Microsoft-Windows-Shell-ZipFolder
28 events across 1 channel
Event ID 1: ZipFolder_ExtractFileStart
#Event ID 2: ZipFolder_ExtractFileStop
#Event ID 3: ZipFolder_DeleteFileStart
#Event ID 4: ZipFolder_DeleteFileStop
#Event ID 5: ZipFolder_WizardExtractAllStart
#Event ID 6: ZipFolder_WizardExtractAllStop
#Event ID 7: ZipFolder_CountFilesStart
#Event ID 8: ZipFolder_CountFilesStop
#Event ID 9: ZipFolder_QueryCMStart
#Event ID 10: ZipFolder_QueryCMStop
#Event ID 11: ZipFolder_CheckEncryptedStart
#Event ID 12: ZipFolder_CheckEncryptedStop
#Event ID 13: ZipFolder_BuildEnumeratorStart
#Event ID 14: ZipFolder_BuildEnumeratorStop
#Event ID 15: ZipFolder_DropInStart
#Event ID 16: ZipFolder_DropInStop
#Event ID 17: ZipFolder_OpenItemStart
#Event ID 18: ZipFolder_OpenItemStop
#Event ID 19: ZipFolder_RemoveItemStart
#Event ID 20: ZipFolder_RemoveItemStop
#Event ID 21: ZipFolder_RenameItemStart
#Event ID 22: ZipFolder_RenameItemStop
#Event ID 23: ZipFolder_ApplyPropsStart
#Event ID 24: ZipFolder_ApplyPropsStop
#Event ID 25: ZipFolder_LeaveFolderStart
#Event ID 26: ZipFolder_LeaveFolderStop
#Event ID 27: ZipFolder_AESCheckStart
#Event ID 28: ZipFolder_AESCheckStop
#Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID 1f84007d-19ce-4b15-9e81-8a3dd8eb9ecb
Defined in zipfldr.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.3624, captured 2026-06-02