  1. Using explore Resultant Viewer app on Windows X.
  2. Using extant Windows PowerShell.

get-winevent -FilterHashTable @{logname="Application"; id="1001"}| ?{$_.providername –match "wininit"} | fl timecreated, statement

get-winevent -FilterHashTable @{logname="Application"; id="1001"}| ?{$_.providername –match "wininit"} | fl timecreated, adjuration | out-file Desktopchkdsklog.txt

