Microsoft-Windows-NtfsLog_49f3487a1cfe37d6fcac571426eb4005
Event ID 10: NtfsLookupRealAllocation: Vcn A10_Vcn!
#Event ID 11: NtfsAllocateAttribute MaxAlloc for Mft's AttrList IC:A10_IrpContext, Scb:A11_Scb.
#Event ID 12: FileObject: A10_FileObject, Scb: A11_Scb, StaringVcn: A12_StartingVcn!
#Event ID 13: NtfsAddAllocation IC:A10_IrpContext, FileObject:A11_FileObject, Scb:A12_Scb, StaringVcn:A13_StartingVcn!
#Event ID 14: Purge failed: Scb: A10_Scb, PurgeOffset: 0xA11_PurgeOffset!
#Event ID 15: Purge failed: Scb: A10_Scb, PurgeOffset: 0xA11_PurgeOffset!
#Event ID 16: NtfsGetLastVcnForNewMappingPairSize IC:A10_IrpContext, Using LastVcn:A11_*LastVcn!
#Event ID 17: Can't find StdInfo in FileRef A10_NtfsFullFileRefNumber( _Fcb->FileReference )!
#Event ID 18: Can't find StdInfo in FileRef A10_NtfsFullFileRefNumber( _Fcb->FileReference )!
#Event ID 19: NtfsCreateNonresidentWithValue Create Mft's NonResident Attribute List IC:A10_IrpContextValueLength:A11_ValueLength, AttrFlags=A12_AttributeFlags.
#Event ID 20: NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Event ID 21: NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64 | |
A14_Context->FoundAttribute.Attribute->Form.Nonresident.LowestVcn HexInt64 → HexInt64 | |
A15_Context->FoundAttribute.Attribute->Form.Nonresident.HighestVcn HexInt64 → HexInt64 | |
A16_Context->AttributeList.Entry->LowestVcn HexInt64 → HexInt64 |
Event ID 22: NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64 | |
A14_Context->FoundAttribute.Attribute->Form.Nonresident.LowestVcn HexInt64 → HexInt64 | |
A15_Context->FoundAttribute.Attribute->Form.Nonresident.HighestVcn HexInt64 → HexInt64 | |
A16_Context->AttributeList.Entry->LowestVcn HexInt64 → HexInt64 |
Event ID 23: NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64 | |
A14_Context->FoundAttribute.Attribute->Form.Nonresident.LowestVcn HexInt64 → HexInt64 | |
A15_Context->FoundAttribute.Attribute->Form.Nonresident.HighestVcn HexInt64 → HexInt64 | |
A16_Context->AttributeList.Entry->LowestVcn HexInt64 → HexInt64 | |
A17_PassCount HexInt32 → HexInt32 |
Event ID 24: NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64 | |
A14_Context->FoundAttribute.Attribute->Form.Nonresident.LowestVcn HexInt64 → HexInt64 | |
A15_Context->FoundAttribute.Attribute->Form.Nonresident.HighestVcn HexInt64 → HexInt64 | |
A16_Context->AttributeList.Entry->LowestVcn HexInt64 → HexInt64 |
Event ID 25: NtfsAddAttributeAllocation(A10_Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Event ID 26: NtfsRestartRemoveAttribute FileRef:0xA10_FileRecord->SegmentNumberHighPart!
#Event ID 27: NtfsRestartChangeValue FileRef:0xA10_FileRecord->SegmentNumberHighPart!
#Event ID 28: AddToAttributeList(A10_Fcb->Vcb,A11_IrpContext): FRef A12_*(PULONGLONG)_Fcb->FileReference!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Fcb->Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_*(PULONGLONG)_Fcb->FileReference HexInt64 → HexInt64 | |
A13_StdInfoAttrListEntry->Signature HexInt32 → HexInt32 | |
A14_StdInfoAttrListEntry->LastCompactedSize HexInt32 → HexInt32 | |
A15_CurrentAttributeListSize HexInt32 → HexInt32 |
Event ID 29: DeleteFromAttributeList(A10_Fcb->Vcb,A11_IrpContext): FRef A12_*(PULONGLONG)_Fcb->FileReference!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Fcb->Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_*(PULONGLONG)_Fcb->FileReference HexInt64 → HexInt64 | |
A13_StdInfoAttrListEntry->Signature HexInt32 → HexInt32 | |
A14_StdInfoAttrListEntry->LastCompactedSize HexInt32 → HexInt32 | |
A15_NewStdInfoAttrListEntry.LastCompactedSize HexInt32 → HexInt32 |
Event ID 30: MakeRoomForAttribute Moving Mft's attribute IC:A10_IrpContext, Moving Attrib A11_i/A12_MAX_MOVEABLE_ATTRIBUTES, Type=A13_Attribute->TypeCode, RecLengh=A14_Attribute->RecordLength, Instance:A15_Attr...
#Event ID 31: MoveAttributeToOwnRecord Moving Mft's $BITMAP IC:A10_IrpContext, SizeNeeded:A11_SizeNeeded, TypeCode:A12_Attribute->TypeCode, RecLen:A13_Attribute->RecordLength, Form:A14_Attribute->FormCode, Insta...
#Event ID 32: MoveAttributeToOwnRecord IC:A10_IrpContext, SizeNeeded:A11_SizeNeeded, Bytes2Free:A12_BytesToFree, OldMappingSize:A13_MappingPairSize, NewMappingSize:A14_NewMappingPairSize.
#Event ID 33: NtfsRestartZeroEndOfFileRecord FileRef:0xA10_FileRecord->SegmentNumberHighPart!
#Event ID 37: MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Event ID 38: MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Event ID 39: MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Event ID 40: MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Scb->Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64 | |
A14_NtfsMcbArray Pointer → HexInt64 | |
A15_NtfsMcbArray->StartingVcn HexInt64 → HexInt64 | |
A16_NtfsMcbArray->EndingVcn HexInt64 → HexInt64 |
Event ID 41: MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Scb->Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64 | |
A14_NtfsMcbArray Pointer → HexInt64 | |
A15_NtfsMcbArray->StartingVcn HexInt64 → HexInt64 | |
A16_NtfsMcbArray->EndingVcn HexInt64 → HexInt64 |
Event ID 42: MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Scb->Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64 | |
A14_NtfsMcbArray Pointer → HexInt64 | |
A15_NtfsMcbArray->StartingVcn HexInt64 → HexInt64 | |
A16_NtfsMcbArray->EndingVcn HexInt64 → HexInt64 |
Event ID 43: MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Scb->Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64 | |
A14_NtfsMcbArray Pointer → HexInt64 | |
A15_NtfsMcbArray->StartingVcn HexInt64 → HexInt64 | |
A16_NtfsMcbArray->EndingVcn HexInt64 → HexInt64 |
Event ID 44: MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Event ID 45: MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Scb->Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13_*(PULONGLONG)_Scb->Fcb->FileReference HexInt64 → HexInt64 | |
A14_NewStartVcn HexInt64 → HexInt64 | |
A15_LastVcn HexInt64 → HexInt64 | |
A16_NewFinalVcn HexInt64 → HexInt64 | |
A17_NewFinalVcnInMcb HexInt64 → HexInt64 | |
A18_NumberOfRanges HexInt32 → HexInt32 | |
A19_DeletedNextAttribute HexInt32 → HexInt32 | |
A20_Mcb1StartWithNewStartVcn HexInt32 → HexInt32 | |
A21_Mcb1HoldNewStartVcn HexInt32 → HexInt32 | |
A22_Mcb2StartWithNewStartVcn HexInt32 → HexInt32 | |
A23_Mcb2HoldNewStartVcn HexInt32 → HexInt32 | |
A24_McbArraySizeInUseChange Int32 → int |
Event ID 46: MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Event ID 47: MergeFRS2(A10_Scb->Vcb,A11_IrpContext): Scb A12_Scb, FileRef A13_*(PULONGLONG)_Scb->Fcb->FileReference!
#Event ID 50: NtfsConsolidateAllFileRecords: Invalid Vcb.
#Event ID 52: NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_*(PULONGLONG)_Fcb->FileReference!
#Event ID 53: NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_*(PULONGLONG)_Fcb->FileReference!
#Event ID 54: NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_*(PULONGLONG)_Fcb->FileReference!
#Event ID 58: NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_*(PULONGLONG)_Fcb->FileReference!
#Event ID 59: NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_*(PULONGLONG)_Fcb->FileReference!
#Event ID 60: NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): FileRef A12_*(PULONGLONG)_FrsConsolidationContext->FileReference!
#Event ID 61: NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_*(PULONGLONG)_Fcb->FileReference!
#Event ID 62: NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_*(PULONGLONG)_Fcb->FileReference!
#Event ID 63: NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_FileRef!
#Event ID 64: NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): Fcb A12_Fcb, FileRef A13_FileRef!
#Event ID 65: NtfsConsolidateAllFileRecords(A10_Vcb,A11_IrpContext): DeltaTime A12_(EndTime.QuadPart*1000)/NtfsPerformanceFrequency.QuadPart!
#Event ID 66: UpdateLCS: Vcb A10_Fcb->Vcb, IC A11_IrpContext, FRef A12_*(PULONGLONG)_Fcb->FileReference!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Fcb->Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_*(PULONGLONG)_Fcb->FileReference HexInt64 → HexInt64 | |
A13_StdInfoAttrListEntry->Signature HexInt32 → HexInt32 | |
A14_StdInfoAttrListEntry->LastCompactedSize HexInt32 → HexInt32 | |
A15_AttributeListSize HexInt32 → HexInt32 |
Event ID 67: NtfsAllocateClustersPriv IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: A13__Scb->Mcb, Vcn: 0xA14_OriginalStartingVcn!
#Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer → HexInt64 | |
A11_Vcb Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13__Scb->Mcb Pointer → HexInt64 | |
A14_OriginalStartingVcn HexInt64 → HexInt64 | |
A15_ClusterCount HexInt64 → HexInt64 | |
A16_AllocateAll UInt32 → unsignedInt | |
A17_(TargetLcn != NULL) ? *TargetLcn : (ULONGLONG)-1 HexInt64 → HexInt64 | |
A18_PreAllocated UInt32 → unsignedInt | |
A19_UseDelayedAllocation UInt32 → unsignedInt |
Event ID 68: NtfsAllocateClustersPriv IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: A13__Scb->Mcb, Vcn: 0xA14_OriginalStartingVcn!
#Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer → HexInt64 | |
A11_Vcb Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13__Scb->Mcb Pointer → HexInt64 | |
A14_OriginalStartingVcn HexInt64 → HexInt64 | |
A15_ClusterCount HexInt64 → HexInt64 | |
A16_AllocateAll UInt32 → unsignedInt | |
A17_(TargetLcn != NULL) ? *TargetLcn : (ULONGLONG)-1 HexInt64 → HexInt64 | |
A18_PreAllocated UInt32 → unsignedInt | |
A19_UseDelayedAllocation UInt32 → unsignedInt |
Event ID 69: NtfsAllocateClustersPriv: Incremented TotalAllocated by 0xA10_FoundClusterCount!
