SYSTEM\CurrentControlSet\Control\ServiceGroupOrder
Boot\BCD
l$ VWATAVAWH
api-ms-win-core-kernel32-legacy-l1-1-0.dll
CreateHardLinkW
@.data
D$hE3
LogMaxFileSize
NtOpenProcessTokenEx
[Exit status: SUCCESS]
Microsoft-Windows-UserPnp%4DeviceInstall.evtx
Select
Section end
RtlUnicodeToMultiByteSize
uS9t$0vM
Control\DeviceClasses\
u*9Q<|%
BSPDRIVERS
Failed to find hive under '%ws'. Error = 0x%08X
@SVWAVH
fE98A
Failed to create hive path '%ws'. Error = 0x%08X
%SystemRoot%\INF
Architecture = %s
A_A^A\_^][
L$xE3
WritePrivateProfileStringW
RtlGetOwnerSecurityDescriptor
BuildGUID
H!]8L
RegSetValueExW
L$HE3
</security>
!
NtOpenProcessToken
Microsoft-Windows-Kernel-PnP/Driver Diagnostic
UVATAVAWH
H AVH
<message string could not be built - 0x%08x>
fD9d]
api-ms-win-core-string-l1-1-0.dll
VWAVH
system
o\$PH
Microsoft Corporation
LCMapStringW
System32
memcmp
_XcptFilter
D$pH;
D$@!t$@E3
System.evtx
D9|$H
USVWATAUAVAWH
@SUVWAVH
UnmapViewOfFile
fE9,@u
GetTempPathA
t.HcC<
SECURITY
H9\$PuIH
Failed to unload hive key '%ws'. Error = 0x%08X
_initterm
uK9t$0vE
LogMask
DiUninstallDriverW
.idata$5
inbox
onecore\base\servicing\offlinehives\offlinehives.cpp
SOFTWARE\Policies\Microsoft\Windows\DeviceInstall
PA_A^A]_^[]
BootDriverFlags
api-ms-win-core-version-l1-1-0.dll
<QueryList><Query Id="0"><Select Path="Microsoft-Windows-Kernel-PnP/Configuration">*[System[Provider[@Name='Microsoft-Windows-Kernel-PnP']]]</Select></Query></QueryList>
l$PE3
SYSTEM\DriverDatabase
<QueryList><Query Id="0"><Select Path="Microsoft-Windows-UserPnp/DeviceInstall">*[System[Provider[@Name='Microsoft-Windows-UserPnp']]]</Select></Query></QueryList>
LdrGetProcedureAddress
.pdata
internal\onecorebase\inc\rtlstringutil.h
wcschr
NtQuerySystemInformation
setupact.log
Microsoft
td!\$@H
C ){(H
CoInstallers32
Enum\
D9d$ht
.didat$2
G8L9@ t
Detail::StaticStringAndBufferImpl<struct _LUNICODE_STRING,255>::Reallocate
SYSTEM\CurrentControlSet\Control\OSExtensionDatabase
Microsoft-Windows-Kernel-PnP/Boot Diagnostic
CloseServiceHandle
System\CurrentControlSet\Hardware Profiles
fD94Bu
l$(H!]
UpperFilterDefaultLevel
SetEvent
Properties
L!d$(H
L$XE3
_exit
DriverStoreImportW
fE9$Hu
SetThreadToken
fD9.u
RtlMultiByteToUnicodeN
tXfA9
LogConf
0A^_^
MoveFileExW
SOFTWARE\Policies\Microsoft\Windows\DriverSearching
SOFTWARE\Microsoft\Windows\CurrentVersion\DriverSearching
D;uHr
L;|$P
*** Source File: %s, line %ld
fD9nL
H!D$0H
ComputeServer
SOFTWARE\Microsoft\Windows Media Foundation\HardwareMFT
NtEnumerateValueKey
api-ms-win-core-file-l1-2-2.dll
UpperFilterLevels
(rfeH
Hardware Profiles
RegSaveKeyW
CM_Get_Device_Interface_ListW
@A_A^A\_]
SYSTEM\CurrentControlSet\Control\Power
\Registry\User\
*Upper
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Update\TargetingInfo\DynamicInstalled
RtlEqualSid
\REGISTRY\MACHINE\SOFTWARE\Classes
.DEFAULT
D9eHvuH
D!d$@
SYSTEM\CurrentControlSet\Control\DeviceContainers
SYSTEM\CurrentControlSet\Control\Video
D9|$@u
CM_MapCrToWin32Err
GetFileAttributesW
u7H!T$0H
Microsoft-Windows-DeviceSetupManager/Operational
RtlTimeToTimeFields
CM_Get_Device_ID_ListW
.CRT$XIA
RtlNtStatusToDosError
{%ws: %ws}
SYSTEM\Setup\Pnp
fD93u
A_A^A\_^]
|$(E3
api-ms-win-core-rtlsupport-l1-1-0.dll
