUC A11_MarkUnusedContext - MCB run A12_RunIndex; offs 0xA13_StartingOffset!
Description
NtfsUpdateSmartTrimState: Vcb A10_Vcb, MUC A11_MarkUnusedContext - MCB run A12_RunIndex; offs 0xA13_StartingOffset!I64X!, len 0xA14_LengthInBytes!I64X!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_MarkUnusedContext Pointer | — |
A12_RunIndex UInt32 | — |
A13_StartingOffset HexInt64 | — |
A14_LengthInBytes HexInt64 | — |
Event ID 233 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - MUC A11_MarkUnusedContext, DSR count A12_DataSetRangeCount, MCB count A13_McbRunCount, ST free slots A14_SmartTrimFreeRangeCount.
Description
NtfsUpdateSmartTrimState: Vcb A10_Vcb - MUC A11_MarkUnusedContext, DSR count A12_DataSetRangeCount, MCB count A13_McbRunCount, ST free slots A14_SmartTrimFreeRangeCount.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_MarkUnusedContext Pointer | — |
A12_DataSetRangeCount UInt32 | — |
A13_McbRunCount UInt32 | — |
A14_SmartTrimFreeRangeCount UInt32 | — |
Event ID 234 — NtfsUpdateSmartTrimState: Vcb A10_Vcb, MUC A11_MarkUnusedContext - DSR range A12_RunIndex; offs 0xA13_DataSetRangeStartingOffset!
Description
NtfsUpdateSmartTrimState: Vcb A10_Vcb, MUC A11_MarkUnusedContext - DSR range A12_RunIndex; offs 0xA13_DataSetRangeStartingOffset!I64X!, len 0xA14_DataSetRangeLengthInBytes!I64X!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_MarkUnusedContext Pointer | — |
A12_RunIndex UInt32 | — |
A13_DataSetRangeStartingOffset HexInt64 | — |
A14_DataSetRangeLengthInBytes HexInt64 | — |
Event ID 235 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - MCB lcn A11_StartingLcn!
Description
NtfsUpdateSmartTrimState: Vcb A10_Vcb - MCB lcn A11_StartingLcn!I64X! len A12_ClusterCount!I64X! maps to TP map bits [0xA13_FirstTpMapBit, 0xA14_LastTpMapBit].
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_StartingLcn HexInt64 | — |
A12_ClusterCount HexInt64 | — |
A13_FirstTpMapBit HexInt32 | — |
A14_LastTpMapBit HexInt32 | — |
Event ID 236 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - Smart trim state on exit; A11_SmartTrimStateSlabRangesCount ranges.
Event ID 237 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - Range A11_SlabRangeIndex: FirstTPMapBit 0xA12_SlabRangeFirstTPMapBit, LastTPMapBit 0xA13_SlabRangeLastTPMapBit.
Description
NtfsUpdateSmartTrimState: Vcb A10_Vcb - Range A11_SlabRangeIndex: FirstTPMapBit 0xA12_SlabRangeFirstTPMapBit, LastTPMapBit 0xA13_SlabRangeLastTPMapBit.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_SlabRangeIndex UInt32 | — |
A12_SlabRangeFirstTPMapBit HexInt32 | — |
A13_SlabRangeLastTPMapBit HexInt32 | — |
Event ID 238 — NtfsUpdateSmartTrimState: Vcb A10_Vcb - Leaving.
Event ID 239 — NtfsEvalSmartTrimState: Vcb A10_Vcb - Entering.
Event ID 240 — NtfsEvalSmartTrimState: Vcb A10_Vcb - Precondition checks failed.
Event ID 241 — NtfsEvalSmartTrimState: Vcb A10_Vcb - Precondition checks failed; AcquiredBitmap A11_AcquiredBitmap.
Event ID 242 — NtfsEvalSmartTrimState: Vcb A10_Vcb - Checking slab 0xA11_TpMapBit for allocations.
Event ID 243 — NtfsEvalSmartTrimState: Vcb A10_Vcb - Slab 0xA11_TpMapBit has allocations, will not trim.
Event ID 244 — NtfsEvalSmartTrimState: Vcb A10_Vcb - Free slab found - TP map bit 0xA11_TpMapBit, lcn A12_SlabBaseLcn!
Event ID 245 — NtfsEvalSmartTrimState: Vcb A10_Vcb - Leaving.
Event ID 246 — NtfsFlushAllTrimHintsSynchronous (A10_Vcb): Calling NtfsFreeRecentlyDeallocated.
Event ID 247 — NtfsFlushAllTrimHintsSynchronous (A10_Vcb): Done calling NtfsFreeRecentlyDeallocated.
Event ID 248 — NtfsCommonDeviceControl: IOCTL_DISK_COPY_DATA is not allowed on unlocked volume.
Description
NtfsCommonDeviceControl: IOCTL_DISK_COPY_DATA is not allowed on unlocked volume. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, VcbState: 0x!08x!, SL control flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_VcbVcbState HexInt32 | — |
A15_IrpSpFlags HexInt32 | — |
Event ID 249 — NtfsVolumeDasdIo: Data section blocking flush.
Description
NtfsVolumeDasdIo: Data section blocking flush. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Flush status: A14_Status.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Status HexInt32 | — |
Event ID 250 — Could not find paging file run.
Description
Could not find paging file run.
Message #
Event ID 251 — Could not find paging file MCB entry.
Description
Could not find paging file MCB entry.
Message #
Event ID 252 — Could not find paging file run.
Description
Could not find paging file run.
Message #
Event ID 253 — Writing to $Bitmap.
Event ID 254 — NTFS: Posting hotfix on file object: A10_FileObject.
Event ID 255 — NTFS: Freeing Bad Vcn: A10_ULONGBadVcn!
Event ID 256 — NTFS: Retiring Bad Lcn: A10_ULONGBadLcn!
Event ID 257 — NTFS: Reallocating Bad Vcn
Description
NTFS: Reallocating Bad Vcn.
Message #
Event ID 258 — NTFS: Bad Cluster replaced
Description
NTFS: Bad Cluster replaced.
Message #
Event ID 259 — IrpContext: A10_IrpContext; Vcb: A11_Vcb; NewBufferSize: 0xA12_NewBufferSize!
Event ID 260 — Compression buffers are already big enough.
Event ID 262 — IrpContext: A10_IrpContext; Vcb: A11_Vcb; NewBufferSize: 0xA12_NewBufferSize!
Event ID 263 — Compression buffers are already big enough.
Event ID 265 — NtfsDefragFileInternal: Defrag is denied.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
A19_ScbPersist HexInt32 | — |
A20_CcbFlags HexInt32 | — |
Event ID 266 — NtfsDefragFileInternal: Vcb A10_Vcb - Calling FRD.
Event ID 267 — NtfsDefragFileInternal: Vcb A10_Vcb - Done calling FRD.
Event ID 268 — NtfsDefragFileInternal: Defrag is denied.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
A19_ScbPersist HexInt32 | — |
A20_CcbFlags HexInt32 | — |
Event ID 269 — NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber_ScbFcbFileReference!
Description
NtfsDefragFileInternal(!p!,!p!): Scb !p!, FRef !I64x!, Vcn !I64x!, CC !I64x!, CurrLcn !I64x!, NewLcn !I64x!, Len !x!, DA !d!, Status !x! - copy offload.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A14_MoveDataStartingVcnQuadPart HexInt64 | — |
A15_TransferClusters HexInt64 | — |
A16_Lcn HexInt64 | — |
A17_MoveDataStartingLcnQuadPart HexInt64 | — |
A18_CopyLength HexInt32 | — |
A19_FlagsUseDelayedAllocation Int32 | — |
A20_Status HexInt32 | — |
Event ID 270 — NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber_ScbFcbFileReference!
Description
NtfsDefragFileInternal(!p!,!p!): Scb !p!, FRef !I64x!, Vcn !I64x!, CC !I64x!, CurrLcn !I64x!, NewLcn !I64x!, Len !x!, DA !d!, Status !x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A14_MoveDataStartingVcnQuadPart HexInt64 | — |
A15_TransferClusters HexInt64 | — |
A16_Lcn HexInt64 | — |
A17_MoveDataStartingLcnQuadPart HexInt64 | — |
A18_CopyLength HexInt32 | — |
A19_FlagsUseDelayedAllocation Int32 | — |
A20_MyStatus HexInt32 | — |
Event ID 271 — NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber_ScbFcbFileReference!
Description
NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber_ScbFcbFileReference!I64x!, CurrLcn A14_Lcn!I64x!, Len A15_CopyLength, Status A16_MyStatus - read completed.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A14_Lcn HexInt64 | — |
A15_CopyLength HexInt32 | — |
A16_MyStatus HexInt32 | — |
Event ID 272 — NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber_ScbFcbFileReference!
Description
NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber_ScbFcbFileReference!I64x!, NewLcn A14_MoveDataStartingLcnQuadPart!I64x!, Len A15_CopyLength, Status A16_MyStatus - write completed.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A14_MoveDataStartingLcnQuadPart HexInt64 | — |
A15_CopyLength HexInt32 | — |
A16_MyStatus HexInt32 | — |
Event ID 273 — NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber_ScbFcbFileReference!
Description
NtfsDefragFileInternal(!p!,!p!): Scb !p!, FRef !I64x!, Vcn !I64x!, CC !I64x!, CurrLcn !I64x!, NewLcn !I64x!, DA !d!, ValidClusters !I64x! - beyond VDL.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A14_MoveDataStartingVcnQuadPart HexInt64 | — |
A15_TransferClusters HexInt64 | — |
A16_Lcn HexInt64 | — |
A17_MoveDataStartingLcnQuadPart HexInt64 | — |
A18_FlagsUseDelayedAllocation Int32 | — |
A19_ValidClusters HexInt64 | — |
Event ID 274 — NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber_ScbFcbFileReference!
Description
NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber_ScbFcbFileReference!I64x!, Vcn A14_MoveDataStartingVcnQuadPart!I64x!, CC A15_TransferClusters!I64x! - committed.
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A14_MoveDataStartingVcnQuadPart HexInt64 | — |
A15_TransferClusters HexInt64 | — |
Event ID 275 — NtfsDefragFile: Defrag is denied without manage volume access.
Description
NtfsDefragFile: Defrag is denied without manage volume access. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, Ccb flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_FcbVcb Pointer | — |
A12__FcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_FcbNULLNtfsFullFileRefNumber_FcbFileReference0 HexInt64 | — |
A16_CcbNULLCcbFlags0 HexInt32 | — |
Event ID 276 — NtfsEncryptDecryptOnline: Defrag is denied.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18_ScbAttributeNameBuffer UnicodeString | — |
A19_ScbPersist HexInt32 | — |
A20_CcbFlags HexInt32 | — |
Event ID 277 — NtfsEncryptDecryptOnline: Vcb A10_Vcb - Calling FRD.
Event ID 278 — NtfsEncryptDecryptOnline: Vcb A10_Vcb - Done calling FRD.
Event ID 279 — NtfsEncryptDecryptOnline: Defrag is denied.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
A19_ScbPersist HexInt32 | — |
A20_CcbNULLCcbFlags0 HexInt32 | — |
Event ID 280 — SCB: A10_Scb, VDL=0xA11_ScbHeaderValidDataLengthQuadPart!
Description
SCB: A10_Scb, VDL=0xA11_ScbHeaderValidDataLengthQuadPart!I64x!, FS=0xA12_ScbHeaderFileSizeQuadPart!I64x!, StartOff=0xA13_QueryDaxExtentsFileOffset!I64x!, StartVcn=0xA14_StartingVcn!I64x!, Length=0xA15_QueryDaxExtentsLength!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer | — |
A11_ScbHeaderValidDataLengthQuadPart HexInt64 | — |
A12_ScbHeaderFileSizeQuadPart HexInt64 | — |
A13_QueryDaxExtentsFileOffset HexInt64 | — |
A14_StartingVcn HexInt64 | — |
A15_QueryDaxExtentsLength HexInt64 | — |
Event ID 281 — StartOff=0xA10_QueryDaxExtentsFileOffset!
Description
StartOff=0x!I64x!, Length=0x!I64x!, EffectiveLength=0x!I64x! StartVcn=0x!I64x!, BeyondEndVcn=0x!I64x!, Clusters=0x!I64x!, LastVcnInFile=0x!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_QueryDaxExtentsFileOffset HexInt64 | — |
A11_QueryDaxExtentsLength HexInt64 | — |
A12_EffectiveInputFileRegionLength HexInt64 | — |
A13_StartingVcn HexInt64 | — |
A14_BeyondEndVcn HexInt64 | — |
A15_RemainingClusterCount HexInt64 | — |
A16_LastVcnInFile HexInt64 | — |
Event ID 282 — NumberOfValidRuns: 0
Description
NumberOfValidRuns: 0.
Message #
Event ID 283 — RemainingClusterCount: 0xA10_RemainingClusterCount!
Event ID 284 — STATUS_BUFFER_TOO_SMALL from FsLib.
Description
STATUS_BUFFER_TOO_SMALL from FsLib. NumberOfValidRuns: 0xA10_ExtentsDescriptorNumberOfValidRuns, MaxRuns: 0xA11_MaxRuns, BytesReturned: 0xA12_BytesReturned!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_ExtentsDescriptorNumberOfValidRuns HexInt32 | — |
A11_MaxRuns HexInt32 | — |
A12_BytesReturned HexInt64 | — |
Event ID 285 — Made an educated guess for remaining runs.
Event ID 286 — Made a wild guess for remaining runs.
Event ID 287 — NumberOfValidRuns: 0xA10_ExtentsDescriptorNumberOfValidRuns!
Description
NumberOfValidRuns: 0xA10_ExtentsDescriptorNumberOfValidRuns!08x!, MaxRuns: 0xA11_MaxRuns!08x!, Status: 0xA12_Status!08x!, BytesReturned: 0xA13_BytesReturned!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_ExtentsDescriptorNumberOfValidRuns HexInt32 | — |
A11_MaxRuns HexInt32 | — |
A12_Status HexInt32 | — |
A13_BytesReturned HexInt64 | — |
Event ID 288 — BasePage: 0xA10_ExtentsDescriptorRunIndexBasePage!
Event ID 289 — About to zero range - ZeroStart: 0xA10_ZeroStart!
Event ID 290 — Zeroed range - ZeroStart: 0xA10_ZeroStart!
Event ID 291 — NtfsCommonQueryInformation: File information query not allowed as file was opened by ID without traversal privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
A19_CcbFlags HexInt32 | — |
Event ID 292 — NtfsQueryCaseSensitiveInfo: Case sensitive info query not allowed without read attributes access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
A19_ARGUMENT_PRESENTCcbCcbAccessFlags0 HexInt32 | — |
A20_ARGUMENT_PRESENTCreateContextCreateContextPreviouslyGrantedAccess0 HexInt32 | — |
Event ID 293 — NtfsQueryNameInfo: Name info query not allowed as file was opened without traverse privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
A19_CcbFlags HexInt32 | — |
Event ID 294 — NtfsQueryLinksInfo: Link info query not allowed as file was opened without traverse privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_FcbVcb Pointer | — |
A12__FcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_CcbNULLCcbFlags0 HexInt32 | — |
Event ID 295 — NtfsSetCaseSensitiveInfo: Cannot mark root directory of a volume case-sensitive.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
A19_ScbVcbVpbRealDeviceFlags HexInt32 | — |
Event ID 296 — NtfsRemoveSupersededTarget: Can not do a superseding rename over a system file.