#Event ID 70: NtfsAllocateClustersPriv: Skipped incrementing TotalAllocated by 0xA10_FoundClusterCount!
#Event ID 71: NtfsAllocateClustersPriv IC: A10_IrpContext, ClustersAllocated: A11_ClustersAllocated.
#Event ID 72: NtfsAllocateClustersPriv IC: A10_IrpContext, ClustersAllocated: A11_ClustersAllocated.
#Event ID 73: NtfsDeallocateClusters IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: A13__Scb->Mcb, StartVcn: 0xA14_StartingVcn!
#Event ID 74: NtfsDeallocateClusters: Vcb A10_Vcb - deleting FR A11_*(PULONGLONG)_Scb->Fcb->FileReference!
#Event ID 75: NtfsDeallocateClusters IC: A10_IrpContext, Vcb: A11_Vcb, Scb: A12_Scb, Mcb: A13__Scb->Mcb, StartVcn: 0xA14_StartingVcn!
#Event ID 76: NtfsDeallocateClusters: Vcb A10_Vcb - deleting FR A11_*(PULONGLONG)_Scb->Fcb->FileReference!
#Event ID 77: NtfsDeallocateClusters: Vcb A10_Vcb - raising logfile full.
#Event ID 78: NtfsDeallocateClusters: Vcb A10_Vcb - adding clusters to DeallocatedClusters: A11_DeallocatedClusters ==> Lsn: A12_DeallocatedClusters->Lsn.QuadPart!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_DeallocatedClusters Pointer → HexInt64 | |
A12_DeallocatedClusters->Lsn.QuadPart HexInt64 → HexInt64 | |
A13_DeallocatedClusters->ClusterCount HexInt64 → HexInt64 | |
A14_DeallocatedClusters->Flags HexInt32 → HexInt32 | |
A15_Vcb->DeallocatedClusters HexInt64 → HexInt64 | |
A16_Vcb->DeallocatedClusters + AdjClusterCount HexInt64 → HexInt64 |
Event ID 79: NtfsDeallocateClusters: Decremented TotalAllocated by 0xA10_ClusterCount!
#Event ID 80: NtfsDeallocateClusters: Skipped decrementing TotalAllocated by 0xA10_ClusterCount!
#Event ID 81: NtfsDeallocateClusters: Vcb A10_Vcb - Undoing some changes to DeallocatedClustersCount from A11_Vcb->DeallocatedClusters!
#Event ID 82: NtfsDeallocateClusters IC: A10_IrpContext, ClustersDeallocated: A11_ClustersDeallocated.
#Event ID 83: NtfsDeallocateClusters IC: A10_IrpContext, ClustersDeallocated: A11_ClustersDeallocated.
#Event ID 84: NtfsModifyBitsInBitmap IC: A10_IrpContext, Vcb: A11_Vcb, FirstBit: 0xA12_FirstBit!
#Event ID 85: NtfsModifyBitsInBitmap IC: A10_IrpContext, Bitmap: A11__Bitmap, BaseLcn: 0xA12_BaseLcn!
#Event ID 86: NtfsAllocateBitmapRun IC: A10_IrpContext, Vcb: A11_Vcb, StartingLcn: 0xA12_StartingLcn!
#Event ID 87: NtfsAllocateBitmapRun IC: A10_IrpContext, Bitmap: A11__Bitmap, BaseLcn: 0xA12_BaseLcn!
#Event ID 88: NtfsRestartSetBitsInBitMap IC: A10_IrpContext, Bitmap: A11_Bitmap, BitMapOffset: 0xA12_BitMapOffset!
#Event ID 89: NtfsFreeBitmapRun IC: A10_IrpContext, Vcb: A11_Vcb, StartingLcn: 0xA12_StartingLcn!
#Event ID 90: NtfsFreeBitmapRun IC: A10_IrpContext, Bitmap: A11__Bitmap, BaseLcn: 0xA12_BaseLcn!
#Event ID 91: NtfsRestartClearBitsInBitMap IC: A10_IrpContext, Bitmap: A11_Bitmap, BitMapOffset: 0xA12_BitMapOffset!
#Event ID 92: NtfsSetOrClearBitsUsingBaseMcb IC: A10_IrpContext, Vcb: A11_Vcb, Bitmap: A12_Bitmap, StartingBitmapLcn: 0xA13_StartingBitmapLcn!
#Event ID 93: NtfsSetOrClearBitsUsingBaseMcb IC: A10_IrpContext, Bitmap: A11_Bitmap, StartLcn: 0xA12_StartingBit!
#Event ID 94: NtfsSetOrClearBitsUsingBaseMcb IC: A10_IrpContext, Result: A11_Results.
#Event ID 95: System files not marked as in use in the MFT bitmap.
#Event ID 97: Length: A10_Length!
#Event ID 98: Length: A10_Length!
#Event ID 99: BinIndex: A10_BinIndex!
#Event ID 100: BinIndex: A10_BinIndex!
#Event ID 101: BinGroupShift: A10_NtfsCachedRunBinGroupShift!
#Event ID 102: BinIndex: A10_BinIndex!
#Event ID 103: Searched committed allocations but didnt find enough free space.
#Event ID 104: NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): first bit 0xA11_FirstBitToClear, last bit 0xA12_BeyondLastBitToClear - 1.
#Event ID 105: NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): no leading partial slab.
#Event ID 106: NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): leading partial slab returned - LCN A11_*FreeClusterBase1!
#Event ID 107: NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): no trailing partial slab.
#Event ID 108: NtfsRemoveClustersFromTPMap: Vcb A10_Vcb - Clearing TP map bit(s): trailing partial slab returned - lcn A11_*FreeClusterBase2!
#Event ID 109: NtfsValidateTotalClustersCommitted(A10_Vcb,A11_PsGetCurrentThread()): TCC A12_Vcb->TotalClustersCommitted!
#Event ID 110: Illegal MDL Complete for major code A10_IrpContext->MajorFunction.
#Event ID 111: Entering: Scb: A10_Scb, StartingZero: 0xA11_StartingZero!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer → HexInt64 | |
A11_StartingZero HexInt64 → HexInt64 | |
A12_ByteCount HexInt64 → HexInt64 | |
A13_ExtentsDescriptor Pointer → HexInt64 | |
A14_*ExtentsDescriptorIndex Int32 → int | |
A15_*ExtentsDescriptorStartOffset HexInt64 → HexInt64 | |
A16_Offset HexInt64 → HexInt64 | |
A17_MaxRuns Int32 → int |
Event ID 112: RunEntry ==> A10_RunIndex!
#Event ID 113: Offset is beyond this extent skipping the extent.
#Event ID 114: Shrinking LengthInExtent.
#Event ID 115: Zeroing: StartingPhysicalAddr: 0xA10_StartingPhysicalAddr.QuadPart!
#Event ID 116: Exiting: ExtentsDescriptorIndex: A10_*ExtentsDescriptorIndex ExtentsDescriptorStartOffset: 0xA11_*ExtentsDescriptorStartOffset!
#Event ID 117: Entering: Scb: A10_Scb, StartingZero: 0xA11_StartingOffset!
#Event ID 118: Dsm Ranges[A10_DataSetRangeIndex]: StartingOffset: 0xA11_DsmBuffer->DataSetRanges[DataSetRangeIndex].StartingOffset!
#Event ID 119: RemainingClusterCount: 0xA10_RemainingClusterCount!
#Event ID 120: Dsm: TotalNumberOfRanges: A10_DsmByteAddressRanges->TotalNumberOfRanges, NumberOfRangesReturned: A11_DsmByteAddressRanges->NumberOfRangesReturned.
#Event ID 121: DsmOut Ranges[A10_Index]: StartingAddress: 0xA11_DsmByteAddressRanges->Ranges[Index].StartAddress!
#Event ID 122: Zeroing: StartingPhysicalAddr: 0xA10_StartingPhysicalAddr.QuadPart!
#Event ID 123: Updating ExtentsDescriptor Index and StartOffset from Locals: ExtentsDescriptorIndex: A10_*ExtentsDescriptorIndex, ExtentsDescriptorStartOffset: 0xA11_*ExtentsDescriptorStartOffset!
#Event ID 124: Entering: Scb: A10_Scb, StartingZero: 0xA11_StartingZero!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer → HexInt64 | |
A11_StartingZero HexInt64 → HexInt64 | |
A12_BeyondEndOffset HexInt64 → HexInt64 | |
A13_ByteCount HexInt64 → HexInt64 | |
A14_ExtentsDescriptor Pointer → HexInt64 | |
A15_ExtentsDescriptorIndex ? *ExtentsDescriptorIndex : 0 Int32 → int | |
A16_ExtentsDescriptorStartOffset ? *ExtentsDescriptorStartOffset : 0 HexInt64 → HexInt64 |
Event ID 125: Updating ExtentsDescriptor Index and StartOffset from Locals: ExtentsDescriptorIndex: A10_*ExtentsDescriptorIndex, ExtentsDescriptorStartOffset: 0xA11_*ExtentsDescriptorStartOffset!
#Event ID 126: IrpContext: A10_IrpContext; Scb: A11_Scb; StartOffset: 0xA12_StartOffset!
#Event ID 128: Unexpected open type received: A10_TypeOfOpen.
#Event ID 129: Raising STATUS_SUCCESS from NtfsCommonCleanup: A10_Status.
#Event ID 130: Raising STATUS_SUCCESS from NtfsCommonCleanup: 0xA10_Status.
#Event ID 131: Raising STATUS_SUCCESS from NtfsCommonCleanup: 0xA10_Status.
#Event ID 132: Irp: %1, IC: %2, Vcb: %3, FileObject: %4, RelatedFileObject: %5, FileIdBuffer: %6, Options: 0x%7!
#Message #
Event ID 133: Irp: %1, IC: %2, Vcb: %3, FileObject: %4, RelatedFileObject: %5, Path: %6, Options: 0x%7!
#Message #
Event ID 135: NtfsCommonVolumeOpen: Invalid create disposition for volume open.
#Event ID 137: NtfsCommonVolumeOpen: Thread: %1, Vcb: %2, VolumeName: %3, VolumeLabel: %4, Requested ShareAccess: 0x%5!
#Message #
Event ID 140: NtfsHandlePagingFile: Paging file already open, paging files can only be opened once.
#Message #
Event ID 146: NtfsOpenFile: Unsafe to acquire parent directory after acquiring a txf-system file.