D$DDtRH
hA_A^A]A\_^][
RegSaveKeyExW
%SystemRoot%\Logs\NetSetup
rBH;E
service.*.etl
D9|$pu
x UAVAWH
[%s - %s]
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
RtlImageNtHeader
FileDescription
\$ UVWH
SYSTEM\CurrentControlSet\Control
SOFTWARE\Microsoft\Windows NT\CurrentVersion\WUDF\Services
MatchingDeviceId
SYSTEM\CurrentControlSet\Hardware Profiles
UWATAVAWH
D9d$t
Firmware
Installer32
ntdll.dll
10.0.17763.1
DeviceIoControl
l$@H!\$8H
SOFTWARE\Microsoft\Windows\CurrentVersion
IconPath
L$hE3
AdjustTokenPrivileges
StorageServer
OsVersion
Microsoft-Windows-Kernel-PnP%4Boot Diagnostic.evtx
HardwareConfig
GetNativeSystemInfo
LdrLoadDll
ShutdownTime
SYSTEM\CurrentControlSet\Control\NetworkSetup
Not-null check failed: Blob
D$(E3
FirmwareBootDevice
SmallBusinessRestricted
c AUAVAWH
RtlInitUnicodeStringEx
0A_A^_^]
RtlLengthSecurityDescriptor
H!\$ I
ext-ms-win-newdev-config-l1-1-2
GetTickCount64
RtlCreateSecurityDescriptor
L$(E3
EvtExportLog
H UATAUAVAWH
%d.%d
ServerNT
UVWAVAWH
{,9{(v,
SYSTEM\CurrentControlSet\Control\CriticalDeviceDatabase
D$ H+
L!|$(E3
api-ms-win-core-file-l1-2-0.dll
WinSxS
SYSTEM\CurrentControlSet\Control\Errata
DriverStoreDeleteW
LdrGetDllHandle
A_A^A\_]
LastConfig
H!t$ I
enum-drivers
RtlSetGroupSecurityDescriptor
GetSystemFirmwareTable
D$`L+
Unloaded private hive '%ws'.
D9D$Xu
TerminateProcess
RtlFormatCurrentUserKeyPath
Personal
f9,Au
oem*.inf
SYSTEM\CurrentControlSet\Control\FirmwareResources
%u.%u
NtCreateKeyTransacted
%04d/%02d/%02d %02d:%02d:%02d.%03d
SYSTEM\CurrentControlSet\Control\ComputerName
*Lower
RtlConvertSidToUnicodeString
\$ A;
Driver Parameters
HcD$x
CompareStringW
A_A^A]
t$hfD
@A_A^A]A\_^[
u fE9
NtSetInformationThread
.text$x
T$ E3
api-ms-win-core-processenvironment-l1-1-0.dll
SetFileAttributesW
setuperr.log
wcstoul
L$HH3
NtAdjustPrivilegesToken
A^_^
GetModuleHandleW
fB9<`u
api-ms-win-core-registry-l1-1-0.dll
L$ E3
.rsrc
fD9,Nu
api-ms-win-core-shutdown-l1-1-0.dll
fD9|E
\REGISTRY\MACHINE
hal.dll
CommunicationServer
0A_A^_
Blade
OriginalFilename
%s\%s\%s\%s
%02d:%02d:%02d.%03d
TerminalServer
%SystemRoot%\Panther
ProviderName
FileTimeToSystemTime
D9t$tt
L$0fD
SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpLockdownFiles
fA9<\u
SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\Sysprep
fD94Au
add-driver
PnpHive
FSFilterClass
RtlAppendUnicodeStringToString
GetFullPathNameW
_resetstkoflw
Enterprise
Control\CriticalDeviceDatabase
@UVWATAVAWH
UVWATAUAVAWH
HcD$0
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
CloseHandle
L$8E3
H9\$Ht
fD9d$4
@.reloc
_vsnprintf
Section start
HA_A^A]A\_^[]
0x%08X
VirtualProtect
D$@L+
GetSystemTimeAsFileTime
Control
Failed to enable backup/restore privileges. Error = 0x%08X
Failed to close hive key '%ws'. Error = 0x%08X
{%ws: exit(0x%08x)}
SeShutdownPrivilege
ControlSet%03d
H!\$(H
fA9\F
T$HD;
GetKernelObjectSecurity
SYSTEM\CurrentControlSet\Control\Network
L$XfA
Microsoft-Windows-Kernel-PnP/Configuration
u4H!\$8H
|$HE3
unconfigure
SetUnhandledExceptionFilter
wcscmp
%SystemRoot%\System32\Sysprep\Panther
api-ms-win-core-file-l2-1-0.dll
EmbeddedRestricted
CM_Get_Device_Interface_List_SizeW
D$ E3
RtlFreeHeap
.text
RegLoadKeyW
Version
DriverPackageGetVersionInfoW
