Microsoft-Windows-Program-Compatibility-Assistant
44 events across 5 channels
Event ID 1 —
Event ID 1 —
Fields
| Name | Description |
|---|---|
ApplicationNameSize | — |
ApplicationName | — |
CommandLineSize | — |
CommandLine | — |
CurrentDirectorySize | — |
CurrentDirectory | — |
DllNameSize | — |
DllName | — |
InterfaceCLSID | — |
SessionId | — |
Flags | — |
Event ID 3 —
Event ID 3 —
Fields
| Name | Description |
|---|---|
ApplicationNameSize | — |
ApplicationName | — |
CommandLineSize | — |
CommandLine | — |
CurrentDirectorySize | — |
CurrentDirectory | — |
DllNameSize | — |
DllName | — |
InterfaceCLSID | — |
SessionId | — |
Flags | — |
Event ID 5 —
Event ID 5 —
Fields
| Name | Description |
|---|---|
ApplicationNameSize | — |
ApplicationName | — |
CommandLineSize | — |
CommandLine | — |
CurrentDirectorySize | — |
CurrentDirectory | — |
DllNameSize | — |
DllName | — |
InterfaceCLSID | — |
SessionId | — |
Flags | — |
Event ID 8 —
Event ID 8 —
Fields
| Name | Description |
|---|---|
ApplicationNameSize | — |
ApplicationName | — |
CommandLineSize | — |
CommandLine | — |
CurrentDirectorySize | — |
CurrentDirectory | — |
DllNameSize | — |
DllName | — |
InterfaceCLSID | — |
SessionId | — |
Flags | — |
Event ID 9 —
Event ID 9 —
Fields
| Name | Description |
|---|---|
ApplicationNameSize | — |
ApplicationName | — |
CommandLineSize | — |
CommandLine | — |
CurrentDirectorySize | — |
CurrentDirectory | — |
DllNameSize | — |
DllName | — |
InterfaceCLSID | — |
SessionId | — |
Flags | — |
Event ID 10 —
Event ID 10 —
Fields
| Name | Description |
|---|---|
ApplicationNameSize | — |
ApplicationName | — |
CommandLineSize | — |
CommandLine | — |
CurrentDirectorySize | — |
CurrentDirectory | — |
DllNameSize | — |
DllName | — |
InterfaceCLSID | — |
SessionId | — |
Flags | — |
Event ID 11 —
Event ID 11 —
Fields
| Name | Description |
|---|---|
DisplayNameSize | — |
DisplayName | — |
FullImagePathSize | — |
FullImagePath | — |
SessionId | — |
Event ID 12 —
Event ID 12 —
Fields
| Name | Description |
|---|---|
ApplicationNameSize | — |
ApplicationName | — |
CommandLineSize | — |
CommandLine | — |
CurrentDirectorySize | — |
CurrentDirectory | — |
DllNameSize | — |
DllName | — |
InterfaceCLSID | — |
SessionId | — |
Flags | — |
Event ID 14 —
Event ID 14 —
Fields
| Name | Description |
|---|---|
ApplicationNameSize | — |
ApplicationName | — |
CommandLineSize | — |
CommandLine | — |
CurrentDirectorySize | — |
CurrentDirectory | — |
DllNameSize | — |
DllName | — |
InterfaceCLSID | — |
SessionId | — |
Flags | — |
Event ID 15 — Binary data sent from PCA Diagnostic Module to PCA service for processing.
Message
Fields
| Name | Description |
|---|---|
TokenDataSize | — |
TokenData | — |
Event ID 15 — Binary data sent from PCA Diagnostic Module to PCA service for processing.
Message
Fields
| Name | Description |
|---|---|
TokenDataSize | — |
TokenData | — |
Event ID 16 — PCA has finished monitoring an application: %1 The problems detected code is: %2 If this number is not 0, PCA observed some indications of compatib...
Message
Fields
| Name | Description |
|---|---|
ExePath | — |
ResolverMap | — |
DialogType | — |
Event ID 17 — Exe: %1 ResolverName: %2.
