Microsoft-Windows-UAC-FileVirtualization

Seen on:

  • Windows Vista

  • Windows 2008

  • Windows 7

  • Windows 2012

  • Windows 8.0

  • Windows 8.1

  • Windows 10 (1511, 1607, 1703, 1709, 1803, 1809, 1903, 1909, 2004, 20H2)

  • Windows 2016

  • Windows 2019

  • Windows 11 (21H2)

Name: Microsoft-Windows-UAC-FileVirtualization
Identifier: {c02afc2b-e24e-4449-ad76-bcc2c2575ead}
Event message file(s): %SystemRoot%\system32\drivers\luafv.sys