D$xeH
pnpstate.ini
.rdata$brc
@USVWATAUAVH
ext-ms-win-newdev-config-l1-1-1.dll
L$`E3
Unable to unload hive key '%ws' loaded by another process. Error = 0x%08X, Time = %u ms
SpVersion
Windows::StringUtil::Rtl::SubStringByCharCount
DriverStoreEnumObjectsW
A_A^A]A\_[]
>>>
.idata$4
CM_Get_Device_Interface_PropertyW
ext-ms-win-setupapi-classinstallers-l1-1-2.dll
DeviceType
CM_Get_Parent
BcdExportStore
pA_A^A\^]
DriverDate
DeviceReported
RtlGetGroupSecurityDescriptor
L$$E;
RegEnumKeyExW
Device Parameters
RtlInitAnsiString
RtlValidRelativeSecurityDescriptor
DHPRebalanceOptOut
D$@8Q
L$X;N
Files
debug
__C_specific_handler
@USVWAVAWH
u:H!l$0H
%02d/%02d/%04d
H!P I
0A_A^A]A\_^]
D;uhv
u,D8d$pL
@8|$4t
SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\PnpResources
%s\%s
CreateEventW
GetFileVersionInfoExW
<QueryList><Query Id="0"><Select Path="Microsoft-Windows-DeviceUpdateAgent/Operational">*[System[Provider[@Name='Microsoft-Windows-DeviceUpdateAgent']]]</Select></Query></QueryList>
H!|$H3
|$ AVH
LoadLibraryExA
RemoveDirectoryW
ntoskrnl.exe
RtlMultiByteToUnicodeSize
Loaded hive '%ws'. Time = %u ms
.text$mn$00
t$ WH
System\HardwareConfig
LanmanNT
SetLastError
RtlValidSecurityDescriptor
Control\DeviceContainers\
.rsrc$01
H!\$8A
ContainerID
D$DE3
9T$8t)
A_A^A]A\_^[]
D$pE3
api-ms-win-core-file-l2-1-2.dll
;\$xs
A_A^A]
Control\DevicePanels
no title
Loaded private hive '%ws'.
! !!!"!#!$!%!&!'!(!)!*!+!,!-!.!/!0!1!2!3!4!5!6!7!8!9!:!;!<!=!>!?!@!A!B!C!D!E!F!G!H!I!J!K!L!M!N!O!P!Q!R!S!T!U!V!W!X!Y!Z![!\!]!^!_!p!q!r!s!t!u!v!w!x!y!z!{!|!}!~!
H!UXM
D$Rf;
Control\DevicePanels\
api-ms-win-core-registry-l2-1-0.dll
TargetOsVersionPnpOverride
9|$Xt5
%04d/%02d/%02d
fD99t
SYSTEM\CurrentControlSet\Services
D$xfD
GetSystemWindowsDirectoryW
%ws_%ws
HcE(H
DriverStoreSetLogContext
CompatibleIDs
BUCL::Rtl::Multiply<TraitsT::TSize>(Offset, TraitsT::TCharSize, cbOffset)
!"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
System\CurrentControlSet\Control
L$ SVWH
Microsoft Corporation. All rights reserved.
RegLoadAppKeyW
Microsoft-Windows-DeviceUpdateAgent/Operational
L$PH3
NtUnloadKeyEx
D9s t
t$ UATAUAVAWH
SetEndOfFile
WindowsUpdate.*.etl
CreateDirectoryW
BUCL::Rtl::Add<TraitsT::TSize>(Offset, Count, TotalSize)
api-ms-win-core-localization-l1-2-0.dll
D$xH;
PA_A^_^]
SYSTEM\CurrentControlSet
LcA<E3
Cannot load registry hive '%ws' under a transaction. Error = 0x%08X
BackOffice
@USVWAUAVAWH
T$ H;W
CurrentType
RSDS&:h
RtlGUIDFromString
H WATAUAVAWH
Failed to delay unload hive key '%ws', hive may fail to unload later. Error = 0x%08X
REBOOT_REQUIRED
Creator
RtlUnicodeToMultiByteN
AcquireSRWLockExclusive
u8H!T$0H
`A_A^A]A\_^]
l$ E3
RegUnLoadKeyW
LegalCopyright
Microsoft-Windows-UserPnp%4ActionCenter.evtx
Control\DeviceContainers
%s\%s\%s
@USWATAUAVAWH
GetSystemTime
Failed to open hive key '%ws'. Error = 0x%08X
xA8MHM
VirtualQuery
CM_Open_Class_KeyW
D9t$pu
fD94Yu
%s.%04d%02d%02d_%02d%02d%02d.%s
D$HH;
@A_A^A]A\_^]
Microsoft-Windows-UserPnp/DeviceInstall
WHServer
fD98tB
SVATAUAVAWH
CM_Get_Sibling
ProductType = %d
Registry
.rdata$zzzdbg
|$2:u
LoadStringW
Failed to open/create classes root key. Error = 0x%08X
WAVAWH
.rdata
|$XE3
*.log
UINumber