Description
NtfsRemoveSupersededTarget: Can not do a superseding rename over a system file. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, Fcb state: !x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_RenameCleanupTargetLinkFcb Pointer | — |
A15_NtfsFullFileRefNumber_RenameCleanupTargetLinkFcbFileReference HexInt64 | — |
A16_RenameCleanupTargetLinkFcbFcbState HexInt32 | — |
Event ID 297 — NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_RenameCleanupTargetLinkFcb Pointer | — |
A15_NtfsFullFileRefNumber_RenameCleanupTargetLinkFcbFileReference HexInt64 | — |
A16_RenameCleanupTargetLinkFcbTxfFcbTxfNumWriters Int32 | — |
Event ID 298 — NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_LcbToDeleteFcb Pointer | — |
A15_NtfsFullFileRefNumber_LcbToDeleteFcbFileReference HexInt64 | — |
A16_LcbToDelete Pointer | — |
A17_WppCountedStringWLcbToDeleteFileNameAttrFileNameUSHORTLcbToDeleteFileNameAttrFileNameLength CountedUtf16String | — |
A18_LcbToDeleteTxfNumWriters Int32 | — |
Event ID 299 — NtfsRemoveSupersededTarget: Can not do a superseding rename over a file opened by ID.
Description
NtfsRemoveSupersededTarget: Can not do a superseding rename over a file opened by ID. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, Cleanup count: !d!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_RenameCleanupTargetLinkFcb Pointer | — |
A15_NtfsFullFileRefNumber_RenameCleanupTargetLinkFcbFileReference HexInt64 | — |
A16_RenameCleanupTargetLinkFcbCleanupCount Int32 | — |
Event ID 300 — NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles via either part of the long/short pair.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_LcbToDeleteFcb Pointer | — |
A15_NtfsFullFileRefNumber_LcbToDeleteFcbFileReference HexInt64 | — |
A16_LcbToDelete Pointer | — |
A17_WppCountedStringWLcbToDeleteFileNameAttrFileNameUSHORTLcbToDeleteFileNameAttrFileNameLength CountedUtf16String | — |
A18_LcbToDeleteCleanupCount Int32 | — |
A19_SplitPrimaryLcb Pointer | — |
A20_SplitPrimaryLcbNULLWppCountedStringWSplitPrimaryLcbFileNameAttrFileNameUSHORTSplitPrimaryLcbFileNameAttrFileNameLengthWppCountedStringWNULL0 CountedUtf16String | — |
A21_SplitPrimaryLcbNULLSplitPrimaryLcbCleanupCount0 Int32 | — |
Event ID 301 — NtfsSetRenameInfo: Can not rename a file marked for deletion.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_LcbFcb Pointer | — |
A15_NtfsFullFileRefNumber_LcbFcbFileReference HexInt64 | — |
A16_LcbFcbFcbState HexInt32 | — |
A17_Lcb Pointer | — |
A18_WppCountedStringWLcbFileNameAttrFileNameUSHORTLcbFileNameAttrFileNameLength CountedUtf16String | — |
A19_LcbFileNameAttrFlags HexInt32 | — |
A20_LcbLcbState HexInt32 | — |
Event ID 302 — NtfsSetRenameInfo: Can not rename a txf directory.
Description
NtfsSetRenameInfo: Can not rename a txf directory. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, File attributes: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_ScbFcbInfoFileAttributes HexInt32 | — |
Event ID 303 — NtfsSetRenameInfo: Can not rename into a system directory.
Description
NtfsSetRenameInfo: Can not rename into a system directory. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, FcbState: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_TargetParentScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_TargetParentScbFcbFileReference HexInt64 | — |
A16_TargetParentScbFcbFcbState HexInt32 | — |
Event ID 304 — NtfsSetRenameInfo: Can not rename a file that is part of a TxF transaction.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_TargetParentScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_TargetParentScbFcbFileReference HexInt64 | — |
A16_TargetParentScbFcbInfoFileAttributes HexInt32 | — |
A17_TargetParentScbFcbFcbState HexInt32 | — |
Event ID 305 — NtfsSetRenameInfo: The file should not have in-memory directory descendents.
Description
NtfsSetRenameInfo: The file should not have in-memory directory descendents. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
Event ID 306 — NtfsSetRenameInfo: Child Scb mismatch.
Description
NtfsSetRenameInfo: Child Scb mismatch. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, Potential child FileRef: !I64x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_NtfsFullFileRefNumber_TargetParentScbFcbFileReference HexInt64 | — |
Event ID 307 — NtfsSetLinkInfo: Set link info is not allowed on txf directory.
Description
NtfsSetLinkInfo: Set link info is not allowed on txf directory. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, FileName: !S!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
Event ID 308 — NtfsSetLinkInfo: Set link info is not allowed on a file in a TxF transaction.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
A17_TxfVisibleLinks Int32 | — |
Event ID 309 — NtfsSetLinkInfo: Set link info failed due to caller not having FILE_WRITE_ATTRIBUTES access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
A17_AccessStatus HexInt32 | — |
Event ID 310 — NtfsSetLinkInfo: Creating a link in system directory is not allowed.
Description
NtfsSetLinkInfo: Creating a link in system directory is not allowed. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, NewLinkName: !S!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_TargetParentScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_TargetParentScbFcbFileReference HexInt64 | — |
A16__NewLinkName CountedUtf16String | — |
Event ID 311 — NtfsSetLinkInfo: Creating a link in $txf is not allowed if the RM is running.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_TargetParentScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_TargetParentScbFcbFileReference HexInt64 | — |
A16__NewLinkName CountedUtf16String | — |
A17_TargetParentScbFcbTxfRmcbRmState HexInt32 | — |
Event ID 312 — NtfsSetShortNameInfo: Can not set a short name on a deleted file.
Description
NtfsSetShortNameInfo: Can not set a short name on a deleted file. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, Lcb: !p!, Link Name: !S!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_LcbFcb Pointer | — |
A15_NtfsFullFileRefNumber_LcbFcbFileReference HexInt64 | — |
A16_Lcb Pointer | — |
A17_WppCountedStringWLcbFileNameAttrFileNameUSHORTLcbFileNameAttrFileNameLength CountedUtf16String | — |
Event ID 313 — NtfsSetShortNameInfo: Can not set a short name on a file under the $TxF directory.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_LcbFcb Pointer | — |
A15_NtfsFullFileRefNumber_LcbFcbFileReference HexInt64 | — |
A16_Lcb Pointer | — |
A17_WppCountedStringWLcbFileNameAttrFileNameUSHORTLcbFileNameAttrFileNameLength CountedUtf16String | — |
A18_NtfsFullFileRefNumber_ParentScbFcbFileReference HexInt64 | — |
Event ID 314 — NtfsCheckScbForLinkRemoval: Existing handles are not allowed if Txf transaction is doing the rename.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_NextScbVcb Pointer | — |
A12__NextScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWNextScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHNextScbVcbVpb CountedUtf16String | — |
A14_NextScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_NextScbFcbFileReference HexInt64 | — |
A16_NextScbCleanupCount Int32 | — |
Event ID 315 — NtfsCheckScbForLinkRemoval: Not all open handles for the stream are by-id opens.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_NextScbVcb Pointer | — |
A12__NextScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWNextScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHNextScbVcbVpb CountedUtf16String | — |
A14_NextScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_NextScbFcbFileReference HexInt64 | — |
A16_ByIdCcbs Int32 | — |
A17_NextScbCleanupCount Int32 | — |
Event ID 316 — NtfsStreamRename: Deny access due to encryption happening on source stream.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
A19_ScbState HexInt32 | — |
A20_ScbScbTypeDataHighWaterMark Int64 | — |
Event ID 317 — NtfsProcessTreeForRename: Deny access due to number of batch oplocks has grown.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_DirectoryScbVcb Pointer | — |
A12__DirectoryScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWDirectoryScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHDirectoryScbVcbVpb CountedUtf16String | — |
A14_DirectoryScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_DirectoryScbFcbFileReference HexInt64 | — |
A16_ULONGIrpIoStatusInformation Int32 | — |
A17_BatchOplockCount Int32 | — |
Event ID 318 — NtfsFlushVolumeFlushSingleFcb: Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, Fcb: A12_Fcb, LocalFlags: A13_LocalFlagsEntireFlags!
Event ID 319 — NtfsFlushVolumeFlushSingleFcb: Thread: A10_PsGetCurrentThread, Scb: A11_Scb.
Event ID 320 — NtfsFlushVolume: Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, LocalFlags: A12_LocalFlagsEntireFlags!
Event ID 321 — NtfsFlushVolume setting SCB_PERSIST_VOLUME_DISMOUNTED on BitmapScb Scb: A10_VcbBitmapScb Vcb: A11_Vcb.
Event ID 322 — NtfsFlushVolume setting SCB_PERSIST_VOLUME_DISMOUNTED on MftScb Scb: A10_VcbMftScb Vcb: A11_Vcb.
Event ID 323 — NtfsFlushCompletionRoutine: Vcb A10_PNTFS_DISK_FLUSH_CONTEXTContextVcb - Add context A11_Context into completion queue.
Event ID 324 — NtfsFlushCompletionRoutine: Vcb A10_PNTFS_DISK_FLUSH_CONTEXTContextVcb - Add context A11_Context into WorkQueue - Flink A12_NtfsDataDiskFlushContextCompletedWorkItemListFlink.
Description
NtfsFlushCompletionRoutine: Vcb A10_PNTFS_DISK_FLUSH_CONTEXTContextVcb - Add context A11_Context into WorkQueue - Flink A12_NtfsDataDiskFlushContextCompletedWorkItemListFlink.
Message #
Fields #
| Name | Description |
|---|---|
A10_PNTFS_DISK_FLUSH_CONTEXTContextVcb Pointer | — |
A11_Context Pointer | — |
A12_NtfsDataDiskFlushContextCompletedWorkItemListFlink Pointer | — |
Event ID 325 — NtfsDiskFlushContextWorkItemProcessing: Process work item
Description
NtfsDiskFlushContextWorkItemProcessing: Process work item.
Message #
Event ID 326 — NtfsDiskFlushContextWorkItemProcessing: Nothing to work on
Description
NtfsDiskFlushContextWorkItemProcessing: Nothing to work on.
Message #
Event ID 327 — Irp: A10_Irp, IC: A11_IrpContext, Vcb: A12_IrpContextVcb, MinorCode: A13_IrpSpMinorFunction!
Description
Irp: A10_Irp, IC: A11_IrpContext, Vcb: A12_IrpContextVcb, MinorCode: A13_IrpSpMinorFunction!02x!, FsControlCode: 0xA14_FsControlCode!08x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Irp Pointer | — |
A11_IrpContext Pointer | — |
A12_IrpContextVcb Pointer | — |
A13_IrpSpMinorFunction HexInt32 | — |
A14_FsControlCode HexInt32 | — |
Event ID 328 — NtfsLockVolumeInternal: Cannot lock the volume.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_VcbVcbState HexInt32 | — |
A15_VcbDisallowDismountCount Int32 | — |
A16_ExplicitLock10 Int32 | — |
A17_ReadULongNoFence_VcbCleanupCount Int32 | — |
A18_UserHandleCountSystemHandleCountVcbExternalMetadataCleanupCount Int32 | — |
Event ID 329 — NtfsLockVolumeInternal: Volume is already locked.
Description
NtfsLockVolumeInternal: Volume is already locked.Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Vcb State: 0xA14_VcbVcbState!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_VcbVcbState HexInt32 | — |
Event ID 330 — NtfsLockVolumeInternal: Failed to flush system files on the volume.
Description
NtfsLockVolumeInternal: Failed to flush system files on the volume. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Flush Status: A14_Status.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Status HexInt32 | — |
Event ID 331 — NtfsLockVolumeInternal: Failed to flush system files on the volume.
Description
NtfsLockVolumeInternal: Failed to flush system files on the volume.Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Flush Status: A14_Status.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Status HexInt32 | — |
Event ID 332 — NtfsLockVolumeInternal: Outstanding user files open after flush and retry.
Event ID 333 — NtfsLockVolume: Cannot lock volume due to caller does not have manage volume privilege.
Description
NtfsLockVolume: Cannot lock volume due to caller does not have manage volume privilege. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Ccb access flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 334 — NtfsLockVolume: Cannot lock volume due to active secondary RMs on the volume.
Description
NtfsLockVolume: Cannot lock volume due to active secondary RMs on the volume. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Active RM count: !d!, Default RM Active: !d!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ActiveRmCount Int32 | — |
A15_DefaultRmActive10 Int32 | — |
Event ID 335 — A10___FUNCTION__: Setting RM at 0xA11_PVOIDVcbTxfVcbDefaultRm ({A12_VcbTxfVcbDefaultRmNULL_VcbTxfVcbDefaultRmRmIdNULL}) up for auto-restart.
Description
A10___FUNCTION__: Setting RM at 0xA11_PVOIDVcbTxfVcbDefaultRm ({A12_VcbTxfVcbDefaultRmNULL_VcbTxfVcbDefaultRmRmIdNULL}) up for auto-restart.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_PVOIDVcbTxfVcbDefaultRm Pointer | — |
A12_VcbTxfVcbDefaultRmNULL_VcbTxfVcbDefaultRmRmIdNULL GUID | — |
Event ID 336 — NtfsUnlockVolume: Cannot unlock volume due to caller does not have manage volume privilege.
Description
NtfsUnlockVolume: Cannot unlock volume due to caller does not have manage volume privilege. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Ccb access flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 337 — NtfsDismountVolume: IC: A10_IrpContext, Vcb: A11_Vcb, Label: A12__VolumeLabel, DeviceName: A13__VcbDeviceName.
Event ID 338 — NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open for write access.
Description
NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open for write access. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Ccb access flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 339 — NtfsDismountVolume: Cannot dismount volume due to volume being locked.
Description
NtfsDismountVolume: Cannot dismount volume due to volume being locked. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, VcbState: 0xA14_VcbVcbState!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_VcbVcbState HexInt32 | — |
Event ID 340 — NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open for write access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_VcbVcbState HexInt32 | — |
A15_VcbReadOnlyCloseCount Int32 | — |
A16_VcbCloseCount Int32 | — |
A17_VcbSystemFileCloseCount Int32 | — |
Event ID 341 — NtfsDismountVolume: Could not flush trim hints.
Description
NtfsDismountVolume: Could not flush trim hints. Couldn't make progress flushing log.Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, VcbState: 0xA14_VcbVcbState!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_VcbVcbState HexInt32 | — |
Event ID 342 — NtfsMarkVolumeDirty: Cannot mark volume dirty due to caller not having manage volume privilege.
Description
NtfsMarkVolumeDirty: Cannot mark volume dirty due to caller not having manage volume privilege. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Ccb access flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 343 — NtfsGetVolumeBitmap: Cannot get volume bitmap due to caller not having manage volume privilege.
Description
NtfsGetVolumeBitmap: Cannot get volume bitmap due to caller not having manage volume privilege. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Ccb access flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 344 — NtfsGetBootAreaInfo: Cannot get boot area info due to caller not having manage volume privilege.
Description
NtfsGetBootAreaInfo: Cannot get boot area info due to caller not having manage volume privilege. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Ccb access flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbAccessFlags HexInt32 | — |
Event ID 345 — NtfsGetRetrievalPointers: Cannot get retrieval pointers due to caller not having manage volume privilege.
Description
NtfsGetRetrievalPointers: Cannot get retrieval pointers due to caller not having manage volume privilege. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Ccb access flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbAccessFlags HexInt32 | — |
Event ID 346 — NtfsGetRetrievalPointerBase: Cannot get revrieval pointer base info due to caller not having manage volume privilege.
