mrcbt
63 events across 1 channel
Event ID 1: Driver Loaded version.
#Event ID 3: The $LogFile restart count has changed on device DeviceName.
#Event ID 4: Successfully attached to device DeviceName.
#Event ID 5: Device DeviceName has been stopped (IRP_MN_STOP_DEVICE).
#Event ID 6: Device DeviceName has been removed (IRP_MN_REMOVE_DEVICE).
#Event ID 7: Device DeviceName has been surprise removed (IRP_MN_SURPRISE_REMOVAL).
#Event ID 8: Tracking has been enabled on device DeviceName.
#Event ID 9: Tracking has been disabled on device DeviceName.
#Event ID 10: MRCBT has detected that Raxco Perfectdisk DefragFs has been scheduled to perform a boot-time defrag of one or more volumes.
#Message #
Event ID 11: Failed to enable tracking on device DeviceName.
#Event ID 12: IRP_MJ_SHUTDOWN received on device DeviceName.
#Event ID 13: IOCTL_MRCBT_QUERY_VOLUME_TRACKING_INFORMATION failed on device DeviceName with status Status.
#Description
IOCTL_MRCBT_QUERY_VOLUME_TRACKING_INFORMATION failed on device DeviceName with status Status.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 14: Invalidating boot sector on device DeviceName.
#Event ID 15: The NTFS $LogFile has been reset.
#Event ID 16: Failed to allocate file buffer with size ReferenceCount for device DeviceName.
#Event ID 17: Reading boot sector on device DeviceName.
#Event ID 18: The file-system on device DeviceName is not supported.
#Event ID 19: The volume DeviceName is offline.
#Event ID 20: The file-system on device DeviceName is locked.
#Event ID 21: Failed to create log file with status ErrorCode.
#Event ID 1000: Received GUID_TARGET_DEVICE_REMOVE_COMPLETE for device DeviceName with ReferenceCount ReferenceCount.
#Event ID 1001: Received GUID_IO_VOLUME_MOUNT for device DeviceName.
#Event ID 1002: Received GUID_IO_VOLUME_DISMOUNT for device DeviceName.
#Event ID 1003: Received GUID_IO_VOLUME_PHYSICAL_CONFIGURATION_CHANGE for device DeviceName.
#Event ID 1004: Failed to initialize the tracking file on device DeviceName.
#Event ID 1005: PlugPlay notification has been registered for device DeviceName with ReferenceCount ReferenceCount.
#Event ID 1006: PlugPlay notification has been unregistered for device DeviceName with ReferenceCount ReferenceCount.
#Event ID 1007: Received GUID_IO_VOLUME_LOCK_FAILED for device DeviceName.
#Event ID 1008: Received GUID_IO_VOLUME_UNLOCK for device DeviceName.
#Event ID 1009: Received GUID_TARGET_DEVICE_REMOVE_CANCELLED for device DeviceName.
#Event ID 1010: Received GUID_TARGET_DEVICE_QUERY_REMOVE for device DeviceName.
#Event ID 1011: Received GUID_IO_VOLUME_LOCK for device DeviceName.
#Event ID 1012: Received GUID_IO_VOLUME_FVE_STATUS_CHANGE for device DeviceName.
#Event ID 1013: IRP_MJ_READ failed on device DeviceName with status ReferenceCount.
#Event ID 1014: IRP_MJ_WRITE failed on device DeviceName with status ReferenceCount.
#Event ID 1015: Received GUID_IO_VOLUME_SIZE_CHANGE for device DeviceName.
#Event ID 1016: Received GUID_IO_VOLUME_DISMOUNT_FAILED for device DeviceName.
#Event ID 1017: Received GUID_IO_VOLUME_NEED_CHKDSK for device DeviceName.
#Event ID 2001: Failed to open an existing tracking file on device DeviceName with status ReferenceCount.
#Event ID 2002: Failed to protect the tracking file on device DeviceName with status ReferenceCount.
#Event ID 2003: Failed to get retrieval pointers for the tracking file on device DeviceName with status ReferenceCount.
#Event ID 2004: The tracking file on device DeviceName is corrupt.
#Event ID 2005: Failed to create the tracking file on device DeviceName with status Status.
#Description
Failed to create the tracking file on device DeviceName with status Status.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 2006: Failed to write to the tracking file on device DeviceName with status Status.
#Description
Failed to write to the tracking file on device DeviceName with status Status.
Message #
Fields #
| Name | Description |
|---|---|
DeviceName UnicodeString | |
Status UInt32 | NTSTATUS reference |
Event ID 2007: The checksum for the tracking file on device DeviceName is incorrect.
#Event ID 2008: The previous session did not finalize the tracking file on device DeviceName.
#Event ID 2009: Failed to reopen an existing tracking file on device DeviceName with status ReferenceCount.
#Event ID 3001: Received IRP_MN_SET_POWER with type of SystemPowerState and SystemState ReferenceCount for device DeviceName.
#Event ID 3002: Received IRP_MN_SET_POWER with type of DevicePowerState and DeviceState ReferenceCount for device DeviceName.
#Event ID 3003: Received IRP_MN_QUERY_POWER with type of SystemPowerState and SystemState ReferenceCount for device DeviceName.
#Event ID 3004: Received IRP_MN_QUERY_POWER with type of DevicePowerState and DeviceState ReferenceCount for device DeviceName.
#Event ID 4004: Received IRP_MJ_WRITE request at DISPATCH_LEVEL for device DeviceName.
#Event ID 5001: An error was encountered while processing the Ntfs system metadata on line SourceLine.
#Description
An error was encountered while processing the Ntfs system metadata on line SourceLine. Status Status.
Message #
Fields #
| Name | Description |
|---|---|
SourceLine UInt32 | |
Status UInt32 | NTSTATUS reference |
Event ID 5002: The size of the $LogFile on device DeviceName is Size bytes with Fragments fragments.
#Event ID 5003: Failed to read the $LogFile metadata for device DeviceName.
#Event ID 5004: Failed to read Length bytes from device DeviceName with status Status.
#Description
Failed to read Length bytes from device DeviceName with status Status.
Message #
Fields #
| Name | Description |
|---|---|
Length UInt32 | |
DeviceName UnicodeString | |
Status UInt32 | NTSTATUS reference |