The event that is logged in the Application log resembles the following:
Log Name: Application
Source: VSS
Date: <date and time>
Event ID: 12333
Task Category: None
Level: Warning
User: N/A
Computer: <computer name>
Description: Volume Shadow Copy Warning: The provider has reported a storage identifier
that is not supported by VSS.
The following are the suggested operations for this VSS warning.
Operation:- Check whether the volume is supported by a provider.
- Add a volume to a shadow copy set.
Context:Execution Context: Provider
Provider Name: <provider name>
Provider Version: 1.0
Provider ID: {b57190af-454a-4dd0-8afd-e57facd5d9af}
Volume Name: \\?\Volume{5b1ced58-7dd1-11dc-b4df-00065ba14874}\
Snapshot Context: 25
Execution Context: Coordinator
Provider ID: {00000000-0000-0000-0000-000000000000}
Volume Name: \\?\Volume{5b1ced58-7dd1-11dc-b4df-00065ba14874}\
Execution Context: Coordinator
Friendly view of the event data:- System
- Provider
[ Name] VSS
- EventID 12333
[ Qualifiers] 0
Level 3
Task 0
Keywords 0x80000000000000
- TimeCreated
[ SystemTime] <time>
EventRecordID 279
Channel Application
Computer <computer name>
Security
- EventData
1
1
60
0
1
Binary data:
In Words
0000: 6F43202D 203A6564 48524F43 43545557
0008: 30303030 38303331 6143202D 203A6C6C
0010: 48524F43 43545557 30303030 35333231
0018: 4950202D 20203A44 30303030 30323031
0020: 4954202D 20203A44 30303030 32393132
0028: 4D43202D 20203A44 575C3A43 6F646E69
0030: 735C7377 65747379 5C32336D 76737376
0038: 78652E63 20202065 7355202D 203A7265
0040: 4120544E 4F485455 59544952 5359535C
0048: 204D4554 20202020 6953202D 20203A64
0050: 2D312D53 38312D35
In Bytes
0000: 2D 20 43 6F 64 65 3A 20 - Code:
0008: 43 4F 52 48 57 55 54 43 CORHWUTC
0010: 30 30 30 30 31 33 30 38 00001308
0018: 2D 20 43 61 6C 6C 3A 20 - Call:
0020: 43 4F 52 48 57 55 54 43 CORHWUTC
0028: 30 30 30 30 31 32 33 35 00001235
0030: 2D 20 50 49 44 3A 20 20 - PID:
0038: 30 30 30 30 31 30 32 30 00001020
0040: 2D 20 54 49 44 3A 20 20 - TID:
0048: 30 30 30 30 32 31 39 32 00002192
0050: 2D 20 43 4D 44 3A 20 20 - CMD:
0058: 43 3A 5C 57 69 6E 64 6F C:\Windo
0060: 77 73 5C 73 79 73 74 65 ws\syste
0068: 6D 33 32 5C 76 73 73 76 m32\vssv
0070: 63 2E 65 78 65 20 20 20 c.exe
0078: 2D 20 55 73 65 72 3A 20 - User:
0080: 4E 54 20 41 55 54 48 4F NT AUTHO
0088: 52 49 54 59 5C 53 59 53 RITY\SYS
0090: 54 45 4D 20 20 20 20 20 TEM
0098: 2D 20 53 69 64 3A 20 20 - Sid:
00a0: 53 2D 31 2D 35 2D 31 38 S-1-5-18