Event ID 347 — NtfsGetRetrievalPointerBase: Cannot get revrieval pointer base info due to caller not having manage volume privilege or this is not a volume open.
Event ID 348 — NtfsCreateUsnJournal: Cannot create Usn journal due to caller not having manage volume privilege.
Event ID 349 — NtfsUsnTrackModifiedRanges: Cannot enable range tracking due to caller not having manage volume privilege.
Description
NtfsUsnTrackModifiedRanges: Cannot enable range tracking due to caller not having manage volume privilege. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Ccb access flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 350 — NtfsEnumerateUsnData: Cannot enumerate Usn data due to caller not having manage volume privilege.
Description
NtfsEnumerateUsnData: Cannot enumerate Usn data due to caller not having manage volume privilege. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Ccb access flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 351 — NtfsFindFilesOwnedBySid: Caller not having manage volume privilege, backup access or can bypass traverse checks.
Event ID 352 — NtfsFindFilesOwnedBySid: Caller not having manage volume privilege or backup access and is not admin.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbAccessFlags HexInt32 | — |
A15_CcbFlags HexInt32 | — |
A16_CallerId Int32 | — |
A17_ContextOwnerId Int32 | — |
Event ID 353 — NtfsSetSparse: Caller does not have appropriate write access to the stream.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
A17_CcbAccessFlags HexInt32 | — |
A18_FileObjectWriteAccess10 Int32 | — |
Event ID 354 — NtfsSetSparse: Cannot desparse encrypted file without write data access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
A17_CcbAccessFlags HexInt32 | — |
A18_ScbAttributeFlags HexInt32 | — |
Event ID 355 — NtfsZeroRange: User mode caller not allowed.
Event ID 356 — IC: A10_IrpContext, Scb: A11_Scb, FileObject: A12_IrpSpFileObject.
Event ID 357 — IC: A10_IrpContext, EncryptionOperation: 0xA11_EncryptionOperation!
Event ID 358 — NtfsReadRawEncrypted: Caller does not have backup access or read data access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
A17_CcbAccessFlags HexInt32 | — |
Event ID 359 — NtfsWriteRawEncrypted: Caller does not have write data access or restore access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
A17_CcbAccessFlags HexInt32 | — |
Event ID 360 — NtfsWriteRawEncrypted: Caller not having manage volume privilege.
Description
NtfsWriteRawEncrypted: Caller not having manage volume privilege. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Ccb access flags: 0xA14_CcbNULLCcbAccessFlags0!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 361 — NtfsLookupStreamFromCluster: Caller not having manage volume privilege.
Description
NtfsLookupStreamFromCluster: Caller not having manage volume privilege. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Ccb access flags: 0xA14_CcbNULLCcbAccessFlags0!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 362 — NtfsChangeVolumeSize: Caller not having manage volume privilege.
Description
NtfsChangeVolumeSize: Caller not having manage volume privilege. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Ccb access flags: 0xA14_CcbNULLCcbAccessFlags0!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 363 — NtfsChangeVolumeSize (A10_Vcb): Calling NtfsFreeRecentlyDeallocated.
Event ID 364 — NtfsChangeVolumeSize (A10_Vcb): Done calling NtfsFreeRecentlyDeallocated.
Event ID 365 — NtfsMarkHandle: Caller does not have a valid volume handle or manage volume access or is not kernel model caller.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
A17_CcbAccessFlags HexInt32 | — |
A18_HandleInfoHandleInfo HexInt32 | — |
A19_IrpRequestorMode Int32 | — |
Event ID 366 — NtfsMarkHandle: Caller not having manage volume privilege.
Description
NtfsMarkHandle: Caller not having manage volume privilege. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Ccb access flags: 0xA14_DasdCcbNULLDasdCcbAccessFlags0!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_DasdCcbNULLDasdCcbAccessFlags0 HexInt32 | — |
Event ID 367 — NtfsMarkHandle: Cannot deny defrag.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
A19_ScbPersist HexInt32 | — |
A20_HandleInfoHandleInfo HexInt32 | — |
Event ID 368 — NtfsMarkHandle: Cannot deny Frs consolidation.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_FcbFcbState2 HexInt32 | — |
A17_Scb Pointer | — |
A18_ScbAttributeTypeCode HexInt32 | — |
A19__ScbAttributeName CountedUtf16String | — |
A20_ScbPersist HexInt32 | — |
A21_HandleInfoHandleInfo HexInt32 | — |
Event ID 369 — NtfsMarkHandle: Cannot filter metadata.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_FcbFcbState HexInt32 | — |
A17_Scb Pointer | — |
A18_ScbAttributeTypeCode HexInt32 | — |
A19__ScbAttributeName CountedUtf16String | — |
A20_ScbPersist HexInt32 | — |
A21_HandleInfoHandleInfo HexInt32 | — |
A22_IrpRequestorMode Int32 | — |
Event ID 370 — NtfsMarkHandle: Mark handle is not allowed on system files.
Description
NtfsMarkHandle: Mark handle is not allowed on system files. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, FcbState: 0x!08x!, HandleInfo flags: !x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_ScbFcbFcbState HexInt32 | — |
A17_HandleInfoHandleInfo HexInt32 | — |
Event ID 371 — NtfsMarkHandle: File already has user writable references.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
A19_HandleInfoHandleInfo HexInt32 | — |
Event ID 372 — NtfsMarkHandle: File was granted write access previously but no oplocks were broken.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
A19_ScbShareAccessWriters Int32 | — |
Event ID 373 — NtfsPrefetchFile: Caller not having manage volume privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_TypeOfOpen Int32 | — |
A12_Vcb Pointer | — |
A13__VcbVolumeName CountedUtf16String | — |
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A15_ScbFcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A18_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 374 — NtfsSetZeroOnDeallocate: Only allowed on regular user files opened for write.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_TypeOfOpen Int32 | — |
A15_IrpSpFileObjectWriteAccess10 Int32 | — |
A16_ScbFcb Pointer | — |
A17_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A18_ScbAttributeTypeCode HexInt32 | — |
A19_ScbFcbFcbState HexInt32 | — |
A20_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
Event ID 375 — NtfsSetShortNameBehavior: Caller not having manage volume privilege.
Description
NtfsSetShortNameBehavior: Caller not having manage volume privilege. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Ccb access flags: 0xA14_CcbNULLCcbAccessFlags0!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 376 — Setting VCB_EXT_CHAR_STATE_ALLOW_EXT_CHAR for volume 0xA10_PVOIDVcb to A11_InputParameter.
Event ID 377 — NtfsQueryPagefileEncryption: Caller not having manage volume privilege.
Description
NtfsQueryPagefileEncryption: Caller not having manage volume privilege. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Ccb access flags: 0xA14_CcbNULLCcbAccessFlags0!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 378 — NtfsQueryPagefileEncryption: Caller not having manage volume privilege.
Description
NtfsQueryPagefileEncryption: Caller not having manage volume privilege. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Ccb access flags: 0xA14_CcbNULLCcbAccessFlags0!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 379 — NtfsResetVolsnapBehaviorForVolume: Volsnap hints are disabled by registry.
Description
NtfsResetVolsnapBehaviorForVolume: Volsnap hints are disabled by registry. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, NtfsData Flags: !x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_IrpContextVcb Pointer | — |
A12__IrpContextVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWIrpContextVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHIrpContextVcbVpb CountedUtf16String | — |
A14_NtfsDataFlags HexInt32 | — |
Event ID 380 — NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege.
Description
NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Ccb access flags: 0xA14_CcbNULLCcbAccessFlags0!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 381 — Resetting Volsnap behavior for VCB = 0xA10_Vcb.
Event ID 382 — NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege.
Description
NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Ccb access flags: 0xA14_CcbNULLCcbAccessFlags0!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 383 — NtfsCorruptionHandling: Caller not having manage volume privilege.
Description
NtfsCorruptionHandling: Caller not having manage volume privilege. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, Ccb access flags: 0xA14_CcbNULLCcbAccessFlags0!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 384 — NtfsGlobalCorruptionHandling: Caller does not have manage volume privilege.
Description
NtfsGlobalCorruptionHandling: Caller does not have manage volume privilege. Thread: A10_PsGetCurrentThread, Vcb: A11_IrpContextVcb, VolumeName: A12__IrpContextVcbVolumeName, VolumeLabel: A13_WppCountedStringWIrpContextVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHIrpContextVcbVpb.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_IrpContextVcb Pointer | — |
A12__IrpContextVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWIrpContextVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHIrpContextVcbVpb CountedUtf16String | — |
Event ID 385 — Scrub resume from SystemScbIndex: A10_ScrubResumeContextSystemScbIndex Vcn: A11_ScrubResumeContextResumeVcn!
Description
Scrub resume from SystemScbIndex: A10_ScrubResumeContextSystemScbIndex Vcn: A11_ScrubResumeContextResumeVcn!#I64x! + A12_ScrubResumeContextResumeVcnOffset!#x!
Message #
Fields #
| Name | Description |
|---|---|
A10_ScrubResumeContextSystemScbIndex UInt32 | — |
A11_ScrubResumeContextResumeVcn HexInt64 | — |
A12_ScrubResumeContextResumeVcnOffset HexInt32 | — |
Event ID 386 — Scb:A10_Scb Scrub resume from Vcn: A11_ScrubResumeContextResumeVcn!
Event ID 387 — Scrub SystemScbIndex: A10_ScrubResumeContextSystemScbIndex.
Event ID 388 — NtfsScrubData: Caller not having manage volume privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_TypeOfOpen Int32 | — |
A15_ScbFcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17__CcbFullFileName CountedUtf16String | — |
A18_CcbAccessFlags HexInt32 | — |
Event ID 389 — Scrub not supported for Txf file, Scb: A10_Scb, TxfScb: A11_ScbTxfScb.
Event ID 390 — Scrub SCRUB_DATA_INPUT_FLAG_SKIP_NON_INTEGRITY_DATA is request.
Description
Scrub SCRUB_DATA_INPUT_FLAG_SKIP_NON_INTEGRITY_DATA is request. noop.
Message #
Event ID 391 — Scb:A10_Scb ScrubInternal OperationStatus: A11_ScrubContextOperationStatus Repaired: A12_ScrubContextNumberOfBytesRepaired!
Description
Scb:!p! ScrubInternal OperationStatus: !S! Repaired: !#I64x! Failed: !#I64x! FileOffset: !#I64x! Length: !#I64x! ParityExtentCount: !u!
Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer | — |
A11_ScrubContextOperationStatus HexInt32 | — |
A12_ScrubContextNumberOfBytesRepaired HexInt64 | — |
A13_ScrubContextNumberOfBytesFailed HexInt64 | — |
A14_ScrubContextErrorFileOffset HexInt64 | — |
A15_ScrubContextErrorLength HexInt64 | — |
A16_ScrubContextParityExtentDataNumberOfParityExtents UInt32 | — |
Event ID 392 — Scb:A10_Scb ScrubInternal Status: A11_Status Repaired: A12_ScrubContextNumberOfBytesRepaired!
Description
Scb:A10_Scb ScrubInternal Status: A11_Status Repaired: A12_ScrubContextNumberOfBytesRepaired!#I64x! Failed: A13_ScrubContextNumberOfBytesFailed!#I64x! ParityExtentCount: A14_ScrubContextParityExtentDataNumberOfParityExtents.
Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer | — |
A11_Status HexInt32 | — |
A12_ScrubContextNumberOfBytesRepaired HexInt64 | — |
A13_ScrubContextNumberOfBytesFailed HexInt64 | — |
A14_ScrubContextParityExtentDataNumberOfParityExtents UInt32 | — |
Event ID 393 — InternalFileReference: A10_InternalFileReference.
Event ID 394 — InternalFileReference:A10_InternalFileReference.
Event ID 395 — Scb:A10_Scb Incomplete IoCount:A11_ScrubIoCount Cancel:A12_IrpCancel ParityExtentCount:A13_ScrubContextParityExtentDataNumberOfParityExtents.
Description
Scb:A10_Scb Incomplete IoCount:A11_ScrubIoCount Cancel:A12_IrpCancel ParityExtentCount:A13_ScrubContextParityExtentDataNumberOfParityExtents.
Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer | — |
A11_ScrubIoCount UInt32 | — |
A12_IrpCancel UInt32 | — |
A13_ScrubContextParityExtentDataNumberOfParityExtents UInt32 | — |
Event ID 396 — Scb:A10_Scb Scrub skipping resident attribute (d) (A11__ScbAttributeName).
Event ID 397 — Scb:A10_Scb Scrub skipping resident attribute (A11__ScbAttributeName).
Event ID 398 — Scb:A10_Scb Scrub StartingVcn.
Event ID 399 — Scb:A10_Scb Scrub starting vcn is beyond VDL.
Event ID 400 — Scb:A10_Scb Scrub no more Mcb entries from StartingVcn:A11_StartingVcn!
Event ID 401 — Scb:A10_Scb Scrub skipping UNUSED_LCN Vcn: A11_StartingVcn!
Event ID 402 — Scb:A10_Scb StartingVcn:A11_StartingVcn!
Event ID 403 — Scb:A10_Scb ScrubDsmRange [A11_DsmRangeStartingOffset!
Description
Scb:A10_Scb ScrubDsmRange [A11_DsmRangeStartingOffset!#I64x!,A12_DsmRangeStartingOffsetDsmRangeLengthInBytes!#I64x!) Length:A13_DsmRangeLengthInBytes!#I64x! (Bytes) StartingVcn:A14_StartingVcn!#I64x! + A15_StartingVcnOffset!#x! SectorAlignedVdl:A16_SectorAlignedVdl!#I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer | — |
A11_DsmRangeStartingOffset HexInt64 | — |
A12_DsmRangeStartingOffsetDsmRangeLengthInBytes HexInt64 | — |
A13_DsmRangeLengthInBytes HexInt64 | — |
A14_StartingVcn HexInt64 | — |
A15_StartingVcnOffset HexInt32 | — |
A16_SectorAlignedVdl HexInt64 | — |
Event ID 404 — Scrub found problems Scb: A10_Scb Vcn A11_StartingVcn!
Description
Scrub found problems Scb: !p! Vcn !#I64x! FileOffset: !#I64x! Length: !#I64x! Status: !S! BytesFailed: !#I64x! BytesRepaired: !#I64x! NewParityExtents: !u!
Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer | — |
A11_StartingVcn HexInt64 | — |
A12_ScrubContextErrorFileOffset HexInt64 | — |
A13_ScrubbedLength HexInt64 | — |
A14_ScrubContextOperationStatus HexInt32 | — |
A15_ScrubContextNumberOfBytesFailed HexInt64 | — |
A16_ScrubContextNumberOfBytesRepaired HexInt64 | — |
A17_NewParityExtentCount UInt32 | — |
Event ID 405 — Scb:A10_Scb DsmAction_Scrub call failed, Status: A11_Status.
Event ID 406 — Scb:A10_Scb DsmAction_Scrub operation failed, Status: A11_Status.
Event ID 407 — FSCTL_REPAIR_COPIES not supported for Txf file, Scb: A10_Scb, TxfScb: A11_ScbTxfScb.
Event ID 408 — Scb:A10_Scb FSCTL_REPAIR_COPIES skipping resident attribute (d) (A11__ScbAttributeName).
Event ID 409 — Scb:A10_Scb FSCTL_REPAIR_COPIES skipping resident attribute (A11__ScbAttributeName).
Event ID 410 — FSCTL_REPAIR_COPIES interrupted by thread termination.
Description
FSCTL_REPAIR_COPIES interrupted by thread termination.
