[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhYt9TDQf-EtqIn0t_fYnmgWERP4dynuLr8_NZGBPe3c":3},{"id":4,"question":5,"answer":6,"answerHtml":7,"slug":8,"keywords":9,"article":10,"status":34,"aiModel":39,"aiConfidence":39,"updatedAt":51,"createdAt":51,"_status":50},827,"What is an EVT file and which Windows systems use it?","An EVT (Windows Event Viewer Log) file is the legacy format used to store system log information before Windows Vista, commonly found on Windows NT 4, 2000, XP, and 2003. It differs from the newer [Windows XML Event Log (EVTX)](\u002Fnews\u002Fwindows-xml-event-log-evtx-single-log-deletion-part-3-deleting-a-single-log-record-from-the-current-system-by-releasing-file-handles) format introduced in Windows 7 and later. Common EVT logs include AppEvent.Evt, SecEvent.Evt, and SysEvent.Evt stored in `%systemroot%\\system32\\config`.","\u003Cp>An EVT (Windows Event Viewer Log) file is the legacy format used to store system log information before Windows Vista, commonly found on Windows NT 4, 2000, XP, and 2003. It differs from the newer [Windows XML Event Log (EVTX)](\u002Fnews\u002Fwindows-xml-event-log-evtx-single-log-deletion-part-3-deleting-a-single-log-record-from-the-current-system-by-releasing-file-handles) format introduced in Windows 7 and later. Common EVT logs include AppEvent.Evt, SecEvent.Evt, and SysEvent.Evt stored in `%systemroot%\\system32\\config`.\u003C\u002Fp>\u003Cp>\u003Ca href=\"\u002Fnews\u002Fwindows-event-viewer-log-evt-single-log-deletion-part-1-deletion-approach-and-examples\">Read the related One Day Sec article\u003C\u002Fa>\u003C\u002Fp>","what-is-an-evt-file-and-which-windows-systems-use-it-1777481514359","EVT, Windows Event Viewer Log, EVTX, system logs, Application log, Security log, System log",{"id":11,"title":12,"slug":13,"description":14,"content":15,"contentHtml":30,"cover":31,"author":32,"views":19,"readingTime":33,"status":34,"publishedAt":35,"seo":36,"tags":41,"qaPairs":42,"meta":47,"updatedAt":48,"createdAt":49,"_status":50},203,"Windows Event Viewer Log (EVT) Single Log Deletion (Part 1) – Deletion Approach and Examples","windows-event-viewer-log-evt-single-log-deletion-part-1-deletion-approach-and-examples","Learn how to delete single logs in Windows EVT files. Covers EVT format basics, deletion approach, and practical examples for Windows XP\u002F2003 systems.",{"root":16},{"type":17,"format":18,"indent":19,"version":20,"children":21,"direction":29},"root","",0,1,[22],{"type":23,"format":18,"indent":19,"version":20,"children":24,"direction":29},"paragraph",[25],{"mode":26,"text":27,"type":28,"style":18,"detail":19,"format":19,"version":20},"normal","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The first article in the series on Windows Event Viewer Log (EVT) single log deletion, focusing on introducing the basics of evt log files and the implementation approach and examples for deleting single logs\u003C\u002Fp>\u003Cp>Windows Event Viewer Log (EVT) is applicable to the following Windows systems:\u003C\u002Fp>\u003Cul>\u003Cli>Windows NT 4\u003C\u002Fli>\u003Cli>Windows 2000\u003C\u002Fli>\u003Cli>Windows XP\u003C\u002Fli>\u003Cli>Windows 2003\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Previously introduced Windows XML Event Log (EVTX) is applicable to Windows 7 and later systems\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>evt file format\u003C\u002Fli>\u003Cli>Approach to deleting a single log entry\u003C\u002Fli>\u003Cli>Example of deleting a single log entry\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The evt file format refers to files used to store system log information before Windows Vista, most commonly found in XP and Server 2003 systems\u003C\u002Fp>\u003Cp>Default log file storage location: %systemroot%\\system32\\config\u003C\u002Fp>\u003Cp>Common log