SOFTWARE\Microsoft\Windows Media Foundation\FrameServer
IncludedInfs
api-ms-win-core-errorhandling-l1-1-0.dll
SYSTEM\CurrentControlSet\Control\Class
SYSTEM\Setup\DeviceCompat
RegDeleteKeyW
A_A^_^[]
tlD8%
EditionID
cch <= (((((SIZE_T)~((SIZE_T)0)) - (((SIZE_T)~((SIZE_T)0)) % sizeof(WCHAR))) / sizeof(WCHAR)) - 1)
D!|$0E
Failed to load private hive '%ws'. Error = 0x%08X
NtOpenThreadTokenEx
<assemblyIdentity
x AWH
fD9,Au
SYSTEM\CurrentControlSet\Control\CrashControl
fA9<@u
D8l$`@
ProductType
install
RtlInitUnicodeString
D9|$Ht
OpenProcessToken
subdirs
4~fA9
@A_A^]
GetModuleFileNameA
SetupUninstallOEMInfW
SVWATAUAVAWH
ProductArchitecture
0A_A^A\
RtlAddAccessAllowedAceEx
DeviceDesc
api-ms-win-core-sysinfo-l1-1-0.dll
RtlValidSid
memcpy
H!\$
.idata$3
RtlCopySid
SYSTEM\CurrentControlSet\Control\DeviceLocations
rvf9/tqI
Filters
.didat$5
SetErrorMode
H!|$8H
!t$@L
SecurityAppliance
RtlSubAuthoritySid
RtlSetOwnerSecurityDescriptor
RtlGetSaclSecurityDescriptor
ExpandEnvironmentStringsW
HcD$HA
DevicePath
(_^][
SYSTEM\Setup\Upgrade\Pnp
__setusermatherr
UATAUAVAWH
Exclusive
HeapFree
UWATAUAVH
SeRestorePrivilege
Opened existing hive key '%ws'.
SetupCopyOEMInfW
GetTickCount
Opened hive key '%ws'.
T$PE3
L$@E3
fE9$@u
<QueryList><Query Id="0"><Select Path="Microsoft-Windows-Kernel-PnP/Configuration Diagnostic">*[System[Provider[@Name='Microsoft-Windows-Kernel-PnP']]]</Select></Query></QueryList>
.CRT$XIY
Microsoft-Windows-DeviceUpdateAgent%4Operational.evtx
fE94@u
L$@H3
D9t$dv4I
SilentInstall
H9\$x
ClassGUID
Closed hive key '%ws'.
/>
SYSTEM\CurrentControlSet\Control\DeviceOverrides
tPfD9'uJH;
SOFTWARE
!t$(I
UWAVH
MultiByteToWideChar
ext-ms-win-newdev-config-l1-1-0
A_A^A\
api-ms-win-core-memory-l1-1-0.dll
\REGISTRY\USER\
Microsoft-Windows-DeviceSetupManager%4Admin.evtx
D;t$8
|$tfD
api-ms-win-core-io-l1-1-0.dll
SYSTEM\CurrentControlSet\Control\StateSeparation
GetFileVersionInfoSizeExW
uninstall
Hive Key Name = %s
Microsoft-Windows-Kernel-PnP%4Configuration Diagnostic.evtx
T$XE3
Default Service
@A^_]
ProductSuite
A^A\]
SYSTEM\CurrentControlSet\Control\ProductOptions
RtlHashEncodedLBlob
LocationInformation
NtSetValueKey
T$PL;
HcD$PH
ApiSetQueryApiSetPresence
t$ Lc
UpperFiltersCache
@SUVWATAVAWH
WATAUAVAWH
NtQueryKey
CM_Get_Device_IDW
L9D$H
NtCreateKey
SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\SysprepExteral
api-ms-win-security-base-l1-1-0.dll
RtlLengthSid
RtlCreateUnicodeString
{bf1a281b-ad7b-4476-ac95-f47682990ce7}
A_A^A]A\_
|$ E3
.CRT$XCAA
api-ms-win-core-sysinfo-l1-2-0.dll
D$xH#
\$ UH
!\$HH
G8L9@(t
NtQueryInformationFile
(v)eH
:/u2H
System\CurrentControlSet\Hardware Profiles\Current
.00cfg
_wcsicmp
FreeLibrary
reboot
SYSTEM\Setup\BuildUpdate
OpenThreadToken
ATAVAWH
@8|$5t
ResourcePickerExceptions
CompanyName
REBOOT_INITIATED
GetCurrentThreadId
@A_A^_
Failed to flush hive '%ws'. Error = 0x%08X
u HcA<H
@SVWATAUAVAWH
9\$pt;
force
GetProcessHeap
SetThreadPreferredUILanguages
E;,$s
Sleep
setupapi.ev3
fD9<_u
SYSTEM\CurrentControlSet\Control\NetworkSetup2
SOFTWARE\Microsoft\Windows NT\CurrentVersion
t$ UWATAVAWH
\REGISTRY\MACHINE\SYSTEM\CURRENTCONTROLSET\HARDWARE PROFILES\CURRENT
@SUVWAVAWH
{ AVH
SOFTWARE\Microsoft\Windows\CurrentVersion\Device Installer