#Message #
Event ID 153: NtfsOpenAttributeInExistingFile: Denying access due to caller being Ea blind.
#Message #
Event ID 160: NtfsCheckValidAttributeAccess: Supersede or overwrite is not allowed on this type of named attribute.
#Message #
Event ID 161: NtfsCheckValidAttributeAccess: Only read attributes access is supported on this attribute.
#Message #
Event ID 162: NtfsCheckValidAttributeAccess: Deny access for protected system attributes.
#Event ID 164: NtfsOpenAttributeCheck: Deny access for online encryption backup data stream.
#Message #
Event ID 165: NtfsOpenAttributeCheck: File was granted write access but has image section.
#Message #
Event ID 173: NtfsOpenExistingEncryptedStream: Opening for read/write access not allowed on compressed file.
#Message #
Event ID 174: NtfsEncryptionCreateCallback: Encrytion engine fail to encrypt all streams for file with open handle.
#Message #
Event ID 175: NtfsFindStartingNode: Opening not allowed for txf name when RM is active.
#Event ID 184: NtfsSendUnusedClustersHint: Vcb A10_Vcb - Will tell storage we are freeing at A11_StartingCluster!
#Event ID 185: NtfsSendUnusedClustersHint: Vcb A10_Vcb - Flush requested.
#Event ID 186: NtfsSendUnusedClustersHint: Vcb A10_Vcb - Created new MarkUnusedContext A11_*MarkUnusedContext, DEALLOCATED_CLUSTERS A12_(*MarkUnusedContext)->DeallocatedClusters, MCB A13__(*MarkUnusedContext)->De...
#Event ID 187: NtfsSendUnusedClustersHint: Vcb A10_Vcb - Successfully added clusters starting at A11_StartingCluster!
#Event ID 188: NtfsSendUnusedClustersHint: Vcb A10_Vcb - MCB A11__(*MarkUnusedContext)->DeallocatedClusters->Mcb is full.
#Event ID 189: NtfsSendUnusedClustersHint: Vcb A10_Vcb - Queuing request to IC pre-trim list, MUC A11_*MarkUnusedContext, IC A12_IrpContext.
#Event ID 190: NtfsSendUnusedClustersHint: Vcb A10_Vcb - Failed to allocate/initial MarkUnusedContext.
#Event ID 191: NtfsTransferMaxDataSetRanges: Src A10_Src, Dst A11_Dst, SrcRemainClusCt A12_Src->ClustersCount!
#Event ID 192: NtfsTransferMaxDataSetRanges: Src A10_Src, Dst A11_Dst, SrcRemainClusCt A12_Src->ClustersCount!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Src Pointer → HexInt64 | |
A11_Dst Pointer → HexInt64 | |
A12_Src->ClustersCount HexInt64 → HexInt64 | |
A13_Dst->ClustersCount HexInt64 → HexInt64 | |
A14_DstDsmAttr->DataSetRangesLength HexInt32 → HexInt32 | |
A15_DstFirstDataSetRangePtr->LengthInBytes HexInt64 → HexInt64 | |
A16_DstFirstDataSetRangePtr->StartingOffset HexInt64 → HexInt64 |
Event ID 193: NtfsMarkUnusedContextPostTrimProcessing: Entering.
#Event ID 194: NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext - DC A12_Vcb->DeallocatedClusters!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_MarkUnusedContext Pointer → HexInt64 | |
A12_Vcb->DeallocatedClusters HexInt64 → HexInt64 | |
A13_Vcb->DeallocatedClustersListLengthInTrim HexInt32 → HexInt32 | |
A14_Vcb->DeallocatedClustersListLengthToDrain HexInt32 → HexInt32 | |
A15_Clusters->ClusterCount HexInt64 → HexInt64 | |
A16_InitialRanges HexInt32 → HexInt32 |
Event ID 195: NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext - Removed interior slab(s) from TP map - [LCN A12_StartingLcn!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_MarkUnusedContext Pointer → HexInt64 | |
A12_StartingLcn HexInt64 → HexInt64 | |
A13_ClusterCount HexInt64 → HexInt64 | |
A14_FreeClusterBase1 HexInt64 → HexInt64 | |
A15_FreeClusterCount1 HexInt64 → HexInt64 | |
A16_FreeClusterBase2 HexInt64 → HexInt64 | |
A17_FreeClusterCount2 HexInt64 → HexInt64 |
Event ID 196: NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb - Releasing bitmap.
#Event ID 197: NtfsMarkUnusedContextPostTrimProcessing: Vcb A10_Vcb - CloseCount A11_Vcb->CloseCount.
#Event ID 198: NtfsMarkUnusedContextPostTrimProcessing: Leaving.
#Event ID 199: NtfsAsyncSendUnusedClustersHintCompletionRoutine: Irp A10_Irp.
#Event ID 200: NtfsMarkUnusedContextPreTrimProcessing: Vcb A10_Vcb, IC A11_IrpContext - Entering.
#Event ID 201: NtfsMarkUnusedContextPreTrimProcessing: Vcb A10_Vcb - Kicked off DelayedWorkQueue.
#Event ID 202: NtfsMarkUnusedContextPreTrimProcessing: Vcb A10_Vcb - Leaving.
#Event ID 203: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Entering Vcb A10_Vcb.
#Event ID 204: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Small MUC A11_SmallMarkUnusedContext instead of MUC A12_MarkUnusedContext.
#Event ID 205: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Failed to allocate small MUC so use MUC A11_MarkUnusedContext.
#Event ID 206: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Sending storage ioctl down.
#Event ID 207: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext - [A12_TrimEntryCount++] Offset A13_DataSetRangePtr->StartingOffset!
#Event ID 208: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb, MUC A11_MarkUnusedContext, Irp A12_IrpUsed - Completed.
#Event ID 210: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Add MUC A11_MarkUnusedContext to post trim list.
#Event ID 211: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Free small MUC A11_MarkUnusedContext.
#Event ID 212: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Vcb A10_Vcb - Sending storage ioctl down failed with A11_Status.
#Event ID 213: NtfsMarkUnusedContextPreTrimWorkItemProcessing: Leaving.
#Event ID 214: NtfsWakeupDeallocatedClustersWaiters: Vcb A10_Vcb - There are waiters for DC A11_DeallocatedClusters.
#Event ID 215: NtfsWakeupDeallocatedClustersWaiters: Vcb A10_Vcb - Waking up waiter for DC A11_DeallocatedClusters.
#Event ID 216: NtfsWakeupDeallocatedClustersWaiters: Vcb A10_Vcb - Done waking up DC A11_DeallocatedClusters.
#Event ID 217: NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb, All A11_All - Entering.
#Event ID 218: NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Waiting to drain.
#Event ID 219: NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Waiting for partial drain.
#Event ID 220: NtfsWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Leaving.
#Event ID 221: NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Entering.
#Event ID 222: NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Inserted A11_DeallocatedClustersToWaitFor->DeallocatedClusters.
#Event ID 223: NtfsPrepareToWaitForDeallocatedClustersToDrain: Vcb A10_Vcb - Leaving.
#Event ID 224: NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Vcb A10_IrpContext->Vcb - Wait for DC A11_DeallocatedClustersToWaitFor->DeallocatedClusters.
#Event ID 225: NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Waited for A10_WaitInSeconds (s), Exceeded by A11_((CurrentTime.QuadPart > DeallocatedClustersToWaitFor->EndTime.QuadPart) ? ...
#Message #
Fields #
| Name | Description |
|---|---|
A10_WaitInSeconds Int32 → int | |
A11_((CurrentTime.QuadPart > DeallocatedClustersToWaitFor->EndTime.QuadPart) ? (ULONG)(((CurrentTime.QuadPart - DeallocatedClustersToWaitFor->EndTime.QuadPart) * NtfsData.SystemTimeIncrement)/INTERVAL_ONE_SECOND) : 0) Int32 → int | |
A12_IrpContext Pointer → HexInt64 | |
A13_IrpContext->Vcb Pointer → HexInt64 | |
A14_DeallocatedClusters Pointer → HexInt64 |
Event ID 226: NtfsWaitForDeallocatedClustersToDrainAfterPrepare: Waited for A10_WaitInSeconds (s), Exceeded by A11_((CurrentTime.QuadPart > DeallocatedClustersToWaitFor->EndTime.QuadPart) ? ...
#Message #
Fields #
| Name | Description |
|---|---|
A10_WaitInSeconds Int32 → int | |
A11_((CurrentTime.QuadPart > DeallocatedClustersToWaitFor->EndTime.QuadPart) ? (ULONG)(((CurrentTime.QuadPart - DeallocatedClustersToWaitFor->EndTime.QuadPart) * NtfsData.SystemTimeIncrement)/INTERVAL_ONE_SECOND) : 0) Int32 → int | |
A12_IrpContext Pointer → HexInt64 | |
A13_IrpContext->Vcb Pointer → HexInt64 | |
A14_DeallocatedClusters Pointer → HexInt64 |
Event ID 227: NtfsCheckForTrimThrottling: Vcb A10_Vcb - hitting trim threshold A11_Vcb->DeallocatedClustersListLengthInTrim.
#Event ID 228: NtfsUpdateSmartTrimState: Vcb A10_Vcb - Entering.
#Event ID 229: NtfsUpdateSmartTrimState: Vcb A10_Vcb - Precondition checks failed.
#Event ID 230: NtfsUpdateSmartTrimState: Vcb A10_Vcb - Precondition checks failed; AcquiredSyncResource A11_AcquiredVcb.
#Event ID 231: NtfsUpdateSmartTrimState: Vcb A10_Vcb, MUC A11_MarkUnusedContext - Skipping deallocated clusters gen'd by smart trim.
#Event ID 232: NtfsUpdateSmartTrimState: Vcb A10_Vcb, MUC A11_MarkUnusedContext - MCB run A12_RunIndex; offs 0xA13_StartingOffset!
#Event ID 233: NtfsUpdateSmartTrimState: Vcb A10_Vcb - MUC A11_MarkUnusedContext, DSR count A12_DataSetRangeCount, MCB count A13_McbRunCount, ST free slots A14_SmartTrimFreeRangeCount.
#Event ID 234: NtfsUpdateSmartTrimState: Vcb A10_Vcb, MUC A11_MarkUnusedContext - DSR range A12_RunIndex; offs 0xA13_DataSetRange->StartingOffset!
#Event ID 235: NtfsUpdateSmartTrimState: Vcb A10_Vcb - MCB lcn A11_StartingLcn!
#Event ID 236: NtfsUpdateSmartTrimState: Vcb A10_Vcb - Smart trim state on exit; A11_SmartTrimState->SlabRangesCount ranges.
