KGRKJGETMRETU895U-589TY5MIGM5JGB5SDFESFREWTGR54TY
Server : Apache/2.4.58 (Win64) OpenSSL/3.1.3 PHP/8.2.12
System : Windows NT SERVER-PC 10.0 build 26200 (Windows 11) AMD64
User : ServerPC ( 0)
PHP Version : 8.2.12
Disable Function : NONE
Directory :  C:/Windows/System32/en-US/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Current File : C:/Windows/System32/en-US/microsoft-windows-system-events.dll.mui
MZ����@���	�!�L�!This program cannot be run in DOS mode.

$A[=�:S�:S�:S�|���:S�|�Q�:S�Rich:S�PEL��ד�!&N

p�~@ 8K8.rdata�@@.rsrc8K L@@��ד
lPP��ד$����8.rdata8.rdata$voltmdP�.rdata$zzzdbg �.rsrc$01� PJ.rsrc$02 Z��d檮[~N�E�+>^;8�jk��3N��ד��(�@�X�p�����	�	�	�� ���!tE�g$�MUI���7��]�.�*B�{�g:�PO .�ĀV9m	?����MUIen-US��,0�36<
�0X[P��p  �&HV'\^d/���/��P7���;���;���<���<��dN���NL�4O����h�xx��@@P�����
�l���4Px���4��	(�`	h	(��	�	��(
0
,����������������
���������
P�2	2	,�a	d	��r	r	�

4��  `	st�	||t
��8�����8�������x���T��		�

x�!"44��
�11$H�$
0011�#22$:$:,$PPL%UU�%[[�%	p
p�%ss4&zz*���*���+��D,���,���,�� -���-���-��`.���.���.��@0���0���1 �*��2��X?���?��,@���@��tA��C��<J���K��LL���L��N���N�
��O��]"�"�`���`��8a	�	��b���c��Pd�����d����j�����p����hr�����u����Tw��x � ��x���z���{!�-� |1�3�$�9�<��>�>���I�K�|�Q�[������������@�����������������8�����T�����������������\�����������������t����������������������������������L�����D�����������������������������#�$�@�'�'���8�8���2�3� �J�K���P�P�t����������2�3����!��`"���*�Q��-e���$a����xn�	�h}�����
�@���,��C�H��ݨ@���A�
�|C�Possible detection of CVE: %1%nAdditional Information: %2%n%nThis Event is generated when an attempt to exploit a known vulnerability (%1) is detected.%nThis Event is raised by a User mode process.%n

�Possible detection of CVE: %1%nAdditional Information: %2%n%nThis Event is generated when an attempt to exploit a known vulnerability (%1) is detected.%nThis Event is raised by a kernel mode driver.%n

PMicrosoft-Windows-Kernel-AppCompat

4Microsoft-Windows-AIT

TMicrosoft-Windows-Kernel-ApphelpCache

HMicrosoft-Windows-AeSwitchBack

\Microsoft-Windows-AeLookupServiceTrigger

%1

%1

%1

�The executable %2 received an access denied error when trying to modify the registry key %4.

LMicrosoft-Windows-Kernel-Network

 Data sent.

(Data received.

4Connection attempted.

0Disconnect issued.

0Data retransmitted.

4Connection accepted.

4Reconnect attempted.

HTCP connection attempt failed.

XProtocol copied data on behalf of user.

DData sent over UDP protocol.

LData received over UDP protocol.

HUDP connection attempt failed.

lTCPv4: %2 bytes transmitted from %4:%6 to %3:%5.

dTCPv4: %2 bytes received from %4:%6 to %3:%5.

tTCPv4: Connection attempted between %4:%6 and %3:%5.

lTCPv4: Connection closed between %4:%6 and %3:%5.

pTCPv4: %2 bytes retransmitted from %4:%6 to %3:%5.

xTCPv4: Connection established between %4:%6 and %3:%5.

lTCPv4: Reconnect attempt between %4:%6 and %3:%5.

tTCPv4: Connection attempt failed with error code %2.

�TCPv4: %2 bytes copied in protocol on behalf of user for connection between %4:%6 and %3:%5.

lUDPv4: %2 bytes transmitted from %4:%6 to %3:%5.

dUDPv4: %2 bytes received from %4:%6 to %3:%5.

tUDPv4: Connection attempt failed with error code %2.

lTCPv6: %2 bytes transmitted from %4:%6 to %3:%5.

dTCPv6: %2 bytes received from %4:%6 to %3:%5.

tTCPv6: Connection attempted between %4:%6 and %3:%5.

lTCPv6: Connection closed between %4:%6 and %3:%5.

pTCPv6: %2 bytes retransmitted from %4:%6 to %3:%5.

xTCPv6: Connection established between %4:%6 and %3:%5.

lTCPv6: Reconnect attempt between %4:%6 and %3:%5.

�TCPv6: %2 bytes copied in protocol on behalf of user for connection between %4:%6 and %3:%5.

lUDPv6: %2 bytes transmitted from %4:%6 to %3:%5.

dUDPv6: %2 bytes received from %4:%6 to %3:%5.

DMicrosoft-Windows-Kernel-Disk

L%3 bytes read from disk %1 at %5.

P%3 bytes written to disk %1 at %5.

@Buffers flushed to disk %1.

DMicrosoft-Windows-Kernel-Boot

LSystem was booted in %1x%2@%3bpp.

`BootUX screen was displayed in %1x%2@%3bpp.

`Video bit transfer rate is %1 bytes per ms.

�Boot library accessed file %2 on Device %1. Read %3 bytes and wrote %4 bytes.

�File IO for boot application %1: Total Bytes Read = %2, Total Bytes Written = %3.

�Image %1 failed IntegrityCheck reason is %3. Image flags are %2. Error ignored due to debugger %4.

TBootmgr duration is %1 milliseconds.

DImage %1 is not self-signed.

�A device (%1) that was enumerated by the BIOS was inaccessible to the boot environment.

|Variable %1 requires %2 bytes and was set with status %3.

hElement %2 of application %1 was not in policy.

pA Secure Boot Policy update resulted in status %1.

�A Secure Boot Revocation List update resulted in status %1.

lRetrieving the driver list took %1 milliseconds.

\Loading the drivers took %1 milliseconds.

TLoading hive %1 took %2 milliseconds.

XThe time elapsed loading %1 was %2 ms.

\The time elapsed executing %1 was %2 ms.

�Building chunk table for WIM compressed file %2 failed with status: %1

�Soft Restart failed to prepare target Operating System. Operation status: %1 failure point: %2

�Boot application failed to process persistent data with status: %1

DMicrosoft-Windows-Kernel-File

�Session "%3" could not be started because LOGGER_FLAG_LARGE_MDL_PAGES is not supported.

�Session "%1" could not be started because because the maximum %2 logging sessions are already active on the system.

0Session "%1" could not be started because because the maximum %2 EVENT_TRACE_SYSTEM_LOGGER_MODE logging sessions are already active on the system.

�Session "%1" could not be started because the process failed its access check to the SessionGuid.

�Session "%1" could not be started because the Memory Partition Handle %2 is invalid.

tSession "%1" failed to create file %2 with error %3.

�Session "%1" could not be started because the process lacks the profiling privilege.

�Group Mask could not be updated for Session "%1", because the requested Group Mask is not supported.

|Capture state requested for provider %1 on session "%2".

$Capture State

hError setting traits on Provider %1. Error: %2

�A registration for Provider %1 has joined Provider Group %2

 Enable Info

0Set Provider Traits

0Join Provider Group

8Lost TraceLogging Event

(Lost WPP Event

,Lost System Event

�The enable state for Provider %1 is about to change on session "%2".

xProvider %1 is about to be disabled from session "%2".

TMicrosoft-Windows-Kernel-EventTracing

�Session "%1" failed to write to log file "%2" with the following error: %3

<The backing-file for the real-time session "%1" has reached its maximum size. As a result, new events will not be logged to this session until space becomes available. This error is often caused by starting a trace session in real-time mode without having any real-time consumers.

|Session "%1" failed to start with the following error: %3

pSession "%1" stopped due to the following error: %3

`The maximum file size for session "%1" has been reached. As a result, events might be lost (not logged) to file "%2". The maximum files size is currently set to %5 bytes.

�An error was encountered while tracing session "%2" was switching to the "%1" event log file. Error: %3

�Provider %1 was registered with Event Tracing for Windows.

�Provider %1 was unregistered from Event Tracing for Windows.

<Session "%3" was started.

<Session "%3" was stopped.

tThe configuration of session "%3" has been modified.

hThe events from session "%3" have been flushed.

dProvider %1 has been enabled to session "%2".

lProvider %1 is no longer enabled to session "%2".

�The security settings of provider %1 have been modified from %2 to %3.

�The security descriptor for session "%3" has been updated.

Provider

Session

Logging

Stop

Start

Disable

Enable

 Unregister

Register

Flush

Configure

$Write Buffer

 File Switch

Provider

Session

Stack correlation event. This event contains a call stack which is associated with a prior event which is correlated by the MatchId.

 Stack Trace

4User Mode Stack Trace

hMicrosoft-Windows-Kernel-EventTracing/Analytic

`Microsoft-Windows-Kernel-EventTracing/Admin

 Lost Event

 Lost Event

\Logger mode incompatible with Append mode

0OS version mismatch

4Pointer size mismatch

8Unsupported BufferSize

0BufferSize mismatch

lPreallocate mode is incompatible with Append mode

8File size query failed

<Maximum file size reached

LNumber of buffers written is zero

HNumberf of processors mismatch

xError saving soft restart persisted log "%1" Error: %5

 GUID Entry

4Provider Group Entry

LMicrosoft-Windows-Kernel-StoreMgr

dMicrosoft-Windows-Kernel-StoreMgr/Operational

�%5%n%nVirtual Address: %2%nPhysical Address: %3%nCorruption Window Size: %4

0A memory corruption was detected and handled. Memory diagnostics should be run on this machine and, if necessary, memory chips should be replaced.

�A data corruption was detected and handled in a ReadyBoost cache. This corruption was most likely caused by faulty hardware. While ReadyBoost will always detect and handle these errors, seeing a lot of these may mean that the ReadyBoost device has worn out which reduces its performance. You should consider replacing the ReadyBoost cache device.

tA ReadyBoost cache failed to persist across boot. This may happen if the cache device was modified on another computer or if this computer was booted into another operating system.

T%1%n%nDevice name: %4%nCache path: %6

�A ReadyBoost cache was deleted due to repeated data corruption instances on the associated device that have been detected and handled. While ReadyBoost will always detect and handle these errors, repeated corruption instances may mean that the ReadyBoost device has worn out which reduces its performance. You should consider replacing the ReadyBoost device.

�A ReadyBoost cache was deleted due to repeated I/O failures on the associated device. This typically happens when the device (e.g. an SD card) is removed, but it may also indicate faulty hardware.

hMicrosoft-Windows-LicensingStartServiceTrigger

hMicrosoft-Windows-WSServiceStartServiceTrigger

LMicrosoft-Windows-Kernel-LiveDump

`Microsoft-Windows-Kernel-LiveDump/Analytic

HLive Dump Capture Dump Data API

(Sizing Workflow

8Capture Pages Workflow

XLive Dump Write Deferred Dump Data API

\Live Dump Discard Deferred Dump Data API

PSizing Workflow: Mirroring started.

\Sizing Workflow: Mirroring Phase 0 ended.

\Sizing Workflow: Mirroring Phase 1 ended.

\Sizing Workflow: System Quiesce started.

XSizing Workflow: System Quiesce ended.

