Microsoft-Windows-ApplicationExperienceInfrastructure

3 events across 1 channel

Event ID 1: The application (AppName, from vendor VendorName) has the following problem: Summary.

#
Provider
Microsoft-Windows-ApplicationExperienceInfrastructure
Channel
Application
Opcode
Stop

Description

The application (AppName, from vendor VendorName) has the following problem: Summary.

Message #

The application (%3, from vendor %5) has the following problem: %7

Fields #

NameDescription
DBType UInt32
AppNameCount UInt32
AppName UnicodeString
VendorNameCount UInt32
VendorName UnicodeString
SummaryCount UInt32
Summary UnicodeString
SessionID UInt32

Event ID 2: The application (AppName, from vendor VendorName) was hard-blocked and raised the following: Summary.

#
Provider
Microsoft-Windows-ApplicationExperienceInfrastructure
Channel
Application
Opcode
Info

Description

The application (AppName, from vendor VendorName) was hard-blocked and raised the following: Summary.

Message #

The application (%3, from vendor %5) was hard-blocked and raised the following: %7

Fields #

NameDescription
DBType UInt32
AppNameCount UInt32
AppName UnicodeString
VendorNameCount UInt32
VendorName UnicodeString
SummaryCount UInt32
Summary UnicodeString
SessionID UInt32

Event ID 3: The application (AppName, from vendor VendorName) was detected containing legacy redistributable software.

#
Provider
Microsoft-Windows-ApplicationExperienceInfrastructure
Channel
Application
Opcode
Info

Description

The application (AppName, from vendor VendorName) was detected containing legacy redistributable software.

Message #

The application (%3, from vendor %5) was detected containing legacy redistributable software.

Fields #

NameDescription
DBType UInt32
AppNameCount UInt32
AppName UnicodeString
VendorNameCount UInt32
VendorName UnicodeString
SummaryCount UInt32
Summary UnicodeString
SessionID UInt32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 5ec13d8e-4b3f-422e-a7e7-3121a1d90c7a

Defined in apphelp.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02

Downloads