#Event ID 237: NtfsUpdateSmartTrimState: Vcb A10_Vcb - Range A11_SlabRangeIndex: FirstTPMapBit 0xA12_SlabRange->FirstTPMapBit, LastTPMapBit 0xA13_SlabRange->LastTPMapBit.
#Event ID 238: NtfsUpdateSmartTrimState: Vcb A10_Vcb - Leaving.
#Event ID 239: NtfsEvalSmartTrimState: Vcb A10_Vcb - Entering.
#Event ID 240: NtfsEvalSmartTrimState: Vcb A10_Vcb - Precondition checks failed.
#Event ID 241: NtfsEvalSmartTrimState: Vcb A10_Vcb - Precondition checks failed; AcquiredBitmap A11_AcquiredBitmap.
#Event ID 242: NtfsEvalSmartTrimState: Vcb A10_Vcb - Checking slab 0xA11_TpMapBit for allocations.
#Event ID 243: NtfsEvalSmartTrimState: Vcb A10_Vcb - Slab 0xA11_TpMapBit has allocations, will not trim.
#Event ID 244: NtfsEvalSmartTrimState: Vcb A10_Vcb - Free slab found - TP map bit 0xA11_TpMapBit, lcn A12_SlabBaseLcn!
#Event ID 245: NtfsEvalSmartTrimState: Vcb A10_Vcb - Leaving.
#Event ID 246: NtfsCommonDeviceControl: IOCTL_DISK_COPY_DATA is not allowed on unlocked volume.
#Message #
Event ID 248: Could not find paging file run.
#Event ID 249: Could not find paging file MCB entry.
#Event ID 250: Could not find paging file run.
#Event ID 251: Writing to $Bitmap.
#Event ID 252: NTFS: Posting hotfix on file object: A10_FileObject.
#Event ID 253: NTFS: Freeing Bad Vcn: A10_((ULONG)BadVcn)!
#Event ID 254: NTFS: Retiring Bad Lcn: A10_((ULONG)BadLcn)!
#Event ID 257: IrpContext: A10_IrpContext; Vcb: A11_Vcb; NewBufferSize: 0xA12_NewBufferSize!
#Event ID 258: Compression buffers are already big enough.
#Event ID 260: IrpContext: A10_IrpContext; Vcb: A11_Vcb; NewBufferSize: 0xA12_NewBufferSize!
#Event ID 261: Compression buffers are already big enough.
#Event ID 264: NtfsDefragFileInternal: Vcb A10_Vcb - Calling FRD.
#Event ID 265: NtfsDefragFileInternal: Vcb A10_Vcb - Done calling FRD.
#Event ID 267: NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference )!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference ) HexInt64 → HexInt64 | |
A14_MoveData->StartingVcn.QuadPart HexInt64 → HexInt64 | |
A15_TransferClusters HexInt64 → HexInt64 | |
A16_Lcn HexInt64 → HexInt64 | |
A17_MoveData->StartingLcn.QuadPart HexInt64 → HexInt64 | |
A18_CopyLength HexInt32 → HexInt32 | |
A19_Flags.UseDelayedAllocation Int32 → int | |
A20_Status HexInt32 → HexInt32 |
Event ID 268: NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference )!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference ) HexInt64 → HexInt64 | |
A14_MoveData->StartingVcn.QuadPart HexInt64 → HexInt64 | |
A15_TransferClusters HexInt64 → HexInt64 | |
A16_Lcn HexInt64 → HexInt64 | |
A17_MoveData->StartingLcn.QuadPart HexInt64 → HexInt64 | |
A18_CopyLength HexInt32 → HexInt32 | |
A19_Flags.UseDelayedAllocation Int32 → int | |
A20_MyStatus HexInt32 → HexInt32 |
Event ID 269: NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference )!
#Event ID 270: NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference )!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference ) HexInt64 → HexInt64 | |
A14_MoveData->StartingLcn.QuadPart HexInt64 → HexInt64 | |
A15_CopyLength HexInt32 → HexInt32 | |
A16_MyStatus HexInt32 → HexInt32 |
Event ID 271: NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference )!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_Scb Pointer → HexInt64 | |
A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference ) HexInt64 → HexInt64 | |
A14_MoveData->StartingVcn.QuadPart HexInt64 → HexInt64 | |
A15_TransferClusters HexInt64 → HexInt64 | |
A16_Lcn HexInt64 → HexInt64 | |
A17_MoveData->StartingLcn.QuadPart HexInt64 → HexInt64 | |
A18_Flags.UseDelayedAllocation Int32 → int | |
A19_ValidClusters HexInt64 → HexInt64 |
Event ID 272: NtfsDefragFileInternal(A10_Vcb,A11_IrpContext): Scb A12_Scb, FRef A13_NtfsFullFileRefNumber( _Scb->Fcb->FileReference )!
#Event ID 275: NtfsEncryptDecryptOnline: Vcb A10_Vcb - Calling FRD.
#Event ID 276: NtfsEncryptDecryptOnline: Vcb A10_Vcb - Done calling FRD.
#Event ID 278: SCB: A10_Scb, VDL=0xA11_Scb->Header.ValidDataLength.QuadPart!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer → HexInt64 | |
A11_Scb->Header.ValidDataLength.QuadPart HexInt64 → HexInt64 | |
A12_Scb->Header.FileSize.QuadPart HexInt64 → HexInt64 | |
A13_QueryDaxExtents->FileOffset HexInt64 → HexInt64 | |
A14_StartingVcn HexInt64 → HexInt64 | |
A15_QueryDaxExtents->Length HexInt64 → HexInt64 |
Event ID 279: StartOff=0xA10_QueryDaxExtents->FileOffset!
#Message #
Fields #
| Name | Description |
|---|---|
A10_QueryDaxExtents->FileOffset HexInt64 → HexInt64 | |
A11_QueryDaxExtents->Length HexInt64 → HexInt64 | |
A12_EffectiveInputFileRegionLength HexInt64 → HexInt64 | |
A13_StartingVcn HexInt64 → HexInt64 | |
A14_BeyondEndVcn HexInt64 → HexInt64 | |
A15_RemainingClusterCount HexInt64 → HexInt64 | |
A16_LastVcnInFile HexInt64 → HexInt64 |
Event ID 280: NumberOfValidRuns: 0.
#Event ID 281: RemainingClusterCount: 0xA10_RemainingClusterCount!
#Event ID 282: STATUS_BUFFER_TOO_SMALL from FsLib.
#Event ID 283: Made an educated guess for remaining runs.
#Event ID 284: Made a wild guess for remaining runs.
#Event ID 285: NumberOfValidRuns: 0xA10_ExtentsDescriptor->NumberOfValidRuns!
#Event ID 286: BasePage: 0xA10_ExtentsDescriptor->Run[Index].BasePage!
#Event ID 287: About to zero range - ZeroStart: 0xA10_ZeroStart!
#Event ID 288: Zeroed range - ZeroStart: 0xA10_ZeroStart!
#Event ID 289: NtfsCommonQueryInformation: File information query not allowed as file was opened by ID without traversal privilege.
#Message #
Event ID 290: NtfsQueryCaseSensitiveInfo: Case sensitive info query not allowed without read attributes access.
#Message #
Event ID 291: NtfsQueryNameInfo: Name info query not allowed as file was opened without traverse privilege.
#Message #
Event ID 292: NtfsQueryLinksInfo: Link info query not allowed as file was opened without traverse privilege.
#Message #
Event ID 293: NtfsSetCaseSensitiveInfo: Cannot mark root directory of a volume case-sensitive.
#Message #
Event ID 294: NtfsRemoveSupersededTarget: Can not do a superseding rename over a system file.
#Message #
Event ID 295: NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles.
#Message #
Event ID 296: NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles.
#Message #
Event ID 297: NtfsRemoveSupersededTarget: Can not do a superseding rename over a file opened by ID.
#Message #
Event ID 298: NtfsRemoveSupersededTarget: Can not do a superseding rename over a file with open handles via either part of the long/short pair.
#Message #
Event ID 303: NtfsSetRenameInfo: The file should not have in-memory directory descendents.
#Message #
Event ID 306: NtfsSetLinkInfo: Set link info is not allowed on a file in a TxF transaction.
#Message #
Event ID 311: NtfsSetShortNameInfo: Can not set a short name on a file under the $TxF directory.
#Message #
Event ID 312: NtfsCheckScbForLinkRemoval: Existing handles are not allowed if Txf transaction is doing the rename.
#Message #
Event ID 313: NtfsCheckScbForLinkRemoval: Not all open handles for the stream are by-id opens.
#Message #
Event ID 315: NtfsProcessTreeForRename: Deny access due to number of batch oplocks has grown.
#Message #
Event ID 316: NtfsFlushVolumeFlushSingleFcb: Thread: A10_PsGetCurrentThread(), Vcb: A11_Vcb, Fcb: A12_Fcb, LocalFlags: A13_LocalFlags->EntireFlags!
#Event ID 317: NtfsFlushVolumeFlushSingleFcb: Thread: A10_PsGetCurrentThread(), Scb: A11_Scb.
#Event ID 318: NtfsFlushVolume: Thread: A10_PsGetCurrentThread(), Vcb: A11_Vcb, LocalFlags: A12_LocalFlags.EntireFlags!
#Event ID 319: NtfsFlushVolume setting SCB_PERSIST_VOLUME_DISMOUNTED on BitmapScb Scb: A10_Vcb->BitmapScb Vcb: A11_Vcb.
#Event ID 320: NtfsFlushVolume setting SCB_PERSIST_VOLUME_DISMOUNTED on MftScb Scb: A10_Vcb->MftScb Vcb: A11_Vcb.
#Event ID 321: NtfsFlushCompletionRoutine: Vcb A10_((PNTFS_DISK_FLUSH_CONTEXT)Context)->Vcb - Add context A11_Context into completion queue.
#Event ID 322: NtfsFlushCompletionRoutine: Vcb A10_((PNTFS_DISK_FLUSH_CONTEXT)Context)->Vcb - Add context A11_Context into WorkQueue - Flink A12_NtfsData.DiskFlushContextCompletedWorkItem.List.Flink.
#Event ID 323: NtfsDiskFlushContextWorkItemProcessing: Process work item.
#Event ID 324: NtfsDiskFlushContextWorkItemProcessing: Nothing to work on.
#Event ID 325: Irp: A10_Irp, IC: A11_IrpContext, Vcb: A12_IrpContext->Vcb, MinorCode: A13_IrpSp->MinorFunction!
#Event ID 331: NtfsLockVolume: Cannot lock volume due to caller does not have manage volume privilege.
#Message #
Event ID 332: NtfsLockVolume: Cannot lock volume due to active secondary RMs on the volume.