`Capture Pages Workflow: Mirroring started.

lCapture Pages Workflow: Mirroring Phase 0 ended.

lCapture Pages Workflow: Mirroring Phase 1 ended.

hCapture Pages Workflow: System Quiesce started.

dCapture Pages Workflow: System Quiesce ended.

pCapture Pages Workflow: Copy memory pages started.

lCapture Pages Workflow: Copy memory pages ended.

�Live Dump Capture Dump Data API started.  Flags: %1.  AddPagesControl: %2

�Live Dump Capture Dump Data API ended. NT Status: %1.  BugcheckCode: %2. BugcheckParameter1: %3. BugcheckParameter2: %4. BugcheckParameter3: %5. BugcheckParameter4: %6. AbortIfMemoryPressure: %7. DumpCaptureDuration: %8ms. SelectiveDump: %9. DynamicLowMemoryThreshold: %10 bytes.  AvailablePhysicalMemory: %11 bytes.  TotalPhysicalMemory: %12 bytes.  IOSpaceEnabled: %13.

@Writing dump file started.

Writing dump file ended. NT Status: %1. Total %2 bytes (Header|Primary|Secondary: %3|%4|%5 bytes). DumpWriteDuration: %6ms.

API Start

API End

4Dump File Write Start

0Dump File Write End

(Mirroring Start

4Mirroring Phase 0 End

4Mirroring Phase 1 End

4System Quiesce Start

0System Quiesce End

@Copying Memory Pages Start

<Copying Memory Pages End

hLive Dump Write Deferred Dump Data API started.

�Live Dump Write Deferred Dump Data API ended. NT Status: %1. BugcheckCode: %2. BugcheckParameter1: %3. BugcheckParameter2: %4. BugcheckParameter3: %5. BugcheckParameter4: %6. DumpWriteDuration: %8ms.  SelectiveDump: %9. DynamicLowMemoryThreshold: %10 bytes.  AvailablePhysicalMemory: %11 bytes.  TotalPhysicalMemory: %12 bytes.  IOSpaceEnabled: %13.

\Write deferred dump data to file started.

 Write deferred dump data to file ended. NT Status: %1. Total %2 bytes (Header|Primary|Secondary: %3|%4|%5 bytes). DumpWriteDuration: %6ms.

lLive Dump Discard Deferred Dump Data API started.

lLive Dump Discard Deferred Dump Data API ended. NT Status: %1. BugcheckCode: %2. BugcheckParameter1: %3. BugcheckParameter2: %4. BugcheckParameter3: %5. BugcheckParameter4: %6.

�Sizing Workflow: Estimation. NT: %2 bytes (Minimum %1 bytes). Hypervisor: Primary %3 bytes. Secondary %4 bytes.

�Sizing Workflow: Allocation. NT: %1 bytes. Hypervisor: Primary %2 bytes. Secondary %3 bytes.

8Buffer Estimation Data

8Buffer Allocation Data

hSizing Workflow: RemovePages Callbacks started.

dSizing Workflow: RemovePages Callbacks ended.

lSizing Workflow: RemovePages Callback %1 started.

hSizing Workflow: RemovePages Callback %1 ended.

�Sizing Workflow: RemovePages Callback %1 failed. NT Status: %2.

8Remove Pages Callbacks

�Live Dump request aborted due to memory pressure on system

dMicrosoft-Windows-Kernel-LiveDump/Operational

�Sizing workflow: %1 pages estimated to be allocated and %2 pages allocated (VM memory partition's IOSpace|VM memory partition|System partition's IOSpace|System partition: %3|%4|%5|%6 pages). Limit dump file size: %7. Dump file size limit: %8 bytes. Dump file size limit reached: %9. Aborted while buffer allocation: %10.

�Sizing Workflow: Estimation. NT: %2 bytes (Minimum %1 bytes). Hypervisor: Primary %3 bytes. Secondary %4 bytes. SecureKernel: %5 bytes. MemoryEstimationDuration: %6ms. SystemQuiescedDuration: %7ms. EndMirroringPhasesDuration: %8ms. MirrorPhysicalMemoryDuration: %9ms. MirrorPhysicalMemorySizeInBytes: %10 bytes. HvlCalculateLiveDumpSizeDuration: %11ms.

�Sizing Workflow: Allocation. NT: %1 bytes. Hypervisor: Primary %2 bytes. Secondary %3 bytes. SecureKernel: %4 bytes. AllocateDumpBuffersDuration: %5ms. AllocateExtraBuffersDuration: %6ms. HvlPrepareLivedumpDescriptorDuration: %7ms.

�Sizing Workflow: Query Hvl for dump size failed. NT Status: %1.

�Sizing Workflow: Open VM memory partition failed. NT Status: %1

�Sizing Workflow: Buffer allocation from the VM memory partition failed. NT Status: %1

�Sizing Workflow: Capture processor context when the system is quiesced. Duration: %1ms.

�Sizing Workflow: Mark required dump data when system is quiesced. Duration: %1ms.

�Sizing Workflow: Mark important dump data when system is quiesced. Duration: %1ms.

(Sizing Workflow: Populate bitmap for dump when system is quiesced. PopulateBitmapForDumpDuration: %1ms. RemoveSystemCacheFromDumpDuration %2ms.

�Capture Pages Workflow: Capture processor context when the system is quiesced. Duration: %1ms.

�Capture Pages Workflow: Mark required dump data when system is quiesced. Duration: %1ms.

�Capture Pages Workflow: Mark important dump data when system is quiesced. Duration: %1ms.

8Capture Pages Workflow: Populate bitmap for dump when system is quiesced. PopulateBitmapForDumpDuration: %1ms. RemoveSystemCacheFromDumpDuration %2ms.

�Capture Pages Workflow: Generate Ipt secondary data when system is quiesced. Duration: %1ms.

<Capture Processor Context

8Mark Required Dump Data

8Mark Important DumpData

<Populate Bitmap For Dump

@Generate Ipt Secondary Data

tSizing Workflow: Corral processors to quiesce the system. CorralDuration: %1ms. DisableInterruptsDuration: %2ms. SaveSupervisorStateDuration: %3ms. SuspendClockTimerDuration: %4ms.

�Capture Pages Workflow: Corral processors to quiesce the system. CorralDuration: %1ms. DisableInterruptsDuration: %2ms. SaveSupervisorStateDuration: %3ms. SuspendClockTimerDuration: %4ms.

|Sizing Workflow: Uncorral processors to quiesce the system. UncorralDuration: %1ms. EnableInterruptsDuration: %2ms. RestoreSupervisorStateDuration: %3ms. ResumeClockTimerDuration: %4ms.

�Capture Pages Workflow: Uncorral processors to quiesce the system. UncorralDuration: %1ms. EnableInterruptsDuration: %2ms. RestoreSupervisorStateDuration: %3ms. ResumeClockTimerDuration: %4ms.

DCapture Pages Workflow: Capture memory pages. MemoryCaptureDuration: %1ms. SystemQuiescedDuration: %2ms. EndMirroringPhasesDuration: %3ms. MirrorPhysicalMemoryDuration: %4ms. MirrorPhysicalMemorySizeInBytes: %5 bytes. HvlCollectLivedumpDuration: %6ms. DumpDataBufferingDuration: %7ms.

,Corral Processors

0Uncorral Processors

4Capture Memory Pages

�Sizing Workflow: MmDuplicateMemory failed. NT Status: %1. MirrorInProgress: %2.

�Capture Pages Workflow: MmDuplicateMemory failed. NT Status: %1. MirrorInProgress: %2.

<MmDuplicateMemory Failure

<AllowLiveDump policy: %1.

�AllowLiveDump policy value changed (AllowLiveDump = %1). Configure live dump. NT status: %2

|LiveDump disabled on boot by policy (AllowLiveDump = %1).

,Live Dump Policy

8Policy Operation Failed

4Policy Value Changed

<LiveDump Disabled On Boot

�IO space utilization disabled when HV/SK pages requested, NoSecrets mode disabled, and SK running.

TLiveDump Disable IOSpace Utilization

<LiveDump Feature Callout

DCallout for %1 (included %2).

�Sizing Workflow: Call to Hvl for preparing livedump descriptor failed. NT Status: %1

THvlPrepareLiveDumpDescriptor Failure

8LiveDump Event Generic

�Windows has started processing the volume mount request.%n%n           Volume GUID: %1%n           Volume Name: %3%n

�The volume has been successfully mounted.%n%n           Volume GUID: %1%n           Volume Name: %3%n

�Windows failed to mount the volume.%n%n           Status: %4%n           Volume GUID: %1%n           Volume Name: %3%n

@Microsoft-Windows-Kernel-IO

XMicrosoft-Windows-Kernel-IO/Operational

�Windows is configured to block legacy file system filters.%n%n           Filter name: %2%n

Legacy file system filters cannot attach to byte addressable volumes.%n%n           Filter name: %2%n           Volume name: %4%n

�Dumps are disabled on the machine since there was an error enabling dump encryption: %1.

                 %nSee http://go.microsoft.com/fwlink/?LinkId=824149 for more information on dump encryption

@An internal error occurred

\Public Key or Thumbprint registry missing

0Invalid Public Key

@Unsupported Public Key Size

�Failed to automatically attach a VHD during system startup.%n%n          VHD name: %2%n          Status: %3%n

This volume is configured to block legacy file system filters.%n%n           Filter name: %2%n           Volume name: %4%n

\Microsoft-Windows-Kernel-Audit-API-Calls

@Microsoft-Windows-Audit-CVE

LMicrosoft-Windows-User-Diagnostic

HMicrosoft-Windows-Heap-Snapshot

TMicrosoft-Windows-Threat-Intelligence

�Microsoft-Windows-Security-LessPrivilegedAppContainer/Operational

tMicrosoft-Windows-Security-LessPrivilegedAppContainer

�Access to the a resource has been denied for a less privileged app container at %1 (StackHash: %2).

XMicrosoft-Windows-Security-Mitigations

 Kernel Mode

User Mode

�Process '%2' (PID %5) would have been blocked from generating dynamic code.

�Process '%2' (PID %5) was blocked from generating dynamic code.

�Process '%2' (PID %5) would have been blocked from creating a child process '%14' with command line '%16'.

�Process '%2' (PID %5) was blocked from creating a child process '%14' with command line '%16'.

�Process '%2' (PID %5) would have been blocked from loading the low-integrity binary '%14'.

�Process '%2' (PID %5) was blocked from loading the low-integrity binary '%14'.

�Process '%2' (PID %5) would have been blocking from loading a binary from a remote share.

�Process '%2' (PID %5) was blocked from loading a binary from a remote share.

�Process '%2' (PID %5) would have been blocked from making system calls to Win32k.sys.

�Process '%2' (PID %5) was blocked from making system calls to Win32k.sys.

�Process '%2' (PID %5) would have been blocked from loading the non-Microsoft-signed binary '%16'.

�Process '%2' (PID %5) was blocked from loading the non-Microsoft-signed binary '%16'.

�Process '%2' (PID %3) would have been blocked from accessing the Export Address Table for module '%8'.

�Process '%2' (PID %3) was blocked from accessing the Export Address Table for module '%8'.

�Process '%2' (PID %3) would have been blocked from accessing the Import Address Table for API '%10'.

�Process '%2' (PID %3) was blocked from accessing the Import Address Table for API '%10'.

Process '%2' (PID %3) would have been blocked from calling the API '%4' due to return-oriented programming (ROP) exploit indications.

�Process '%2' (PID %3) was blocked from calling the API '%4' due to return-oriented programming (ROP) exploit indications.

