Microsoft-Windows-MSPaint

38 events across 2 channels

Event ID 1: Intializing current instance of the application

#
Provider
Microsoft-Windows-MSPaint
Channel
Debug

Description

Intializing current instance of the application.

Message #

Intializing current instance of the application

Event ID 2: Exiting current Instance of the application

#
Provider
Microsoft-Windows-MSPaint
Channel
Debug

Description

Exiting current Instance of the application.

Message #

Exiting current Instance of the application

Event ID 3: MSPaint Launch Start

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
MSPaint_Launch
Opcode
Start

Description

MSPaint Launch Start.

Message #

MSPaint Launch Start

Event ID 4: MSPaint Launch End

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
MSPaint_Launch
Opcode
Stop

Description

MSPaint Launch End.

Message #

MSPaint Launch End

Event ID 5: MSPaint Exit Start

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
MSPaint_Exit
Opcode
Start

Description

MSPaint Exit Start.

Message #

MSPaint Exit Start

Event ID 6: MSPaint Exit End

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
MSPaint_Exit
Opcode
Stop

Description

MSPaint Exit End.

Message #

MSPaint Exit End

Event ID 7: Select Tool(ID: ToolID) Start.

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
Select_Tool
Opcode
Start

Description

Select Tool(ID: ToolID) Start.

Message #

Select Tool(ID: %1) Start

Fields #

NameDescription
ToolID Int32

Event ID 8: Select Tool End

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
Select_Tool
Opcode
Stop

Description

Select Tool End.

Message #

Select Tool End

Event ID 9: Commit Tool(ID: ToolID)b Start.

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
Commit_Tool
Opcode
Start

Description

Commit Tool(ID: ToolID)b Start.

Message #

Commit Tool(ID: %1)b Start

Fields #

NameDescription
ToolID Int32

Event ID 10: Commit Tool End

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
Commit_Tool
Opcode
Stop

Description

Commit Tool End.

Message #

Commit Tool End

Event ID 11: Undo Start

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
Undo
Opcode
Start

Description

Undo Start.

Message #

Undo Start

Event ID 12: Undo End

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
Undo
Opcode
Stop

Description

Undo End

Message #

Undo End

Event ID 13: Change Tool(ID: ToolID) Thickness(ToolThickness).

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic

Description

Change Tool(ID: ToolID) Thickness(ToolThickness).

Message #

Change Tool(ID: %1) Thickness(%2)

Fields #

NameDescription
ToolID Int32
ToolThickness Int32

Event ID 14: Change Stroke Color(RGB: Color).

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic

Description

Change Stroke Color(RGB: Color).

Message #

Change Stroke Color(RGB: %1)

Fields #

NameDescription
Color UInt64

Event ID 15: Change Fill Color(RGB: Color).

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic

Description

Change Fill Color(RGB: Color).

Message #

Change Fill Color(RGB: %1)

Fields #

NameDescription
Color UInt64

Event ID 16: Change DrawMode(ShapeDrawMode).

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic

Description

Change DrawMode(ShapeDrawMode).

Message #

Change DrawMode(%1)

Fields #

NameDescription
ShapeDrawMode Int32

Event ID 17: Change Brush CrossSection(ToolCrosssection).

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic

Description

Change Brush CrossSection(ToolCrosssection).

Message #

Change Brush CrossSection(%1)

Fields #

NameDescription
ToolCrosssection Int32

Event ID 18: Change Caligraphic Brush CrossSection(ToolCrosssection).

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic

Description

Change Caligraphic Brush CrossSection(ToolCrosssection).

Message #

Change Caligraphic Brush CrossSection(%1)

Fields #

NameDescription
ToolCrosssection Int32

Event ID 19: Change Glitter Color(Color).

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic

Description

Change Glitter Color(Color).

Message #

Change Glitter Color(%1)

Fields #

NameDescription
Color UInt64

Event ID 20: Error enabling/disabling RTS

#
Provider
Microsoft-Windows-MSPaint
Channel
Debug

Description

Error enabling/disabling RTS.

Message #

Error enabling/disabling RTS

Fields #

NameDescription
HResult UInt32

Event ID 21: Failed to load msftedit.

#
Provider
Microsoft-Windows-MSPaint
Channel
Debug

Description

Failed to load msftedit.dll.

Message #

Failed to load msftedit.dll

Event ID 22: Start measure paint lag

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
MeasurePaintLag
Opcode
Start

Description

Start measure paint lag.

Message #

Start measure paint lag

Event ID 23: Stop measure paint lag

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
MeasurePaintLag
Opcode
Stop

Description

Stop measure paint lag.

Message #

Stop measure paint lag

Event ID 24: Recieved RTS Packet

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
MeasurePaintLag

Description

Recieved RTS Packet.

Message #

Recieved RTS Packet

Event ID 25: Start save drawing

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
SaveDrawing
Opcode
Start

Description

Start save drawing.

Message #

Start save drawing

Event ID 26: Stop save drawing

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
SaveDrawing
Opcode
Stop

Description

Stop save drawing.

Message #

Stop save drawing

Fields #

NameDescription
Saveoperationresult Int32

Event ID 27: Start open image

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
OpenImage
Opcode
Start

Description

Start open image.

Message #

Start open image

Event ID 28: Stop open image

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
OpenImage
Opcode
Stop

Description

Stop open image.

Message #

Stop open image

Event ID 29: Start flip operation

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
FlipOperation
Opcode
Start

Description

Start flip operation.

Message #

Start flip operation

Event ID 30: Stop flip operation

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
FlipOperation
Opcode
Stop

Description

Stop flip operation.

Message #

Stop flip operation

Event ID 31: Start rotate operation

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
RotateOperation
Opcode
Start

Description

Start rotate operation.

Message #

Start rotate operation

Event ID 32: Stop rotate operation

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
RotateOperation
Opcode
Stop

Description

Stop rotate operation.

Message #

Stop rotate operation

Event ID 33: Start crop operation

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
CropOperation
Opcode
Start

Description

Start crop operation.

Message #

Start crop operation

Event ID 34: Stop crop operation

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
CropOperation
Opcode
Stop

Description

Stop crop operation.

Message #

Stop crop operation

Event ID 35: Start invert color operation

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
InvertColorOperation
Opcode
Start

Description

Start invert color operation.

Message #

Start invert color operation

Event ID 36: Stop invert color operation

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
InvertColorOperation
Opcode
Stop

Description

Stop invert color operation.

Message #

Stop invert color operation

Event ID 37: Start resize skew operation

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
ResizeSkewOperation
Opcode
Start

Description

Start resize skew operation.

Message #

Start resize skew operation

Event ID 38: Stop resize skew operation

#
Provider
Microsoft-Windows-MSPaint
Channel
Diagnostic
Task
ResizeSkewOperation
Opcode
Stop

Description

Stop resize skew operation.

Message #

Stop resize skew operation

Fields #

NameDescription
ResizeskewOperationresult Int32
Widthofthecanvas Int32
Heightofthecanvas Int32
Horizontalresizepercentage Int32
Verticalresizepercentage Int32
Horizontalskewangle Int32
Verticalskewangle Int32

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 1d75856d-36a7-4ecb-a3f5-b13152222d29

Defined in mspaint.exe, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02

Downloads