oT$@f
RegOpenKeyExW
Windows::StringUtil::Rtl::SubStringByByteCount
u7H!\$8H
SYSTEM\CurrentControlSet\Control\Wdf
RtlAbsoluteToSelfRelativeSD
_wcsnicmp
FindFirstFileW
G8L9@0u
Events
sSOFTWARE\Classes
{%08lx-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x}
PA_A^A]A\_^]
setupapi.ev1
l$ VWAVH
SOFTWARE\Microsoft\DriverFlighting\Partner
<QueryList><Query Id="0"><Select Path="Microsoft-Windows-Kernel-PnP/Boot Diagnostic">*[System[Provider[@Name='Microsoft-Windows-Kernel-PnP']]]</Select></Query></QueryList>
{00000000-0000-0000-0000-000000000000}
CM_Get_Child
api-ms-win-core-console-l1-1-0.dll
A^_^][
XUnload Offline Registry Hive
fE94Au
Failed to open current control set key. Error = 0x%08X
NtUnloadKey2
NtOpenKeyTransacted
%s\%04u\%s\%s\%s
L$ SUVWH
H9\$@u
ext-ms-win-wevtapi-eventlog-l1-1-0.dll
WinNT
Default
[Exit]
name="Microsoft.Windows.PnpUtil"
Microsoft-Windows-DeviceSetupManager%4Operational.evtx
wcsrchr
Failed to close current control set key. Error = 0x%08X
DriverPackageOpenW
SYSTEM\CurrentControlSet\Control\Session Manager
ext-ms-win-newdev-config-l1-1-2.dll
UATAVH
D$XH+
D$PE3
OS Version = %d.%d.%d
Microsoft-Windows-DeviceSetupManager/Admin
!\$@A
D9|$tt
::RtlStringCchCopyNW(KeyNameBuffer, KeyNameBufferSize, lusKeyName.Buffer, cchKeyName)
.didat$7
NtQuerySecurityObject
T$hE3
memmove
SOFTWARE\Microsoft\Analog\Providers
setupapi.ev?
E`HcM0H
C(H!L$8H!L$HH!L$@I
fD94Fu
uiAccess="false"
D$@eH
SYSTEM\HardwareConfig
PnpUtil
FriendlyName
__set_app_type
SystemStartOptions
SYSTEM\CurrentControlSet\Control\PnP
fD9\A
T$8E3
RtlInitLUnicodeStringFromNullTerminatedString
BUCL::Rtl::Multiply<TraitsT::TSize>(Count, TraitsT::TCharSize, cbCount)
DriverStoreFindW
DriverStoreGetObjectPropertyW
040904B0
SetupOverride
CreateFileMappingW
%s\%04u\%s
@USVWAVH
RegRestoreKeyW
swprintf_s
HcA<H
A_A^A]A\_^]
ext-ms-win-wevtapi-eventlog-l1-1-2
<QueryList><Query Id="0"><Select Path="Microsoft-Windows-Kernel-PnP/Driver Diagnostic">*[System[Provider[@Name='Microsoft-Windows-Kernel-PnP']]]</Select></Query></QueryList>
L$PL+
CurrentControlSet
A_A^]
CM_Locate_DevNodeW
fA9,Xu
u6H!\$8H
RtlAcquireSRWLockExclusive
DriverVersion
configure
DeviceCharacteristics
@SUWATAUAVAWH
\Registry\Machine\
DEFAULT
!\$8H!\$0H!\$(H!\$
<QueryList><Query Id="0"><Select Path="Microsoft-Windows-DeviceSetupManager/Operational">*[System[Provider[@Name='Microsoft-Windows-DeviceSetupManager']]]</Select></Query></QueryList>
ReadFile
!\$XA
WideCharToMultiByte
RegQueryValueExW
InstallationType
t$(E3
@SVWH
^w$fA
Offline
VarFileInfo
t,D!}
Control\CoDeviceInstallers
_fmode
(reeH
Class
NtSetSecurityObject
System\CurrentControlSet\Control\DeviceContainers\%s
SingleUserTS
_vsnwprintf
Configuration
api-ms-win-core-libraryloader-l1-2-0.dll
ProcessorArchitecture
%u.%u.%u.%u
tCI9X
CreateFileW
CM_Get_Class_PropertyW
fD98t
CopyFileW
FileTimeToDosDateTime
L$PE3
unattend.xml
SYSTEM\CurrentControlSet\Control\ManufacturingMode
FormatMessageW
version="5.1.0.0"
<security>
DRIVERS
Failed to load hive from '%ws'. Error = 0x%08X, Time = %u ms
<!-- Copyright (c) Microsoft Corporation -->
<requestedExecutionLevel
A_A^A]A\_
10.0.17763.1 (WinBuild.160101.0800)
RtlPrefixUnicodeString
D84;u
GetTempFileNameA