�Process '%2' (PID %5) has encountered a shadow stack return address mismatch. The process will be allowed to continue execution.%n%nReturn instruction executed from module '%12'.%nAttempting to return to module '%14'.

�Process '%2' (PID %5) has encountered a shadow stack return address mismatch. The process will be terminated.%n%nReturn instruction executed from module '%12'.%nAttempting to return to module '%14'.

<Process '%2' (PID %5) would have been blocked from setting context due to instruction pointer validation failure when user-mode shadow stack is enabled.

$Process '%2' (PID %5) was blocked from setting context due to instruction pointer validation failure when user-mode shadow stack is enabled.

Process '%2' (PID %5) has encountered a shadow stack return address mismatch. The process will be allowed to continue execution.%nProcess shadow stack strict mode: %15%n%nReturn instruction executed from module '%12'.%nAttempting to return to module '%14'.

�Process '%2' (PID %5) has encountered a shadow stack return address mismatch. The process will be terminated.%nProcess shadow stack strict mode: %15%n%nReturn instruction executed from module '%12'.%nAttempting to return to module '%14'.

 Process '%2' (PID %5) would have been blocked from loading an image binary due to the binary not being compatible with shadow stacks and/or missing exception handling continuation data.%nProcess requires binaries to also contain exception handling continuation data: %15%n%nBinary path: %12%nBinary compatible with shadow stacks: %13%nBinary contains exception handling continuation data: %14%n

Process '%2' (PID %5) was blocked from loading an image binary due to the binary not being compatible with shadow stacks and/or missing exception handling continuation data.%nProcess requires binaries to also contain exception handling continuation data: %15%n%nBinary path: %12%nBinary compatible with shadow stacks: %13%nBinary contains exception handling continuation data: %14%n

�Process '%2' (PID %5) would have been blocked from following an untrusted redirection: %n%nBinary path: %2%nArguments: %4%nRedirection Type: %11%nOperation Path: %13%nImpersonating: %14%n

hProcess '%2' (PID %5) was blocked from following an untrusted redirection: %n%nBinary path: %2%nArguments: %4%nRedirection Type: %11%nOperation Path: %13%nImpersonating: %14%n

Process '%2' (PID %5) would have been blocked from setting context due to instruction pointer validation failure when user-mode shadow stack is enabled.%nProcess set context validation strict mode: %13%nSet context type: %14%n%nSet context target module '%12'.

�Process '%2' (PID %5) was blocked from setting context due to instruction pointer validation failure when user-mode shadow stack is enabled.%nProcess set context validation strict mode: %13%nSet context type: %14%n%nSet context target module '%12'.

<Exception handling unwind

`Context resumption without unwind semantics

(Longjump unwind

0Set thread context

@Unknown redirection type%n

0NTFS mount point%n

(NTFS symlink%n

�Process '%2' (PID %5) has encountered a shadow stack return address mismatch. The process will be allowed to continue execution because: %17.%nProcess shadow stack strict mode: %15%nAppcompat options: %16%n%nReturn instruction executed from module '%12'.%n(Instruction address: %18, module offset: %19, module compatible with shadow stacks: %20)%n%nAttempting to return to module '%14'.%n(Instruction address: %21, module offset: %22, module compatible with shadow stacks: %23)

�Process '%2' (PID %5) has encountered a shadow stack return address mismatch. The process will be terminated.%nProcess shadow stack strict mode: %15%nAppcompat options: %16%n%nReturn instruction executed from module '%12'.%n(Instruction address: %18, module offset: %19, module compatible with shadow stacks: %20)%n%nAttempting to return to module '%14'.%n(Instruction address: %21, module offset: %22, module compatible with shadow stacks: %23)

Tthe process is running in audit mode

the process is running in compatibility mode, and the mismatch occurred in a module that is not compatible with shadow stacks

�The system has encountered a kernel-mode shadow stack return address mismatch. The system will be allowed to continue execution because: %5.%n%nReturn instruction executed from module '%2'.%n(Instruction address: %6, module offset: %7)%n%nAttempting to return to module '%4'.%n(Instruction address: %9, module offset: %10)

PThe system has encountered a kernel-mode shadow stack return address mismatch. The system will be terminated.%n%nReturn instruction executed from module '%2'.%n(Instruction address: %6, module offset: %7)%n%nAttempting to return to module '%4'.%n(Instruction address: %9, module offset: %10)

Pthe system is running in audit mode

�Process '%2' (PID %5) would have been blocked from making the NtFsControlFile system call.

�Process '%2' (PID %5) was blocked from making the NtFsControlFile system call.

DMicrosoft-Windows-Kernel-Dump

\Microsoft-Windows-Kernel-Dump/Operational

,CrashDump Policy

@AllowCrashDump policy: %1.

�AllowCrashDump policy value changed (AllowCrashDump = %1). Configure crash dump. NT status: %2

�CrashDump disabled on boot by policy (AllowCrashDump = %1).

8Policy Operation Failed

4Policy Value Changed

@CrashDump Disabled On Boot

,CrashDump Config

\Crash dump disable failed. NT status: %1.

lCrash dump initialization failed. NT status: %1.

dCrash dump load driver failed. NT status: %1.

�Crash dump dump stack initialization failed. NT status: %1.

lCrash dump free dump stack failed. NT status: %1.

lCrash dump load dump stack failed. NT status: %1.

0Dump Disable Failed

@Dump Initialization Failed.

<Dump Load Driver Failed.

LDump Stack Initialization Failed

8Free Dump Stack Failed

8Load Dump Stack Failed

4Crash dump disabled.

$Dump Disabled

XCrash dump reconfigured. NT status: %1.

,Dump Reconfigured

lDump disabled forcefully (ForceDumpDisabled: %1).

<Dump disabled forcefully

 Dump Config

XMicrosoft-Windows-Kernel-CPU-Starvation

pMicrosoft-Windows-Kernel-CPU-Starvation/Operational

,DPC Soft Timeout

<CPU %3 exceeded its single DPC soft timeout of %5 clock ticks. A single DPC in module %7, with key %1, ran for %4 clock ticks on the thread with TID %2.

hCPU %2 exceeded its cumulative DPC soft timeout of %4 clock ticks, by running at an IRQL greater than or equal to DISPATCH_LEVEL for %3 clock ticks on the thread with TID %1.

HSingle DPC Soft Timeout Reached

PCumulative DPC Soft Timeout Reached

$DPC Profiling

`Capture DPC sequence number %1 at tick %2.

Thread %1 on CPU %2 exceeded the threshold of %4 ticks running at DISPATCH_LEVEL or higher, profiling started with sequence number %3.

@DPC Profiling Stack Capture

HDPC Profiling Threshold Reached

DMicrosoft-Windows-Kernel-Prm

\Microsoft-Windows-Kernel-Prm/Operational

4PRM has been invoked.

�PRM module update failed. Module GUID %1, module version %2, status %3.

�PRM invocation failed. Handler GUID %1, module GUID %2, module version %3, interface status %4, handler status %5.

�Excessive PRM handler runtime. Handler GUID %1, module GUID %2, module version %3, duration %4 us.

Execution at elevated IRQL reached threshold of %2 ticks (DPC ticks: %3 ticks, total ticks: %4 ticks), sequence number %1 for %5.

4cumulative execution

4single Dpc execution

0Pool Tracked Tables

Processes

8Session Space Structure

,Triage Dump Data

$PFN Database

,IPT Trace Buffer

XMicrosoft-Windows-Kernel-CPU-Partition

hMicrosoft-Windows-Kernel-CPU-Partition/Analytic

8CPU Partition violation

An affinitization request (Kernel = %1) for the thread with TID %2 violated CPU Partitions with the following affinity: %4.

�A DPC (Pointer = %1) was scheduled on processor %2, across CPU Partition reservations.

�A DPC (Pointer = %1) was scheduled as a generic DPC call, across CPU Partition reservations.

lAn affinitization request violated CPU Partitions

lA DPC scheduling request violated CPU Partitions

pA generic DPC call request violated CPU Partitions

H{Remote Registy Service} Access Denied to key: %2 under parent key: %4 as the parent is mentioned under AllowedExactPaths and hence subkey cannot be accessed.

DMicrosoft-Windows-DriverProxy

<Dirver Proxy Performance

<Driver Proxy Operational

(Serviceability

 Performance

Log

�Driver %2 Average Hot-Swap acquire rundown time in last log period(us):%3; Average Hot-Swap acquire rundown time(us):%4; Total rundown acquire count:%5; Total rundown acquire failure:%6;

0Driver %2 Last Hot-Swap result:%3 (LKG phase=%4); Last Hot-Swap total time (us):%5; Last Hot-Swap pre-process time (us):%6; Last Hot-Swap acquire rundown time (us):%7; Last Hot-Swap driver callback time with rundown lock held (us):%8; Last Hot-Swap post-process time (us):%9;

$Driver %2: %3

4Microsoft-Windows-PCI

(PCI Diagnostic

(PCI Operational

 Diagnostic

Log

%6

�The system time has changed to %1 from %2.%nTime Delta: %3 ms%n%nChange Reason: %4.%nProcess: '%5' (PID %6).%n%nRTC time: %7%nCurrent time zone bias: %8%nRTC time is in UTC: %9%nSystem time was based on RTC time: %10

\License policy-cache corruption detected.

hLicense policy-cache corruption has been fixed.

�License policy-cache has expired because it was not updated within expected duration.

{Registry Hive Recovered} Registry hive (file): '%3' was corrupted and it has been recovered. Some data might have been lost.

�An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): '%3'.

�TxR init phase for hive %2 (TM: %3, RM: %4) finished with result=%5 (Internal code=%6).

hThe operating system started at system time %7.

|The operating system is shutting down at system time %1.

�Hive %2 was reorganized with a starting size of %3 bytes and an ending size of %4 bytes.

�The access history in hive %2 was cleared updating %3 keys and creating %4 modified pages.

�The operating system is starting after soft restart. BugcheckRecovery: %4

 The leap second configuration has been updated.%nReason: %1%nLeap seconds enabled: %2%nNew leap second count: %3%nOld leap second count: %4

�Failed to update leap second data from the registry. Reason: %1

dThe time zone bias has changed to %1 from %2.

�The time zone information was refreshed with exit reason %1. Current time zone bias is %2.

`The system time was initialized to %1. %n%nLoader time: %2%nInternal boot flags: %3%nHAL RTC error code: %4%nRTC time is in UTC: %5%nSoft boot: %6%nSuccess: %7%nPhase: %8

xToken information was queried for TokenIsAppContainer.

�Error status code %1 returned when %3 attempted to load dependency %2.

�Loading dependency %2 from the current directory was not allowed when attempted by %1. Another DLL was found: %3. For more information, see http://go.microsoft.com/fwlink/?LinkId=718136.

�Loading dependency %2 from the current directory was not allowed when attempted by %1. No other DLL was found and the dependency resolution failed. For more information, see http://go.microsoft.com/fwlink/?LinkId=718136.

dAccess to %1 is monitored by policy rule %2.

�Access to %1 has been restricted by your Administrator by the default software restriction policy level.

�Access to %1 has been restricted by your Administrator by location with policy rule %2 placed on path %3.

�Access to %1 has been restricted by your Administrator by software publisher policy.

�Access to %1 has been restricted by your Administrator by policy rule %2.

�Access to %1 has been restricted by your Administrator by policy rule %2.

TThe system firmware has allocated a memory region previously determined to be unreliable. This has the potential to cause system instability and/or data corruption.

�Windows failed to resume from hibernate with error status %1.

|The boot manager multi OS selection screen was displayed.

