$(@%SystemRoot%\system32\MemoryDiagnostic.dll,-600) $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-601) \Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents D:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;AU) 1.0 $(@%SystemRoot%\system32\MemoryDiagnostic.dll,-603) false true true IgnoreNew true true false true true true true true false PT2H true <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[Provider[@Name='Microsoft-Windows-WER-SystemErrorReporting'] and (EventID=1000 or EventID=1001 or EventID=1006)]]</Select></Query></QueryList> true <QueryList><Query Id="0" Path="Application"><Select Path="Application">*[System[Provider[@Name='Application Error'] and EventID=1000]]</Select></Query></QueryList> true <QueryList><Query Id="0" Path="System"><Select Path="System">*[System[Provider[@Name='Application Popup'] and EventID=1801]]</Select></Query></QueryList> true <QueryList><Query Id="0" Path="Microsoft-Windows-Kernel-StoreMgr/Operational"><Select Path="Microsoft-Windows-Kernel-StoreMgr/Operational">*[System[Provider[@Name='Microsoft-Windows-Kernel-StoreMgr'] and EventID=6]]</Select></Query></QueryList> S-1-5-32-544 HighestAvailable {8168e74a-b39f-46d8-adcd-7bed477b80a3} Event