Message #
Event ID 411 — FSCTL_REPAIR_COPIES canceled
Description
FSCTL_REPAIR_COPIES canceled.
Message #
Event ID 412 — Scb:A10_Scb FSCTL_REPAIR_COPIES no more Mcb entries from StartingVcn:A11_StartingVcn!
Event ID 413 — Scb:A10_Scb FSCTL_REPAIR_COPIES No more Mcb entries (unallocated) from StartingVcn:A11_StartingVcn!
Event ID 414 — Scb:A10_Scb FSCTL_REPAIR_COPIES skipping UNUSED_LCN Vcn: A11_StartingVcn!
Event ID 415 — Scb:A10_Scb RepairDsmRange [A11_RepairDataSetRangeStartingOffset!
Description
Scb:A10_Scb RepairDsmRange [A11_RepairDataSetRangeStartingOffset!#I64x!,A12_RepairDataSetRangeStartingOffsetRepairDataSetRangeLengthInBytes!#I64x!) Length:A13_RepairDataSetRangeLengthInBytes!#I64x! (Bytes) FileOffset: A14_RepairFileOffset!#I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer | — |
A11_RepairDataSetRangeStartingOffset HexInt64 | — |
A12_RepairDataSetRangeStartingOffsetRepairDataSetRangeLengthInBytes HexInt64 | — |
A13_RepairDataSetRangeLengthInBytes HexInt64 | — |
A14_RepairFileOffset HexInt64 | — |
Event ID 416 — Scb:A10_Scb DsmAction_Repair call failed, Status: A11_Status.
Event ID 417 — Scb:A10_Scb DsmAction_Repair operation failed, Status: A11_IrpStatus.
Event ID 418 — Scb:A10_Scb DsmAction_Repair completed, IrpStatus: A11_RepairCopiesOutputStatus.
Event ID 419 — NtfsQueryCachedRuns: Caller not having manage volume privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_TypeOfOpen Int32 | — |
A15_ScbFcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17__CcbFullFileName CountedUtf16String | — |
A18_CcbAccessFlags HexInt32 | — |
Event ID 420 — NtfsQueryStorageClasses: Caller not having manage volume privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_TypeOfOpen Int32 | — |
A15_ScbFcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A18_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 421 — NtfsQueryRegionInfo: Caller not having manage volume privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_TypeOfOpen Int32 | — |
A15_ScbFcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A18_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 422 — NtfsUnloadFile: Caller not having manage volume privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_TypeOfOpen Int32 | — |
A15_ScbFcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A18_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 423 — NtfsCheckForSection: File already has image section.
Description
NtfsCheckForSection: File already has image section. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, Scb: !p!, Scb Type Code: 0x!x!, Scb Name: !S!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
Event ID 424 — NtfsShuffleFile: User mode caller is not allowed.
Description
NtfsShuffleFile: User mode caller is not allowed. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, TypeOfOpen: !d!, Fcb: !p!, FileRef: 0x!I64x!, Ccb FullFileName: !S!, Irp RequestorMode: !d!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_TypeOfOpen Int32 | — |
A15_ScbFcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A18_IrpRequestorMode Int32 | — |
Event ID 425 — NtfsShuffleFile: Denying access due to volume is locked.
Description
NtfsShuffleFile: Denying access due to volume is locked. Thread: !p!, TypeOfOpen: !d!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: !I64x!, Ccb FullFileName: !S!, VcbState: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_TypeOfOpen Int32 | — |
A12_Vcb Pointer | — |
A13__VcbVolumeName CountedUtf16String | — |
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A15_ScbFcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A18_VcbVcbState HexInt32 | — |
Event ID 426 — NtfsShuffleFile: Defrag is denied.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
A19_ScbPersist HexInt32 | — |
A20_CcbNULLCcbFlags0 HexInt32 | — |
Event ID 427 — NtfsShuffleFile: Denying access due to conflicting with read-only state.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_FcbInfoFileAttributes HexInt32 | — |
A17_IrpSpFlags HexInt32 | — |
Event ID 428 — NtfsRearrangeFile: User mode caller is not allowed.
Description
NtfsRearrangeFile: User mode caller is not allowed. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, Ccb FullFileName: !S!, Irp RequestorMode: !d!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A17_IrpRequestorMode Int32 | — |
Event ID 429 — NtfsRearrangeFile: Denying access due to volume is locked.
Description
NtfsRearrangeFile: Denying access due to volume is locked. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, Ccb FullFileName: !S!, VcbState: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A17_VcbVcbState HexInt32 | — |
Event ID 430 — NtfsRearrangeFile: Defrag is denied.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
A19_ScbPersist HexInt32 | — |
A20_CcbNULLCcbFlags0 HexInt32 | — |
Event ID 431 — NtfsShuffleFile: Denying access due to conflicting with read-only state.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_FcbInfoFileAttributes HexInt32 | — |
A17_IrpSpFlags HexInt32 | — |
Event ID 432 — NtfsSparseOverAllocate: Caller does not have appropriate write access.
Description
NtfsSparseOverAllocate: Caller does not have appropriate write access. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, FileRef: !I64x!, FullFileName: !S!, Ccb access flags: !x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A15_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A16_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 433 — NtfsInitiateFileMetadataOptimization: Only allowed on regular user files/directories opened for write.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_TypeOfOpen Int32 | — |
A12_Vcb Pointer | — |
A13__VcbVolumeName CountedUtf16String | — |
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A15_ScbFcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18_ScbFcbFcbState2 HexInt32 | — |
A19_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A20_CcbNULLCcbAccessFlags0 HexInt32 | — |
A21_CcbNULLCcbFlags20 HexInt32 | — |
Event ID 434 — NtfsQueryFileMetadataOptimization: Only allowed on regular user files/directories opened for read.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_TypeOfOpen Int32 | — |
A12_Vcb Pointer | — |
A13__VcbVolumeName CountedUtf16String | — |
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A15_ScbFcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A19_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 435 — NtfsCleanVolumeMetadata: Caller not having manage volume privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A17_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 436 — NtfsEnumOnMountToDeleteWorker(A10_Vcb,A11_PsGetCurrentThread): Open status=0xA12_Status, path="A13__DeletedFiles".
Event ID 437 — NtfsEnumOnMountToDeleteWorker(A10_Vcb,A11_PsGetCurrentThread): Enumerate status=0xA12_Status.
Event ID 438 — NtfsEnumMountWorker(A10_Vcb,A11_PsGetCurrentThread): Open status=0xA12_Status, file="A13__FileNameToDelete".
Event ID 439 — NtfsEnumMountWorker(A10_Vcb,A11_PsGetCurrentThread): Close status=0xA12_Status.
Event ID 440 — NtfsEnumOnMountToDeleteWorker(A10_Vcb,A11_PsGetCurrentThread): Close dir status=0xA12_Status.
Event ID 441 — NtfsCleanVolumeMetadata: Caller not having manage volume privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_TypeOfOpen Int32 | — |
A12_Vcb Pointer | — |
A13__VcbVolumeName CountedUtf16String | — |
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A15_ScbFcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A18_CcbNULLCcbAccessFlags0 HexInt32 | — |
A19_EffectiveMode Int32 | — |
Event ID 442 — SCB: A10_Scb, StartOffset: 0xA11_StartOffset!
Description
SCB: A10_Scb, StartOffset: 0xA11_StartOffset!I64x!, Length: 0xA12_Length!I64x!, StartVcn=0xA13_StartVcn!I64x!, BeyondEndVcn=0xA14_BeyondEndVcn!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer | — |
A11_StartOffset HexInt64 | — |
A12_Length HexInt64 | — |
A13_StartVcn HexInt64 | — |
A14_BeyondEndVcn HexInt64 | — |
Event ID 443 — FsLibGetBadAddressRanges returned Status: A10_Status, NumBadRanges: 0xA11_OutputNumBadRanges.
Event ID 444 — FsInputRangeIndex: A10_FsInputRangeIndex, FileOffset: 0xA11_FsInputRangesFsInputRangeIndexFileOffset!
Description
FsInputRangeIndex: A10_FsInputRangeIndex, FileOffset: 0xA11_FsInputRangesFsInputRangeIndexFileOffset!I64x!, VolumeOffset: 0xA12_FsInputRangesFsInputRangeIndexVolumeOffset!I64x!, LengthInBytes: 0xA13_FsInputRangesFsInputRangeIndexLengthInBytes!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_FsInputRangeIndex UInt32 | — |
A11_FsInputRangesFsInputRangeIndexFileOffset HexInt64 | — |
A12_FsInputRangesFsInputRangeIndexVolumeOffset HexInt64 | — |
A13_FsInputRangesFsInputRangeIndexLengthInBytes HexInt64 | — |
Event ID 445 — Scb: A10_Scb, Status: A11_Status, AbnormalTermination: A12_BOOLEANAbnormalTermination.
Event ID 446 — Scb: A10_Scb, Status: A11_Status.
Event ID 447 — NtfsEncryptionKeyCtl: Caller does not have SE_TCB_PRIVILEGE.
Description
NtfsEncryptionKeyCtl: Caller does not have SE_TCB_PRIVILEGE. Thread: A10_PsGetCurrentThread, Vcb: A11_IrpContextVcb, VolumeName: A12__IrpContextVcbVolumeName, VolumeLabel: A13_WppCountedStringWIrpContextVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHIrpContextVcbVpb.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_IrpContextVcb Pointer | — |
A12__IrpContextVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWIrpContextVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHIrpContextVcbVpb CountedUtf16String | — |
Event ID 448 — Logic error of posting close to work queue.
Description
Logic error of posting close to work queue.
Message #
Event ID 449 — NtfsFindPrefixHashEntry: {Hash table: A10_Table} {ParentScb: A11_ParentScb, 'A12__ParentScbScbTypeIndexNormalizedName'} {RemainingName: 'A13_RemainingName'}.
Description
NtfsFindPrefixHashEntry: {Hash table: A10_Table} {ParentScb: A11_ParentScb, 'A12__ParentScbScbTypeIndexNormalizedName'} {RemainingName: 'A13_RemainingName'}.
Message #
Fields #
| Name | Description |
|---|---|
A10_Table Pointer | — |
A11_ParentScb Pointer | — |
A12__ParentScbScbTypeIndexNormalizedName CountedUtf16String | — |
A13_RemainingName CountedUtf16String | — |
Event ID 450 — NtfsFindPrefixHashEntry: {Lcb: NULL}
Description
NtfsFindPrefixHashEntry: {Lcb: NULL}.
Message #
Event ID 451 — NtfsFindPrefixHashEntry: {Lcb: A10_FoundLcb, 'A11__FoundLcbExactCaseLinkLinkName'}.
Event ID 452 — NtfsFindPrefixHashEntry: {Lcb not found}
Description
NtfsFindPrefixHashEntry: {Lcb not found}.
Message #
Event ID 453 — NtfsInsertHashEntry: {Hash table: A10_Table} {HashValue: A11_NewHashEntryHashValue!
Description
NtfsInsertHashEntry: {Hash table: A10_Table} {HashValue: A11_NewHashEntryHashValue!08x!} {FullNameLength: A12_NewHashEntryFullNameLength} {Lcb: A13_NewHashEntryHashLcb, 'A14__NewHashEntryHashLcbExactCaseLinkLinkName'}.
Message #
Fields #
| Name | Description |
|---|---|
A10_Table Pointer | — |
A11_NewHashEntryHashValue HexInt32 | — |
A12_NewHashEntryFullNameLength Int32 | — |
A13_NewHashEntryHashLcb Pointer | — |
A14__NewHashEntryHashLcbExactCaseLinkLinkName CountedUtf16String | — |
Event ID 454 — NtfsRemoveHashEntry: {Hash table: A10_Table} {HashValue: A11_HashValue!
Event ID 455 — Vcb A10_Vcb.
Event ID 456 — Vcb A10_Vcb.
Event ID 457 — Vcb A10_Vcb.
Event ID 458 — Vcb A10_Vcb.
Event ID 459 — Vcb A10_Vcb.
Event ID 460 — Vcb A10_Vcb.
Event ID 461 — Vcb A10_Vcb.
Event ID 462 — Vcb A10_Vcb.
Event ID 463 — Vcb A10_Vcb.
Event ID 464 — Vcb A10_Vcb.
Event ID 465 — Vcb A10_Vcb.
Event ID 466 — NtfsCheckpointForVolumeSnapshot: Denying access due to volume is locked.
Description
NtfsCheckpointForVolumeSnapshot: Denying access due to volume is locked. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, VcbState: 0xA14_VcbVcbState!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_VcbVcbState HexInt32 | — |
Event ID 467 — Vcb A10_Vcb.
Event ID 468 — Vcb A10_Vcb.
Event ID 469 — NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContextTransactionId!
Event ID 470 — NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContextTransactionId!
Event ID 471 — NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContextOriginatingIrp,A12_PsGetCurrentThread): Pre NtfsWriteLog failure A13_IrpContextExceptionStatus.
Description
NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContextOriginatingIrp,A12_PsGetCurrentThread): Pre NtfsWriteLog failure A13_IrpContextExceptionStatus.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_IrpContextOriginatingIrp Pointer | — |
A12_PsGetCurrentThread Pointer | — |
A13_IrpContextExceptionStatus HexInt32 | — |
Event ID 472 — NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContextOriginatingIrp,A12_PsGetCurrentThread): Post NtfsWriteLog failure A13_IrpContextExceptionStatus.
Description
NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContextOriginatingIrp,A12_PsGetCurrentThread): Post NtfsWriteLog failure A13_IrpContextExceptionStatus.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_IrpContextOriginatingIrp Pointer | — |
A12_PsGetCurrentThread Pointer | — |
A13_IrpContextExceptionStatus HexInt32 | — |
Event ID 473 — NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContextOriginatingIrp,A12_PsGetCurrentThread): LfsFlushToLsn failure A13_IrpContextExceptionStatus Count A14_FailedFlushCount.
Description
NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContextOriginatingIrp,A12_PsGetCurrentThread): LfsFlushToLsn failure A13_IrpContextExceptionStatus Count A14_FailedFlushCount.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_IrpContextOriginatingIrp Pointer | — |
A12_PsGetCurrentThread Pointer | — |
A13_IrpContextExceptionStatus HexInt32 | — |
A14_FailedFlushCount Int32 | — |
Event ID 474 — NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContextOriginatingIrp,A12_PsGetCurrentThread): Pre NtfsProcessNewLengthQueue failure A13_IrpContextExceptionStatus.
Description
NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContextOriginatingIrp,A12_PsGetCurrentThread): Pre NtfsProcessNewLengthQueue failure A13_IrpContextExceptionStatus.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_IrpContextOriginatingIrp Pointer | — |
A12_PsGetCurrentThread Pointer | — |
A13_IrpContextExceptionStatus HexInt32 | — |
Event ID 475 — NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContextOriginatingIrp,A12_PsGetCurrentThread): Post NtfsProcessNewLengthQueue failure A13_IrpContextExceptionStatus.
Description
NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContextOriginatingIrp,A12_PsGetCurrentThread): Post NtfsProcessNewLengthQueue failure A13_IrpContextExceptionStatus.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_IrpContextOriginatingIrp Pointer | — |
A12_PsGetCurrentThread Pointer | — |
A13_IrpContextExceptionStatus HexInt32 | — |
Event ID 476 — NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContextTransactionId!
Event ID 477 — NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContextTransactionId!
Event ID 478 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Entering - ActiveLsn: A11_ActiveLsnQuadPart!
Event ID 479 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb empty list - Leaving.
Event ID 480 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb empty list - Leaving.