\There are %1 boot options on this system.

hThere are %1 boot tool options on this system.

�The last shutdown's success status was %1. The last boot's success status was %2.

�The OS loader advanced options menu was displayed and the user selected option %1.

hThe OS loader edit options menu was displayed.

\The Windows key was pressed during boot.

PThe F8 key was pressed during boot.

DThe boot menu policy was %1.

pA one-time boot sequence was used during this boot.

4The boot type was %1.

lWindows failed fast startup with error status %1.

PThe firmware reported boot metrics.

hThe bootmgr spent %1 ms waiting for user input.

TSoft reboot cancellation started: %1

XSoft reboot cancellation finished: %1.

�The virtualization-based security enablement policy check at phase %1 failed with status: %2

pVirtualization-based security (policies: %3) is %2.

�Virtualization-based security (policies: %3) is %2 with status: %1

tSoft reboot prepare started (complete requested: %1).

LSoft reboot prepare finished: %1.

TSoft reboot complete prepare started.

`Soft reboot complete prepare finished: %1.

pSoft reboot call to %1 failed: %2 (checkpoint: %3).

lSystem drivers need update to support VBS launch.

hSMM configuration failed validation. Reason: %1

�EFI time zone bias: %1. Daylight flags: %2. Firmware time: %3.

LSMM isolation detected. Level: %1

�Unable to load Pluton-Windows firmware. StatusCode: %1, Reason: %2

\AMD DRTM Firmware Anti-Rollback Disabled.

8PPAM Manifest Info: %1

�Bootmgr Security Version Number check failed. Svn Value: %1, Previous SVN Value: %2.

�App %1 was terminated with error %2 because of an issue with Windows binary %3. This could be because the binary is unsigned, contains an untrusted signature, or has been corrupted or tampered with. Refresh your PC to fix this issue.

�Failure to load the application settings for package %1. Error Code: %2

�Failure to read an application setting for package %1. Error Code: %2

�Failure to write an application setting for package %1. Error Code: %2

�Failure to instantiate storage folder %1 for package %2 with Error Code: %3

�Triggered repair because operation %1 against package %2 hit error %3.

�Repair for operation %1 against package %2 with error %3 returned Error Code: %4

pFolder path %1 failed access check: Error Code: %2

�Triggered repair of state locations because operation %1 against package %2 hit error %3.

�Repair of state locations for operation %1 against package %2 with error %3 returned Error Code: %4

8Verbose context events

8Scenario trigger events

SQM

Time

(Deprecated dlls

DFatal user callback exception

4A dll failed to load.

<Launch 16bit application

DWindows component on demand.

TThe Loader encountered a fatal error.

$Response Time

<Deprecated COM interfaces

Process

$AppContainer

0DesktopAppXProcess

4DesktopAppXContainer

,Structured State

0Unstructured Reset

$Out Of Memory

$Apiset Error

WinRT

@Low-level Data Store Error

�Scenario start enables context providers to the WDI context logger.

�Scenario end disables context providers to the WDI context logger.

�When a scenario has remained in-flight beyond the maximum time window it is automatically terminated by the SEM.

`A scenario start attempt failed in the SEM.

\A scenario end attempt failed in the SEM.

�The SEM received a request to start a new scenario, but the maximum number of scenarios were already in-flight.

�There is an invalid configuration parameter in the SEM registry namespace.

�The SEM is configured with more scenarios than the maximum allowed count.

�The SEM is configured with a scenario with too many context providers.

�The SEM is configured with a scenario that has too many end events.

�The number of providers specified across all scenarios is above the maximum allowed amount.

Info

Start

Stop

Start

<Invoke callback function

0Disable live cache

HUpdate resource cache manifest

4Build resource cache

Start

End

Error

Warning

 Information

Critical

Verbose

8SEM Scenario Lifecycle

0SEM Initialization

�This group of events tracks the performance of mounting hives from existing files.

�This group of events tracks the performance of unloading hives.

�This group of events tracks the performance of flushing hives.

�This group of events tracks the performance of registry shutdown.

�This group of events tracks the performance of loading hives.

�This group of events tracks the performance of restoring hives.

�This group of events tracks the performance of exporting hives.

HMUI NotifyUILanguageChange task

@MUI resource cache builder

DMicrosoft-Windows-Kernel-WDI

TMicrosoft-Windows-Kernel-WDI/Analytic

PMicrosoft-Windows-Kernel-WDI/Debug

\Microsoft-Windows-Kernel-WDI/Operational

LMicrosoft-Windows-Kernel-General

System

LMicrosoft-Windows-Kernel-Process

LMicrosoft-Windows-Kernel-Registry

DMicrosoft-Windows-Kernel-Acpi

DMicrosoft-Windows-User-Loader

 Application

\Microsoft-Windows-Kernel-BootDiagnostics

4Microsoft-Windows-UAC

LMicrosoft-Windows-UAC/Operational

4Microsoft-Windows-COM

dMicrosoft-Windows-SoftwareRestrictionPolicies

4Microsoft-Windows-MUI

LMicrosoft-Windows-MUI/Operational

@Microsoft-Windows-MUI/Admin

HMicrosoft-Windows-MUI/Analytic

@Microsoft-Windows-MUI/Debug

PMicrosoft-Windows-Kernel-ShimEngine

hMicrosoft-Windows-Kernel-ShimEngine/Operational

PMicrosoft-Windows-AppModel-Runtime

`Microsoft-Windows-AppModel-Runtime/Analytic

LMicrosoft-Windows-AppModel-State

XMicrosoft-Windows-AppModel-State/Debug

`Microsoft-Windows-AppModel-State/Diagnostic

4The Scenario Event Mapper started a scenario for provider %1 (event ID %2) with %4 context providers.  The context logger dropped event count was %3.

4The Scenario Event Mapper stopped a scenario for provider %1 (event ID %2) with %4 context providers.  The context logger dropped event count was %3.

An in-flight scenario from provider %1 (event ID %2) timed out and was stopped automatically by the Scenario Event Mapper.

<The Scenario Event Mapper was unable to start a new scenario for provider %1 (event ID %2) because the maximum number of scenarios are already in flight.

�The Scenario Event Mapper was unable to start a scenario for provider %1 (event ID %2).  The error code was %3.

�The Scenario Event Mapper was unable to stop a scenario for provider %1 (event ID %2).  The error code was %3.

4The Scenario Event Mapper is configured with more than the maximum number of scenarios.  The scenario for provider %1 (event ID %2) will be ignored.

hThe Scenario Event Mapper is configured with more than the maximum number of context providers for the scenario with provider %1 (event ID %2).  The scenario will be ignored.

XThe Scenario Event Mapper is configured with more than the maximum number of end events for the scenario with provider %1 (event ID %2).  The scenario will be ignored.

�The Scenario Event Mapper is configured with more than the maximum number of providers.  The provider %1 will be ignored.

HThe Scenario Event Mapper is configured with an unsupported scenario. The scenario for provider %1 (event ID %2) encountered error code %3 and will be ignored.

`The system time has changed to %1 from %2.

tThe operating system is starting after soft restart.

�The system time has changed to %1 from %2.%n%nChange Reason: %3.

�The system time has changed to %1 from %2.%n%nChange Reason: %3.%nProcess: '%4' (PID %5).

�The system time has changed to %1 from %2.%n%nChange Reason: %3.%nProcess: '%4' (PID %5).%n%nRTC time: %6%nCurrent time zone bias: %7%nRTC time is in UTC: %8%nSystem time was based on RTC time: %9

�Process %1 started at time %2 by parent %3 running in session %4 with name %5.

�Process %1 (which started at time %3) stopped at time %4 with exit code %5.

PThread %2 (in Process %1) started.

PThread %2 (in Process %1) stopped.

dProcess %3 had an image loaded with name %7.

hProcess %3 had an image unloaded with name %7.

�Base CPU priority of thread %2 in process %1 was changed from %3 to %4.

�CPU priority of thread %2 in process %1 was changed from %3 to %4.

�Page priority of thread %2 in process %1 was changed from %3 to %4.

�I/O priority of thread %2 in process %1 was changed from %3 to %4.

hExecution of the process %1 has been suspended.

dExecution of the process %1 has been resumed.

PJob %1 started with status code %2.

XJob %1 terminated with status code %2.

�Enumerated process %1 had started at time %2 by parent %3 running in session %4 with name %6.

�Process %1 started at time %2 by parent %3 running in session %4 with name %6.

�Process %1 (which started at time %2) stopped at time %3 with exit code %4.

�Enumerated process %1 had started at time %3 by parent %4 running in session %6 with name %11.

�Process %1 started at time %2 by parent %3 running in session %4 with name %6.

Enumerated process %1 had started at time %3 by parent %4 running in session %6 with name %11.%nEnabled security mitigations: %16.

�Process %1 started at time %3 by parent %4 running in session %6 with name %11.

�Process %1 started at time %3 by parent %4 running in session %6 with name %11.%nEnabled security mitigations: %16.

xA memory range descriptor has been marked as reserved.

�Unexpected GPE event was fired on GPE bits that should be disabled.

�A temperature change notification (Notify(thermal_zone, 0x80)) for ACPI thermal zone %2 has been received.             %n_TMP = %3K             %n_PSV = %4K             %n_AC0 = %5K             %n_AC1 = %6K             %n_AC2 = %7K             %n_AC3 = %8K             %n_AC4 = %9K             %n_AC5 = %10K             %n_AC6 = %11K             %n_AC7 = %12K             %n_AC8 = %13K             %n_AC9 = %14K             %n_HOT = %15K             %n_CRT = %16K

�A trip point change notification (Notify(thermal_zone, 0x81)) for ACPI thermal zone %2 has been received.             %n_TMP = %3K             %n_PSV = %4K             %n_AC0 = %5K             %n_AC1 = %6K             %n_AC2 = %7K             %n_AC3 = %8K             %n_AC4 = %9K             %n_AC5 = %10K             %n_AC6 = %11K             %n_AC7 = %12K             %n_AC8 = %13K             %n_AC9 = %14K             %n_HOT = %15K             %n_CRT = %16K

lThe active cooling device %6 has been turned %8.             %nThermal zone device instance: %2             %nActive cooling package: _AC%3             %nNamespace object: _AL%4

lThe active cooling device %6 has been turned %7.             %nThermal zone device instance: %2             %nActive cooling package: _AC%3             %nNamespace object: _AL%4

LACPI method %2 evaluation has %3.

lThe active cooling device %2 has been turned %3.

�The passive cooling device %2 throttle has changed to %3 percent.

�The device %2 has the following cooling state.             %nActive cooling: %3             %nPassive cooling: %4 percent

`ACPI device %2 is undergoing %3. Status %4.

<ACPI device OverRide - %1

�Error occured while interpreting AML code: scope %1, object %2. Status %3.

TACPI method %2 has high frequency %3.

�A button notification for ACPI button %2 has been received. Capabilities = %3, EventMask = %4.

�A button IRP for ACPI button %2 has been completed. EventMask = %3, IRP = %4.

�The strict S4 enforcement _DSM failed evaluation. Status %1.

4Deprecated module %1.

xProcess %2 encountered a fatal user callback exception.

XThe process launches a 16 bit process.

HWindows component on demand %1.

�The Loader encountered a fatal error while loading a thread from process image name %1.

lA fatal error occured during initalization of %1.

�The Loader encountered a fatal error running process image name %1.

�The process failed to handle ERROR_ELEVATION_REQUIRED during the creation of a child process.

<Deprecated COM CLSID %1.

�MUI notify operation failed with status code %1. No callbacks were invoked.

