Microsoft-Windows-ApplicationExperienceInfrastructure
3 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | The application (AppName, from vendor VendorName) has the following problem: … | Application | N |
| 2 | The application (AppName, from vendor VendorName) was hard-blocked and raised … | Application | N |
| 3 | The application (AppName, from vendor VendorName) was detected containing legacy … | Application | N |
Event ID 1: The application (AppName, from vendor VendorName) has the following problem: Summary.
#Event ID 2: The application (AppName, from vendor VendorName) was hard-blocked and raised the following: Summary.
#Event ID 3: The application (AppName, from vendor VendorName) was detected containing legacy redistributable software.
#Description
The application (AppName, from vendor VendorName) was detected containing legacy redistributable software.
Message #
Fields #
| Name | Description |
|---|---|
DBType UInt32 | |
AppNameCount UInt32 | |
AppName UnicodeString | |
VendorNameCount UInt32 | |
VendorName UnicodeString | |
SummaryCount UInt32 | |
Summary UnicodeString | |
SessionID UInt32 |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 5ec13d8e-4b3f-422e-a7e7-3121a1d90c7a
Defined in apphelp.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02