files:\u003C\u002Fp>\u003Cul>\u003Cli>Application log: AppEvent.Evt\u003C\u002Fli>\u003Cli>Security log: SecEvent.Evt\u003C\u002Fli>\u003Cli>System log: SysEvent.Evt\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Methods for viewing logs\u003C\u002Fh3>\u003Ch4>(1) Via interface\u003C\u002Fh4>\u003Cp>cmd -&gt; eventvwr\u003C\u002Fp>\u003Ch4>(2) Via command line\u003C\u002Fh4>\u003Cp>Query system logs and output detailed information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cscript c:\\windows\\system32\\eventquery.vbs \u002Fl system \u002Fv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query system logs within the specified time range (2017.12.05,01:00:00AM to 2018.01.02,10:00:00AM):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cscript c:\\windows\\system32\\eventquery.vbs \u002Fl system \u002Ffi \"Datetime eq 12\u002F05\u002F2017,01:00:00AM-01\u002F02\u002F2018,10:00:00AM\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Official parameter description:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-xp\u002Fbb490900(v=technet.10)\u003C\u002Fp>\u003Ch3>EVT file format\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Flibyal\u002Flibevt\u002Fblob\u002Fmaster\u002Fdocumentation\u002FWindows%20Event%20Log%20(EVT)%20format.asciidoc\u003C\u002Fp>\u003Cp>The EVT file structure consists of three parts:\u003C\u002Fp>\u003Cul>\u003Cli>file header\u003C\u002Fli>\u003Cli>event records\u003C\u002Fli>\u003Cli>end of file record\u003C\u002Fli>\u003Cli>trailing empty values\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The file header stores basic information of the EVTX file. Notably, it includes the End of file record offset, Last (newest) record number, and Maximum file size.\u003C\u002Fp>\u003Cp>Event records correspond to the content of each log entry, notably the Record number\u003C\u002Fp>\u003Cp>End of file record has a fixed structure, notably the End of file record offset and Last (newest) record number\u003C\u002Fp>\u003Cp>Trailing empty values are used to pad the file length, with arbitrary content that does not affect the validity of the evtx file\u003C\u002Fp>\u003Ch4>(1) File header\u003C\u002Fh4>\u003Cp>Format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Flibyal\u002Flibevt\u002Fblob\u002Fmaster\u002Fdocumentation\u002FWindows%20Event%20Log%20(EVT)%20format.asciidoc#2-file-header\u003C\u002Fp>\u003Cp>First 48 bits, no checksum flag\u003C\u002Fp>\u003Cp>The following five items must be correctly configured:\u003C\u002Fp>\u003Cul>\u003Cli>First (oldest) record offset\u003C\u002Fli>\u003Cli>End of file record offset\u003C\u002Fli>\u003Cli>Last (newest) record number\u003C\u002Fli>\u003Cli>First (oldest) record number\u003C\u002Fli>\u003Cli>Maximum file size\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(2) Event records\u003C\u002Fh4>\u003Cp>Format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Flibyal\u002Flibevt\u002Fblob\u002Fmaster\u002Fdocumentation\u002FWindows%20Event%20Log%20(EVT)%20format.asciidoc#3-event-record\u003C\u002Fp>\u003Cp>Modifying the Record number (even if duplicated) does not affect normal log file recognition\u003C\u002Fp>\u003Ch4>(3) end of file record\u003C\u002Fh4>\u003Cp>Format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Flibyal\u002Flibevt\u002Fblob\u002Fmaster\u002Fdocumentation\u002FWindows%20Event%20Log%20(EVT)%20format.asciidoc#4-end-of-file-record\u003C\u002Fp>\u003Cp>Similar to file header, the following four items must be correctly configured:\u003C\u002Fp>\u003Cul>\u003Cli>First (oldest) record offset\u003C\u002Fli>\u003Cli>End of file record offset\u003C\u002Fli>\u003Cli>Last (newest) record number\u003C\u002Fli>\u003Cli>First (oldest) record number\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Deletion approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Since EVT files lack