 MUI Callback failed for file %1 because it can not be loaded. To correct this error, replace this file or repair your Windows installation.

`MUI Callback failed for file %1 registered as type %2 because the function %3 does not exist in the dll. To correct this error, replace the file or fix the registry entry.

XMUI Callback failed for file %1 because it is not signed by Microsoft. To correct this error, replace with the original file that came with this Windows installation.

MUI Callback file %1 cannot be found. To correct this error, repair the registry or copy the file to the specified location.

�Wow redirection could not be disabled. New resource cache will not be built.

�Resource cache cannot be opened in writable mode. New resource cache will not be built.

`Live resource cache could not be disabled.

�Unable to retrieve language settings from MUI API. New resource cache will not be built.

�Unable to parse the cacheable file list or write to the resource cache manifest. If configuration file was specified as command-line parameter, check that file exists and has correct format.  New resource cache will not be built.

�Changes made to resource cache manifest cannot be written to disk. New resource cache will not be built.

�New resource cache could not be built due to internal error: %1.

�Newly built resource cache could not be installed on the system.

�Resource cache manifest could not be created. New resource cache will not be built.

pMUI notification for UI Language change has been invoked with flags set to %1 and the new languages set to %2 and the previous languages set to %3. The extended flags is set to %4

�MUI notification callback API %2 in %1 returned with code %3.

�MUI resource cache builder has been called with the following parameters: %1.

�MUI resource cache manifest entry for file %1 has been updated. Affinity: '%2', Sequence: %3, and Priority: %4

Start: %1

End: %1

�New resource cache built and installed on system. New cache index is %1, live cache index is %2 and config is set to %3.

�Resource file %1 will not be cached since it is not used frequently in the system.

�The system is constrained in RAM, total disk space or free disk space, so the MUI resource cache will not be maintained.

�Unable to parse configuration parameters. The configuration parameters will be ignored.

�Provider %1 from process %3 does not have permission to write events to session "%2". Error: %4

(Failed to read debug info for WPP provider %1 from process %3 for session "%2". Error: %4. The image registering the provider may be malformed or may be an unsupported format (e.g. managed C++). ETW traces for this session will not include the image's debug information.

�The time elapsed before Bootmgr, based on the TSC, is %1 ms.

�Initialization of the firmware crypto hash provider resulted in status %1.

�The firmware update capsule (%1) failed to load with status %2.

�The PE/COFF image firmware update capsule (%1) failed to load with status %2.

�The Efi UpdateCapsule failed to apply updates with status %1.

�Firmware update supported status is %3. The BitLocker device flags are %1 and the PCR bitmap is %2.

�The firmware update capsule (%1) code integrity check failed with status %2.

�Windows failed to load the required system file %1 with error status %2.

�Windows failed to load the system registry file %1 with error status %2.

�Windows failed to initialize the ACPI with error status %1.

dWindows failed to load with error status %1.

�Windows failed to load image %2 imported from %1 with error status %3.

�Windows failed to import %2 from image %1 with error status %3.

`Windows failed to provision VSM Identity Key. Unsealing cached copy status: %1. New key generation status: %2. Measuring to PCR status: %3. Sealing and caching status: %4.

DVSM Identity Key Provisioning. Unsealing cached copy status: %1. New key generation status: %2. Measuring to PCR status: %3. Sealing and caching status: %4.

�Windows system integrity policy does not allow to load the required system file %1 with error status %2.

Windows failed to provision VSM Master Encryption Key. Using cached copy status: %1. Unsealing cached copy status: %2. New key generation status: %3. Sealing status: %4. TPM PCR mask: %5. Protector-assisted unseal status: %6. Protector-assisted re-seal status: %7. Protector update status: %8. Tpm Counter validation status: %9. Tpm Counter creation status: %10. Backup sealed blob used: %11.

�VSM Master Encryption Key Provisioning. Using cached copy status: %1. Unsealing cached copy status: %2. New key generation status: %3. Sealing status: %4. TPM PCR mask: %5. Protector-assisted unseal status: %6. Protector-assisted re-seal status: %7. Protector update status: %8. Tpm Counter validation status: %9. Tpm Counter creation status: %10. Backup sealed blob used: %11.

 Windows failed to provision the TPM Storage Root Key with error status:%1. Reading SrkPolicy status: %2. SrkSymKeyPolicy value: %3. TPM symmetric key capability: %4. AES bits used: %5. SrkAsymKeyPolicy value: %6. TPM asymmetric key capability: %7. Rsa bits used: %8.

HWindows successfully provisioned the TPM Storage Root Key. This operation took %1 milliseconds. Reading SrkPolicy status: %2. SrkSymKeyPolicy value: %3. TPM symmetric key capability: %4. AES bits used: %5. SrkAsymKeyPolicy value: %6. TPM asymmetric key capability: %7. Rsa bits used: %8.

�Windows failed to provision TPM binding information with error status:%1.

�NFIT ACPI table is not properly formed, and could not be parsed.

�Previous error detected while attempting to execute Measured Launch Environment. TXT error code: %1.

\Firmware provided SINIT ACM not used. %1

�Windows failed to provision DRTM-bound VSM Master Encryption Key . Using cached copy status: %1. New key generation status: %2. Sealing status: %3. UEFI keys provided to Secure Kernel status: %4.

�Windows successfully provisioned DRTM-bound VSM Master Encryption Key. Using cached copy status: %1. New key generation status: %2. Sealing status: %3. UEFI keys provided to Secure Kernel status: %4.

�Windows skipped provisioning the TPM Storage Root Key because the NoAutoProvision registry value was set.

`Trace point: Function:%1 Point:%2 Status:%3

PVSM Master Key Array Package Read and Unseal From Disk%n%nStatus: %1%nOsDeviceId: %2%nSystemRoot: %3%nVsmLKeyRelPath: %4%nLatchedUnsealPolicyRelPath: %5%nUnlatchedUnsealPolicyRelPath: %6%nLatchedPrimaryProtectorVariableName: %7%nLatchedSecondaryProtectorVariableName: %8%nUnlatchedPrimaryProtectorVariableName: %9%nUnlatchedSecondaryProtectorVariableName: %10%nLatchedProtectorUsedLocal: %11%nLatchTheUnlatchedLocal: %12%nUnsupportedRollbackLocal: %13%nUpgradedAntirollbackPolicyExistsLocal: %14%nPkgWasCorruptOrUnavailableLocal: %15%nCreationStateVerifiedLocal: %16%nPrimaryProtectorTargetPcrSealMaskLocal: %17%nLatchedProtectorExists: %18%nUnlatchedProtectorExists: %19%nKeyPkgIdTpmCounterValue: %20%nActivePolicyVersion: %21%nUseUnlatchedProtector: %22%nNeedToResealPrimaryProtector: %23%nNeedToResealSecondaryProtector: %24%nNeedToResealPca2023Protector: %25%n%nSubstatus%n%nPrimaryBlobUnsealStatus: %26%nBackupBlobUnsealStatus: %27%nPca2023ProtectorUnsealStatus: %28%nBackupBlobValidityCheckStatus: %29%nBackupBlobStillValid: %30%nPca2023ProtectorValidityCheckStatus: %31%nPca2023ProtectorStillValid: %32%nPrimaryBlobResealStatus: %33%nBackupBlobResealStatus: %34%nPca2023ProtectorResealStatus: %35%nV2ProtectorsUsed: %36%nLegacyUefiVarQueryStatus: %37%nLegacyUefiVarCleanupStatus: %38%nActivePolicyVersion: %39%nLatchedPolicyVersion: %40%nUnlatchedPolicyVersion: %41%nLatchedUnsealPolicyValid: %42%n%nLatched unseal policy%n%nVersion: %43%nVarDataOffset: %44%nStructureSize: %45%nPolicyVersion: %46%nPolicyHashLength: %47%nWinloadSVN: %48%nWinresumeSVN: %49%nBootmgrSVN: %50%nLKeyPkgId: %51%nUnlatchedUnsealPolicyValid: %52%n%nUnlatched unseal policy%n%nVersion: %53%nVarDataOffset: %54%nStructureSize: %55%nPolicyVersion: %56%nPolicyHashLength: %57%nWinloadSVN: %58%nWinresumeSVN: %59%nBootmgrSVN: %60%nLKeyPkgId: %61%n

Seal and Store on Disk Status%n%nStatus: %1%nOsDeviceId: %2%nSystemRoot: %3%nPcrSealMask: %4%nLatchTheUnlatched: %5%nUpgradedAntirollbackPolicyExists: %6%nEncryptionStatus: %7%nKeyPkgIdTpmCounterValue: %8%nEncryptedLKeyArrayPkgSize: %9%nEncryptedLKeyPkgPdGuid: %10%nUnlatchedUnsealPolicySize: %11%nUnlatchedProtectorExists: %12%nLatchedUnsealPolicySize: %13%nLatchedProtectorExists: %14%n%nLatched unseal policy%n%nVersion: %15%nVarDataOffset: %16%nStructureSize: %17%nPolicyVersion: %18%nPolicyHashLength: %19%nWinloadSVN: %20%nWinresumeSVN: %21%nBootmgrSVN: %22%nLKeyPkgId: %23%n%nUnlatched unseal policy%n%nVersion: %24%nVarDataOffset: %25%nStructureSize: %26%nPolicyVersion: %27%nPolicyHashLength: %28%nWinloadSVN: %29%nWinresumeSVN: %30%nBootmgrSVN: %31%nLKeyPkgId: %32%n

lRead and Unseal Master Key Array Package Status%n%nStatus: %1%nPrimarySealedBlobName: %2%nSecondaryProtectorVariableName: %3%nBlobFromUefiVariableSize: %4%nUefiContentIsSealed: %5%nUnsealedBlobSize: %6%nPcr7SealingUsed: %7%nPkgTpmSealMaskLocal: %8%nPkgTpmCreationMaskLocal: %9%nNeedToResealKeyPkg: %10%nNeedToResealBackup: %11%nNeedToResealPca2023Backup: %12%nPlaintextBlobSize: %13%nPlaintextIsLegacyFormat: %14%nUefiBlobIsCorrupt: %15%nNewKeyID: %16%nVerifiedMicrosoftAuthority: %17%nContainsAuthorityData: %18%nBootmgrAuthorityEventCount: %19%nAuthority: %20%n%nSubstatus%n%nPrimaryBlobUnsealStatus: %21%nBackupBlobUnsealStatus: %22%nPca2023ProtectorUnsealStatus: %23%nBackupBlobValidityCheckStatus: %24%nBackupBlobStillValid: %25%nPca2023ProtectorValidityCheckStatus: %26%nPca2023ProtectorStillValid: %27%nPrimaryBlobResealStatus: %28%nBackupBlobResealStatus: %29%nPca2023ProtectorResealStatus: %30%nV2ProtectorsUsed: %31%nLegacyUefiVarQueryStatus: %32%nLegacyUefiVarCleanupStatus: %33%nActivePolicyVersion: %34%nLatchedPolicyVersion: %35%nUnlatchedPolicyVersion: %36%n

l	Get Plaintext Master Key Array Status%n%nStatus: %1%nSecondaryProtectorVariableName: %2%nNeedToResealPrimaryProtector: %3%nNeedToResealSecondaryProtector: %4%nNeedToResealPca2023Protector: %5%nSealedBackupEncryptionKeySize: %6%nSealedPca2023EncryptionKeySize: %7%nUefiBlobIsCorrupt: %8%nPcr7SealingUsed: %9%nCreationStateVerifiedLocal: %10%nVerifiedMicrosoftAuthority: %11%nContainsAuthorityData: %12%nBootmgrAuthorityEventCount: %13%nPrimaryProtectorTargetPcrSealMaskLocal: %14%nAuthority: %15%n%nSubstatus%n%nPrimaryBlobUnsealStatus: %16%nBackupBlobUnsealStatus: %17%nPca2023ProtectorUnsealStatus: %18%nBackupBlobValidityCheckStatus: %19%nBackupBlobStillValid: %20%nPca2023ProtectorValidityCheckStatus: %21%nPca2023ProtectorStillValid: %22%nPrimaryBlobResealStatus: %23%nBackupBlobResealStatus: %24%nPca2023ProtectorResealStatus: %25%nV2ProtectorsUsed: %26%nLegacyUefiVarQueryStatus: %27%nLegacyUefiVarCleanupStatus: %28%nActivePolicyVersion: %29%nLatchedPolicyVersion: %30%nUnlatchedPolicyVersion: %31%n%nValidated Unseal Policy%n%nVersion: %32%nVarDataOffset: %33%nStructureSize: %34%nPolicyVersion: %35%nPolicyHashLength: %36%nWinloadSVN: %37%nWinresumeSVN: %38%nBootmgrSVN: %39%nLKeyPkgId: %40%n