#Message #
Event ID 333: A10___FUNCTION__: Setting RM at 0xA11_(PVOID)Vcb->TxfVcb.DefaultRm ({A12_(Vcb->TxfVcb.DefaultRm != NULL) ? _Vcb->TxfVcb.DefaultRm->RmId : ...
#Event ID 334: NtfsUnlockVolume: Cannot unlock volume due to caller does not have manage volume privilege.
#Message #
Event ID 336: NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open for write access.
#Message #
Event ID 338: NtfsDismountVolume: Cannot dismount volume due to system/pagefiles being open for write access.
#Message #
Event ID 339: NtfsMarkVolumeDirty: Cannot mark volume dirty due to caller not having manage volume privilege.
#Message #
Event ID 340: NtfsGetVolumeBitmap: Cannot get volume bitmap due to caller not having manage volume privilege.
#Message #
Event ID 341: NtfsGetBootAreaInfo: Cannot get boot area info due to caller not having manage volume privilege.
#Message #
Event ID 342: NtfsGetRetrievalPointers: Cannot get retrieval pointers due to caller not having manage volume privilege.
#Message #
Event ID 343: NtfsGetRetrievalPointerBase: Cannot get revrieval pointer base info due to caller not having manage volume privilege.
#Message #
Event ID 344: NtfsGetRetrievalPointerBase: Cannot get revrieval pointer base info due to caller not having manage volume privilege or this is not a volume open.
#Message #
Event ID 345: NtfsCreateUsnJournal: Cannot create Usn journal due to caller not having manage volume privilege.
#Message #
Event ID 346: NtfsUsnTrackModifiedRanges: Cannot enable range tracking due to caller not having manage volume privilege.
#Message #
Event ID 347: NtfsEnumerateUsnData: Cannot enumerate Usn data due to caller not having manage volume privilege.
#Message #
Event ID 348: NtfsFindFilesOwnedBySid: Caller not having manage volume privilege, backup access or can bypass traverse checks.
#Message #
Event ID 349: NtfsFindFilesOwnedBySid: Caller not having manage volume privilege or backup access and is not admin.
#Message #
Event ID 352: NtfsZeroRange: User mode caller not allowed.
#Event ID 353: IC: A10_IrpContext, Scb: A11_Scb, FileObject: A12_IrpSp->FileObject.
#Event ID 354: IC: A10_IrpContext, EncryptionOperation: 0xA11_EncryptionOperation!
#Event ID 355: NtfsReadRawEncrypted: Caller does not have backup access or read data access.
#Message #
Event ID 360: NtfsChangeVolumeSize (A10_Vcb): Calling NtfsFreeRecentlyDeallocated.
#Event ID 361: NtfsChangeVolumeSize (A10_Vcb): Done calling NtfsFreeRecentlyDeallocated.
#Event ID 362: NtfsMarkHandle: Caller does not have a valid volume handle or manage volume access or is not kernel model caller.
#Message #
Event ID 369: NtfsMarkHandle: File was granted write access previously but no oplocks were broken.
#Message #
Event ID 371: NtfsSetZeroOnDeallocate: Only allowed on regular user files opened for write.
#Message #
Event ID 373: Setting VCB_EXT_CHAR_STATE_ALLOW_EXT_CHAR for volume 0xA10_(PVOID)Vcb to A11_InputParameter.
#Event ID 377: NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege.
#Message #
Event ID 378: Resetting Volsnap behavior for VCB = 0xA10_Vcb.
#Event ID 379: NtfsResetVolsnapBehaviorForVolume: Caller not having manage volume privilege.
#Message #
Event ID 382: Scrub resume from SystemScbIndex: A10_ScrubResumeContext.SystemScbIndex Vcn: A11_ScrubResumeContext.ResumeVcn!
#Event ID 383: Scb:A10_Scb Scrub resume from Vcn: A11_ScrubResumeContext.ResumeVcn!
#Event ID 384: Scrub SystemScbIndex: A10_ScrubResumeContext.SystemScbIndex.
#Event ID 386: Scrub not supported for Txf file, Scb: A10_Scb, TxfScb: A11_Scb->TxfScb.
#Event ID 388: Scb:A10_Scb ScrubInternal OperationStatus: A11_ScrubContext.OperationStatus Repaired: A12_ScrubContext.NumberOfBytesRepaired!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer → HexInt64 | |
A11_ScrubContext.OperationStatus HexInt32 → NTStatus | |
A12_ScrubContext.NumberOfBytesRepaired HexInt64 → HexInt64 | |
A13_ScrubContext.NumberOfBytesFailed HexInt64 → HexInt64 | |
A14_ScrubContext.ErrorFileOffset HexInt64 → HexInt64 | |
A15_ScrubContext.ErrorLength HexInt64 → HexInt64 | |
A16_ScrubContext.ParityExtentData->NumberOfParityExtents UInt32 → unsignedInt |
Event ID 389: Scb:A10_Scb ScrubInternal Status: A11_Status Repaired: A12_ScrubContext.NumberOfBytesRepaired!
#Event ID 390: InternalFileReference: A10_InternalFileReference.
#Event ID 391: InternalFileReference:A10_InternalFileReference.
#Event ID 392: Scb:A10_Scb Incomplete IoCount:A11_ScrubIoCount Cancel:A12_Irp->Cancel ParityExtentCount:A13_ScrubContext.ParityExtentData->NumberOfParityExtents.
#Event ID 395: Scb:A10_Scb Scrub StartingVcn.
#Event ID 396: Scb:A10_Scb Scrub starting vcn is beyond VDL.
#Event ID 397: Scb:A10_Scb Scrub no more Mcb entries from StartingVcn:A11_StartingVcn!
#Event ID 398: Scb:A10_Scb Scrub skipping UNUSED_LCN Vcn: A11_StartingVcn!
#Event ID 399: Scb:A10_Scb StartingVcn:A11_StartingVcn!
#Event ID 400: Scb:A10_Scb ScrubDsmRange [A11_DsmRange.StartingOffset!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer → HexInt64 | |
A11_DsmRange.StartingOffset HexInt64 → HexInt64 | |
A12_DsmRange.StartingOffset + DsmRange.LengthInBytes HexInt64 → HexInt64 | |
A13_DsmRange.LengthInBytes HexInt64 → HexInt64 | |
A14_StartingVcn HexInt64 → HexInt64 | |
A15_StartingVcnOffset HexInt32 → HexInt32 | |
A16_SectorAlignedVdl HexInt64 → HexInt64 |
Event ID 401: Scrub found problems Scb: A10_Scb Vcn A11_StartingVcn!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer → HexInt64 | |
A11_StartingVcn HexInt64 → HexInt64 | |
A12_ScrubContext->ErrorFileOffset HexInt64 → HexInt64 | |
A13_ScrubbedLength HexInt64 → HexInt64 | |
A14_ScrubContext->OperationStatus HexInt32 → NTStatus | |
A15_ScrubContext->NumberOfBytesFailed HexInt64 → HexInt64 | |
A16_ScrubContext->NumberOfBytesRepaired HexInt64 → HexInt64 | |
A17_NewParityExtentCount UInt32 → unsignedInt |
Event ID 402: Scb:A10_Scb DsmAction_Scrub call failed, Status: A11_Status.
#Event ID 403: Scb:A10_Scb DsmAction_Scrub operation failed, Status: A11_Status.
#Event ID 404: FSCTL_REPAIR_COPIES not supported for Txf file, Scb: A10_Scb, TxfScb: A11_Scb->TxfScb.
#Event ID 407: FSCTL_REPAIR_COPIES interrupted by thread termination.
#Event ID 408: FSCTL_REPAIR_COPIES canceled.
#Event ID 410: Scb:A10_Scb FSCTL_REPAIR_COPIES No more Mcb entries (unallocated) from StartingVcn:A11_StartingVcn!
#Event ID 411: Scb:A10_Scb FSCTL_REPAIR_COPIES skipping UNUSED_LCN Vcn: A11_StartingVcn!
#Event ID 412: Scb:A10_Scb RepairDsmRange [A11_RepairDataSetRange->StartingOffset!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Scb Pointer → HexInt64 | |
A11_RepairDataSetRange->StartingOffset HexInt64 → HexInt64 | |
A12_RepairDataSetRange->StartingOffset + RepairDataSetRange->LengthInBytes HexInt64 → HexInt64 | |
A13_RepairDataSetRange->LengthInBytes HexInt64 → HexInt64 | |
A14_RepairFileOffset HexInt64 → HexInt64 |
Event ID 413: Scb:A10_Scb DsmAction_Repair call failed, Status: A11_Status.
#Event ID 414: Scb:A10_Scb DsmAction_Repair operation failed, Status: A11_IrpStatus.
#Event ID 415: Scb:A10_Scb DsmAction_Repair completed, IrpStatus: A11_RepairCopiesOutput->Status.
#Event ID 430: NtfsInitiateFileMetadataOptimization: Only allowed on regular user files/directories opened for write.
#Message #
Event ID 431: NtfsQueryFileMetadataOptimization: Only allowed on regular user files/directories opened for read.
#Message #
Event ID 434: NtfsEnumOnMountToDeleteWorker(A10_Vcb,A11_PsGetCurrentThread()): Enumerate status=0xA12_Status.
#Event ID 436: NtfsEnumMountWorker(A10_Vcb,A11_PsGetCurrentThread()): Close status=0xA12_Status.
#Event ID 437: NtfsEnumOnMountToDeleteWorker(A10_Vcb,A11_PsGetCurrentThread()): Close dir status=0xA12_Status.
#Event ID 439: SCB: A10_Scb, StartOffset: 0xA11_StartOffset!
#Event ID 440: FsLibGetBadAddressRanges returned Status: A10_Status, NumBadRanges: 0xA11_Output->NumBadRanges.
#Event ID 441: FsInputRangeIndex: A10_FsInputRangeIndex, FileOffset: 0xA11_FsInputRanges[FsInputRangeIndex].FileOffset!
#Event ID 442: Scb: A10_Scb, Status: A11_Status, AbnormalTermination: A12_(BOOLEAN)AbnormalTermination().
#Event ID 443: Scb: A10_Scb, Status: A11_Status.
#Event ID 445: Logic error of posting close to work queue.
#Event ID 446: NtfsFindPrefixHashEntry: {Hash table: %1} {ParentScb: %2, '%3'} {RemainingName: '%4'}.
#Message #
Event ID 447: NtfsFindPrefixHashEntry: {Lcb: NULL}.
#Event ID 449: NtfsFindPrefixHashEntry: {Lcb not found}.
#Event ID 452: Vcb A10_Vcb.
#Event ID 453: Vcb A10_Vcb.
#Event ID 457: Vcb A10_Vcb.
