Microsoft-Windows-CorruptedFileRecovery-Client
3 events across 1 channel
| Event | Title | Channel | Sample |
|---|---|---|---|
| 1 | The system file FileName may be corrupted, which may have caused the application … | Operational | N |
| 2 | The system file FileName may be corrupted, which may have caused the application … | Operational | N |
| 3 | The system file FileName is corrupted, which may have caused the application … | Operational | N |
Event ID 1: The system file FileName may be corrupted, which may have caused the application AppName to stop working.
#Description
The system file FileName may be corrupted, which may have caused the application AppName to stop working. Windows could not repair this file automatically (error code ErrorCode). Run the command "sfc /scannow" at an administrative command prompt to check for errors and to repair the file if necessary.
Message #
Fields #
| Name | Description |
|---|---|
FileName UnicodeString | |
AppName UnicodeString | |
ErrorCode UInt32 |
Event ID 2: The system file FileName may be corrupted, which may have caused the application AppName to stop working.
#Description
The system file FileName may be corrupted, which may have caused the application AppName to stop working. Windows attempted to repair the file, but the operation was disabled by group policy. Run the command "sfc /scannow" at an administrative command prompt to check for errors and to repair the file if necessary.
Message #
Fields #
| Name | Description |
|---|---|
FileName UnicodeString | |
AppName UnicodeString |
Event ID 3: The system file FileName is corrupted, which may have caused the application AppName to stop working.
#Description
The system file FileName is corrupted, which may have caused the application AppName to stop working. Windows could not attempt to repair FileName because the operation was disabled by group policy. Run the command "sfc /scannow" at an administrative command prompt to check for errors and to repair the file if necessary.
Message #
Fields #
| Name | Description |
|---|---|
FileName UnicodeString | |
AppName UnicodeString |
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID ba093605-3909-4345-990b-26b746adee0a
Defined in cofiredm.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02