Jump to content

An event in the Event Viewer - The access history in hive


Recommended Posts

I've found this event in the Viewer. Does anyone know what does it mean and if it's something that I should be worrying about? It's Windows 11 and I don't use any other devices that are connected to this PC.

Edit: I've checked the Viewer after my PC's sudden reboot.

The access history in hive \??\C:\ProgramData\Packages\MicrosoftWindows.CrossDevice_cw5n1h2txyewy\S-1-5-21-843964876-1476730523-4276338635-1001\SystemAppData\Helium\Cache\dddc6edc5efe05d0_COM15.dat was cleared updating (1) keys and creating (1) modified pages.

I'm posting copied event below (it's in Polish though).

Nazwa dziennika:System
Źródło:        Microsoft-Windows-Kernel-General
Data:          16.04.2024 17:57:47
Identyfikator zdarzenia:16
Kategoria zadania:Brak
Poziom:        Informacje
Słowa kluczowe:
Użytkownik:    SYSTEM
Komputer:      MiloszKomputer
Opis:
Historia dostępu do gałęzi \??\C:\ProgramData\Packages\MicrosoftWindows.CrossDevice_cw5n1h2txyewy\S-1-5-21-843964876-1476730523-4276338635-1001\SystemAppData\Helium\Cache\dddc6edc5efe05d0_COM15.dat została wyczyszczona. Zaktualizowano klucze (1) i utworzono zmodyfikowane strony (1).
Kod XML zdarzenia:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Kernel-General" Guid="{a68ca8b7-004f-d7b6-a698-07e2de0f1f5d}" />
    <EventID>16</EventID>
    <Version>0</Version>
    <Level>4</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2024-04-16T15:57:47.4944088Z" />
    <EventRecordID>170270</EventRecordID>
    <Correlation />
    <Execution ProcessID="952" ThreadID="1232" />
    <Channel>System</Channel>
    <Computer>MiloszKomputer</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData>
    <Data Name="HiveNameLength">170</Data>
    <Data Name="HiveName">\??\C:\ProgramData\Packages\MicrosoftWindows.CrossDevice_cw5n1h2txyewy\S-1-5-21-843964876-1476730523-4276338635-1001\SystemAppData\Helium\Cache\dddc6edc5efe05d0_COM15.dat</Data>
    <Data Name="KeysUpdated">1</Data>
    <Data Name="DirtyPages">1</Data>
  </EventData>
</Event>

Edited by Manaphy0220
Link to post
Share on other sites

  • Root Admin

It's just an information event. I would not worry about it.

If you're concerned then perhaps do a couple of antivirus scans but Trojans and other threats are not well known for documenting their activity, thus I'm sure it's quite normal.

If you'd like to run some AV scans though, please let me know.

Cheers

 

 

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.