- Joined
- Jan 14, 2017
- Messages
- 4
- Reaction score
- 0
I just wonder if this event will tell if there was an USB memory mounted on the PC?
Eventxmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-Kernel-General"Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
<EventID>16</EventID>
<Version>0</Version>
<Level>4</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2016-10-27T05:03:05.198973100Z" />
<EventRecordID>3913</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="7560" />
<Channel>System</Channel>
<Computer>AndersH2015</Computer>
<Security UserID="S-1-5-18" />
</System>
- <EventData>
<Data Name="HiveNameLength">46</Data>
<DataName="HiveName">\Device\HarddiskVolume2\EFI\Microsoft\Boot\BCD</Data>
<Data Name="KeysUpdated">103</Data>
<Data Name="DirtyPages">11</Data>
</EventData>
</Event>
Eventxmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-Kernel-General"Guid="{A68CA8B7-004F-D7B6-A698-07E2DE0F1F5D}" />
<EventID>16</EventID>
<Version>0</Version>
<Level>4</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2016-10-27T05:03:05.198973100Z" />
<EventRecordID>3913</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="7560" />
<Channel>System</Channel>
<Computer>AndersH2015</Computer>
<Security UserID="S-1-5-18" />
</System>
- <EventData>
<Data Name="HiveNameLength">46</Data>
<DataName="HiveName">\Device\HarddiskVolume2\EFI\Microsoft\Boot\BCD</Data>
<Data Name="KeysUpdated">103</Data>
<Data Name="DirtyPages">11</Data>
</EventData>
</Event>