#Event ID 458: Vcb A10_Vcb.
#Event ID 460: Vcb A10_Vcb.
#Event ID 461: Vcb A10_Vcb.
#Event ID 462: Vcb A10_Vcb.
#Event ID 465: NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContext->TransactionId!
#Event ID 466: NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContext->TransactionId!
#Event ID 467: NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContext->OriginatingIrp,A12_PsGetCurrentThread()): Pre NtfsWriteLog failure A13_IrpContext->ExceptionStatus.
#Event ID 468: NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContext->OriginatingIrp,A12_PsGetCurrentThread()): Post NtfsWriteLog failure A13_IrpContext->ExceptionStatus.
#Event ID 469: NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContext->OriginatingIrp,A12_PsGetCurrentThread()): LfsFlushToLsn failure A13_IrpContext->ExceptionStatus Count A14_FailedFlushCount.
#Event ID 470: NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContext->OriginatingIrp,A12_PsGetCurrentThread()): Pre NtfsProcessNewLengthQueue failure A13_IrpContext->ExceptionStatus.
#Event ID 471: NtfsCommitCurrentTransaction (A10_IrpContext,A11_IrpContext->OriginatingIrp,A12_PsGetCurrentThread()): Post NtfsProcessNewLengthQueue failure A13_IrpContext->ExceptionStatus.
#Event ID 472: NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContext->TransactionId!
#Event ID 473: NtfsCommitCurrentTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContext->TransactionId!
#Event ID 474: NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Entering - ActiveLsn: A11_ActiveLsn->QuadPart!
#Event ID 475: NtfsFreeRecentlyDeallocated: Vcb A10_Vcb empty list - Leaving.
#Event ID 476: NtfsFreeRecentlyDeallocated: Vcb A10_Vcb empty list - Leaving.
#Event ID 477: NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Found frozen deallocated clusters with A11_Clusters->ClusterCount!
#Event ID 478: NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - No actionable deallocated clusters.
#Event ID 479: NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - No actionable deallocated clusters.
#Event ID 480: NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Found a deallocated clusters A11_Clusters with A12_Clusters->ClusterCount!
#Event ID 481: Vcb: A10_Vcb, Processing range.
#Event ID 482: Looking for dangling MDLs.
#Event ID 483: FsLibGroupSubExtentsByDanglingMdl failed: A10_Status.
#Event ID 484: FsLibAddBaseMcbEntryEx failed: A10_Status.
#Event ID 485: NtfsAddToMatchingDeallocatedClusters( ExtentsWithoutDanglingMdl ) failed: A10_Status.
#Event ID 486: NtfsAddToMatchingDeallocatedClusters( ExtentsWithDanglingMdl ) failed: A10_Status.
#Event ID 487: No sub extents has dangling MDL.
#Event ID 488: NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Telling volsnap freeing at A11_StartingLcn!
#Event ID 489: NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Volsnap responsed with freeing at A11_StartingLcn + StartingIndex!
#Event ID 490: NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Got error 0xA11_Status from below.
#Event ID 491: NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Deleting MarkUnusedContext A11_MarkUnusedContext.
#Event ID 492: NtfsFreeRecentlyDeallocated: Vcb A10_Vcb - Leaving.
#Event ID 493: NtfsRemoveNtfsMcbEntry Scb: A10_Mcb->Scb, Mcb: A11_Mcb, Vcn: 0xA12_StartingVcn!
#Event ID 494: NtfsRemoveNtfsMcbEntry Mcb: A10_Mcb Completed.
#Event ID 495: NtfsAddNtfsMcbEntry Scb: A10_Mcb->Scb, Mcb: A11_Mcb, Vcn: 0xA12_Vcn!
#Event ID 496: NtfsAddNtfsMcbEntry Mcb: A10_Mcb, Result: A11_Result.
#Event ID 497: NtfsUnloadNtfsMcbRange Scb: A10_Mcb->Scb, Mcb: A11_Mcb, StartVcn: 0xA12_StartingVcn!
#Event ID 498: NtfsUnloadNtfsMcbRange Mcb: A10_Mcb Completed.
#Event ID 499: Valid NTFS boot sector.
#Event ID 500: Not an NTFS boot sector.
#Event ID 501: NtfsMountVolume: Vcb:A10_Vcb, IC:A11_IrpContext, Growing allocation for Mft's Attribute List failed with exception:0xA12_IrpContext->ExceptionStatus.
#Event ID 504: DAX volume mounted without DAX support because storage is not DAX capable.
#Event ID 505: NtfsGrowMftsAttributeListAllocation Vcb:A10_Vcb, IC:A11_IrpContext Mft AttributeList not found, skipping growth.
#Event ID 506: NtfsGrowMftsAttributeListAllocation Vcb:A10_Vcb, IC:A11_IrpContext Converting Resident AttributeList.
#Event ID 507: NtfsGrowMftsAttributeListAllocation Vcb:A10_Vcb, IC:A11_IrpContext, AttrListScb:A12_Scb Added Allocation for NonResident AttributeList.
#Event ID 508: Unexpected exception code of 0xA10_ExceptionCode received.
#Event ID 510: Unexpected exception code of 0xA10_ExceptionCode received.
#Event ID 511: LogFileFull A10_IrpContext->LogFullReason BackTrace: ln A11_BackTrace[0]; ln A12_BackTrace[1]; ln A13_BackTrace[2]; ln A14_BackTrace[3]; ln A15_BackTrace[4]; ln A16_BackTrace[5]; ln A17_BackTrace[6...
#Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext->LogFullReason UInt32 → unsignedInt | |
A11_BackTrace[0] Pointer → HexInt64 | |
A12_BackTrace[1] Pointer → HexInt64 | |
A13_BackTrace[2] Pointer → HexInt64 | |
A14_BackTrace[3] Pointer → HexInt64 | |
A15_BackTrace[4] Pointer → HexInt64 | |
A16_BackTrace[5] Pointer → HexInt64 | |
A17_BackTrace[6] Pointer → HexInt64 | |
A18_BackTrace[7] Pointer → HexInt64 | |
A19_BackTrace[8] Pointer → HexInt64 | |
A20_BackTrace[9] Pointer → HexInt64 | |
A21_BackTrace[10] Pointer → HexInt64 | |
A22_BackTrace[11] Pointer → HexInt64 | |
A23_BackTrace[12] Pointer → HexInt64 | |
A24_BackTrace[13] Pointer → HexInt64 | |
A25_BackTrace[14] Pointer → HexInt64 | |
A26_BackTrace[15] Pointer → HexInt64 | |
A27_BackTrace[16] Pointer → HexInt64 | |
A28_BackTrace[17] Pointer → HexInt64 | |
A29_BackTrace[18] Pointer → HexInt64 | |
A30_BackTrace[19] Pointer → HexInt64 |
Event ID 512: Unexpected raise of 0xA10_ExceptionCode during critical non-raise code.
#Event ID 513: NtfsProcessException IC: A10_IrpContext, ExceptionCode: 0xA11_ExceptionCode!
#Event ID 514: NtfsProcessException IC: A10_IrpContext, ExceptionCode: 0xA11_ExceptionCode!
#Event ID 515: Failed to abort - IrpContext A10_IrpContext, Irp A11_Irp, Vcb A12_IrpContext->Vcb, Count A13_NtfsFailedAborts, Status A14_GetExceptionCode().
#Event ID 516: Failed to abort - IrpContext A10_IrpContext, Irp A11_Irp, Vcb A12_IrpContext->Vcb, Scb A13_NextScb, FileRef A14_*(PULONGLONG)_NextScb->Fcb->FileReference!
#Event ID 517: Setting STATUS_CANT_WAIT in top-level exception status for write @ 0xA10_IrpSp->Parameters.Write.ByteOffset.HighPart!
#Event ID 518: Setting 0xA10_ExceptionCode in top-level exception status for write @ 0xA11_IrpSp->Parameters.Write.ByteOffset.HighPart!
#Event ID 519: [A10_IrpSp->MajorFunction, A11_IrpSp->MinorFunction!
#Event ID 520: [A10_IrpSp->MajorFunction, A11_IrpSp->MinorFunction!
#Event ID 521: Can't handle invalid bitmap in a positive way.
#Event ID 522: NTFS ETW tracing is now active.
#Event ID 523: Updating NtfsMinTrimTotalSize to A10_MinTrimTotalSize.
#Event ID 524: Updating NtfsMaxTrimTotalSize to A10_MaxTrimTotalSize.
#Event ID 528: A10___FUNCTION__: Setting RM at 0xA11_(PVOID)Vcb->TxfVcb.DefaultRm ({A12__Vcb->TxfVcb.DefaultRm->RmId}) up for auto-restart.
#Event ID 530: NtfsCommonSetQuota: Caller does not have manage volume privilege and it's not quota file.
#Message #
Event ID 531: Unexpected Paging-Read on DAX mappable stream, Scb=A10_Scb.
#Event ID 535: NtfsAbortTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContext->TransactionId!
#Event ID 536: NtfsAbortTransaction IC: A10_IrpContext, TransactionId: 0xA11_IrpContext->TransactionId!
#Event ID 537: DoAction::InitializeFRS IC:A10_IrpContext, FileRef:0xA11_FileRecord->SegmentNumberHighPart!
#Event ID 538: DoAction::DeallocateFRS IC:A10_IrpContext, FileRef:0xA11_FileRecord->SegmentNumberHighPart!
#Event ID 539: DoAction::WriteEndOfFRS IC:A10_IrpContext, FileRef:0xA11_FileRecord->SegmentNumberHighPart!
#Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer → HexInt64 | |
A11_FileRecord->SegmentNumberHighPart HexInt32 → HexInt32 | |
A12_FileRecord->SegmentNumberLowPart HexInt32 → HexInt32 | |
A13_NtfsFullSegmentNumber( _FileRecord->BaseFileRecordSegment ) HexInt64 → HexInt64 | |
A14_Attribute->TypeCode HexInt32 → HexInt32 | |
A15_LogRecord->RecordOffset HexInt32 → HexInt32 | |
A16_Length HexInt32 → HexInt32 |
Event ID 540: DoAction::CreateAttribute IC:A10_IrpContext, FileRef:0xA11_FileRecord->SegmentNumberHighPart!
#Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer → HexInt64 | |
A11_FileRecord->SegmentNumberHighPart HexInt32 → HexInt32 | |
A12_FileRecord->SegmentNumberLowPart HexInt32 → HexInt32 | |
A13_NtfsFullSegmentNumber( _FileRecord->BaseFileRecordSegment ) HexInt64 → HexInt64 | |
A14_((PATTRIBUTE_RECORD_HEADER)Data)->TypeCode HexInt32 → HexInt32 |
Event ID 541: NtfsRestartChangeValue IC:A10_IrpContext, FileRef:0xA11_FileRecord->SegmentNumberHighPart!
#Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer → HexInt64 | |
A11_FileRecord->SegmentNumberHighPart HexInt32 → HexInt32 | |
A12_FileRecord->SegmentNumberLowPart HexInt32 → HexInt32 | |
A13_NtfsFullSegmentNumber( _FileRecord->BaseFileRecordSegment ) HexInt64 → HexInt64 | |
A14_NtfsFullSegmentNumber( _FileReference ) HexInt64 → HexInt64 |
Event ID 542: DoAction::SetNewAttributeSizes IC:A10_IrpContext, FileRef:0xA11_FileRecord->SegmentNumberHighPart!
#Message #
Fields #
| Name | Description |
|---|---|
A10_IrpContext Pointer → HexInt64 | |
A11_FileRecord->SegmentNumberHighPart HexInt32 → HexInt32 | |
A12_FileRecord->SegmentNumberLowPart HexInt32 → HexInt32 | |
A13_NtfsFullSegmentNumber( _FileRecord->BaseFileRecordSegment ) HexInt64 → HexInt64 | |
A14_Attribute->Form.Nonresident.AllocatedLength HexInt64 → HexInt64 | |
A15_Attribute->Form.Nonresident.FileSize HexInt64 → HexInt64 | |
A16_Attribute->Form.Nonresident.ValidDataLength HexInt64 → HexInt64 | |
A17_Attribute->Form.Nonresident.TotalAllocated HexInt64 → HexInt64 | |
A18_Sizes->AllocationSize HexInt64 → HexInt64 | |
A19_Sizes->FileSize HexInt64 → HexInt64 | |
A20_Sizes->ValidDataLength HexInt64 → HexInt64 | |
A21_Sizes->TotalAllocated HexInt64 → HexInt64 |
Event ID 543: DoAction(SetBitsInNonresidentBitMap) IC: A10_IrpContext, Vcb: A11_Vcb, Bitmap: A12__Bitmap.
#Event ID 544: DoAction(ClearBitsInNonresidentBitMap) IC: A10_IrpContext, Vcb: A11_Vcb, Bitmap: A12__Bitmap.
#Event ID 548: NtfsCheckFileForDelete: Denying access due to there are same-tx handles open to this file.
#Message #
Event ID 549: NtfsCheckFileForDelete: Denying access due to TxfCheckForLockConflict failed.
#Message #
Event ID 550: NtfsCheckFileForDelete: Denying access due to superseding view indexes are not allowed.
#Message #
Event ID 551: NtfsCheckFileForDelete: Denying access due to non-posix delete of target directory open is not allowed.
#Message #
Event ID 554: NtfsCheckFileForDelete: Caller does not have write attributes access (TxfAccessCheck failed).
#Message #
Event ID 560: NTFS ETW tracing is shutting down.
#Event ID 564: NtfsSetStorageReserveIdInfo: System files are not allowed to be part of a storage reserve.
#Message #
Event ID 567: NtfsChangeStorageReserveId: Caller does not have manage volume privilege to explicitly setting reserve ID to/from a "restricted area".
#Message #
Event ID 568: Failed to get a non-volatile token for Vcb: A10_Vcb, Status: A11_Status.
#Event ID 569: Failed to free non-volatile token for Vcb: A10_Vcb, Status: A11_Status.
#Event ID 570: NtfsRestoreScbSnapshots: Restored TotalAllocated, Scb: A10_Scb, TotalAllocated: 0xA11_Scb->TotalAllocated!
#Event ID 571: NtfsGetDeallocatedClusters: Lsn updated for DeallocatedClusters: A10_CurrentClusters, Lsn: A11_CurrentClusters->Lsn.QuadPart!
#Event ID 572: ClustersLinkAsHead: A10_ClustersLinkAsHead, FlagsToMatch: 0xA11_FlagsToMatch, InsertAfter: A12_InsertAfter.
#Event ID 573: Clusters: A10_Clusters, Flags: 0xA11_Clusters->Flags.
#Event ID 574: Matching cluster: A10_Clusters, NumberOfRuns: 0xA11_NumberOfRuns.
#Event ID 575: Clusters: A10_Clusters.
#Event ID 576: Allocated new deallocated clusters.
#Event ID 577: Need to add Range.
#Event ID 578: Added range.
#Event ID 580: TxfCheckForLockConflict: Locking transaction is doomed and caller is non-trans or different trans who wants to modify.
#Message #
Event ID 582: TxfCheckForLockConflict: File has user handle opened on one of the versions or user-mapping on a section.
#Message #
Event ID 583: A10___FUNCTION__: from A11_CallerFunction (A12_CallerFile:A13_CallerLineNumber) RM at 0xA14_(PVOID)TxfRmcb {A15__TxfRmcb->RmId}, Tx at 0xA16_(PVOID)TxfTrans {A17__TxfTrans->KtmUow}, Status was 0xA1...
#Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString → string | |
A11_CallerFunction AnsiString → string | |
A12_CallerFile AnsiString → string | |
A13_CallerLineNumber Int32 → int | |
A14_(PVOID)TxfRmcb Pointer → HexInt64 | |
A15__TxfRmcb->RmId GUID → GUID | |
A16_(PVOID)TxfTrans Pointer → HexInt64 | |
A17__TxfTrans->KtmUow GUID → GUID | |
A18_AbortReasonStatus HexInt32 → HexInt32 |
Event ID 584: A10___FUNCTION__: from A11_CallerFunction (A12_CallerFile:A13_CallerLineNumber) RM at 0xA14_(PVOID)TxfRmcb {A15__TxfRmcb->RmId}, Tx at 0xA16_(PVOID)TxfTrans {A17__TxfTrans->KtmUow}, Status was 0xA1...
#Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString → string | |
A11_CallerFunction AnsiString → string | |
A12_CallerFile AnsiString → string | |
A13_CallerLineNumber Int32 → int | |
A14_(PVOID)TxfRmcb Pointer → HexInt64 | |
A15__TxfRmcb->RmId GUID → GUID | |
A16_(PVOID)TxfTrans Pointer → HexInt64 | |
A17__TxfTrans->KtmUow GUID → GUID | |
A18_Status HexInt32 → HexInt32 |
Event ID 585: A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting transaction at 0xA13_TxfTrans {A14__TxfTrans->KtmUow}.
#Event ID 586: A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting transaction at 0xA13_TxfTrans {A14__TxfTrans->KtmUow}.
#Event ID 587: A10___FUNCTION__: RM at 0xA11_(PVOID)CalloutParameters->TxfFlush.TxfRmcb {A12__CalloutParameters->TxfFlush.TxfRmcb->RmId}: Unexpected exception code of 0xA13_GetExceptionCode() received.
#Event ID 588: A10___FUNCTION__: TxfStartRm reports RM will be reset: RM metadata corrupt.
#Event ID 589: A10___FUNCTION__: TxfStartRm reports RM will be reset: TM could not be initialized.
#Event ID 590: A10___FUNCTION__: TxfStartRm reports RM will be reset: RM log corrupt.
#Event ID 591: A10___FUNCTION__: TxfStartRm reports RM will be reset: log version changed.
#Event ID 592: A10___FUNCTION__: TxfStartRm reports RM will be reset: dedicated log found, need multiplexed.
#Event ID 593: A10___FUNCTION__: TxfStartRm reports RM will be reset: multiplexed log found, need dedicated.
#Event ID 594: A10___FUNCTION__: TxfStartRm reports RM will be reset: CLFS log metadata corrupt.
#Event ID 595: A10___FUNCTION__: TxfStartRm reports RM will be reset: 0xA11_FailureStatus.
#Event ID 596: A10___FUNCTION__: RM did not start and WILL NOT be reset, status code is 0xA11_FailureStatus!
#Event ID 597: A10___FUNCTION__: Could not initialize IrpContext: 0xA11_Status.
#Event ID 598: TxfInitializeVolume: Denying access due to Txf start is not allowed (possible racing with dismount or volume shutdown).
#Message #
Event ID 599: A10___FUNCTION__: IOCTL_VOLUME_GET_GPT_ATTRIBUTES returned 0xA11_TempStatus for default RM on VCB at 0xA12_(PVOID)Vcb.
#Event ID 600: A10___FUNCTION__: Exception code 0xA11_GetExceptionCode(), Status 0xA12_Status for default RM on VCB at 0xA13_(PVOID)Vcb.
#Event ID 601: A10___FUNCTION__: Couldn't reset default RM on VCB at 0xA11_(PVOID)Vcb after A12_TXF_MAX_RESET_ATTEMPTS_ON_MOUNT tries: 0xA13_OldStatus.
#Event ID 602: A10___FUNCTION__: Exception 0xA11_GetExceptionCode() raised from TxfConvertRmStartFailureStatusCode for default RM on VCB at 0xA12_(PVOID)Vcb.
#Event ID 603: A10___FUNCTION__: A11_(NT_SUCCESS( Status ) ? 'Succeeded' : 'FAILED') auto-restart of RM at 0xA12_(PVOID)TxfRmcb ({A13__TxfRmcb->RmId}): 0xA14_Status.
#Event ID 604: A10___FUNCTION__: Attempting auto-restart of RM at 0xA11_(PVOID)TxfRmcb ({A12__TxfRmcb->RmId}).
#Event ID 605: A10___FUNCTION__: Volume too small to start RM at 0xA11_(PVOID)TxfRmcb ({A12__TxfRmcb->RmId}).
#Event ID 606: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: invalid flags in $Tops.
#Event ID 607: TxfStartRm: Denying access due to Txf start is not allowed (possible racing with dismount or volume shutdown).
#Message #
Event ID 608: A10___FUNCTION__: Raising to reset RM at 0xA11_(PVOID)TxfRmcb ({A12__TxfRmcb->RmId}): Explicit reset requested.
#Event ID 610: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: no TXF_DATA in root.
#Event ID 611: A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Different nesting levels of 0xA13_LogNestingLevel and 0xA14_DiskNestingLevel.
#Event ID 612: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: restart area already exists.
#Event ID 613: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: restart area already exists.
#Event ID 614: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: RmID in restart area does not match {A13__ClfsRestartArea->RmId}.
#Event ID 615: A10___FUNCTION__: Got A11_Status from ClfsGetLogFileInformation for RM at 0xA12_(PVOID)TxfRmcb {A13__TxfRmcb->RmId}.
#Event ID 616: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Restart LSN is before beginning of log.
#Event ID 617: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: MinRollforwardEndLsn is beyond end of log.
#Event ID 618: A10___FUNCTION__: TxF RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} started successfully.
#Event ID 619: A10___FUNCTION__: TxF RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} failed to start with Status 0xA13_Status A14_AbnormalTermination() ? '(abnormal termination)' : ''.