checksums, we can use the following process when deleting individual log entries:\u003C\u002Fp>\u003Cul>\u003Cli>Directly delete the content of a specific log entry\u003C\u002Fli>\u003Cli>Update Record numbers for subsequent logs (decrement by 1)\u003C\u002Fli>\u003Cli>Update five items in the file header\u003C\u002Fli>\u003Cli>Synchronously update four items in the end of file record\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Delete instance\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>View logs:\u003C\u002Fp>\u003Cp>cmd -&gt; eventvwr\u003C\u002Fp>\u003Cp>Obtain a total of 9 logs under the System category, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017290246_0_864ccf4a19.jpeg\">\u003C\u002Fp>\u003Cp>Select System, right-click, choose Save Log File As..., and save the log file as sys1.evt\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Copying the file SysEvent.Evt from %systemroot%\\system32\\config results in a log file that cannot be opened normally\u003C\u002Fp>\u003Cp>Reason:\u003C\u002Fp>\u003Cp>The file header of the evt file in %systemroot%\\system32\\config was not synchronously updated, causing a format error when opening the evt file\u003C\u002Fp>\u003Cp>After repairing the file header, the file can be opened normally\u003C\u002Fp>\u003Cp>sys1.evt has been uploaded, download link:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>Open this log in eventvwr, select System as Log Type, successfully opened\u003C\u002Fp>\u003Cp>The file contains 9 logs, now attempt to delete the 5th log, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017320988_1_0e2e434269.jpeg\">\u003C\u002Fp>\u003Ch3>1. Locate the 5th log\u003C\u002Fh3>\u003Cp>Search for 4c664c6505000000\u003C\u002Fp>\u003Cp>4c664c65 is ELF_LOG_SIGNATURE, a fixed structure\u003C\u002Fp>\u003Cp>05000000 is the Record number\u003C\u002Fp>\u003Ch3>2. Delete the 5th log\u003C\u002Fh3>\u003Cp>Starting position is the 4 bytes before 4c664c6505000000\u003C\u002Fp>\u003Cp>Delete length is the 4 bytes before 4c664c6505000000\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017363654_2_2c2ebedfc5.jpeg\">\u003C\u002Fp>\u003Cp>Starting position is 0x320h\u003C\u002Fp>\u003Cp>Delete length is 0x00000070h (i.e., 112)\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Operations performed via UltraEdit:\u003C\u002Fp>\u003Cp>Select the starting position at 0x320h, right-click, choose Hex Insert\u002FDelete\u003C\u002Fp>\u003Cp>Select Delete, enter the number of bytes to delete: 112\u003C\u002Fp>\u003Ch3>3. Update the Record number for subsequent logs (decrease by 1)\u003C\u002Fh3>\u003Cp>Specifically, the Record numbers for the 6th, 7th, 8th, and 9th logs\u003C\u002Fp>\u003Ch3>4. Update three items in the file header\u003C\u002Fh3>\u003Ch4>(1) End of file record offset\u003C\u002Fh4>\u003Cp>Located at offset 20 in the File header, 4 bytes\u003C\u002Fp>\u003Cp>Stores the starting address of the end of file record\u003C\u002Fp>\u003Cp>Two calculation methods:\u003C\u002Fp>\u003Col>\u003Cli>Original offset address - length of the 5th log (112)\u003C\u002Fli>\u003Cli>Locate the end of file record directly to obtain it\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The new End of file record offset is 0x00000640h\u003C\u002Fp>\u003Ch4>(2) Last (newest) record number\u003C\u002Fh4>\u003Cp>4 bytes at offset 24 in the File header\u003C\u002Fp>\u003Cp>Decrement the value by 1, changing from 0x0000000A to 0x00000009\u003C\u002Fp>\u003Ch4>(3) Maximum file size\u003C\u002Fh4>\u003Cp>4 bytes at offset 32 in the File header\u003C\u002Fp>\u003Cp>The new Maximum file size is 0x00000668h\u003C\u002Fp>\u003Ch3>5. Synchronously update two items in the end of file record\u003C\u002Fh3>\u003Cul>\u003Cli>End of file record offset\u003C\u002Fli>\u003Cli>Last (newest) record number\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Save the modified file as sys2.evt\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>Successfully deleted the 5th log entry\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fuploads\u002Fdocx_image_1770017392740_3_8189e89a21.