RaiseException
ext-ms-win-newdev-config-l1-1-1
RtlCaptureContext
RtlCompareMemory
Microsoft-Windows-Kernel-PnP%4Driver Diagnostic.evtx
x ATAVAWH
D!d$0L
DataCenter
HardwareID
%04d/%02d/%02d %02d:%02d:%02d:%04d
GetLoadedHiveKeyNameInternal
GetFileSize
api-ms-win-service-management-l1-1-0.dll
::RtlIsLBlobValid(Blob)
0r1eH
` UAVAWH
A^A]A\_^[]
SYSTEM\CurrentControlSet\Control\DevicePanels
HeapReAlloc
GetStdHandle
l$(E3
A_A^_
Control\DeviceClasses
WriteFile
NtClose
api-ms-win-core-privateprofile-l1-1-0.dll
LowerFilterLevels
os: Version = %d.%d.%d, Service Pack = %d.%d, Suite = 0x%04x, ProductType = %d, Architecture = %s
pnputil.pdb
A_A^A\
RtlReleaseSRWLockExclusive
Control\DeviceInterfaces
t5fD9 u/M
D$ I;
D$0!\$(H!\$
D$0H;
KD9l$\uD
NoInstallClass
api-ms-win-core-heap-l2-1-0.dll
x AUAVAWH
api-ms-win-core-processthreads-l1-1-0.dll
Microsoft-Windows-Kernel-PnP/Configuration Diagnostic
SYSTEM\CurrentControlSet\Control\Nsi
@USVWATAVAWH
u,H!\$0H
SYSTEM\CurrentControlSet\Control\Windows
T$(E3
SYSTEM\CurrentControlSet\Control\IDConfigDB
InfSectionExt
Hardware Profiles\
TRichN
SYSTEM\CurrentControlSet\Control\CoDeviceInstallers
UINumberDescFormat
Not-null check failed: FullOfflineHiveFilePath
api-ms-win-devices-config-l1-1-1.dll
__wgetmainargs
ReleaseSRWLockExclusive
smbios.dat
SystemBootDevice
RtlLookupFunctionEntry
\REGISTRY\MACHINE\SOFTWARE\CLASSES
<QueryList><Query Id="0"><Select Path="System">*[System[Provider[@Name='Microsoft-Windows-UserPnp']]]</Select></Query></QueryList>
QueryPerformanceCounter
L$0H+
NtSetInformationFile
GetCommandLineA
SYSTEM\CurrentControlSet\Control\GraphicsDrivers
<description>PnPutil</description>
DI_DO_DEFAULT
msvcrt.dll
\$ UVWATAUAVAWH
StringFileInfo
oD$ f
t$ WAVAWH
L9.u=H
0A_A^A]A\_
L$hH;
api-ms-win-core-handle-l1-1-0.dll
BSP\Windows
H!X I
SYSTEM\CurrentControlSet\Control\SystemResources
Control\Class
%d-%d-%d
Pv/eH
HARDWARE
@A_A^A]
.text$mn
D$XE3
D!P H
Suite = 0x%04x
D$T="
RtlUnicodeStringToInteger
SOFTWARE\Policies\Microsoft\Windows\Device Metadata
Timestamp
RtlGetDaclSecurityDescriptor
SOFTWARE\Microsoft\Windows\CurrentVersion\Setup
9|$Ht
SUVWATAUAVAWH
Load Offline Registry Hive
Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic
Microsoft-Windows-UserPnp/ActionCenter
HTREE\ROOT\0
u(H!L$(H
arm64
K UATAUAVAWH
t$XE3
D9"v3fE
` AUAVAWH
RESTART_REQUIRED
E@HcM
oL$0f
setupapi.dev.log
Delay unloading hive key '%ws'.
D$ H!]
NtQueryValueKey
L$`H3
D$8E#
!p!q!r!s!t!u!v!w!x!y!z!{!|!}!~!
Failed to create hive under '%ws'. Error = 0x%08X
D$@E3
GetFileInformationByHandle
ext-ms-win-wevtapi-eventlog-l1-1-0
setupapi.ev2
.didat$6
RtlRandomEx
setupapi.app.log
t"D9U
D!t$xH
DEVICES
IsDebuggerPresent
u2H!\$0H
CM_Get_Device_ID_List_SizeW
DeleteFileA
@A_A^A\
\$4H9
Ex!uxA
[BeginLog]
RtlVirtualUnwind
USVWAUAVAWH
D9t$hv<I
System
SYSTEM\CurrentControlSet\Control\GroupOrderList
Created hive '%ws'.
H!L$PH
fD9,~u
DeviceInstance
.CRT$XCA
A^A]A\_]
34j&V
System\CurrentControlSet\Control\DeviceClasses
\REGISTRY\USER
H;}Xu
fA9;t
UnhandledExceptionFilter
DriverStoreUpdateDevicesW
Service Pack = %d.%d
Microsoft-Windows-Kernel-PnP%4Device Enumeration Diagnostic.evtx
fD9 t
ResourcePickerTags
D$@!t$@A
Unloaded hive key '%ws'.