Read and Unseal Master Key Array Package error%n%nLegacyMainBlobVariableName: %1%nLegacySecondaryProtectorVariableName: %2%nPkgWasCorruptOrUnavailableLocal: %3%nKeysAreLegacyLocal: %4%nCreationStateVerifiedLocal: %5%nPrimaryProtectorTargetPcrSealMaskLocal: %6%n%nSubstatus%n%nPrimaryBlobUnsealStatus: %7%nBackupBlobUnsealStatus: %8%nPca2023ProtectorUnsealStatus: %9%nBackupBlobValidityCheckStatus: %10%nBackupBlobStillValid: %11%nPca2023ProtectorValidityCheckStatus: %12%nPca2023ProtectorStillValid: %13%nPrimaryBlobResealStatus: %14%nBackupBlobResealStatus: %15%nPca2023ProtectorResealStatus: %16%nV2ProtectorsUsed: %17%nLegacyUefiVarQueryStatus: %18%nLegacyUefiVarCleanupStatus: %19%nActivePolicyVersion: %20%nLatchedPolicyVersion: %21%nUnlatchedPolicyVersion: %22%n

$
Read and Unseal Master Key Array Package Status%n%nStatus: %1%nOsDeviceId: %2%nOsDataDeviceId: %3%nSystemRoot: %4%nVsmLKeyRelPath: %5%nLatchedUnsealPolicyRelPath: %6%nUnlatchedUnsealPolicyRelPath: %7%nLatchedPrimaryProtectorVariableName: %8%nLatchedSecondaryProtectorVariableName: %9%nUnlatchedPrimaryProtectorVariableName: %10%nUnlatchedSecondaryProtectorVariableName: %11%nLegacyMainBlobVariableName: %12%nLegacySecondaryProtectorVariableName: %13%nLatchedProtectorUsedLocal: %14%nLatchTheUnlatchedLocal: %15%nUnsupportedRollbackLocal: %16%nUpgradedAntirollbackPolicyExistsLocal: %17%nFirstWriteToDiskLocal: %18%nWritePkgToUefiLocal: %19%nPkgWasCorruptOrUnavailableLocal: %20%nKeysAreLegacyLocal: %21%nCreationStateVerifiedLocal: %22%nPrimaryProtectorTargetPcrSealMaskLocal: %23%n%nSubstatus%n%nPrimaryBlobUnsealStatus: %24%nBackupBlobUnsealStatus: %25%nPca2023ProtectorUnsealStatus: %26%nBackupBlobValidityCheckStatus: %27%nBackupBlobStillValid: %28%nPca2023ProtectorValidityCheckStatus: %29%nPca2023ProtectorStillValid: %30%nPrimaryBlobResealStatus: %31%nBackupBlobResealStatus: %32%nPca2023ProtectorResealStatus: %33%nV2ProtectorsUsed: %34%nLegacyUefiVarQueryStatus: %35%nLegacyUefiVarCleanupStatus: %36%nActivePolicyVersion: %37%nLatchedPolicyVersion: %38%nUnlatchedPolicyVersion: %39%n

 Create Sealed Encrypt Key Status%n%nStatus: %1%nPcrMask: %2%nUnsealPolicyPdGuid: %3%nSealingProtectorFixedBufferSize: %4%nSealingProtectorUsedBufferSize: %5%nSealedSecretBufferSize: %6%nPcrInfoArrayElCount: %7%n%nUnseal policy%n%nVersion: %8%nVarDataOffset: %9%nStructureSize: %10%nPolicyVersion: %11%nPolicyHashLength: %12%nWinloadSVN: %13%nWinresumeSVN: %14%nBootmgrSVN: %15%nLKeyPkgId: %16%n

Get Sealed Protector Status%n%nStatus: %1%nProtectorName: %2%nSealedEncryptionKeySize: %3%nProtectorBlobFromUefiVariableSize: %4%n

�SRTM PCR Values%n%nalgId: %1%ndigestLength:%2%nPcrIndex: %3%nPcrValue: %4%n

�Soft Restart failed to complete with status: %1 due to %2 outstanding unclaimed allocations

�Soft Restart failed to restore memory partition %1 with status: %2

�Soft Restart failed to register with Soft Restart extension. The versions are not compatible.

�Soft Restart failed to establish connection with secure load with status: %1

�Boot Policy Migration used an authenticated variable.  Status: %1

�Boot Policy Migration used an unauthenticated variable.  Status: %1

0Info: %1 Status: %2

4Error: %1 Status: %2

dMeasured Boot Measurement Failure. Status: %1

PTPM Measurement Failure. Status: %1

TFailure to close TCG log. Status: %1

�Soft Restart driver failed to register itself as a filter with status: %1

�Soft Restart driver failed to store BCD store when BCDCache is enabled with status: %1

�Soft Restart driver failed to query MEMDISK configuration from the current OS with status: %1

�A command was submitted to the TPM.%nCommand code: %1.%nResponse code: %2.%nElapsed time: %3ms.

�A command could not be submitted to the TPM.%nCommand code: %1.%nError code: %2.%nElapsed time: %3ms.

�The TPM was found not to be useable for BitLocker. Flags: %1.

�Measured Boot library was initialized. Phase: %1, StatusCode: %2.

HMeasured Boot library encountered a failure and entered insecure state. InitState: %1, StatusCode: %2, Failure Address: %3, Reference Address: %4, Reason: %5.

�DRTM Security Version Number check failed. SvnCounterId: %1, StatusCode: %2, Svn Value: %3, Previous SVN Value: %4.

DIntel TXT SENTER time: %1 ms.

`File modification detected after load: %1.

hRegistry modification detected after load: %1.

XIntel TXT prepared. ACM date: %2/%1/%3.

pSystem Guard enabled but not supported. Reason: %1

\VBS is configured to disallow trustlets.

`Boot menu timer canceled due to key press.

�Windows boot environment failed to initialize TPM device. StatusCode: %1, Position: %2.

\SMM isolation level decreased. Reason: %1

�Hardware memory mirroring is not supported. MirrorStatus: %1

`EFI time zone bias: %1. Daylight flags: %2.

dHardware memory mirroring support is enabled.

�Previous error detected while attempting to execute Measured Launch Environment. Source: %1 Error code: %2.

�This system has not supplied a valid framebuffer and the graphical boot menu is not used.

�HotPatch %4 failed to apply with Status: %2 at failure point: %1.

�Failed to build image path for dump stack module %1. Status: %2.

lFailed to load dump stack module %1. Status: %2.

lEarly dump stack succesfully loaded by OS loader.

pEarly boot crash dump generation is not supported.

�Soft restart prepare was vetoed by component %2 with status %1.

�Soft restart finalize was vetoed by component %2 with status %1.

�Early crash dump support is disabled by registry configuration.

�Failed to query early dump enablement information from the registry with status %1.

Failed to query dedicated dump file name for the target OS with status %1. Early crash dump functinality will not be loaded.

�Dedicated dump file names do not match (%1, %2). Early crash dump functinality will not be loaded.

dFailed to query dump module list. Status: %1.

tBoot Application %1 dropped %2 events during logging.

|Cached boot BCD store was loaded by the boot environment.

�TPRs are supported, TPR setup will be requested while attempting to execute Measured Launch Environment.

�BCD Option '%1' was not applied due to Secure Boot being enabled. Option: %2

HACM InfoTable version used: %1.

�Windows boot manager revocation policy version %1 is applied.

�Windows boot manager revocation policy version %1 was not found. It is recommended that it be redeployed.

`Succeeded in updating the SBAT value in FW.

XFailed to update the SBAT value in FW.

�Secure Boot revoked boot app %4 with SVN %1. Min SVN required: %2. Status: %3.

�Failed to compose API Set schema extension with status: %1

\Windows failed to provision VSM Master Encryption Key. Using cached copy status: %1. Primary Blob Unseal Status: %2. Backup Blob Unseal Status: %3. Pca2023 Protector Unseal Status: %4. Backup Blob Validity Check Status: %5. Backup Blob Validity Check Result: %6. Pca2023 Protector Validity Check Status: %7. Pca2023 Protector Validity Check Result: %8. Primary Blob Reseal Status: %9. Backup Blob Reseal Status: %10. Pca2023 Protector Reseal Status: %11. New key generation status: %12. Sealing status: %13. TPM PCR mask: %14. Tpm Counter validation status: %15. Tpm Counter creation status: %16. Backup sealed blob used: %17. Pca2023 Protector cleaned up post upgrade status: %18.

@VSM Master Encryption Key Provisioning. Using cached copy status: %1. Primary Blob Unseal Status: %2. Backup Blob Unseal Status: %3. Pca2023 Protector Unseal Status: %4. Backup Blob Validity Check Status: %5. Backup Blob Validity Check Result: %6. Pca2023 Protector Validity Check Status: %7. Pca2023 Protector Validity Check Result: %8. Primary Blob Reseal Status: %9. Backup Blob Reseal Status: %10. Pca2023 Protector Reseal Status: %11. New key generation status: %12. Sealing status: %13. TPM PCR mask: %14. Tpm Counter validation status: %15. Tpm Counter creation status: %16. Backup sealed blob used: %17. Pca2023 Protector cleaned up post upgrade status: %18.

XWindows failed to provision DRTM-bound VSM Master Encryption Key . Using cached copy status: %1. New key generation status: %2. Sealing status: %3. UEFI keys provided to Secure Kernel status: %4. UnLatchedCiPolicy version: %5. LatchedCiPolicyVersion: %6. LatchedAntiRollbackCounterValue: %7. CurrentCiPolicyVersion: %8. CurrentAntiRollbackCounterValue: %9. MinimumUnsealCiPolicyVersion: %10. AuthorizationIsDelegated: %11.

`Windows successfully provisioned DRTM-bound VSM Master Encryption Key. Using cached copy status: %1. New key generation status: %2. Sealing status: %3. UEFI keys provided to Secure Kernel status: %4. UnLatchedCiPolicy version: %5. LatchedCiPolicyVersion: %6. LatchedAntiRollbackCounterValue: %7. CurrentCiPolicyVersion: %8. CurrentAntiRollbackCounterValue: %9. MinimumUnsealCiPolicyVersion: %10. AuthorizationIsDelegated: %11.

dFASR Platform Verification. FASR cert present: %1. FASR cert signature validation status: %2. BootmgrAuthorityEventCount: %3. VerifiedMicrosoftAuthority: %4. FASR PCR values validation status: %5. PCR mismatch index: %6. FASR cert size: %7. FASR cert: %8. FASR signature size: %9. FASR signature: %10.