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the basics of evt log files and the implementation approach for deleting individual log entries, with a practical demonstration on how to modify evt files to hide a specific log.\u003C\u002Fp>\u003Cp>The next article will follow the previous research approach to explain how to write a program for automatically deleting logs from a specified date.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>","text","ltr","\u003Chtml>\u003Chead>\u003C\u002Fhead>\u003Cbody>\u003Ch2>0x00 Preface\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The first article in the series on Windows Event Viewer Log (EVT) single log deletion, focusing on introducing the basics of evt log files and the implementation approach and examples for deleting single logs\u003C\u002Fp>\u003Cp>Windows Event Viewer Log (EVT) is applicable to the following Windows systems:\u003C\u002Fp>\u003Cul>\u003Cli>Windows NT 4\u003C\u002Fli>\u003Cli>Windows 2000\u003C\u002Fli>\u003Cli>Windows XP\u003C\u002Fli>\u003Cli>Windows 2003\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Previously introduced Windows XML Event Log (EVTX) is applicable to Windows 7 and later systems\u003C\u002Fp>\u003Ch2>0x01 Introduction\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article will cover the following topics:\u003C\u002Fp>\u003Cul>\u003Cli>evt file format\u003C\u002Fli>\u003Cli>Approach to deleting a single log entry\u003C\u002Fli>\u003Cli>Example of deleting a single log entry\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x02 Basic Knowledge\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>The evt file format refers to files used to store system log information before Windows Vista, most commonly found in XP and Server 2003 systems\u003C\u002Fp>\u003Cp>Default log file storage location: %systemroot%\\system32\\config\u003C\u002Fp>\u003Cp>Common log files:\u003C\u002Fp>\u003Cul>\u003Cli>Application log: AppEvent.Evt\u003C\u002Fli>\u003Cli>Security log: SecEvent.Evt\u003C\u002Fli>\u003Cli>System log: SysEvent.Evt\u003C\u002Fli>\u003C\u002Ful>\u003Ch3>Methods for viewing logs\u003C\u002Fh3>\u003Ch4>(1) Via interface\u003C\u002Fh4>\u003Cp>cmd -&gt; eventvwr\u003C\u002Fp>\u003Ch4>(2) Via command line\u003C\u002Fh4>\u003Cp>Query system logs and output detailed information:\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cscript c:\\windows\\system32\\eventquery.vbs \u002Fl system \u002Fv\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Query system logs within the specified time range (2017.12.05,01:00:00AM to 2018.01.02,10:00:00AM):\u003C\u002Fp>\u003Ctable>\u003Ctbody>\u003Ctr>\u003Ctd>\u003Cp>cscript c:\\windows\\system32\\eventquery.vbs \u002Fl system \u002Ffi \"Datetime eq 12\u002F05\u002F2017,01:00:00AM-01\u002F02\u002F2018,10:00:00AM\"\u003C\u002Fp>\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003Cp>Official parameter description:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fdocs.microsoft.com\u002Fen-us\u002Fprevious-versions\u002Fwindows\u002Fit-pro\u002Fwindows-xp\u002Fbb490900(v=technet.10)\u003C\u002Fp>\u003Ch3>EVT file format\u003C\u002Fh3>\u003Cp>Reference materials:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Flibyal\u002Flibevt\u002Fblob\u002Fmaster\u002Fdocumentation\u002FWindows%20Event%20Log%20(EVT)%20format.asciidoc\u003C\u002Fp>\u003Cp>The EVT file structure consists of three parts:\u003C\u002Fp>\u003Cul>\u003Cli>file header\u003C\u002Fli>\u003Cli>event records\u003C\u002Fli>\u003Cli>end of file record\u003C\u002Fli>\u003Cli>trailing empty values\u003C\u002Fli>\u003C\u002Ful>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>The file header stores basic information of the EVTX file. Notably, it includes the End of file record offset, Last (newest) record number, and Maximum file size.