D$Pf;
@SUVWATAUAVAWH
SOFTWARE\Microsoft\Windows Media Foundation\Platform
%u.%u.%u
MapViewOfFile
SYSTEM\CurrentControlSet\Control\NetDrivers
VS_VERSION_INFO
api-ms-win-core-synch-l1-2-0.dll
x UATAUAVAWH
t$4fA;
A_A^_^]
.CRT$XCZ
Devices
\$PE3
Driver
ext-ms-win-newdev-config-l1-1-3
Control\Class\
SeBackupPrivilege
L$pE3
.data
A_A^A]A\^[
A_A^A]A\_^][
Failed to close classes root key. Error = 0x%08X
LogPath
memset
SleepEx
CoreNT
RtlSetDaclSecurityDescriptor
LastDeleteDate
CreateFileA
ProductID
DriverDateData
\$ UVWAVAWH
GetProcAddress
Security
System32\DriverStore
</trustInfo>
ProductName
DuplicateTokenEx
NoDisplayClass
u9H!\$8H
.idata$6
T$xE3
H!|$PI!>D
D$`E3
api-ms-win-core-heap-l1-1-0.dll
Bunknown
NtEnumerateKey
%04lX
@A_A^_^]
SYSTEM\CurrentControlSet\Control\NetworkProvider
D$HE3
Software\Microsoft\Windows\CurrentVersion\Setup
SYSTEM\CurrentControlSet\Control\SystemInformation
type="win32"
PA^_^
t$ UWAVH
FileVersion
Failed to unload hive key '%ws' loaded above. Error = 0x%08X, Time = %u ms
\REGISTRY\MACHINE\SYSTEM\CurrentControlSet\Hardware Profiles\Current
p AWH
PendingFileRenameOperations
t D9#s
GetConsoleMode
t$ E3
xA^_^[
D!d$
RtlDosPathNameToNtPathName_U
UAVAWH
A_A^_
RtlFreeUnicodeString
Address
%SystemRoot%\Logs\WindowsUpdate
SetFilePointer
USVWATAVAWH
<requestedPrivileges>
SYSTEM\CurrentControlSet\Control\COM Name Arbiter
FileTimeToLocalFileTime
|$ HcL$,HcT$$HcD$(H
xA_A^A]A\_^[]
<<<
DriverDesc
D$PH;
VerQueryValueW
*** Assertion failed: %s
[Exit status: FAILURE(0x%08x)]
L$4D;
{%ws}
H!t$(H
fA90t
toupper
DeleteFileW
OSDATA\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Update\TargetingInfo\DynamicInstalled
SYSTEM\CurrentControlSet\Control\DeviceClasses
system32
ConfigFlags
UpperFilters
L$ H;
RemovalPolicy
HeapAlloc
A_A^A\_^
d$(L+
BaseContainers
G8H!|$@H!|$0eH
BuildLab
Hardware Configuration: %s
A_A^A]A\_][
D9d$0
DbgPrintEx
.data$brc
L$pH3
Services
onecore\base\lstring\lblob.cpp
H3E H3E
InternalName
Not-null check failed: KeyNameBuffer
D9l$0u>H
NoUseClass
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
api-ms-win-core-profile-l1-1-0.dll
NtOpenKey
.rsrc$02
OSData\Windows
Current
System\CurrentControlSet\
SmallBusiness
RtlEqualUnicodeString
SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing
NtDuplicateToken
;D$pv
en-US
\$(A!
FindNextFileW
Service
kernel32.dll
SuiteMask
FindClose
t$tfD
Windows
VWATAVAWH
</requestedPrivileges>
GetTempPathW
Hive Filename = %s
\$0E3
GetCurrentProcessId
L$XH3
RegCreateKeyExW
System32\config
SYSTEM\CurrentControlSet\Enum
%SystemRoot%\System32\LogFiles\SRT
}PfD97t
NtDeleteValueKey
api-ms-win-core-file-l1-1-0.dll
RegFlushKey
H9\$@t
SYSTEM\CurrentControlSet\Control\DeviceMigration
WaitForSingleObjectEx
HcD$HI
d$(E3
System\CurrentControlSet\Control\Class
WriteConsoleW
export-driver
[Boot Session: %04d/%02d/%02d %02d:%02d:%02d.%03d]
ssshim.dll
InfSection
@USWH
D9l$\
<ins>
LowerLogoVersion
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Update\TargetingInfo\Installed
processorArchitecture="amd64"
SYSTEM\CurrentControlSet\Control\SafeBoot
.CRT$XIZ
EnumPropPages32
bcd.dll
PortableOperatingSystem
!This program cannot be run in DOS mode.