Event ID 481 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Found frozen deallocated clusters with A11_ClustersClusterCount!
Event ID 482 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - No actionable deallocated clusters.
Event ID 483 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - No actionable deallocated clusters.
Event ID 484 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Found a deallocated clusters A11_Clusters with A12_ClustersClusterCount!
Description
NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Found a deallocated clusters A11_Clusters with A12_ClustersClusterCount!I64x! clusters, Lsn: A13_ClustersLsnQuadPart!I64x!, Flags: A14_ClustersFlags!08x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_Clusters Pointer | — |
A12_ClustersClusterCount HexInt64 | — |
A13_ClustersLsnQuadPart HexInt64 | — |
A14_ClustersFlags HexInt32 | — |
Event ID 485 — Vcb: A10_Vcb, Processing range.
Event ID 486 — Looking for dangling MDLs
Description
Looking for dangling MDLs.
Message #
Event ID 487 — FsLibGroupSubExtentsByDanglingMdl failed: A10_Status.
Event ID 488 — FsLibAddBaseMcbEntryEx failed: A10_Status.
Event ID 489 — NtfsAddToMatchingDeallocatedClusters( ExtentsWithoutDanglingMdl ) failed: A10_Status.
Event ID 490 — NtfsAddToMatchingDeallocatedClusters( ExtentsWithDanglingMdl ) failed: A10_Status.
Event ID 491 — No sub extents has dangling MDL
Description
No sub extents has dangling MDL.
Message #
Event ID 492 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Telling volsnap freeing at A11_StartingLcn!
Event ID 493 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Volsnap responsed with freeing at A11_StartingLcnStartingIndex!
Event ID 494 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Got error 0xA11_Status from below.
Event ID 495 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Deleting MarkUnusedContext A11_MarkUnusedContext.
Event ID 496 — NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Leaving.
Event ID 497 — NtfsRemoveNtfsMcbEntry Scb: A10_McbScb, Mcb: A11_Mcb, Vcn: 0xA12_StartingVcn!
Event ID 498 — NtfsRemoveNtfsMcbEntry Mcb: A10_Mcb Completed.
Event ID 499 — NtfsAddNtfsMcbEntry Scb: A10_McbScb, Mcb: A11_Mcb, Vcn: 0xA12_Vcn!
Event ID 500 — NtfsAddNtfsMcbEntry Mcb: A10_Mcb, Result: A11_Result.
Event ID 501 — NtfsUnloadNtfsMcbRange Scb: A10_McbScb, Mcb: A11_Mcb, StartVcn: 0xA12_StartingVcn!
Description
NtfsUnloadNtfsMcbRange Scb: A10_McbScb, Mcb: A11_Mcb, StartVcn: 0xA12_StartingVcn!I64x!, EndVcn: 0xA13_EndingVcn!I64x!, TruncateOnly: A14_TruncateOnly.
Message #
Fields #
| Name | Description |
|---|---|
A10_McbScb Pointer | — |
A11_Mcb Pointer | — |
A12_StartingVcn HexInt64 | — |
A13_EndingVcn HexInt64 | — |
A14_TruncateOnly UInt32 | — |
Event ID 502 — NtfsUnloadNtfsMcbRange Mcb: A10_Mcb Completed.
Event ID 503 — Valid NTFS boot sector.
Event ID 504 — Not an NTFS boot sector.
Event ID 505 — NtfsMountVolume: Vcb:A10_Vcb, IC:A11_IrpContext, Growing allocation for Mft's Attribute List failed with exception:0xA12_IrpContextExceptionStatus.
Event ID 506 — NtfsMountVolume: IC: A10_IrpContext, Vcb: A11_Vcb, Label: A12__VolumeLabel, DeviceName: A13__VcbDeviceName.
Event ID 507 — Mounting DAX partition.
Event ID 508 — DAX volume mounted without DAX support because storage is not DAX capable.
Event ID 509 — NtfsGrowMftsAttributeListAllocation Vcb:A10_Vcb, IC:A11_IrpContext Mft AttributeList not found, skipping growth.
Event ID 510 — NtfsGrowMftsAttributeListAllocation Vcb:A10_Vcb, IC:A11_IrpContext Converting Resident AttributeList.
Event ID 511 — NtfsGrowMftsAttributeListAllocation Vcb:A10_Vcb, IC:A11_IrpContext, AttrListScb:A12_Scb Added Allocation for NonResident AttributeList.
Description
NtfsGrowMftsAttributeListAllocation Vcb:A10_Vcb, IC:A11_IrpContext, AttrListScb:A12_Scb Added Allocation for NonResident AttributeList (old size:0xA13_AttrListAllocationSize!I64x!).
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_Scb Pointer | — |
A13_AttrListAllocationSize HexInt64 | — |
Event ID 512 — Unexpected exception code of 0xA10_ExceptionCode received.
Event ID 513 — Exception code of 0xA10_ExceptionCode received during mount.
Event ID 514 — Unexpected exception code of 0xA10_ExceptionCode received.
Event ID 515 — LogFileFull A10_IrpContextLogFullReason BackTrace: ln A11_BackTrace0; ln A12_BackTrace1; ln A13_BackTrace2; ln A14_BackTrace3; ln A15_BackTrace4; ln A16_BackTrace5; ln A17_BackTrace6; ln A18_BackTr...
Description
LogFileFull BackTrace: ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!; ln !p!
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContextLogFullReason UInt32 | — |
A11_BackTrace0 Pointer | — |
A12_BackTrace1 Pointer | — |
A13_BackTrace2 Pointer | — |
A14_BackTrace3 Pointer | — |
A15_BackTrace4 Pointer | — |
A16_BackTrace5 Pointer | — |
A17_BackTrace6 Pointer | — |
A18_BackTrace7 Pointer | — |
A19_BackTrace8 Pointer | — |
A20_BackTrace9 Pointer | — |
A21_BackTrace10 Pointer | — |
A22_BackTrace11 Pointer | — |
A23_BackTrace12 Pointer | — |
A24_BackTrace13 Pointer | — |
A25_BackTrace14 Pointer | — |
A26_BackTrace15 Pointer | — |
A27_BackTrace16 Pointer | — |
A28_BackTrace17 Pointer | — |
A29_BackTrace18 Pointer | — |
A30_BackTrace19 Pointer | — |
Event ID 516 — Unexpected raise of 0xA10_ExceptionCode during critical non-raise code.
Event ID 517 — NtfsProcessException IC: A10_IrpContext, ExceptionCode: 0xA11_ExceptionCode!
Event ID 518 — NtfsProcessException IC: A10_IrpContext, ExceptionCode: 0xA11_ExceptionCode!
Event ID 519 — Failed to abort - IrpContext A10_IrpContext, Irp A11_Irp, Vcb A12_IrpContextVcb, Count A13_NtfsFailedAborts, Status A14_GetExceptionCode.
Description
Failed to abort - IrpContext A10_IrpContext, Irp A11_Irp, Vcb A12_IrpContextVcb, Count A13_NtfsFailedAborts, Status A14_GetExceptionCode.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_Irp Pointer | — |
A12_IrpContextVcb Pointer | — |
A13_NtfsFailedAborts HexInt32 | — |
A14_GetExceptionCode HexInt32 | — |
Event ID 520 — Failed to abort - IrpContext A10_IrpContext, Irp A11_Irp, Vcb A12_IrpContextVcb, Scb A13_NextScb, FileRef A14_PULONGLONG_NextScbFcbFileReference!
Description
Failed to abort - IrpContext A10_IrpContext, Irp A11_Irp, Vcb A12_IrpContextVcb, Scb A13_NextScb, FileRef A14_PULONGLONG_NextScbFcbFileReference!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_Irp Pointer | — |
A12_IrpContextVcb Pointer | — |
A13_NextScb Pointer | — |
A14_PULONGLONG_NextScbFcbFileReference HexInt64 | — |
Event ID 521 — Setting STATUS_CANT_WAIT in top-level exception status for write @ 0xA10_IrpSpParametersWriteByteOffsetHighPart!
Description
Setting STATUS_CANT_WAIT in top-level exception status for write @ 0xA10_IrpSpParametersWriteByteOffsetHighPart!08x!A11_IrpSpParametersWriteByteOffsetLowPart!08x!
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpSpParametersWriteByteOffsetHighPart HexInt32 | — |
A11_IrpSpParametersWriteByteOffsetLowPart HexInt32 | — |
Event ID 522 — Setting 0xA10_ExceptionCode in top-level exception status for write @ 0xA11_IrpSpParametersWriteByteOffsetHighPart!
Description
Setting 0xA10_ExceptionCode in top-level exception status for write @ 0xA11_IrpSpParametersWriteByteOffsetHighPart!08x!A12_IrpSpParametersWriteByteOffsetLowPart!08x!
Message #
Fields #
| Name | Description |
|---|---|
A10_ExceptionCode HexInt32 | — |
A11_IrpSpParametersWriteByteOffsetHighPart HexInt32 | — |
A12_IrpSpParametersWriteByteOffsetLowPart HexInt32 | — |
Event ID 523 — [A10_IrpSpMajorFunction, A11_IrpSpMinorFunction!
Event ID 524 — [A10_IrpSpMajorFunction, A11_IrpSpMinorFunction!
Event ID 525 — Can't handle invalid bitmap in a positive way.
Description
Can't handle invalid bitmap in a positive way.
Message #
Event ID 526 — NTFS ETW tracing is now active.
Description
NTFS ETW tracing is now active.
Message #
Event ID 527 — Updating NtfsMinTrimTotalSize to A10_MinTrimTotalSize.
Event ID 528 — Updating NtfsMaxTrimTotalSize to A10_MaxTrimTotalSize.
Event ID 529 — NtfsSetObjectId: Caller does not have restore access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
A17_CcbAccessFlags HexInt32 | — |
A18_IrpSpMinorFunction HexInt32 | — |
Event ID 530 — NtfsSetObjectIdExtendedInfo: Caller does not have write access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
A17_CcbAccessFlags HexInt32 | — |
A18_IrpSpMinorFunction HexInt32 | — |
Event ID 531 — NtfsDeleteObjectId: Caller does not have write access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
A17_CcbAccessFlags HexInt32 | — |
A18_IrpSpMinorFunction HexInt32 | — |
Event ID 532 — A10___FUNCTION__: Setting RM at 0xA11_PVOIDVcbTxfVcbDefaultRm ({A12__VcbTxfVcbDefaultRmRmId}) up for auto-restart.
Event ID 533 — NtfsFsQuotaSetInfo: Denying access due to administrator limit.
Description
NtfsFsQuotaSetInfo: Denying access due to administrator limit. Thread: A10_PsGetCurrentThread, Vcb: A11_IrpContextVcb, VolumeName: A12__IrpContextVcbVolumeName, VolumeLabel: A13_WppCountedStringWIrpContextVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHIrpContextVcbVpb.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_IrpContextVcb Pointer | — |
A12__IrpContextVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWIrpContextVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHIrpContextVcbVpb CountedUtf16String | — |
Event ID 534 — NtfsCommonSetQuota: Caller does not have manage volume privilege and it's not quota file.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_TypeOfOpen Int32 | — |
A12_Vcb Pointer | — |
A13__VcbVolumeName CountedUtf16String | — |
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A15_ScbFcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17__CcbFullFileName CountedUtf16String | — |
A18_CcbAccessFlags HexInt32 | — |
A19_CcbFlags HexInt32 | — |
Event ID 535 — Unexpected Paging-Read on DAX mappable stream, Scb=A10_Scb.
Event ID 536 — NtfsSetReparsePoint: Caller does not have write access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
A17_CcbAccessFlags HexInt32 | — |
A18_IrpSpFileObjectWriteAccess Int32 | — |
Event ID 537 — NtfsSetReparsePointEx: Caller does not have write access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
A17_CcbAccessFlags HexInt32 | — |
A18_IrpSpFileObjectWriteAccess Int32 | — |
Event ID 538 — NtfsDeleteReparsePoint: Caller does not have write access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
A17_CcbAccessFlags HexInt32 | — |
A18_IrpSpFileObjectWriteAccess Int32 | — |
Event ID 539 — NtfsReleaseVcbCheckDelete - NtfsDeleteVcb() returned FALSE; scheduling checkpoint.
Event ID 540 — NtfsReleaseVcbCheckDelete - deleted Vcb: A10_Vcb, IC: A11_IrpContext.
Event ID 541 — NtfsReleaseVcbCheckDelete - Scheduling checkpoint due to dismounted Vcb: A10_Vcb, Vcb->LogFileObject: A11_VcbLogFileObject, IC: A12_IrpContext.
Event ID 542 — NtfsAbortTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContextTransactionId!
Event ID 543 — NtfsAbortTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContextTransactionId!
Event ID 544 — DoAction::InitializeFRS IC:A10_IrpContext, FileRef:0xA11_FileRecordSegmentNumberHighPart!
Description
DoAction::InitializeFRS IC:A10_IrpContext, FileRef:0xA11_FileRecordSegmentNumberHighPart!04x!_A12_FileRecordSegmentNumberLowPart!08x!, BaseFRS:0xA13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment!012I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_FileRecordSegmentNumberHighPart HexInt32 | — |
A12_FileRecordSegmentNumberLowPart HexInt32 | — |
A13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment HexInt64 | — |
Event ID 545 — DoAction::DeallocateFRS IC:A10_IrpContext, FileRef:0xA11_FileRecordSegmentNumberHighPart!
Description
DoAction::DeallocateFRS IC:A10_IrpContext, FileRef:0xA11_FileRecordSegmentNumberHighPart!04x!_A12_FileRecordSegmentNumberLowPart!08x!, BaseFRS:0xA13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment!012I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_FileRecordSegmentNumberHighPart HexInt32 | — |
A12_FileRecordSegmentNumberLowPart HexInt32 | — |
A13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment HexInt64 | — |
Event ID 546 — DoAction::WriteEndOfFRS IC:A10_IrpContext, FileRef:0xA11_FileRecordSegmentNumberHighPart!
Description
DoAction::WriteEndOfFRS IC:A10_IrpContext, FileRef:0xA11_FileRecordSegmentNumberHighPart!04x!_A12_FileRecordSegmentNumberLowPart!08x!, BaseFRS:0xA13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment!012I64x!, Attrib:0xA14_AttributeTypeCode Off:0xA15_LogRecordRecordOffset, Len:0xA16_Length.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_FileRecordSegmentNumberHighPart HexInt32 | — |
A12_FileRecordSegmentNumberLowPart HexInt32 | — |
A13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment HexInt64 | — |
A14_AttributeTypeCode HexInt32 | — |
A15_LogRecordRecordOffset HexInt32 | — |
A16_Length HexInt32 | — |
Event ID 547 — DoAction::CreateAttribute IC:A10_IrpContext, FileRef:0xA11_FileRecordSegmentNumberHighPart!
Description
DoAction::CreateAttribute IC:A10_IrpContext, FileRef:0xA11_FileRecordSegmentNumberHighPart!04x!_A12_FileRecordSegmentNumberLowPart!08x!, BaseFRS:0xA13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment!012I64x!, Attrib:0xA14_PATTRIBUTE_RECORD_HEADERDataTypeCode.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_FileRecordSegmentNumberHighPart HexInt32 | — |
A12_FileRecordSegmentNumberLowPart HexInt32 | — |
A13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment HexInt64 | — |
A14_PATTRIBUTE_RECORD_HEADERDataTypeCode HexInt32 | — |
Event ID 548 — NtfsRestartChangeValue IC:A10_IrpContext, FileRef:0xA11_FileRecordSegmentNumberHighPart!