\u003C\u002Fp>\u003Cp>Event records correspond to the content of each log entry, notably the Record number\u003C\u002Fp>\u003Cp>End of file record has a fixed structure, notably the End of file record offset and Last (newest) record number\u003C\u002Fp>\u003Cp>Trailing empty values are used to pad the file length, with arbitrary content that does not affect the validity of the evtx file\u003C\u002Fp>\u003Ch4>(1) File header\u003C\u002Fh4>\u003Cp>Format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Flibyal\u002Flibevt\u002Fblob\u002Fmaster\u002Fdocumentation\u002FWindows%20Event%20Log%20(EVT)%20format.asciidoc#2-file-header\u003C\u002Fp>\u003Cp>First 48 bits, no checksum flag\u003C\u002Fp>\u003Cp>The following five items must be correctly configured:\u003C\u002Fp>\u003Cul>\u003Cli>First (oldest) record offset\u003C\u002Fli>\u003Cli>End of file record offset\u003C\u002Fli>\u003Cli>Last (newest) record number\u003C\u002Fli>\u003Cli>First (oldest) record number\u003C\u002Fli>\u003Cli>Maximum file size\u003C\u002Fli>\u003C\u002Ful>\u003Ch4>(2) Event records\u003C\u002Fh4>\u003Cp>Format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Flibyal\u002Flibevt\u002Fblob\u002Fmaster\u002Fdocumentation\u002FWindows%20Event%20Log%20(EVT)%20format.asciidoc#3-event-record\u003C\u002Fp>\u003Cp>Modifying the Record number (even if duplicated) does not affect normal log file recognition\u003C\u002Fp>\u003Ch4>(3) end of file record\u003C\u002Fh4>\u003Cp>Format reference:\u003C\u002Fp>\u003Cp>https:\u002F\u002Fgithub.com\u002Flibyal\u002Flibevt\u002Fblob\u002Fmaster\u002Fdocumentation\u002FWindows%20Event%20Log%20(EVT)%20format.asciidoc#4-end-of-file-record\u003C\u002Fp>\u003Cp>Similar to file header, the following four items must be correctly configured:\u003C\u002Fp>\u003Cul>\u003Cli>First (oldest) record offset\u003C\u002Fli>\u003Cli>End of file record offset\u003C\u002Fli>\u003Cli>Last (newest) record number\u003C\u002Fli>\u003Cli>First (oldest) record number\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x03 Deletion approach\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>Since EVT files lack checksums, we can use the following process when deleting individual log entries:\u003C\u002Fp>\u003Cul>\u003Cli>Directly delete the content of a specific log entry\u003C\u002Fli>\u003Cli>Update Record numbers for subsequent logs (decrement by 1)\u003C\u002Fli>\u003Cli>Update five items in the file header\u003C\u002Fli>\u003Cli>Synchronously update four items in the end of file record\u003C\u002Fli>\u003C\u002Ful>\u003Ch2>0x04 Delete instance\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>View logs:\u003C\u002Fp>\u003Cp>cmd -&gt; eventvwr\u003C\u002Fp>\u003Cp>Obtain a total of 9 logs under the System category, as shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017290246_0_864ccf4a19-1.jpeg\">\u003C\u002Fp>\u003Cp>Select System, right-click, choose Save Log File As..., and save the log file as sys1.evt\u003C\u002Fp>\u003Cp>\u003Cstrong>Note:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Copying the file SysEvent.Evt from %systemroot%\\system32\\config results in a log file that cannot be opened normally\u003C\u002Fp>\u003Cp>Reason:\u003C\u002Fp>\u003Cp>The file header of the evt file in %systemroot%\\system32\\config was not synchronously updated, causing a format error when opening the evt file\u003C\u002Fp>\u003Cp>After repairing the file header, the file can be opened normally\u003C\u002Fp>\u003Cp>sys1.evt has been uploaded, download link:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>Open this log in eventvwr, select System as Log