Microsoft-Windows-Shell-ZipFolder

28 events across 1 channel

Event ID 1: ZipFolder_ExtractFileStart

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_ExtractFile
Opcode
Start

Event ID 2: ZipFolder_ExtractFileStop

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_ExtractFile
Opcode
Stop

Event ID 3: ZipFolder_DeleteFileStart

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_DeleteFile
Opcode
Start

Event ID 4: ZipFolder_DeleteFileStop

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_DeleteFile
Opcode
Stop

Event ID 5: ZipFolder_WizardExtractAllStart

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_WizardExtractAll
Opcode
Start

Event ID 6: ZipFolder_WizardExtractAllStop

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_WizardExtractAll
Opcode
Stop

Event ID 7: ZipFolder_CountFilesStart

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_CountFiles
Opcode
Start

Event ID 8: ZipFolder_CountFilesStop

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_CountFiles
Opcode
Stop

Event ID 9: ZipFolder_QueryCMStart

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_QueryCM
Opcode
Start

Event ID 10: ZipFolder_QueryCMStop

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_QueryCM
Opcode
Stop

Event ID 11: ZipFolder_CheckEncryptedStart

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_CheckEncrypted
Opcode
Start

Event ID 12: ZipFolder_CheckEncryptedStop

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_CheckEncrypted
Opcode
Stop

Event ID 13: ZipFolder_BuildEnumeratorStart

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_BuildEnumerator
Opcode
Start

Event ID 14: ZipFolder_BuildEnumeratorStop

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_BuildEnumerator
Opcode
Stop

Event ID 15: ZipFolder_DropInStart

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_DropIn
Opcode
Start

Event ID 16: ZipFolder_DropInStop

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_DropIn
Opcode
Stop

Event ID 17: ZipFolder_OpenItemStart

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_OpenItem
Opcode
Start

Event ID 18: ZipFolder_OpenItemStop

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_OpenItem
Opcode
Stop

Event ID 19: ZipFolder_RemoveItemStart

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_RemoveItem
Opcode
Start

Event ID 20: ZipFolder_RemoveItemStop

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_RemoveItem
Opcode
Stop

Event ID 21: ZipFolder_RenameItemStart

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_RenameItem
Opcode
Start

Event ID 22: ZipFolder_RenameItemStop

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_RenameItem
Opcode
Stop

Event ID 23: ZipFolder_ApplyPropsStart

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_ApplyProps
Opcode
Start

Event ID 24: ZipFolder_ApplyPropsStop

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_ApplyProps
Opcode
Stop

Event ID 25: ZipFolder_LeaveFolderStart

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_LeaveFolder
Opcode
Start

Event ID 26: ZipFolder_LeaveFolderStop

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_LeaveFolder
Opcode
Stop

Event ID 27: ZipFolder_AESCheckStart

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_AESCheck
Opcode
Start

Event ID 28: ZipFolder_AESCheckStop

#
Provider
Microsoft-Windows-Shell-ZipFolder
Channel
Diagnostic
Task
ZipFolder_AESCheck
Opcode
Stop

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID 1f84007d-19ce-4b15-9e81-8a3dd8eb9ecb

Defined in zipfldr.dll, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.3624, captured 2026-06-02

Downloads