Microsoft-Windows-UAC-FileVirtualization
27 events across 1 channel
Event ID 2000 — Failed to register with Filter Manager.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 2001 — Failed to read the settings.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 2002 — Failed to read the file list.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 2003 — Failed to initialize security.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 2004 — Failed to start filtering.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 2005 — Failed to set up the instance for a volume.
Message
Fields
| Name | Description |
|---|---|
Error | — |
Event ID 2006 — Failed to query the virtualization mode.
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Error | — |
Event ID 2007 — Failed to query virtual store file information.
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Error | — |
Event ID 2008 — Failed to select which file to create.
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Error | — |
Event ID 2009 — Failed to create a stream handle context.
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Error | — |
Event ID 2010 — Failed to set the stream handle context.
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Error | — |
Event ID 2011 — Failed to perform the administrator access check.
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Error | — |
Event ID 2012 — Failed to prepare for delayed virtualization.
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Error | — |
Event ID 2013 — Failed to perform delayed virtualization.
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Error | — |
Event ID 2014 — Failed to switch one or more delayed file objects.
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Error | — |
Event ID 2015 — Failed to create the virtual file path.
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Error | — |
Event ID 2016 — Failed to copy the file into the virtual store.
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Error | — |
Event ID 2017 — Failed to perform the merged directory query.
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Error | — |
Event ID 2018 — Failed to query information for the file object.
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Error | — |
Event ID 2019 — Failed to check target file for WRP protection.
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Error | — |
Event ID 4000 — Virtual file ".
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
CreateOptions | — |
DesiredAccess | — |
IrpMajorFunction | — |
Event ID 4001 — Virtual file ".
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
TargetFileNameLength | — |
TargetFileNameBuffer | — |
Event ID 4002 — Virtual delete of file ".
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Event ID 5000 — Operation on file ".
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
CreateOptions | — |
DesiredAccess | — |
IrpMajorFunction | — |
Exclusions | — |
Event ID 5002 — Delayed virtual file ".
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
CreateOptions | — |
DesiredAccess | — |
Event ID 5003 — Access was denied on WRP file ".
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |
Event ID 5004 — Access was denied to delete file ".
Message
Fields
| Name | Description |
|---|---|
Flags | — |
SidLength | — |
Sid | — |
FileNameLength | — |
FileNameBuffer | — |
ProcessImageNameLength | — |
ProcessImageNameBuffer | — |