Type, successfully opened\u003C\u002Fp>\u003Cp>The file contains 9 logs, now attempt to delete the 5th log, as shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017320988_1_0e2e434269-1.jpeg\">\u003C\u002Fp>\u003Ch3>1. Locate the 5th log\u003C\u002Fh3>\u003Cp>Search for 4c664c6505000000\u003C\u002Fp>\u003Cp>4c664c65 is ELF_LOG_SIGNATURE, a fixed structure\u003C\u002Fp>\u003Cp>05000000 is the Record number\u003C\u002Fp>\u003Ch3>2. Delete the 5th log\u003C\u002Fh3>\u003Cp>Starting position is the 4 bytes before 4c664c6505000000\u003C\u002Fp>\u003Cp>Delete length is the 4 bytes before 4c664c6505000000\u003C\u002Fp>\u003Cp>As shown below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017363654_2_2c2ebedfc5-1.jpeg\">\u003C\u002Fp>\u003Cp>Starting position is 0x320h\u003C\u002Fp>\u003Cp>Delete length is 0x00000070h (i.e., 112)\u003C\u002Fp>\u003Cp>\u003Cstrong>Supplement:\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>Operations performed via UltraEdit:\u003C\u002Fp>\u003Cp>Select the starting position at 0x320h, right-click, choose Hex Insert\u002FDelete\u003C\u002Fp>\u003Cp>Select Delete, enter the number of bytes to delete: 112\u003C\u002Fp>\u003Ch3>3. Update the Record number for subsequent logs (decrease by 1)\u003C\u002Fh3>\u003Cp>Specifically, the Record numbers for the 6th, 7th, 8th, and 9th logs\u003C\u002Fp>\u003Ch3>4. Update three items in the file header\u003C\u002Fh3>\u003Ch4>(1) End of file record offset\u003C\u002Fh4>\u003Cp>Located at offset 20 in the File header, 4 bytes\u003C\u002Fp>\u003Cp>Stores the starting address of the end of file record\u003C\u002Fp>\u003Cp>Two calculation methods:\u003C\u002Fp>\u003Col>\u003Cli>Original offset address - length of the 5th log (112)\u003C\u002Fli>\u003Cli>Locate the end of file record directly to obtain it\u003C\u002Fli>\u003C\u002Fol>\u003Cp>The new End of file record offset is 0x00000640h\u003C\u002Fp>\u003Ch4>(2) Last (newest) record number\u003C\u002Fh4>\u003Cp>4 bytes at offset 24 in the File header\u003C\u002Fp>\u003Cp>Decrement the value by 1, changing from 0x0000000A to 0x00000009\u003C\u002Fp>\u003Ch4>(3) Maximum file size\u003C\u002Fh4>\u003Cp>4 bytes at offset 32 in the File header\u003C\u002Fp>\u003Cp>The new Maximum file size is 0x00000668h\u003C\u002Fp>\u003Ch3>5. Synchronously update two items in the end of file record\u003C\u002Fh3>\u003Cul>\u003Cli>End of file record offset\u003C\u002Fli>\u003Cli>Last (newest) record number\u003C\u002Fli>\u003C\u002Ful>\u003Cp>Save the modified file as sys2.evt\u003C\u002Fp>\u003Cp>Download link:\u003C\u002Fp>\u003Cp>`An open-source project\u003C\u002Fp>\u003Cp>Successfully deleted the 5th log entry\u003C\u002Fp>\u003Cp>As shown in the figure below\u003C\u002Fp>\u003Cp>\u003Cimg alt=\"Alt text\" src=\"\u002Fapi\u002Fmedia\u002Ffile\u002Fdocx_image_1770017392740_3_8189e89a21-1.jpeg\">\u003C\u002Fp>\u003Ch2>0x05 Summary\u003C\u002Fh2>\u003Cp>---\u003C\u002Fp>\u003Cp>This article introduces the basics of evt log files and the implementation approach for deleting individual log entries, with a practical demonstration on how to modify evt files to hide a specific log.\u003C\u002Fp>\u003Cp>The next article will follow the previous research approach to explain how to write a program for automatically deleting logs from a specified date.\u003C\u002Fp>\u003C\u002Fbody>\u003C\u002Fhtml>",745,"Onedaysec",4,"published","2026-02-02T07:38:21.197Z",{"title":37,"description":14,"keywords":38,"ogImage":39,"canonicalUrl":39,"noIndex":40},"Windows EVT Log Single Deletion: Approach & Examples","Windows EVT log deletion, event viewer log, EVT file format, single log removal, Windows XP, Server 2003",null,false,[],{"docs":43,"hasNextPage":40},[44,45,46,4],830,829,828,{"title":39,"description":39,"image":39},"2026-07-24T15:37:11.322Z","2026-07-23T16:02:09.012Z","draft","2026-07-23T16:14:59.747Z"]