�Soft Restart failed to register with Soft Restart extension. The versions are not compatible. Status: %1, Vtl: %4

�Previous error detected while attempting to execute Measured Launch Environment. AMDSL error code: %1.

�Windows failed to provision VSM Master Encryption Key. Using cached copy status: %1. Primary Blob Unseal Status: %2. Backup Blob Unseal Status: %3. Pca2023 Protector Unseal Status: %4. Backup Blob Validity Check Status: %5. Backup Blob Validity Check Result: %6. Pca2023 Protector Validity Check Status: %7. Pca2023 Protector Validity Check Result: %8. Primary Blob Reseal Status: %9. Backup Blob Reseal Status: %10. Pca2023 Protector Reseal Status: %11. New key generation status: %12. Sealing status: %13. TPM PCR mask: %14. Tpm Counter validation status: %15. Tpm Counter creation status: %16. Backup sealed blob used: %17. Pca2023 Protector cleaned up post upgrade status: %18. Need To Roll Lkey: %19. CreationState Verified: %20. V2 Protectors Used: %21. Legacy UEFI Var Query Status: %22. Legacy UEFI Var Cleanup Status: %23. VBS Data Protection Enabled: %24. Vbs Data Protection Opted In Registry: %25. Vbs Data Protection TPM Counter Status: %26. First Pkg Write To Disk: %27. Write Pkg To UEFI: %28. Latched Protector Used: %29. Update Latched Protectors: %30. Unsupported Rollback: %31. Upgraded VBS Policy Exists: %32. TPM Counter Increment Status: %33. Active Policy Version: %34. Latched Policy Version: %35. Unlatched Policy Version: %36. Latched Primary Blob Reseal Status: %37. Latched Backup Blob Reseal Status: %38. Latched Pca2023 Protector Reseal Status: %39. Latched Pca2023 Protector Cleanup PostUpgrade Status: %40. Unlatched Primary Blob Reseal Status: %41. Unlatched Backup Blob Reseal Status: %42. Unlatched Pca2023 Protector Reseal Status: %43. Unlatched Pca2023 Protector Cleanup PostUpgrade Status: %44.

�VSM Master Encryption Key Provisioning. Using cached copy status: %1. Primary Blob Unseal Status: %2. Backup Blob Unseal Status: %3. Pca2023 Protector Unseal Status: %4. Backup Blob Validity Check Status: %5. Backup Blob Validity Check Result: %6. Pca2023 Protector Validity Check Status: %7. Pca2023 Protector Validity Check Result: %8. Primary Blob Reseal Status: %9. Backup Blob Reseal Status: %10. Pca2023 Protector Reseal Status: %11. New key generation status: %12. Sealing status: %13. TPM PCR mask: %14. Tpm Counter validation status: %15. Tpm Counter creation status: %16. Backup sealed blob used: %17. Pca2023 Protector cleaned up post upgrade status: %18. Need To Roll Lkey: %19. CreationState Verified: %20. V2 Protectors Used: %21. Legacy UEFI Var Query Status: %22. Legacy UEFI Var Cleanup Status: %23. VBS Data Protection Enabled: %24. Vbs Data Protection Opted In Registry: %25. Vbs Data Protection TPM Counter Status: %26. First Pkg Write To Disk: %27. Write Pkg To UEFI: %28. Latched Protector Used: %29. Update Latched Protectors: %30. Unsupported Rollback: %31. Upgraded VBS Policy Exists: %32. TPM Counter Increment Status: %33. Active Policy Version: %34. Latched Policy Version: %35. Unlatched Policy Version: %36. Latched Primary Blob Reseal Status: %37. Latched Backup Blob Reseal Status: %38. Latched Pca2023 Protector Reseal Status: %39. Latched Pca2023 Protector Cleanup PostUpgrade Status: %40. Unlatched Primary Blob Reseal Status: %41. Unlatched Backup Blob Reseal Status: %42. Unlatched Pca2023 Protector Reseal Status: %43. Unlatched Pca2023 Protector Cleanup PostUpgrade Status: %44.

�%3 shim(s) were applied to driver [%1].%n%nShim(s) source: %2.%n%nShim GUID(s): %4.

�Flags [%4] were applied to device [%1] - class [%2].%n%nFlags source: %3.

�Process %1 started at time %2 by parent %3 running as package %4 with executable %5 is application %6.

�%2: Cannot create the process for package %1 because an error was encountered. %3

�%2: Cannot create the process for package %1 because an error was encountered while querying the fast cache. %3

�%2: Cannot create the process for package %1 because an error was encountered while preparing the App credentials. %3

%2: Cannot create the process for package %1 because an error was encountered while checking the user-level package status. %3

%2: Cannot create the process for package %1 because an error was encountered while checking the machine-level package status. %3

�%2: Cannot create the process for package %1 because an error was encountered while verifying the App credentials. %3

�App %1 was terminated with error %2 because of an issue with application binary %3. This could be because the binary is unsigned, contains an untrusted signature, or has been corrupted or tampered with. Reinstall the application to fix this issue.

|App %1 prevented the load of generated binary %3 due to error %2. This could be because the binary is unsigned, contains an untrusted signature, or has been corrupted or tampered with.

dAn app prevented the load of a binary due to error %1. This could be because the binary is unsigned, contains an untrusted signature, or has been corrupted or tampered with.

4%2: Package runtime information %1 is corrupted (address=%5, size=%3, offset=%4, section=%6, processid=%7). Reinstall the package to fix this issue.

4%2: Package runtime information %1 is missing expected data (address=%4, size=%3, section=%5, processid=%6). Reinstall the package to fix this issue.

L%2: Package runtime information %1 contains conflicting data (address=%5, size=%3, offset=%4, section=%6, processid=%7). Reinstall the package to fix this issue.

L%2: Package runtime information %1 contains unexpected data (address=%5, size=%3, offset=%4, section=%6, processid=%7). Reinstall the package to fix this issue.

�%2: Package runtime information %1 failed to load (processid=%3).

�Package runtime information %1 failed to load because exception %2 occurred.

�%2: Cannot create the process for package %1 because an error was encountered while loading the runtime information. %3

�CreateAppContainerProfile failed for AppContainer %2 with error %1.

�DeleteAppContainerProfile failed for AppContainer %2 with error %1.

�UpdateAppContainerProfile failed for AppContainer %2 with error %1.

�CreateAppContainerProfile failed with error %1 because it was unable to create registry key %2.

�CreateAppContainerProfile failed with error %1 because it was unable to set security on registry key %2.

�AppContainer profile failed with error %1 because it was unable to delete registry key %2.

�CreateAppContainerProfile failed with error %1 because it was unable to create folder %2.

�CreateAppContainerProfile failed with error %1 because it was unable to set attributes on folder %2.

�CreateAppContainerProfile failed with error %1 because it was unable to verify the existence of registry key %2.

�CreateAppContainerProfile failed with error %1 because it was unable to verify the existence of folder %2.

�CreateAppContainerProfile failed with error %1 because it was unable to find the users local app data folder.

�AppContainer profile failed with error %1 because it was unable to delete folder %2 or its contents.

�AppContainer profile failed with error %1 because it was unable to look up the AppContainer name.

�AppContainer profile failed with error %1 because it was unable to look up the AppContainer display name.

�CreateAppContainerProfile failed with error %1 because it was unable to register with the firewall.

�DeleteAppContainerProfile failed with error %1 because it was unable to unregister with the firewall.

�App Container profile failed with error %1 because it was unable to register the AppContainer SID.

�DeleteAppContainerProfile failed with error %1 because it was unable to unregister the AppContainer SID.

TSuccessfully created AppContainer %1.

�AppContainer %1 was not created because it already exists.

TSuccessfully deleted AppContainer %1.

TSuccessfully updated AppContainer %1.

4%2: Package runtime information %1 is missing expected data (address=%4, size=%3, section=%5, processid=%6). Reinstall the package to fix this issue.

�%2: Application identity not accessible while loading package runtime information %1 (address=%4, size=%3, processid=%5).

�Failed with %1 while retrieving AppContainer %2 information during interaction with Restricted AppContainer.

�Failed with %1 while retrieving AppContainer information during interaction with Restricted AppContainer.

�Failed with %1 while retrieving AppContainer information. Call invalid from this process type.

�Failed to create shared context object for Restricted AppContainer %2 with %1.

xFailed to activate Restricted AppContainer %2 with %1.

�Creation of Restricted AppContainer %2 failed with %1 because an invalid capability was specified.

�Opening existing Restricted AppContainer %2 failed with %1 because the capabilities storage value could not be read.

�Failed to create the capabilities storage value for Restricted AppContainer %2 with %1.

PThe package %1 requires validation.

\Modification was detected in package %1.

\Failed to terminate app with package %1.

lValidation of app with package %1 was successful.

�Failed with %1 to retrieve the trust state of the package %2 folder.

tApp Integrity check failed with %1 while checking %2.

�App Integrity terminated an application. Integrity check for %2 returned %1.

TApp Integrity check for %1 timed out.

�%2: Cannot create the process for package %1 because an error was encountered while performing the integrity check. %3

�Deployment server integrity check of package %1 failed with %2.

�Failed with %1 retrieving AppModel Runtime group policy values.

�Failed with %1 validating AppModel Runtime group policy values.

�Failed with %1 retrieving AppModel Runtime status for package %2.

�Failed with %1 retrieving AppModel Runtime status for package %2 for user %3.

�Failed with %1 modifying AppModel Runtime status for package %2 (current status = %4, desired status = %3).

�AppModel Runtime status for package %1 successfully updated to %2 (previous status = %3).

�Failed with %1 modifying AppModel Runtime status for package %2 for user %3 (clear=%4, set=%5).

�Successfully updated AppModel Runtime status for package %1 for user %2 (clear=%3, set=%4).

�Failed with %1 modifying AppModel Runtime status version (context = %2).

tAppModel Runtime status version successfully updated.

�%2: Cannot create the process for package %1 because an error was encountered while performing the app data creation. %3

�Package runtime information %1 failed to refresh because the following error %2 occurred in operation type %3.

error %2: Cannot register the %1 package because the following error was encountered while opening the HKEY_USERS registry key

8error %4: Cannot register the %1 package because the following error was encountered while enumerating to remove the %2\%3 package family registry key

 error %4 : Cannot register the %1 package because the following error was encountered while creating the %2\%3 package family registry key

error %4: Cannot register the %1 package because the following error was encountered while removing the %2\%3 package family registry key

�%2: Package family %1 runtime information is corrupted. Attempting to correct the issue.

�%2: Package family %1 runtime information is corrupted but we cannot repair it at this time.

$Failed with %1 to get IsPackageStageInPlace info from State Repository cache for package %2. The app will by default require integrity check.

<Creating AppContainer %1.

`Finished creating AppContainer %2 with %1.

<Deleting AppContainer %1.

`Finished deleting AppContainer %2 with %1.

<Updating AppContainer %1.

`Finished updating AppContainer %2 with %1.

dCreating firewall rules for AppContainer %1.

�Finished creating firewall rules for AppContainer %2 with %1.

dDeleting firewall rules for AppContainer %1.

�Finished deleting firewall rules for AppContainer %2 with %1.

TCreating Restricted AppContainer %1.

tFinished creating Restricted AppContainer %2 with %1.

TDeleting Restricted AppContainer %1.

tFinished deleting Restricted AppContainer %2 with %1.