A_A^A]_^[]
f98t4f9
SetupVerifyInfFileW
A_A^A]A\_^[
LdrUnloadDll
L$ H+
D$xE3
LowerFilters
A^_^[]
{%08lx-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x}\%04lX
cmd: %s
GetCurrentThread
ext-ms-win-setupapi-classinstallers-l1-1-1
ext-ms-win-wevtapi-eventlog-l1-1-3
onecore\base\lstring\lunicode_string.cpp
api-ms-win-core-synch-l1-1-0.dll
NtOpenThreadToken
u6fD9d$2u.A
%s\%04u\%s\%s
\$(E3
f9H\u
RegDeleteKeyExW
\$ E3
D9l$Tv
ConvertStringSecurityDescriptorToSecurityDescriptorW
f9<ku
$D;/s
RtlInitializeSRWLock
L$D;L$x
DiInstallDriverW
8A_A^A]A\_^[]
GetCurrentProcess
RtlRaiseStatus
G8L9@
[Exit status: SUCCESS (%s)]
d$ E3
NtQueryInformationToken
LocalFree
D$8E3
BuildLabEx
</assembly>
L$Lf;
.didat$3
A_A^_^][
Translation
RtlCreateAcl
H!\$@
SYSTEM\Setup\Upgrade\NsiMigrationRoot
<QueryList><Query Id="0"><Select Path="Microsoft-Windows-DeviceSetupManager/Admin">*[System[Provider[@Name='Microsoft-Windows-DeviceSetupManager']]]</Select></Query></QueryList>
f9,yu
fD9<Gu
System32\winevt\Logs
H9D$H
System\CurrentControlSet\Control\DevicePanels\%s
ProductVersion
L$0H;
GetTempFileNameW
FlushFileBuffers
LogLevel
%s.????????_??????.%s
SOFTWARE\Microsoft\Windows\CurrentVersion\Setup\State
SYSTEM\CurrentControlSet\Control\DevQuery
t$PE3
fD9,{u
H!](E3
.didat$4
setupapi.offline.log
SysARM32
.CRT$XIAA
@A_A^A\_^[]
fD9<Au
fB9,{u
fE97t3H
A_A^A\_^[]
!!!
Windows
amd64
TargetRing
Unloaded hive key '%ws'. Time = %u ms
Cabinet.dll
export-pnpstate
D$0E3
ext-ms-win-setupapi-classinstallers-l1-1-0
level="asInvoker"
api-ms-win-core-apiquery-l1-1-0.dll
.idata$2
NtDeleteKey
DriverStoreCopyW
api-ms-win-core-debug-l1-1-0.dll
x AVH
BootTime
Microsoft-Windows-Kernel-PnP%4Configuration.evtx
CM_Get_DevNode_PropertyW
_ultow_s
}HfD97t
|$PE3
SYSTEM
InitiateSystemShutdownExW
RtlAddAce
fD94Cu
InstallFlags
Not-null check failed: PseudoKeyOut
LowerFiltersCache
LookupPrivilegeValueW
.xdata
.gfids
< H9/u
delete-driver
Operating System
,NfD9m
<A%uDE
t ;D$0s
@.didat
ext-ms-win-wevtapi-eventlog-l1-1-1
t4A9~
LowerFilterDefaultLevel
RtlInitializeSid
SYSTEM\Setup\SetupapiLogStatus
InfPath
RtlGetVersion
<QueryList><Query Id="0"><Select Path="Microsoft-Windows-Kernel-PnP/Device Enumeration Diagnostic">*[System[Provider[@Name='Microsoft-Windows-Kernel-PnP']]]</Select></Query></QueryList>
_cexit
GetLocalTime
SOFTWARE\Microsoft\Windows\CurrentVersion\DeviceSetup
H!D$HH
|$0E3
EmbeddedNT
Microsoft PnP Utility - Tool to add, delete, export, and enumerate driver packages.
SysWOW64
SYSTEM\%ws
t$ WATAUAVAWH
ext-ms-win-setupapi-classinstallers-l1-1-2
*.txt
GetLastError
@USVWATAUAVAWH
_commode
RtlIsStateSeparationEnabled
u3H!\$8H
drvstore.dll
_amsg_exit
?terminate@@YAXXZ
|$ UAVAWH
lusSanitizedFilePath.Length != 0
ConvertSecurityDescriptorToStringSecurityDescriptorW
T$@H+
.
u4H!T$0H
Capabilities
api-ms-win-security-lsalookup-l2-1-0.dll
fD94Gu
api-ms-win-security-sddl-l1-1-0.dll
u/H!\$0H
pnputil.exe
DriverStoreEnumW
<QueryList><Query Id="0"><Select Path="Microsoft-Windows-UserPnp/ActionCenter">*[System[Provider[@Name='Microsoft-Windows-UserPnp']]]</Select></Query></QueryList>
ClassDesc
uUD!T$PH
pA_A^A]A\_^]
D$`D!d$0L!d$(H
[Device Install Log]
api-ms-win-core-timezone-l1-1-0.dll
Classes
A_A^A]A\]
GetSystemInfo
setupapi.*.log
`.rdata
Failed to unload private hive '%ws'. Error = 0x%08X
pnputil
Exported %ws
RegQueryInfoKeyW
RegCloseKey
fD9$^u
System\CurrentControlSet\Enum
RtlAllocateHeap
T$ H+
fD9'u