Description
NtfsRestartChangeValue IC:A10_IrpContext, FileRef:0xA11_FileRecordSegmentNumberHighPart!04x!_A12_FileRecordSegmentNumberLowPart!08x!, BaseFRS:0xA13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment!012I64x!, FileRef:0xA14_NtfsFullSegmentNumber_FileReference!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_FileRecordSegmentNumberHighPart HexInt32 | — |
A12_FileRecordSegmentNumberLowPart HexInt32 | — |
A13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment HexInt64 | — |
A14_NtfsFullSegmentNumber_FileReference HexInt64 | — |
Event ID 549 — DoAction::SetNewAttributeSizes IC.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_FileRecordSegmentNumberHighPart HexInt32 | — |
A12_FileRecordSegmentNumberLowPart HexInt32 | — |
A13_NtfsFullSegmentNumber_FileRecordBaseFileRecordSegment HexInt64 | — |
A14_AttributeFormNonresidentAllocatedLength HexInt64 | — |
A15_AttributeFormNonresidentFileSize HexInt64 | — |
A16_AttributeFormNonresidentValidDataLength HexInt64 | — |
A17_AttributeFormNonresidentTotalAllocated HexInt64 | — |
A18_SizesAllocationSize HexInt64 | — |
A19_SizesFileSize HexInt64 | — |
A20_SizesValidDataLength HexInt64 | — |
A21_SizesTotalAllocated HexInt64 | — |
Event ID 550 — DoAction(SetBitsInNonresidentBitMap) IC: A10_IrpContext, Vcb: A11_Vcb, Bitmap: A12__Bitmap.
Event ID 551 — DoAction(ClearBitsInNonresidentBitMap) IC: A10_IrpContext, Vcb: A11_Vcb, Bitmap: A12__Bitmap.
Event ID 552 — NtfsUpgradeFileSecurity: Denying access due to volume does not support Txf.
Description
NtfsUpgradeFileSecurity: Denying access due to volume does not support Txf. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: !I64x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_FcbVcb Pointer | — |
A12__FcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
Event ID 553 — NtfsCaseSensitiveInfoAccessCheck: Caller does not have write access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_FcbVcb Pointer | — |
A12__FcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
A17_CcbAccessFlags HexInt32 | — |
Event ID 554 — NtfsCaseSensitiveInfoAccessCheck: Caller does not have appropriate access.
Description
NtfsCaseSensitiveInfoAccessCheck: Caller does not have appropriate access. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: !I64x!, Ccb FullFileName: !S!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_FcbVcb Pointer | — |
A12__FcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16__CcbFullFileName CountedUtf16String | — |
Event ID 555 — NtfsCheckFileForDelete: Denying access due to there are same-tx handles open to this file.
Description
NtfsCheckFileForDelete: Denying access due to there are same-tx handles open to this file. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: !I64x!, Txf Writers Count: !d!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_ThisFcbTxfFcbTxfNumWriters Int32 | — |
Event ID 556 — NtfsCheckFileForDelete: Denying access due to TxfCheckForLockConflict failed.
Description
NtfsCheckFileForDelete: Denying access due to TxfCheckForLockConflict failed. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: !I64x!, Original status: !S!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_Status HexInt32 | — |
Event ID 557 — NtfsCheckFileForDelete: Denying access due to superseding view indexes are not allowed.
Description
NtfsCheckFileForDelete: Denying access due to superseding view indexes are not allowed. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: !I64x!, File Attributes: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_ThisFcbInfoFileAttributes HexInt32 | — |
Event ID 558 — NtfsCheckFileForDelete: Denying access due to non-posix delete of target directory open is not allowed.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_ThisFcbInfoFileAttributes HexInt32 | — |
Event ID 559 — NtfsCheckFileForDelete: Denying access due to file is not deleteable.
Description
NtfsCheckFileForDelete: Denying access due to file is not deleteable. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: !I64x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
Event ID 560 — NtfsCheckFileForDelete: Denying access due to target file is read only.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_ThisFcbInfoFileAttributes HexInt32 | — |
A17_IrpSpFlags HexInt32 | — |
Event ID 561 — NtfsCheckFileForDelete: Caller does not have write attributes access (TxfAccessCheck failed).
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_CcbAccessFlags HexInt32 | — |
A17_AccessStatus HexInt32 | — |
Event ID 562 — NtfsCheckFileForDelete: Denying access due to failing to remove image section.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ThisFcbVcb Pointer | — |
A12__ThisFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWThisFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHThisFcbVcbVpb CountedUtf16String | — |
A14_ThisFcb Pointer | — |
A15_NtfsFullFileRefNumber_ThisFcbFileReference HexInt64 | — |
A16_NextScb Pointer | — |
A17_NextScbAttributeTypeCode HexInt32 | — |
A18__NextScbAttributeName CountedUtf16String | — |
Event ID 563 — NtfsGlobalSdUpdate: Caller does not have manage volume privilege.
Description
NtfsGlobalSdUpdate: Caller does not have manage volume privilege. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: !I64x!, Ccb FullFileName: !S!, Ccb access flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A17_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 564 — NtfsRepairItem: Denying access due to volume is locked.
Description
NtfsRepairItem: Denying access due to volume is locked. Thread: A10_PsGetCurrentThread, Vcb: A11_Vcb, VolumeName: A12__VcbVolumeName, VolumeLabel: A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb, VcbState: 0xA14_VcbVcbState!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_VcbVcbState HexInt32 | — |
Event ID 565 — NtfsSetRepairState: Caller does not have manage volume privilege.
Description
NtfsSetRepairState: Caller does not have manage volume privilege. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: !I64x!, Ccb FullFileName: !S!, Ccb access flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A17_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 566 — NtfsInitiateRepair: Caller does not have manage volume privilege.
Description
NtfsInitiateRepair: Caller does not have manage volume privilege. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: !I64x!, Ccb FullFileName: !S!, Ccb access flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A17_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 567 — NTFS ETW tracing is shutting down.
Description
NTFS ETW tracing is shutting down.
Message #
Event ID 568 — NtfsDefineStorageReserve: Caller does not have manage volume privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_TypeOfOpen Int32 | — |
A12_Vcb Pointer | — |
A13__VcbVolumeName CountedUtf16String | — |
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A15_Fcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A18_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 569 — NtfsDeleteStorageReserve: Caller does not have manage volume privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_TypeOfOpen Int32 | — |
A12_Vcb Pointer | — |
A13__VcbVolumeName CountedUtf16String | — |
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A15_Fcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A18_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 570 — NtfsRepairStorageReserve: Caller does not have manage volume privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_TypeOfOpen Int32 | — |
A12_Vcb Pointer | — |
A13__VcbVolumeName CountedUtf16String | — |
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A15_Fcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A18_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 571 — NtfsSetStorageReserveIdInfo: System files are not allowed to be part of a storage reserve.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_FcbVcb Pointer | — |
A12__FcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_FcbFcbState HexInt32 | — |
A17_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
Event ID 572 — NtfsSetStorageReserveIdInfo: Caller does not have appropriate access.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_FcbVcb Pointer | — |
A12__FcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A17_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 573 — NtfsChangeStorageReserveId: Caller does not have manage volume privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A17_CcbNULLCcbAccessFlags0 HexInt32 | — |
A18_Flags HexInt32 | — |
Event ID 574 — NtfsChangeStorageReserveId: Caller does not have manage volume privilege to explicitly setting reserve ID to/from a "restricted area".
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A17_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 575 — Failed to get a non-volatile token for Vcb: A10_Vcb, Status: A11_Status.
Event ID 576 — Failed to free non-volatile token for Vcb: A10_Vcb, Status: A11_Status.
Event ID 577 — NtfsRestoreScbSnapshots: Restored TotalAllocated, Scb: A10_Scb, TotalAllocated: 0xA11_ScbTotalAllocated!
Event ID 578 — NtfsGetDeallocatedClusters: Lsn updated for DeallocatedClusters: A10_CurrentClusters, Lsn: A11_CurrentClustersLsnQuadPart!
Event ID 579 — ClustersLinkAsHead: A10_ClustersLinkAsHead, FlagsToMatch: 0xA11_FlagsToMatch, InsertAfter: A12_InsertAfter.
Event ID 580 — Clusters: A10_Clusters, Flags: 0xA11_ClustersFlags.
Event ID 581 — Matching cluster: A10_Clusters, NumberOfRuns: 0xA11_NumberOfRuns.
Event ID 582 — Clusters: A10_Clusters.
Event ID 583 — Allocated new deallocated clusters
Description
Allocated new deallocated clusters.
Message #
Event ID 584 — Need to add Range.
Description
Need to add Range. DanglingMdl: DanglingMdl, DeallocatedClusters: A11_Clusters, Lcn: A12_Lcn!I64x!, ClusterCount: A13_ClusterCount!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_FlagOnClustersFlagsDEALLOCATED_CLUSTERS_FLAG_NO_DANGLING_MDL UInt32 | — |
A11_Clusters Pointer | — |
A12_Lcn HexInt64 | — |
A13_ClusterCount HexInt64 | — |
Event ID 585 — Added range.
Description
Added range. DanglingMdl: DanglingMdl, DeallocatedClusters: A11_Clusters, Lcn: A12_Lcn!I64x!, ClusterCount: A13_ClusterCount!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_FlagOnClustersFlagsDEALLOCATED_CLUSTERS_FLAG_NO_DANGLING_MDL UInt32 | — |
A11_Clusters Pointer | — |
A12_Lcn HexInt64 | — |
A13_ClusterCount HexInt64 | — |
Event ID 586 — TxfCheckForLockConflict: File locked for modify transaction.
Description
TxfCheckForLockConflict: File locked for modify transaction. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!,Fcb: !p!, FileRef: 0x!I64x!, TxfFcb Flags: 0x!08x!, ShareMode: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_TxfFcbFlags HexInt32 | — |
A17_ShareMode HexInt32 | — |
Event ID 587 — TxfCheckForLockConflict: Locking transaction is doomed and caller is non-trans or different trans who wants to modify.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_GrantedAccess HexInt32 | — |
Event ID 588 — TxfCheckForLockConflict: Modification access desired.
Description
TxfCheckForLockConflict: Modification access desired. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, Granted Access: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_GrantedAccess HexInt32 | — |
Event ID 589 — TxfCheckForLockConflict: File has user handle opened on one of the versions or user-mapping on a section.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_GrantedAccess HexInt32 | — |
A17_NextTxfVscbReaderCleanupCount Int32 | — |
Event ID 590 — A10___FUNCTION__: from A11_CallerFunction (A12_CallerFile:A13_CallerLineNumber) RM at 0xA14_PVOIDTxfRmcb {A15__TxfRmcbRmId}, Tx at 0xA16_PVOIDTxfTrans {A17__TxfTransKtmUow}, Status was 0xA18_AbortR...
Description
A10___FUNCTION__: from A11_CallerFunction (A12_CallerFile:A13_CallerLineNumber) RM at 0xA14_PVOIDTxfRmcb {A15__TxfRmcbRmId}, Tx at 0xA16_PVOIDTxfTrans {A17__TxfTransKtmUow}, Status was 0xA18_AbortReasonStatus.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_CallerFunction AnsiString | — |
A12_CallerFile AnsiString | — |
A13_CallerLineNumber Int32 | — |
A14_PVOIDTxfRmcb Pointer | — |
A15__TxfRmcbRmId GUID | — |
A16_PVOIDTxfTrans Pointer | — |
A17__TxfTransKtmUow GUID | — |
A18_AbortReasonStatus HexInt32 | — |
Event ID 591 — A10___FUNCTION__: from A11_CallerFunction (A12_CallerFile:A13_CallerLineNumber) RM at 0xA14_PVOIDTxfRmcb {A15__TxfRmcbRmId}, Tx at 0xA16_PVOIDTxfTrans {A17__TxfTransKtmUow}, Status was 0xA18_Status.
Description
A10___FUNCTION__: from A11_CallerFunction (A12_CallerFile:A13_CallerLineNumber) RM at 0xA14_PVOIDTxfRmcb {A15__TxfRmcbRmId}, Tx at 0xA16_PVOIDTxfTrans {A17__TxfTransKtmUow}, Status was 0xA18_Status.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_CallerFunction AnsiString | — |
A12_CallerFile AnsiString | — |
A13_CallerLineNumber Int32 | — |
A14_PVOIDTxfRmcb Pointer | — |
A15__TxfRmcbRmId GUID | — |
A16_PVOIDTxfTrans Pointer | — |
A17__TxfTransKtmUow GUID | — |
A18_Status HexInt32 | — |
Event ID 592 — A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} aborting transaction at 0xA13_TxfTrans {A14__TxfTransKtmUow}.
Event ID 593 — A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} aborting transaction at 0xA13_TxfTrans {A14__TxfTransKtmUow}.
Event ID 594 — A10___FUNCTION__: RM at 0xA11_PVOIDCalloutParametersTxfFlushTxfRmcb {A12__CalloutParametersTxfFlushTxfRmcbRmId}: Unexpected exception code of 0xA13_GetExceptionCode received.
Description
A10___FUNCTION__: RM at 0xA11_PVOIDCalloutParametersTxfFlushTxfRmcb {A12__CalloutParametersTxfFlushTxfRmcbRmId}: Unexpected exception code of 0xA13_GetExceptionCode received.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_PVOIDCalloutParametersTxfFlushTxfRmcb Pointer | — |
A12__CalloutParametersTxfFlushTxfRmcbRmId GUID | — |
A13_GetExceptionCode HexInt32 | — |
Event ID 595 — A10___FUNCTION__: TxfStartRm reports RM will be reset: RM metadata corrupt.
Event ID 596 — A10___FUNCTION__: TxfStartRm reports RM will be reset: TM could not be initialized.
Event ID 597 — A10___FUNCTION__: TxfStartRm reports RM will be reset: RM log corrupt.
Event ID 598 — A10___FUNCTION__: TxfStartRm reports RM will be reset: log version changed.
Event ID 599 — A10___FUNCTION__: TxfStartRm reports RM will be reset: dedicated log found, need multiplexed.
Event ID 600 — A10___FUNCTION__: TxfStartRm reports RM will be reset: multiplexed log found, need dedicated.
Event ID 601 — A10___FUNCTION__: TxfStartRm reports RM will be reset: CLFS log metadata corrupt.
Event ID 602 — A10___FUNCTION__: TxfStartRm reports RM will be reset: 0xA11_FailureStatus.
Event ID 603 — A10___FUNCTION__: RM did not start and WILL NOT be reset, status code is 0xA11_FailureStatus!
Event ID 604 — A10___FUNCTION__: Could not initialize IrpContext: 0xA11_Status.
Event ID 605 — TxfInitializeVolume: Denying access due to Txf start is not allowed (possible racing with dismount or volume shutdown).
Description
TxfInitializeVolume: Denying access due to Txf start is not allowed (possible racing with dismount or volume shutdown). Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, FxfVcb flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_VcbTxfVcbFlags HexInt32 | — |
Event ID 606 — A10___FUNCTION__: IOCTL_VOLUME_GET_GPT_ATTRIBUTES returned 0xA11_TempStatus for default RM on VCB at 0xA12_PVOIDVcb.
Event ID 607 — A10___FUNCTION__: Exception code 0xA11_GetExceptionCode, Status 0xA12_Status for default RM on VCB at 0xA13_PVOIDVcb.
Event ID 608 — A10___FUNCTION__: Couldn't reset default RM on VCB at 0xA11_PVOIDVcb after A12_TXF_MAX_RESET_ATTEMPTS_ON_MOUNT tries: 0xA13_OldStatus.