#Event ID 620: A10___FUNCTION__: Shutting down A11_(TxfIsDefaultRm( TxfRmcb ) ? 'default' : 'secondary') RM at 0xA12_(PVOID)TxfRmcb {A13__TxfRmcb->RmId}.
#Event ID 621: A10___FUNCTION__: Setting RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} up for auto-restart.
#Event ID 623: (A10_FILEID_FROM_SOURCE( FileNLine ):A11_LINENUM_FROM_SOURCE( FileNLine )) - TXF_HARD_ERROR on RM at 0xA12_TxfRmcb ({A13__TxfRmcb->RmId}): A14_Status).
#Event ID 624: A10___FUNCTION__: Renamed RM at 0xA11_(PVOID)TxfRmcb from {A12__OldGuid} to {A13__TxfRmcb->RmId}.
#Event ID 625: A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}, rolling back Tx at 0xA13_(PVOID)TxfTrans {A14__TxfTrans->KtmUow}, Status was 0xA15_Status.
#Event ID 626: A10___FUNCTION__: Renamed RM at 0xA11_(PVOID)TxfRmcb from {A12__OldGuid} to {A13__TxfRmcb->RmId}.
#Event ID 629: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Found too high of a TxF ID in log.
#Event ID 630: A10___FUNCTION__: Error Setting Delete Disposition: 0xA11_Status FileObject: 0xA12_(PVOID)FileObject.
#Event ID 631: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Got a RECOVER notification for a transaction that isn't in-doubt.
#Event ID 632: TxfSetupTransactionContextFromCcb: Modifying operation is now allowed with a non-TxF modify handle.
#Message #
Event ID 634: TxfSetupTransactionContextFromCcb: Denying access of modifying operation on a read-only handle.
#Message #
Event ID 635: A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} raising 0xA13_ExceptionCode to KTM!
#Event ID 636: A10___FUNCTION__: Commit (0xA11_TransactionNotification) ofA12_(TransactionAlreadyPrepared ? ' **PREPARED** ' : ' ')tx {A13__TxfTrans->KtmUow} on RM at 0xA14_(PVOID)TxfRmcb {A15__TxfRmcb->RmId} fai...
#Message #
Fields #
| Name | Description |
|---|---|
A10___FUNCTION__ AnsiString → string | |
A11_TransactionNotification HexInt32 → HexInt32 | |
A12_(TransactionAlreadyPrepared ? ' **PREPARED** ' : ' ') AnsiString → string | |
A13__TxfTrans->KtmUow GUID → GUID | |
A14_(PVOID)TxfRmcb Pointer → HexInt64 | |
A15__TxfRmcb->RmId GUID → GUID | |
A16_Status HexInt32 → HexInt32 |
Event ID 637: A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting transaction at 0xA13_TxfTrans {A14__TxfTrans->KtmUow} (notify commit).
#Event ID 638: A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting transaction at 0xA13_TxfTrans {A14__TxfTrans->KtmUow} (notify rollback).
#Event ID 639: A10___FUNCTION__: Error doing IRP_MJ_FLUSH_BUFFERS on RM at 0xA11_(PVOID)Trans->TxfRmcb {A12__Trans->TxfRmcb->RmId}: 0xA13_FlushStatus.
#Event ID 640: A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} trying to abort transaction at 0xA13_Trans {A14__Trans->KtmUow}.
#Event ID 641: A10___FUNCTION__: Aborting call stack: 0xA11_CallStack[0] 0xA12_CallStack[1] 0xA13_CallStack[2] 0xA14_CallStack[3] 0xA15_CallStack[4].
#Event ID 642: A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} aborting transaction at 0xA13_Trans {A14__Trans->KtmUow}.
#Event ID 643: A10___FUNCTION__: 0xA11_Status initializing IrpContext for tx at A12_(PVOID)Trans {A13__Trans->KtmUow}, RM at A14_(PVOID)TxfRmcb {A15__TxfRmcb->RmId}.
#Event ID 644: A10___FUNCTION__: 0xA11_Status writing log record for RM at 0xA12_(PVOID)TxfRmcb {A13__TxfRmcb->RmId}, Tx at 0xA14_(PVOID)Trans {A15__Trans->KtmUow}.
#Event ID 645: A10___FUNCTION__: About to force aborts on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.
#Event ID 646: A10___FUNCTION__: BaseLsn is greater than TargetLsn on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.
#Event ID 647: A10___FUNCTION__: No transactions remain on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.
#Event ID 648: A10___FUNCTION__: Transaction's first undo LSN greater than TargetLsn on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.
#Event ID 649: A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} surprise-aborting transaction at 0xA13_OldestTrans {A14__OldestTrans->KtmUow}.
#Event ID 650: A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId} got 0xA13_Status from TxfTryAbortTransaction on Tx 0xA14_OldestTrans {A15__OldestTrans->KtmUow}.
#Event ID 651: A10___FUNCTION__: Inactive RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.
#Event ID 652: A10___FUNCTION__: Log is pinned on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.
#Event ID 653: A10___FUNCTION__: RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}, rolling back KTM Tx at 0xA13_(PVOID)TransToDereference {A14__TransToDereference->KtmUow}, Status was 0xA15_Status.
#Event ID 654: A10___FUNCTION__: Log pinned trying to advance RestartLsn on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.
#Event ID 655: A10___FUNCTION__: Log pinned by doomed transaction on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.
#Event ID 656: A10___FUNCTION__: Reporting 0xA11_PinnedStatus to CLFS from RM at 0xA12_(PVOID)TxfRmcb {A13__TxfRmcb->RmId}: 0xA14_Status.
#Event ID 657: A10___FUNCTION__: Done forcing aborts on RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}.
#Event ID 658: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Txf directory is missing in pre-existing RM.
#Event ID 660: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Found non-empty $Txf but there is no log.
#Event ID 661: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Couldn't find $INDEX_ROOT on $Txf.
#Event ID 662: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Couldn't find TXF_DATA_ATTR on $Txf.
#Event ID 663: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Found TXF_DATA_ATTR for normal file on $Txf.
#Event ID 664: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Expected a secondary RM here.
#Event ID 665: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops is missing but $Txf is non-empty.
#Event ID 666: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops is missing but there is already a log.
#Event ID 667: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops is A13_(IsEncrypted( _TopsFcb->Info ) ? 'encrypted' : 'compressed').
#Event ID 668: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Missing $STANDARD_INFORMATION.
#Event ID 669: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Couldn't find file attributes.
#Event ID 670: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops is corrupt.
#Event ID 671: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Could not find unnamed data stream.
#Event ID 672: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops metadata is the wrong version or records wrong size.
#Event ID 673: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: $Tops metadata is the wrong size.
#Event ID 674: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Non-NULL RM ID found in $Tops and there is no log.
#Event ID 675: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Epoch in $Tops metadata doesn't match RM.
#Event ID 676: A10___FUNCTION__: Corrupt RM at 0xA11_(PVOID)TxfRmcb {A12__TxfRmcb->RmId}: Couldn't find $T stream.
#Event ID 678: TrimUsnJournal (A10_Vcb, A11_IrpContext): Decided to trim usn journal.
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_Vcb->FirstValidUsn HexInt64 → HexInt64 | |
A13_FirstValidUsn HexInt64 → HexInt64 | |
A14_TrackUsnJournalFileSize HexInt64 → HexInt64 | |
A15_TrackUsnJournalAllocationSize HexInt64 → HexInt64 | |
A16_TrackUsnJournalMaxSize HexInt64 → HexInt64 | |
A17_TrackUsnJournalDeltaAllocation HexInt64 → HexInt64 |
Event ID 679: TrimUsnJournal (A10_Vcb, A11_IrpContext): About to delete allocation till A12_FirstValidUsn - 1!
#Event ID 680: TrimUsnJournal (A10_Vcb, A11_IrpContext): Before trimming journal AS A12_UsnJournal->Header.AllocationSize.QuadPart!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_UsnJournal->Header.AllocationSize.QuadPart HexInt64 → HexInt64 | |
A13_UsnJournal->Header.FileSize.QuadPart HexInt64 → HexInt64 | |
A14_UsnJournal->Header.ValidDataLength.QuadPart HexInt64 → HexInt64 | |
A15_UsnJournal->TotalAllocated HexInt64 → HexInt64 |
Event ID 681: TrimUsnJournal (A10_Vcb, A11_IrpContext): After trimming journal AS A12_UsnJournal->Header.AllocationSize.QuadPart!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_UsnJournal->Header.AllocationSize.QuadPart HexInt64 → HexInt64 | |
A13_UsnJournal->Header.FileSize.QuadPart HexInt64 → HexInt64 | |
A14_UsnJournal->Header.ValidDataLength.QuadPart HexInt64 → HexInt64 | |
A15_UsnJournal->TotalAllocated HexInt64 → HexInt64 |
Event ID 682: TrimUsnJournal (A10_Vcb, A11_IrpContext): Mapping pairs validated.
#Event ID 683: TrimUsnJournal (A10_Vcb, A11_IrpContext): Checkpointed.
#Event ID 688: OfsSetLength (A10_Vcb,A11_IrpContext,A12_IrpContext->OriginatingIrp,A13_PsGetCurrentThread()): Extending journal from AS A14_Scb->Header.AllocationSize.QuadPart!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_IrpContext->OriginatingIrp Pointer → HexInt64 | |
A13_PsGetCurrentThread() Pointer → HexInt64 | |
A14_Scb->Header.AllocationSize.QuadPart HexInt64 → HexInt64 | |
A15_Scb->Header.FileSize.QuadPart HexInt64 → HexInt64 | |
A16_Scb->Header.ValidDataLength.QuadPart HexInt64 → HexInt64 | |
A17_NewAllocationSize HexInt64 → HexInt64 |
Event ID 689: OfsSetLength (A10_Vcb,A11_IrpContext,A12_IrpContext->OriginatingIrp,A13_PsGetCurrentThread()): Done extending journal AS A14_Scb->Header.AllocationSize.QuadPart!
#Message #
Fields #
| Name | Description |
|---|---|
A10_Vcb Pointer → HexInt64 | |
A11_IrpContext Pointer → HexInt64 | |
A12_IrpContext->OriginatingIrp Pointer → HexInt64 | |
A13_PsGetCurrentThread() Pointer → HexInt64 | |
A14_Scb->Header.AllocationSize.QuadPart HexInt64 → HexInt64 | |
A15_Scb->Header.FileSize.QuadPart HexInt64 → HexInt64 | |
A16_Scb->Header.ValidDataLength.QuadPart HexInt64 → HexInt64 | |
A17_Scb->TotalAllocated HexInt64 → HexInt64 |