Microsoft-Windows-UxTheme
33 events across 1 channel
Event ID 1: ThemesAndMetric_SwitchThemeStart
#Event ID 2: ThemesAndMetric_SwitchThemeStop
#Event ID 3: ThemesAndMetric_IsThemePartDefined
#Fields #
| Name | Description |
|---|---|
PartId Int32 | |
StateId Int32 |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088E6-CD0C-4F99-BD0B-6985FA290BDF}",
"event_source_name": "",
"event_id": 3,
"version": 0,
"level": 4,
"task": 3,
"opcode": 1,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:06:08.414+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 15420,
"thread_id": 11180
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {
"PartId": 1,
"StateId": 0
},
"message": "ThemesAndMetric_IsThemePartDefined"
}
Event ID 4: ThemesAndMetric_IsThemePartDefined
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088E6-CD0C-4F99-BD0B-6985FA290BDF}",
"event_source_name": "",
"event_id": 4,
"version": 0,
"level": 4,
"task": 3,
"opcode": 2,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:06:08.414+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 15420,
"thread_id": 11180
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "ThemesAndMetric_IsThemePartDefined"
}
Event ID 5: ThemesAndMetric_GetCurrentThemeNameStart
#Event ID 7: ThemesAndMetric_GetThemeFont
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088E6-CD0C-4F99-BD0B-6985FA290BDF}",
"event_source_name": "",
"event_id": 7,
"version": 0,
"level": 4,
"task": 7,
"opcode": 1,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T04:02:00.029+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 4304,
"thread_id": 3088
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "ThemesAndMetric_GetThemeFont"
}
Event ID 8: ThemesAndMetric_GetThemeFont
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088E6-CD0C-4F99-BD0B-6985FA290BDF}",
"event_source_name": "",
"event_id": 8,
"version": 0,
"level": 4,
"task": 7,
"opcode": 2,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T04:02:00.029+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 4304,
"thread_id": 3088
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "ThemesAndMetric_GetThemeFont"
}
Event ID 9: BufferedPaint_ThreadContention
#Event ID 11: BufferedPaint_PruningBuffers
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088E6-CD0C-4F99-BD0B-6985FA290BDF}",
"event_source_name": "",
"event_id": 11,
"version": 0,
"level": 4,
"task": 11,
"opcode": 0,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T04:02:01.046+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 4304,
"thread_id": 3088
},
"channel": "ETW Trace",
"computer": "JD-DC01-2022",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "BufferedPaint_PruningBuffers"
}
Event ID 13: Shake_PreMovingMessageHandlerStart
#Event ID 15: Shake_PreMovingMessageHandlerStop
#Event ID 23: ThemesAndMetric_ThemeWindow
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088E6-CD0C-4F99-BD0B-6985FA290BDF}",
"event_source_name": "",
"event_id": 23,
"version": 0,
"level": 4,
"task": 15,
"opcode": 0,
"keywords": "0x0000000000000000",
"time_created": "2026-06-02T06:06:08.456+00:00",
"event_record_id": 0,
"correlation": {},
"execution": {
"process_id": 15420,
"thread_id": 11180
},
"channel": "ETW Trace",
"computer": "DESKTOP-FF3N5XK",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": "ThemesAndMetric_ThemeWindow"
}
Event ID 24: ApiExecutionStart
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "24",
"version": "0",
"level": "4",
"task": "16",
"opcode": "1",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:37.122315900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": ""
}
Event ID 25: ApiExecutionStop
#Fields #
| Name | Description |
|---|---|
ApiNumber Int64 | |
ClientSessionId Int32 | |
status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "25",
"version": "0",
"level": "4",
"task": "16",
"opcode": "2",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:37.122483600+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"ApiNumber": "2",
"ClientSessionId": "3",
"status": " 0"
},
"message": ""
}
Event ID 26: GetClientSessionDataStart
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "26",
"version": "0",
"level": "4",
"task": "17",
"opcode": "1",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:37.122316400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": ""
}
Event ID 27: GetClientSessionDataStop
#Fields #
| Name | Description |
|---|---|
ClientSessionId Int32 | |
status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "27",
"version": "0",
"level": "4",
"task": "17",
"opcode": "2",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:37.122318700+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"ClientSessionId": "3",
"status": " 0"
},
"message": ""
}
Event ID 28: HandleServerRequestStart
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "28",
"version": "0",
"level": "4",
"task": "18",
