Microsoft-Windows-WER-Diag

5 events across 1 channel

Event ID 1: Possible disk corruption detected for executable image CorruptedFilePath, causing application CrashedAppName to stop working with exception ExceptionCode, status code ExceptionStatusCode.

#
Provider
Microsoft-Windows-WER-Diag
Channel
Operational
Opcode
Info

Description

Possible disk corruption detected for executable image CorruptedFilePath, causing application CrashedAppName to stop working with exception ExceptionCode, status code ExceptionStatusCode. Initiating further diagnostics.

Message #

Possible disk corruption detected for executable image %1, causing application %2 to stop working with exception %3, status code %4. Initiating further diagnostics.

Fields #

NameDescription
CorruptedFilePath UnicodeString
CrashedAppName UnicodeString
ExceptionCode UInt32
ExceptionStatusCode UInt32

Event ID 2: Possible heap corruption detected (exception code Name).

#
Provider
Microsoft-Windows-WER-Diag
Channel
Operational
Level
Informational
Opcode
Info

Description

Possible heap corruption detected (exception code Name). Initiating further diagnostics.

Message #

Possible heap corruption detected (exception code %1). Initiating further diagnostics.

Fields #

NameDescription
ExceptionCode UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WER-Diag",
    "guid": "AD8AA069-A01B-40A0-BA40-948D1D8DEDC5",
    "event_source_name": "",
    "event_id": 2,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9224497936761618432,
    "time_created": "2026-03-09T01:01:32.206209+00:00",
    "event_record_id": 1,
    "correlation": {},
    "execution": {
      "process_id": 7856,
      "thread_id": 2516
    },
    "channel": "Microsoft-Windows-WER-Diag/Operational",
    "computer": "LAB-WIN11",
    "security": {
      "user_id": "S-1-5-18"
    }
  },
  "event_data": {
    "Name": "FTH_EXCEPTION_OF_INTEREST",
    "ExceptionCode": 3221225477
  },
  "message": ""
}

Event ID 3: Possible crash in an unloaded dll detected.

#
Provider
Microsoft-Windows-WER-Diag
Channel
Operational
Opcode
Info

Description

Possible crash in an unloaded dll detected. Initiating further diagnostics.

Message #

Possible crash in an unloaded dll detected. Initiating further diagnostics.

Fields #

NameDescription
ProcessId UInt32
ModuleNameLength UInt32
ModuleName UnicodeString

Event ID 4: Crash on launch is detected.

#
Provider
Microsoft-Windows-WER-Diag
Channel
Operational
Level
Informational
Opcode
Info

Description

Crash on launch is detected. Initiating further diagnostics.

Message #

Crash on launch is detected. Initiating further diagnostics.

Fields #

NameDescription
ProcessId UInt32
ModuleName UnicodeString
StartTime UInt64
CrashTimeFromStart UInt64

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WER-Diag",
    "guid": "AD8AA069-A01B-40A0-BA40-948D1D8DEDC5",
    "event_source_name": "",
    "event_id": 4,
    "version": 0,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "keywords": 9224497936761618432,
    "time_created": "2026-03-13T22:05:01.557312+00:00",
    "event_record_id": 2,
    "correlation": {},
    "execution": {
      "process_id": 7740,
      "thread_id": 1108
    },
    "channel": "Microsoft-Windows-WER-Diag/Operational",
    "computer": "LAB-WIN11.ludus.domain",
    "security": {
      "user_id": "S-1-5-21-1006758700-2167138679-1475694448-1105"
    }
  },
  "event_data": {
    "Name": "CRASH_ON_LAUNCH",
    "ProcessId": 8748,
    "ModuleName": "C:\\Windows\\System32\\Magnify.exe",
    "StartTime": 134179130996217430,
    "CrashTimeFromStart": 19353291
  },
  "message": ""
}

Event ID 5: CFG violation is detected.

#
Provider
Microsoft-Windows-WER-Diag
Channel
Operational
Level
Informational
Collection Priority
Recommended (JSCU-NL)
Opcode
Info

Description

CFG violation is detected.

Message #

CFG violation is detected.

Fields #

NameDescription
AppPath UnicodeString
ProcessId UInt32
ProcessStartTime FILETIME
Is64Bit Boolean
CallReturnAddress Pointer
CallReturnModName UnicodeString
CallReturnModOffset UInt32
CallReturnInstructionBytesLength UInt32
CallReturnInstructionBytes Binary
CallReturnBaseAddress Pointer
CallReturnRegionSize Pointer
CallReturnState UInt32
CallReturnProtect UInt32
CallReturnType UInt32
TargetAddress Pointer
TargetModName UnicodeString
TargetModOffset UInt32
TargetInstructionBytesLength UInt32
TargetInstructionBytes Binary
TargetBaseAddress Pointer
TargetRegionSize Pointer
TargetState UInt32
TargetProtect UInt32
TargetType UInt32

Example Event #

{
  "system": {
    "provider": "Microsoft-Windows-WER-Diag",
    "event_id": 5,
    "level": 4,
    "task": 0,
    "opcode": 0,
    "time_created": "2026-05-27T16:20:07.7628068+00:00",
    "computer": "DESKTOP-FF3N5XK.ludus.domain",
    "channel": "Microsoft-Windows-WER-Diag"
  },
  "event_data": {
    "ProcessStartTime": "2026-04-28T02:27:40.0821642Z",
    "TargetProtect": "0",
    "CallReturnType": "0",
    "TargetInstructionBytesLength": "0",
    "AppPath": "C:\\WINDOWS\\system32\\svchost.exe",
    "TargetAddress": "0x0",
    "Is64Bit": "true",
    "TargetBaseAddress": "0x0",
    "CallReturnRegionSize": "0x0",
    "CallReturnInstructionBytesLength": "0",
    "TargetRegionSize": "0x0",
    "CallReturnBaseAddress": "0x0",
    "TargetModOffset": "0",
    "CallReturnProtect": "0",
    "ProcessId": "5744",
    "TargetType": "0",
    "CallReturnModOffset": "0",
    "TargetState": "0",
    "CallReturnState": "0",
    "CallReturnAddress": "0x0"
  }
}

Provenance

Where this provider's schema came from, and which Windows build it was observed on. Windows can change a provider's event schema between builds, so use this to judge whether it matches the build you collect from.

ETW provider GUID ad8aa069-a01b-40a0-ba40-948d1d8dedc5

Defined in werfault.exe, which carries the event manifest.

Observed on:

  • WS2022-20348.4893, schema read from the registered manifest, binary version 10.0.20348.2849, captured 2026-06-02
  • Win11-26200.6584, schema read from the registered manifest, binary version 10.0.26100.5074, captured 2026-06-02

Downloads