Message
Fields
| Name | Description |
|---|---|
ResolverFiredEvent.ExePath | Exe. |
ResolverFiredEvent.ResolverName | ResolverName. |
Example Event
system:
provider: Microsoft-Windows-Program-Compatibility-Assistant
guid: 4CB314DF-C11F-47D7-9C04-65FB0051561B
event_source_name: ''
event_id: 17
version: 0
level: 4
task: 0
opcode: 0
keywords: 4611686018427387904
time_created: '2023-11-06T02:02:45.055790+00:00'
event_record_id: 42
correlation: {}
execution:
process_id: 5756
thread_id: 8424
channel: Microsoft-Windows-Application-Experience/Program-Compatibility-Assistant
computer: WinDev2310Eval
security:
user_id: S-1-5-18
user_data:
ResolverFiredEvent:
ExePath: C:\Program Files (x86)\OpenOffice 4\program\soffice.exe
ResolverName: DetectorShim_KernelDriver
message: ''
References
- Example event sourced from https://github.com/NextronSystems/evtx-baseline
Event ID 30 — The Program Compatibility Assistant was invoked to correct a compatibility problem.
Message
Fields
| Name | Description |
|---|---|
Application_name | — |
Application_version | — |
Executable_path | — |
Scenario_ID | — |
User_action | — |
Compatibility_layer | — |
ApplicationName | — |
ApplicationVersion | — |
ExecutablePath | — |
ScenarioId | — |
UserAction | — |
CompatibilityLayer | — |
Event ID 31 — The Program Compatibility Assistant was invoked to correct a compatibility problem.
Message
Fields
| Name | Description |
|---|---|
Application_name | — |
Application_version | — |
Executable_path | — |
Scenario_ID | — |
User_action | — |
Compatibility_layer | — |
Deprecated_component | — |
ApplicationName | — |
ApplicationVersion | — |
ExecutablePath | — |
ScenarioId | — |
UserAction | — |
CompatibilityLayer | — |
DeprecatedComponent | — |
Event ID 32 — The Program Compatibility Assistant was invoked due to an unsigned driver install.
Message
Fields
| Name | Description |
|---|---|
Driver | — |
Service | — |
Publisher | — |
Location | — |
Version | — |
DriverName | — |
ServiceName | — |
PublisherName | — |
DriverPath | — |
DriverVersion | — |
Event ID 101 — PCA Service startup begin.
Message
Event ID 102 — PCA Service startup finished.
Message
Event ID 103 — PCA Process Monitor begin.
Message
Event ID 104 — PCA Process Monitor finished.
Message
Event ID 105 — PCA Service initialization begin.
Message
Event ID 106 — PCA Service initialization finished.
Message
Event ID 107 — PCA Service initialization begin.
Message
Event ID 108 — PCA Service initialization finished.
Message
Event ID 200 — The Program Compatibility Assistant service was stopped successfully.
Message
Event ID 201 — The Program Compatibility Assistant service started successfully.
Message
Event ID 202 — The Program Compatibility Assistant service failed to initialize.
Message
Event ID 203 — The Program Compatibility Assistant service failed to start.
Message
Event ID 204 — The Program Compatibility Assistant service failed to stop.
Message
Event ID 205 — The Program Compatibility Assistant service failed to perform the phase two initialization.
Message
Event ID 206 — The Program Compatibility Assistant service successfully performed phase two initialization.
Message
Event ID 1100 — Notified PCA service of status icon registration.
Message
Event ID 1200 — PCA Trigger event:%1.
Message
Fields
| Name | Description |
|---|---|
TriggerID | — |
ExtraDataSize | — |
ExtraData | — |
Event ID 1200 — PCA Trigger event.
Message
Fields
| Name | Description |
|---|---|
PCA_Trigger_event | — |
Event ID 1234 — Exe: AppId.
Message
Fields
| Name | Description |
|---|---|
ApplicationID | — |
Uptime | — |