"opcode": "1",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:34.638819800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "2076"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": ""
}
Event ID 29: HandleServerRequestStop
#Fields #
| Name | Description |
|---|---|
ApiNumber Int64 | |
ClientSessionId Int32 | |
status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "29",
"version": "0",
"level": "4",
"task": "18",
"opcode": "2",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:34.638839400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "2076"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"ApiNumber": "1007",
"ClientSessionId": "3",
"status": " 0"
},
"message": ""
}
Event ID 30: HandleServerConnectionRequestStart
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "30",
"version": "0",
"level": "4",
"task": "19",
"opcode": "1",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:34.638429900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "2076"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": ""
}
Event ID 31: HandleServerConnectionRequestStop
#Fields #
| Name | Description |
|---|---|
status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "31",
"version": "0",
"level": "4",
"task": "19",
"opcode": "2",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:34.638553900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "2076"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"status": " 0"
},
"message": ""
}
Event ID 32: SignalRequestPendingStart
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "32",
"version": "0",
"level": "4",
"task": "20",
"opcode": "1",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:34.638827400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "2076"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": ""
}
Event ID 33: SignalRequestPendingStop
#Fields #
| Name | Description |
|---|---|
fRequestPending Boolean | |
status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "33",
"version": "0",
"level": "4",
"task": "20",
"opcode": "2",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:34.638834900+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "2076"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"fRequestPending": "true",
"status": " 0"
},
"message": ""
}
Event ID 34: QueuingThreadpoolWorker
#Fields #
| Name | Description |
|---|---|
status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "34",
"version": "0",
"level": "4",
"task": "21",
"opcode": "0",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:34.638834400+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "2076"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"status": " 0"
},
"message": ""
}
Event ID 35: QueueApiRequestStart
#Fields #
| Name | Description |
|---|---|
fConnectionClosed Boolean |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "35",
"version": "0",
"level": "4",
"task": "22",
"opcode": "1",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:34.638820500+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "2076"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"fConnectionClosed": "false"
},
"message": ""
}
Event ID 36: QueueApiRequestStop
#Fields #
| Name | Description |
|---|---|
status UInt32 | NTSTATUS reference |
Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "36",
"version": "0",
"level": "4",
"task": "22",
"opcode": "2",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:34.638838000+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "2076"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {
"status": " 0"
},
"message": ""
}
Event ID 38: WorkerThreadEntryStart
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "38",
"version": "0",
"level": "4",
"task": "24",
"opcode": "1",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:37.122313800+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": ""
}
Event ID 39: WorkerThreadEntryStop
#Example Event #
{
"system": {
"provider": "Microsoft-Windows-UxTheme",
"guid": "{422088e6-cd0c-4f99-bd0b-6985fa290bdf}",
"event_source_name": "",
"event_id": "39",
"version": "0",
"level": "4",
"task": "24",
"opcode": "2",
"keywords": 9223372036854775808,
"time_created": "2026-03-15T04:33:37.122492200+00:00",
"event_record_id": 0,
"correlation": {
"ActivityID": "{00000000-0000-0000-0000-000000000000}"
},
"execution": {
"process_id": "1420",
"thread_id": "12888"
},
"channel": "Microsoft-Windows-UxTheme/Diagnostic",
"computer": "",
"security": {
"user_id": ""
}
},
"event_data": {},
"message": ""
}
Provenance
Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.
ETW provider GUID {422088E6-CD0C-4F99-BD0B-6985FA290BDF}
Defined in shsvcs.dll, which carries the event manifest.
Observed on:
- WS2022-20348.4893, sample captured from a live trace, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, sample captured from a live trace, binary version 10.0.26100.1, captured 2026-06-02
- WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.1, captured 2026-06-02
- Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.1, captured 2026-06-02