Microsoft-Windows-CoreSystem-InitMachineConfig
6 events across 1 channel
Event ID 1: An error with reference Id=evtErrorId was encountered while processing the hive 'evtHiveName'.
#Description
An error with reference Id=evtErrorId was encountered while processing the hive 'evtHiveName'. The status was: evtStatus. The additional information was evtAdditionalInfo.
Message #
Fields #
| Name | Description |
|---|---|
evtErrorId UInt64 | |
evtHiveNameLength UInt16 | |
evtHiveName UnicodeString | |
evtStatus HexInt32 | |
evtAdditionalInfo HexInt64 |
Event ID 2: Initial Machine Configuration processing of hive 'evtHiveName' has completed.
#Event ID 3: Initial Machine Configuration was unable to unload the IMC hive once processing was completed.
#Event ID 4: Initial Machine Configuration was unable to update the system BCD to prevent future execution.
#Event ID 5: Value blocked: evtValueNameLength under the key, evtKeyPathLength, was NOT set after failing validation.
#Event ID 6: Value set: evtValueNameLength under the key, evtKeyPathLength, was set after passing validation.
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 0b886108-1899-4d3a-9c0d-42d8fc4b9108
Defined in cmimcext.sys, the binary that emits these events.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.3089, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.3323, captured 2026-06-02