Event ID 609 — A10___FUNCTION__: Exception 0xA11_GetExceptionCode raised from TxfConvertRmStartFailureStatusCode for default RM on VCB at 0xA12_PVOIDVcb.
Event ID 610 — A10___FUNCTION__: A11_NT_SUCCESSStatusSucceededFAILED auto-restart of RM at 0xA12_PVOIDTxfRmcb ({A13__TxfRmcbRmId}): 0xA14_Status.
Description
A10___FUNCTION__: A11_NT_SUCCESSStatusSucceededFAILED auto-restart of RM at 0xA12_PVOIDTxfRmcb ({A13__TxfRmcbRmId}): 0xA14_Status.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_NT_SUCCESSStatusSucceededFAILED AnsiString | — |
A12_PVOIDTxfRmcb Pointer | — |
A13__TxfRmcbRmId GUID | — |
A14_Status HexInt32 | — |
Event ID 611 — A10___FUNCTION__: Attempting auto-restart of RM at 0xA11_PVOIDTxfRmcb ({A12__TxfRmcbRmId}).
Event ID 612 — A10___FUNCTION__: Volume too small to start RM at 0xA11_PVOIDTxfRmcb ({A12__TxfRmcbRmId}).
Event ID 613 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: invalid flags in $Tops.
Event ID 614 — TxfStartRm: Denying access due to Txf start is not allowed (possible racing with dismount or volume shutdown).
Description
TxfStartRm: Denying access due to Txf start is not allowed (possible racing with dismount or volume shutdown). Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, FxfVcb flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_VcbTxfVcbFlags HexInt32 | — |
Event ID 615 — A10___FUNCTION__: Raising to reset RM at 0xA11_PVOIDTxfRmcb ({A12__TxfRmcbRmId}): Explicit reset requested.
Event ID 616 — TxfStartRm: Denying access due to Txf start is not allowed (possible racing with dismount or volume shutdown).
Description
TxfStartRm: Denying access due to Txf start is not allowed (possible racing with dismount or volume shutdown). Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, FxfVcb flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_VcbTxfVcbFlags HexInt32 | — |
Event ID 617 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: no TXF_DATA in root.
Event ID 618 — A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Different nesting levels of 0xA13_LogNestingLevel and 0xA14_DiskNestingLevel.
Description
A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Different nesting levels of 0xA13_LogNestingLevel and 0xA14_DiskNestingLevel.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_PVOIDTxfRmcb Pointer | — |
A12__TxfRmcbRmId GUID | — |
A13_LogNestingLevel HexInt32 | — |
A14_DiskNestingLevel HexInt32 | — |
Event ID 619 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: restart area already exists.
Event ID 620 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: restart area already exists.
Event ID 621 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: RmID in restart area does not match {A13__ClfsRestartAreaRmId}.
Event ID 622 — A10___FUNCTION__: Got A11_Status from ClfsGetLogFileInformation for RM at 0xA12_PVOIDTxfRmcb {A13__TxfRmcbRmId}.
Event ID 623 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Restart LSN is before beginning of log.
Event ID 624 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: MinRollforwardEndLsn is beyond end of log.
Event ID 625 — A10___FUNCTION__: TxF RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} started successfully.
Event ID 626 — A10___FUNCTION__: TxF RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} failed to start with Status 0xA13_Status A14_AbnormalTerminationabnormaltermination.
Description
A10___FUNCTION__: TxF RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} failed to start with Status 0xA13_Status A14_AbnormalTerminationabnormaltermination.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_PVOIDTxfRmcb Pointer | — |
A12__TxfRmcbRmId GUID | — |
A13_Status HexInt32 | — |
A14_AbnormalTerminationabnormaltermination AnsiString | — |
Event ID 627 — A10___FUNCTION__: Shutting down A11_TxfIsDefaultRmTxfRmcbdefaultsecondary RM at 0xA12_PVOIDTxfRmcb {A13__TxfRmcbRmId}.
Description
A10___FUNCTION__: Shutting down A11_TxfIsDefaultRmTxfRmcbdefaultsecondary RM at 0xA12_PVOIDTxfRmcb {A13__TxfRmcbRmId}. Shutdown is A14_ForceDirtyShutdownDIRTYCLEAN.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_TxfIsDefaultRmTxfRmcbdefaultsecondary AnsiString | — |
A12_PVOIDTxfRmcb Pointer | — |
A13__TxfRmcbRmId GUID | — |
A14_ForceDirtyShutdownDIRTYCLEAN AnsiString | — |
Event ID 628 — A10___FUNCTION__: Setting RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} up for auto-restart.
Event ID 629 — TxfFlushAndInvalidateExistingStructures: File has open user handles.
Description
TxfFlushAndInvalidateExistingStructures: File has open user handles. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: 0x!I64x!, CleanupCount: !d!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_FcbVcb Pointer | — |
A12__FcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_FcbFileReference HexInt64 | — |
A16_FcbCleanupCount Int32 | — |
Event ID 630 — (A10_FILEID_FROM_SOURCEFileNLine:A11_LINENUM_FROM_SOURCEFileNLine) - TXF_HARD_ERROR on RM at 0xA12_TxfRmcb ({A13__TxfRmcbRmId}): A14_Status).
Description
(A10_FILEID_FROM_SOURCEFileNLine:A11_LINENUM_FROM_SOURCEFileNLine) - TXF_HARD_ERROR on RM at 0xA12_TxfRmcb ({A13__TxfRmcbRmId}): A14_Status).
Message #
Fields #
| Name | Description |
|---|---|
A10_FILEID_FROM_SOURCEFileNLine UInt32 | — |
A11_LINENUM_FROM_SOURCEFileNLine Int32 | — |
A12_TxfRmcb Pointer | — |
A13__TxfRmcbRmId GUID | — |
A14_Status HexInt32 | — |
Event ID 631 — A10___FUNCTION__: Renamed RM at 0xA11_PVOIDTxfRmcb from {A12__OldGuid} to {A13__TxfRmcbRmId}.
Event ID 632 — A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}, rolling back Tx at 0xA13_PVOIDTxfTrans {A14__TxfTransKtmUow}, Status was 0xA15_Status.
Description
A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}, rolling back Tx at 0xA13_PVOIDTxfTrans {A14__TxfTransKtmUow}, Status was 0xA15_Status.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_PVOIDTxfRmcb Pointer | — |
A12__TxfRmcbRmId GUID | — |
A13_PVOIDTxfTrans Pointer | — |
A14__TxfTransKtmUow GUID | — |
A15_Status HexInt32 | — |
Event ID 633 — A10___FUNCTION__: Renamed RM at 0xA11_PVOIDTxfRmcb from {A12__OldGuid} to {A13__TxfRmcbRmId}.
Event ID 634 — TxfFsctlStartRm: Denying access due starting default RM is not allowed.
Description
TxfFsctlStartRm: Denying access due starting default RM is not allowed. Thread: A10_PsGetCurrentThread, Vcb: A11_RmRootFcbVcb, VolumeName: A12__RmRootFcbVcbVolumeName, VolumeLabel: A13_WppCountedStringWRmRootFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHRmRootFcbVcbVpb, RmRootFcb: A14_RmRootFcb.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_RmRootFcbVcb Pointer | — |
A12__RmRootFcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWRmRootFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHRmRootFcbVcbVpb CountedUtf16String | — |
A14_RmRootFcb Pointer | — |
Event ID 635 — TxfFsctlWriteBackupInformation: Denying access due RM is active.
Description
TxfFsctlWriteBackupInformation: Denying access due RM is active. Thread: A10_PsGetCurrentThread, Vcb: A11_FcbVcb, VolumeName: A12__FcbVcbVolumeName, VolumeLabel: A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb, BackupInfo flags: 0xA14_BackupInfoFlags!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_FcbVcb Pointer | — |
A12__FcbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWFcbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHFcbVcbVpb CountedUtf16String | — |
A14_BackupInfoFlags HexInt32 | — |
Event ID 636 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Found too high of a TxF ID in log.
Event ID 637 — A10___FUNCTION__: Error Setting Delete Disposition: 0xA11_Status FileObject: 0xA12_PVOIDFileObject.
Event ID 638 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Got a RECOVER notification for a transaction that isn't in-doubt.
Event ID 639 — TxfSetupTransactionContextFromCcb: Modifying operation is now allowed with a non-TxF modify handle.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__CcbFullFileName CountedUtf16String | — |
A19_CcbFlags HexInt32 | — |
Event ID 640 — TxfSetupTransactionContextFromCcb: Invalid TxF structure.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_CcbTxfFo Pointer | — |
A18_CcbTxfFoKtmTrans Pointer | — |
A19_ScbFcbTxfRmcb Pointer | — |
A20_CcbFullFileNameBuffer UnicodeString | — |
Event ID 641 — TxfSetupTransactionContextFromCcb: Denying access of modifying operation on a read-only handle.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17__CcbFullFileName CountedUtf16String | — |
A18_CcbAccessFlags HexInt32 | — |
A19_FileObjectWriteAccess Int32 | — |
A20_FileObjectDeleteAccess Int32 | — |
Event ID 642 — A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} raising 0xA13_ExceptionCode to KTM!
Event ID 643 — A10___FUNCTION__: Commit (0xA11_TransactionNotification) ofA12_TransactionAlreadyPreparedPREPAREDtx {A13__TxfTransKtmUow} on RM at 0xA14_PVOIDTxfRmcb {A15__TxfRmcbRmId} failed with 0xA16_Status.
Description
A10___FUNCTION__: Commit (0xA11_TransactionNotification) ofA12_TransactionAlreadyPreparedPREPAREDtx {A13__TxfTransKtmUow} on RM at 0xA14_PVOIDTxfRmcb {A15__TxfRmcbRmId} failed with 0xA16_Status.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_TransactionNotification HexInt32 | — |
A12_TransactionAlreadyPreparedPREPARED AnsiString | — |
A13__TxfTransKtmUow GUID | — |
A14_PVOIDTxfRmcb Pointer | — |
A15__TxfRmcbRmId GUID | — |
A16_Status HexInt32 | — |
Event ID 644 — A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} aborting transaction at 0xA13_TxfTrans {A14__TxfTransKtmUow} (notify commit).
Description
A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} aborting transaction at 0xA13_TxfTrans {A14__TxfTransKtmUow} (notify commit).
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_PVOIDTxfRmcb Pointer | — |
A12__TxfRmcbRmId GUID | — |
A13_TxfTrans Pointer | — |
A14__TxfTransKtmUow GUID | — |
Event ID 645 — A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} aborting transaction at 0xA13_TxfTrans {A14__TxfTransKtmUow} (notify rollback).
Description
A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} aborting transaction at 0xA13_TxfTrans {A14__TxfTransKtmUow} (notify rollback).
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_PVOIDTxfRmcb Pointer | — |
A12__TxfRmcbRmId GUID | — |
A13_TxfTrans Pointer | — |
A14__TxfTransKtmUow GUID | — |
Event ID 646 — A10___FUNCTION__: Error doing IRP_MJ_FLUSH_BUFFERS on RM at 0xA11_PVOIDTransTxfRmcb {A12__TransTxfRmcbRmId}: 0xA13_FlushStatus.
Event ID 647 — A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} trying to abort transaction at 0xA13_Trans {A14__TransKtmUow}.
Event ID 648 — A10___FUNCTION__: Aborting call stack: 0xA11_CallStack0 0xA12_CallStack1 0xA13_CallStack2 0xA14_CallStack3 0xA15_CallStack4.
Description
A10___FUNCTION__: Aborting call stack: 0xA11_CallStack0 0xA12_CallStack1 0xA13_CallStack2 0xA14_CallStack3 0xA15_CallStack4.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_CallStack0 Pointer | — |
A12_CallStack1 Pointer | — |
A13_CallStack2 Pointer | — |
A14_CallStack3 Pointer | — |
A15_CallStack4 Pointer | — |
Event ID 649 — A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} aborting transaction at 0xA13_Trans {A14__TransKtmUow}.
Event ID 650 — A10___FUNCTION__: 0xA11_Status initializing IrpContext for tx at A12_PVOIDTrans {A13__TransKtmUow}, RM at A14_PVOIDTxfRmcb {A15__TxfRmcbRmId}.
Description
A10___FUNCTION__: 0xA11_Status initializing IrpContext for tx at A12_PVOIDTrans {A13__TransKtmUow}, RM at A14_PVOIDTxfRmcb {A15__TxfRmcbRmId}.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_Status HexInt32 | — |
A12_PVOIDTrans Pointer | — |
A13__TransKtmUow GUID | — |
A14_PVOIDTxfRmcb Pointer | — |
A15__TxfRmcbRmId GUID | — |
Event ID 651 — A10___FUNCTION__: 0xA11_Status writing log record for RM at 0xA12_PVOIDTxfRmcb {A13__TxfRmcbRmId}, Tx at 0xA14_PVOIDTrans {A15__TransKtmUow}.
Description
A10___FUNCTION__: 0xA11_Status writing log record for RM at 0xA12_PVOIDTxfRmcb {A13__TxfRmcbRmId}, Tx at 0xA14_PVOIDTrans {A15__TransKtmUow}.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_Status HexInt32 | — |
A12_PVOIDTxfRmcb Pointer | — |
A13__TxfRmcbRmId GUID | — |
A14_PVOIDTrans Pointer | — |
A15__TransKtmUow GUID | — |
Event ID 652 — A10___FUNCTION__: About to force aborts on RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}.
Event ID 653 — A10___FUNCTION__: BaseLsn is greater than TargetLsn on RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}.
Event ID 654 — A10___FUNCTION__: No transactions remain on RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}.
Event ID 655 — A10___FUNCTION__: Transaction's first undo LSN greater than TargetLsn on RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}.
Event ID 656 — A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} surprise-aborting transaction at 0xA13_OldestTrans {A14__OldestTransKtmUow}.
Description
A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} surprise-aborting transaction at 0xA13_OldestTrans {A14__OldestTransKtmUow}.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_PVOIDTxfRmcb Pointer | — |
A12__TxfRmcbRmId GUID | — |
A13_OldestTrans Pointer | — |
A14__OldestTransKtmUow GUID | — |
Event ID 657 — A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} got 0xA13_Status from TxfTryAbortTransaction on Tx 0xA14_OldestTrans {A15__OldestTransKtmUow}.
Description
A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId} got 0xA13_Status from TxfTryAbortTransaction on Tx 0xA14_OldestTrans {A15__OldestTransKtmUow}.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_PVOIDTxfRmcb Pointer | — |
A12__TxfRmcbRmId GUID | — |
A13_Status HexInt32 | — |
A14_OldestTrans Pointer | — |
A15__OldestTransKtmUow GUID | — |
Event ID 658 — A10___FUNCTION__: Inactive RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}.
Event ID 659 — A10___FUNCTION__: Log is pinned on RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}.
Event ID 660 — A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}, rolling back KTM Tx at 0xA13_PVOIDTransToDereference {A14__TransToDereferenceKtmUow}, Status was 0xA15_Status.
Description
A10___FUNCTION__: RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}, rolling back KTM Tx at 0xA13_PVOIDTransToDereference {A14__TransToDereferenceKtmUow}, Status was 0xA15_Status.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_PVOIDTxfRmcb Pointer | — |
A12__TxfRmcbRmId GUID | — |
A13_PVOIDTransToDereference Pointer | — |
A14__TransToDereferenceKtmUow GUID | — |
A15_Status HexInt32 | — |
Event ID 661 — A10___FUNCTION__: Log pinned trying to advance RestartLsn on RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}.
Event ID 662 — A10___FUNCTION__: Log pinned by doomed transaction on RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}.
Event ID 663 — A10___FUNCTION__: Reporting 0xA11_PinnedStatus to CLFS from RM at 0xA12_PVOIDTxfRmcb {A13__TxfRmcbRmId}: 0xA14_Status.
Event ID 664 — A10___FUNCTION__: Done forcing aborts on RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}.
Event ID 665 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: $Txf directory is missing in pre-existing RM.
Event ID 666 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Found $Txf without DUP_INDEX_IS_DOLLAR_TXF_DIRECTORY.
Event ID 667 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Found non-empty $Txf but there is no log.
Event ID 668 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Couldn't find $INDEX_ROOT on $Txf.
Event ID 669 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Couldn't find TXF_DATA_ATTR on $Txf.
Event ID 670 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Found TXF_DATA_ATTR for normal file on $Txf.
Event ID 671 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Expected a secondary RM here.
Event ID 672 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: $Tops is missing but $Txf is non-empty.
Event ID 673 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: $Tops is missing but there is already a log.
Event ID 674 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: $Tops is A13_IsEncrypted_TopsFcbInfoencryptedcompressed.
Description
A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: $Tops is A13_IsEncrypted_TopsFcbInfoencryptedcompressed.
Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString | — |
A11_PVOIDTxfRmcb Pointer | — |
A12__TxfRmcbRmId GUID | — |
A13_IsEncrypted_TopsFcbInfoencryptedcompressed AnsiString | — |
Event ID 675 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Missing $STANDARD_INFORMATION.
Event ID 676 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Couldn't find file attributes.
Event ID 677 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: $Tops is corrupt.
Event ID 678 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Could not find unnamed data stream.
Event ID 679 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: $Tops metadata is the wrong version or records wrong size.
Event ID 680 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: $Tops metadata is the wrong size.
Event ID 681 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Non-NULL RM ID found in $Tops and there is no log.
Event ID 682 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Epoch in $Tops metadata doesn't match RM.
Event ID 683 — A10___FUNCTION__: Corrupt RM at 0xA11_PVOIDTxfRmcb {A12__TxfRmcbRmId}: Couldn't find $T stream.
Event ID 684 — NtfsReadUsnJournal: Caller does not have manage volume privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_TypeOfOpen Int32 | — |
A12_Vcb Pointer | — |
A13__VcbVolumeName CountedUtf16String | — |
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A15_Fcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A18_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 685 — TrimUsnJournal (A10_Vcb, A11_IrpContext): Decided to trim usn journal.
Description
TrimUsnJournal (!p!, !p!): Decided to trim usn journal. FirstValidUsn !I64x!, new FirstValidUsn !I64x!, FS !I64x!, AS !I64x!, MaxSize !I64x!, DeltaSize !I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_VcbFirstValidUsn HexInt64 | — |
A13_FirstValidUsn HexInt64 | — |
A14_TrackUsnJournalFileSize HexInt64 | — |
A15_TrackUsnJournalAllocationSize HexInt64 | — |
A16_TrackUsnJournalMaxSize HexInt64 | — |
A17_TrackUsnJournalDeltaAllocation HexInt64 | — |
Event ID 686 — TrimUsnJournal (A10_Vcb, A11_IrpContext): About to delete allocation till A12_FirstValidUsn1!
Description
TrimUsnJournal (A10_Vcb, A11_IrpContext): About to delete allocation till A12_FirstValidUsn1!I64x!, SavedReserve A13_SavedReserved!I64x!, RequiredReserve A14_RequiredReserved!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_FirstValidUsn1 HexInt64 | — |
A13_SavedReserved HexInt64 | — |
A14_RequiredReserved HexInt64 | — |
Event ID 687 — TrimUsnJournal (A10_Vcb, A11_IrpContext): Before trimming journal AS A12_UsnJournalHeaderAllocationSizeQuadPart!
Description
TrimUsnJournal (A10_Vcb, A11_IrpContext): Before trimming journal AS A12_UsnJournalHeaderAllocationSizeQuadPart!I64x!, FS A13_UsnJournalHeaderFileSizeQuadPart!I64x!, VDL A14_UsnJournalHeaderValidDataLengthQuadPart!I64x!, TA A15_UsnJournalTotalAllocated!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_UsnJournalHeaderAllocationSizeQuadPart HexInt64 | — |
A13_UsnJournalHeaderFileSizeQuadPart HexInt64 | — |
A14_UsnJournalHeaderValidDataLengthQuadPart HexInt64 | — |
A15_UsnJournalTotalAllocated HexInt64 | — |
Event ID 688 — TrimUsnJournal (A10_Vcb, A11_IrpContext): After trimming journal AS A12_UsnJournalHeaderAllocationSizeQuadPart!
Description
TrimUsnJournal (A10_Vcb, A11_IrpContext): After trimming journal AS A12_UsnJournalHeaderAllocationSizeQuadPart!I64x!, FS A13_UsnJournalHeaderFileSizeQuadPart!I64x!, VDL A14_UsnJournalHeaderValidDataLengthQuadPart!I64x!, TA A15_UsnJournalTotalAllocated!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_UsnJournalHeaderAllocationSizeQuadPart HexInt64 | — |
A13_UsnJournalHeaderFileSizeQuadPart HexInt64 | — |
A14_UsnJournalHeaderValidDataLengthQuadPart HexInt64 | — |
A15_UsnJournalTotalAllocated HexInt64 | — |
Event ID 689 — TrimUsnJournal (A10_Vcb, A11_IrpContext): Mapping pairs validated.
Event ID 690 — TrimUsnJournal (A10_Vcb, A11_IrpContext): Checkpointed.
Event ID 691 — NtfsQueryUsnJournal: Denying access due to NULL Ccb.
Description
NtfsQueryUsnJournal: Denying access due to NULL Ccb. Thread: !p!, TypeOfOpen: !d!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: !I64x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_TypeOfOpen Int32 | — |
A12_Vcb Pointer | — |
A13__VcbVolumeName CountedUtf16String | — |
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A15_Fcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
Event ID 692 — NtfsDeleteUsnJournal: Caller does not have manage volume access.
Description
NtfsDeleteUsnJournal: Caller does not have manage volume access. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, Fcb: !p!, FileRef: !I64x!, Ccb FullFileName: !S!, Ccb access flags: 0x!08x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_Fcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A17_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 693 — NtfsRestartUsnJournal: Caller does not have manage volume privilege.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_TypeOfOpen Int32 | — |
A12_Vcb Pointer | — |
A13__VcbVolumeName CountedUtf16String | — |
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A15_Fcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_CcbNULL_CcbFullFileNameNULL CountedUtf16String | — |
A18_CcbNULLCcbAccessFlags0 HexInt32 | — |
Event ID 694 — NtOfsCreateAttributeEx: Stream already has a open user handle.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_ScbVcb Pointer | — |
A12__ScbVcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWScbVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHScbVcbVpb CountedUtf16String | — |
A14_ScbFcb Pointer | — |
A15_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A16_Scb Pointer | — |
A17_ScbAttributeTypeCode HexInt32 | — |
A18__ScbAttributeName CountedUtf16String | — |
A19_ScbCleanupCount Int32 | — |
Event ID 695 — OfsSetLength (A10_Vcb,A11_IrpContext,A12_IrpContextOriginatingIrp,A13_PsGetCurrentThread): Extending journal from AS A14_ScbHeaderAllocationSizeQuadPart!
Description
OfsSetLength (A10_Vcb,A11_IrpContext,A12_IrpContextOriginatingIrp,A13_PsGetCurrentThread): Extending journal from AS A14_ScbHeaderAllocationSizeQuadPart!I64x!, FS A15_ScbHeaderFileSizeQuadPart!I64x!, VDL A16_ScbHeaderValidDataLengthQuadPart!I64x!, to AS A17_NewAllocationSize!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_IrpContextOriginatingIrp Pointer | — |
A13_PsGetCurrentThread Pointer | — |
A14_ScbHeaderAllocationSizeQuadPart HexInt64 | — |
A15_ScbHeaderFileSizeQuadPart HexInt64 | — |
A16_ScbHeaderValidDataLengthQuadPart HexInt64 | — |
A17_NewAllocationSize HexInt64 | — |
Event ID 696 — OfsSetLength (A10_Vcb,A11_IrpContext,A12_IrpContextOriginatingIrp,A13_PsGetCurrentThread): Done extending journal AS A14_ScbHeaderAllocationSizeQuadPart!
Description
OfsSetLength (A10_Vcb,A11_IrpContext,A12_IrpContextOriginatingIrp,A13_PsGetCurrentThread): Done extending journal AS A14_ScbHeaderAllocationSizeQuadPart!I64x!, FS A15_ScbHeaderFileSizeQuadPart!I64x!, VDL A16_ScbHeaderValidDataLengthQuadPart!I64x!, TA A17_ScbTotalAllocated!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_IrpContext Pointer | — |
A12_IrpContextOriginatingIrp Pointer | — |
A13_PsGetCurrentThread Pointer | — |
A14_ScbHeaderAllocationSizeQuadPart HexInt64 | — |
A15_ScbHeaderFileSizeQuadPart HexInt64 | — |
A16_ScbHeaderValidDataLengthQuadPart HexInt64 | — |
A17_ScbTotalAllocated HexInt64 | — |
Event ID 697 — OfsSetLength (A10_Vcb,A11_IrpContext,A12_IrpContextOriginatingIrp,A13_PsGetCurrentThread): After NtfsWriteFileSizes.
Event ID 698 — OfsSetLength (A10_Vcb,A11_IrpContext,A12_IrpContextOriginatingIrp,A13_PsGetCurrentThread): After NtfsSetCcFileSizesUsnBiasAware.
Event ID 699 — NtOfsPostNewLength (A10_IrpContext,A11_IrpContextOriginatingIrp,A12_PsGetCurrentThread): Status A13_IrpContextExceptionStatus before calling NtfsReadUsnJournal.
Description
NtOfsPostNewLength (A10_IrpContext,A11_IrpContextOriginatingIrp,A12_PsGetCurrentThread): Status A13_IrpContextExceptionStatus before calling NtfsReadUsnJournal.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_IrpContextOriginatingIrp Pointer | — |
A12_PsGetCurrentThread Pointer | — |
A13_IrpContextExceptionStatus HexInt32 | — |
Event ID 700 — NtfsIsRegionDangling: RemainingClusterCount: 0xA10_RemainingClusterCount!
Description
NtfsIsRegionDangling: RemainingClusterCount: 0xA10_RemainingClusterCount!I64x!, Scb: A11_Scb, Vcn: 0xA12_Vcn!I64x!, Lcn: 0xA13_Lcn!I64x!, Clusters: 0xA14_ClusterCount!I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_RemainingClusterCount HexInt64 | — |
A11_Scb Pointer | — |
A12_Vcn HexInt64 | — |
A13_Lcn HexInt64 | — |
A14_ClusterCount HexInt64 | — |
Event ID 701 — Vcb A10_Vcb - has *no* active PFNs.
Event ID 702 — Vcb A10_Vcb - failed to query active PFNs assuming there are some.
Event ID 703 — Vcb A10_Vcb - has active PFNs.
Event ID 704 — NtfsPerformDismountOnVcb: Vcb A10_Vcb.
Event ID 705 — NtfsPerformDismountOnVcb: Vcb A10_Vcb - Found frozen deallocated clusters.
Event ID 706 — NtfsPerformDismountOnVcb: Vcb A10_Vcb - Wait for any on going trim to finish.
Event ID 707 — NtfsPerformDismountOnVcb: Vcb A10_Vcb - No more on going trim.
Event ID 708 — NtfsPerformDismountOnVcb: IC: A10_IrpContext, Vcb: A11_Vcb, Label: A12__VolumeLabel, DeviceName: A13__VcbDeviceName.
Event ID 709 — NtfsPostVcbIsCorrupt.
Description
NtfsPostVcbIsCorrupt(A10_IrpContext, A11_Status, A12_FileReference, A13_Fcb, A14_Source!016I64x!): IrpContext->TopLevelIrpContext->ExceptionStatus == A15_TopLevelExceptionStatus before NtfsSetVcbDirtyFlag.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer | — |
A11_Status HexInt32 | — |
A12_FileReference Pointer | — |
A13_Fcb Pointer | — |
A14_Source HexInt64 | — |
A15_TopLevelExceptionStatus HexInt32 | — |
Event ID 710 — NtfsPostVcbIsCorrupt: Marking volume dirty.
Description
NtfsPostVcbIsCorrupt: Marking volume dirty. Vcb A10_Vcb, WasDirty: A11_WasDirty, FileReference A12_NtfsFullSegmentNumber_BugCheckFileReference!I64x!, Source A13_Source!016I64x!
Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer | — |
A11_WasDirty HexInt32 | — |
A12_NtfsFullSegmentNumber_BugCheckFileReference HexInt64 | — |
A13_Source HexInt64 | — |
Event ID 711 — NtfsCommonSetVolumeInfo: Operation is only allowed on a VolumeOpen except for IndexOpen of \$Extend\$Quota with FileFsControlInformation.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_TypeOfOpen Int32 | — |
A12_Vcb Pointer | — |
A13__VcbVolumeName CountedUtf16String | — |
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A15_Fcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_FsInformationClass HexInt32 | — |
A18_Scb Pointer | — |
Event ID 712 — NtfsCommonSetVolumeInfo: Operation is only allowed on a VolumeOpen except for IndexOpen of \$Extend\$Quota with FileFsControlInformation.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_TypeOfOpen Int32 | — |
A12_Vcb Pointer | — |
A13__VcbVolumeName CountedUtf16String | — |
A14_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A15_Fcb Pointer | — |
A16_NtfsFullFileRefNumber_ScbFcbFileReference HexInt64 | — |
A17_FsInformationClass HexInt32 | — |
A18_Scb Pointer | — |
Event ID 713 — Succeeding log write @ 0xA10_IrpSpParametersWriteByteOffsetHighPart!
Description
Succeeding log write @ 0xA10_IrpSpParametersWriteByteOffsetHighPart!08x!A11_IrpSpParametersWriteByteOffsetLowPart!08x! after getting 0xA12_IrpContextTopLevelIrpContextExceptionStatus in top-level irpcontext.
Message #
Fields #
| Name | Description |
|---|---|
A10_IrpSpParametersWriteByteOffsetHighPart HexInt32 | — |
A11_IrpSpParametersWriteByteOffsetLowPart HexInt32 | — |
A12_IrpContextTopLevelIrpContextExceptionStatus HexInt32 | — |
Event ID 714 — Unexpected Paging-Write on stream accessed in Direct-Access mode, Scb=A10_Scb.
Event ID 715 — NtfsCommonWrite: Writing beyond highest writable sector on active volume is not allowed.
Description
NtfsCommonWrite: Writing beyond highest writable sector on active volume is not allowed. Thread: !p!, Vcb: !p!, VolumeName: !S!, VolumeLabel: !S!, RequestedRange: 0x!I64x!, AllowedRange: 0x!I64x!.
Message #
Fields #
| Name | Description |
|---|---|
A10_PsGetCurrentThread Pointer | — |
A11_Vcb Pointer | — |
A12__VcbVolumeName CountedUtf16String | — |
A13_WppCountedStringWVcbVpbVolumeLabelSAFE_VPB_VOLUME_LABEL_LENGTHVcbVpb CountedUtf16String | — |
A14_ByteRange HexInt64 | — |
A15_HIGHEST_WRITABLE_SECTOR_ON_ACTIVE_VOLUMEVcbSectorSizeInfoLogicalBytesPerSector HexInt64 | — |