POpening Restricted AppContainer %1.

tFinished opening Restricted AppContainer %2 with %1.

lEnumerating all Restricted AppContainers for %1.

�Finished enumerating all Restricted AppContainers for AppContainer %2 with %1.

lLaunching process in Restricted AppContainer %1.

�Finished launching process in Restricted AppContainer %2 with %1.

|Terminating all processes in Restricted AppContainer %1.

�Finished terminating all processes in Restricted AppContainer %2 with %1.

HChecking package graph for %1.

dPackage graph check for %2 finished with %1.

hPerforming app integrity check for package %1.

tApp integrity check for package %2 finished with %1.

xPerforming runtime app integrity check for package %1.

�Runtime app integrity check for package %2 finished with %1.

�Firewall Service not running. Skipping creation of firewall rules for AppContainer %1.

lUpdating Restricted AppContainer Capabilities %1.

�Finished Updating Restricted AppContainer Capabilities %2 with %1.

xCreated process %1 for application %4 in package %2. %5

�%4: Cannot create the process for package %1 because an error was encountered. %5

�%4: Cannot create the process for package %1 because an error was encountered while preparing for activation. %5

�%4: Cannot create the process for package %1 because an error was encountered while elevating the token. %5

�%4: Cannot create the process for package %1 because UI Access is not supported for Desktop AppX processes. %5

�%4: Cannot create the process for package %1 because an error was encountered while adjusting the token. %5

�%4: Cannot create the process for package %1 because an error was encountered while launching. %5

�%4: Cannot create the process for package %1 because an error was encountered while configuring runtime. %5

�%4: Cannot create the process for package %1 because an error was encountered while resuming the thread. %5

lCreated Desktop AppX container %3 for package %1.

�Added process %1 to Desktop AppX container %3 for package %2.

�%1: Cannot add process %2 to Desktop AppX container %4 for package %3 because an error was encountered.

�%1: Cannot create the Desktop AppX container for package %2 because an error was encountered creating the job.

�%1: Cannot create the Desktop AppX container for package %2 because an error was encountered creating the description.

�%1: Cannot create the Desktop AppX container for package %2 because an error was encountered converting the job.

�%1: Cannot create the Desktop AppX container for package %2 because an error was encountered configuring the runtime.

pDestroyed Desktop AppX container %2 for package %1.

|Cannot destroy Desktop AppX container %2 for package %1.

�PSMFlags for Desktop AppX process %1 with applicationID %2 is %3.

�Cannot start the process %2 because the executable was not found the package %1.

dError while deleting file: %1. Error Code: %2

pError while deleting directory: %1. Error Code: %2

DError while allocating memory

lApiSet Function: %1 returned with Error Code: %2

�Low-level data store access error. Function: %1 returned with Error Code: %2

�Cleanup of temporary state has been skipped due to low disk usage.

\Cleanup of temporary state has completed.

�Cleanup of temporary state was unable to enumerate the user profiles.  Object: %1, Error Code: %2.

tCleanup of temporary state has aborted unexpectedly.

�Need to update state locations of package %1 for user %2 because the schema is not found. Error Code: %3

�Need to update state locations of package %1 for user %2 because the package is not found. Error Code: %3

�Need to update state locations of package %1 for user %2 because the package full name has changed. Error Code: %3

�Need to update state locations of package %1 for user %2 because the schema version has changed. Error Code: %3

lSucceeded to fix state locations for package %1.

�Failure to fix state locations for package %1. Error Code: %2

PSystem time initialized during boot

pAn application or system component changed the time

lSystem time synchronized with the hardware clock

\System time adjusted to the new time zone

xLeap second data initialized from registry during boot

XLeap second data updated from registry

TRegistry value invalid format or size

4Too many leap seconds

�Cannot decrease the number of leap seconds while the system is running

LAn invalid leap second was found

tThe list of leap seconds must be strictly increasing

�Cannot modify the existing leap seconds while the system is running

$Other reason

on

off

started

finished

@Platform-level Device Reset

@Function-level Device Reset

LAcpi Override attribute - MpSleep

PAcpi Override attribute - DisableS1

PAcpi Override attribute - DisableS2

PAcpi Override attribute - DisableS3

hAcpi Override attribute - DellMaxUlongBugcheck

lAcpi Override attribute - PciBusNumberTranslation

pAcpi Override attribute - RunRegMethodOnPciDevices

lAcpi Override attribute - RescanPostDependencies

�Acpi Override attribute - PlatformCheckD3ColdOnSurpriseRemoval

�Acpi Override attribute - PlatformCheckFailResetOnOpenHandles

PFan speed reporting is unsupported

disabled

Hdisabled due to HyperV opt-out

Tdisabled due to opt-out UEFI variable

`disabled due to secure boot being disabled

ldisabled due to DMA protection being unavailable

ldisabled due to the hypervisor being unavailable

`disabled due to VBS initialization failure

Tdisabled due to hardware constraints

pdisabled due to VBS anti-rollback policy is missing

\enabled due to VBS registry configuration

4enabled due to HyperV

Xenabled due to VBS locked configuration

Tenabled due to Code Integrity policy

8enabled due to Velocity

Penabled due to Hardware constraints

@BL_LOG_INFO_NONE: Info none

�BL_LOG_INFO_BLI_IO_INITED: IO initialized in boot library initialization.

�BL_LOG_INFO_BLI_FINISHED: Finished in boot library initialization.

�BL_LOG_INFO_BM_BL_INITED: The boot library has been initialized for bootmgr.

�BL_LOG_INFO_BM_GET_BOOT_SEQ: Getting boot sequence in bootmgr.

�BL_LOG_INFO_BM_LAUNCH_ENTRY: Launching boot entry in bootmgr.

�BL_LOG_INFO_BM_URI_UDP_REDIRECT: Attempting to redirect URI device to UDP device in bootmgr.

�BL_LOG_INFO_BM_BL_DESTROYED: The boot library about to be destroyed for bootmgr.

�BL_LOG_INFO_BM_RESTART: The bootmgr is about to be restarted.

�BL_LOG_INFO_WDS_BL_INITED: The boot library has been initialized for wdsmgr.

�BL_LOG_INFO_WDS_BL_DESTROYED: The boot library about to be destroyed for wdsmgr.

�BL_LOG_INFO_OSL_PREPARE_ENTERED: Reached prepare target within osloader.

�BL_LOG_INFO_OSL_OPEN_DEVICE: Preparing to open OS device in osloader.

�BL_LOG_INFO_OSL_LOAD_HYPERV: Loaded hypervisor if enabled.

�BL_LOG_INFO_OSL_LOAD_MODULES: Preparing to load OS modules within osloader.

�BL_LOG_INFO_OSL_KERNEL_SETUP: Setting up kernel within osloader.

�BL_LOG_INFO_OSL_PRELOAD_HYPERV: Preloaded hypervisor if enabled.

pBL_LOG_INFO_OSL_BOOT_CANCELLED: Boot was cancelled.

�BL_LOG_INFO_OSL_VSM_HIBERFILE_REPLAY_PROTECTION_PROVISION: TPM provisioned for the Hiberfile replay protection

�BL_LOG_INFO_TCB_LAUNCH_HYPERV: Preparing to launch hyper-v.

@BL_LOG_ERROR: Generic Error

�BL_LOG_ERROR_BLI_NET_INIT: BlNetInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_UTL_INIT: BlUtlInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_SEC_BOOT_INIT: BlSecureBootInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_PDATA_INIT: BlpPdInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_RES_INIT: BlpResourceInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_SEC_LAUNCH_INIT: BlpTcbLaunchInitialize failed in BL initialization.

�ERROR_BLI_CIPOLICY_BOOT_INIT: BlpSIPolicyInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_REFS_VOLUME_MOUNT: ReFS volume mount failed.

�BL_LOG_ERROR_BM_INIT_MACH_POL: BmSecureBootInitializeMachinePolicy failed in bootmgr.

�BL_LOG_ERROR_BM_FW_REG_SYSINT: BmFwRegisterSystemIntegrityPolicies failed in bootmgr.

�BL_LOG_ERROR_BM_RES_FIND_HTML: BlResourceFindHtml failed to find BOOTMGR.XSL in bootmgr.

�BL_LOG_ERROR_BM_XMI_INIT: BlXmiInitialize failed in bootmgr.

�BL_LOG_ERROR_BM_OPEN_DATA_STORE: BmOpenDataStore failed in bootmgr.

�BL_LOG_ERROR_BM_SELF_INT_CHK: BmpSelfIntegrityCheck failed in bootmgr.

�BL_LOG_ERROR_BM_FW_REG_REV_LIST: BmFwRegisterRevocationList failed in bootmgr.

�BL_LOG_ERROR_BM_RESUME_HIBER: BmResumeFromHibernate failed in bootmgr.

�BL_LOG_ERROR_BM_PURGE_OPT_START_SEQ: BL_ERROR_BM_PURGE_OPT_START_SEQ failed in bootmgr.

�BL_LOG_ERROR_BM_PURGE_OPT_BOOT_SEQ: BmPurgeOption failed for BCDE_BOOTMGR_TYPE_BOOT_SEQUENCE in bootmgr.

�BL_LOG_ERROR_BM_REOPEN_DATA_STORE: BmOpenDataStore failed on reopen in bootmgr.

�BL_LOG_ERROR_BM_UPDATE_APP_OPTS: BmpUpdateApplicationOptions failed in bootmgr.

�BL_LOG_ERROR_BM_LAUNCH_BOOT_ENTRY: BmpLaunchBootEntry failed in bootmgr.

�BL_LOG_ERROR_BM_CREATE_DEVICES: BmpCreateDevices failed in bootmgr.

�BL_LOG_ERROR_BM_LAUNCH_FLIGHT_BM: BmFwLaunchFlightedBootmgr failed in bootmgr.

�BL_LOG_ERROR_BM_FE_BOOTAPP_LD: Fatal error: failure to load boot app in bootmgr.

�BL_LOG_ERROR_BM_FE_CONFIG_DATA: Fatal error: failure attempting to read boot config file in bootmgr.

�BL_LOG_ERROR_BM_FE_NO_VALID_OS_ENTRY: Fatal error: no valid os entires found in bootmgr.

�BL_LOG_ERROR_BM_FE_NO_VALID_PXE_ENTRY: Fatal error: no valid entries found from PXE server in bootmgr.

�BL_LOG_ERROR_BM_FE_FAILURE_STATUS: Fatal error: failure status in bootmgr.

�BL_LOG_ERROR_BM_FE_BOOT_DEVICE: Fatal error: boot device inaccessible in bootmgr.

�BL_LOG_ERROR_BM_FE_RAMDISK_MEM: Fatal error: ramdisk device creation had insufficient memory in bootmgr.

�BL_LOG_ERROR_BM_FE_INVALID_BCD_STORE: Fatal error: BCD is invalid in bootmgr.

�BL_LOG_ERROR_BM_FE_INVALID_BCD_ENTRY: Fatal error: Invalid BCD entry in bootmgr.

�BL_LOG_ERROR_BM_FE_NO_SECUREBOOT_POL: Fatal error: Default Secure Boot policy not found in bootmgr.

�BL_LOG_ERROR_BM_FE_NO_PAE_SUPPORT: Fatal error: CPU does not support PAE in bootmgr.

�BL_LOG_ERROR_BM_FE_UNSEAL_NOT_POS: Fatal error: Cannot unseal sensitive data in bootmgr.

�BL_LOG_ERROR_BM_FE_GENERIC: Fatal error: Generic failure in bootmgr.

�BL_LOG_ERROR_BM_FAILED_URI_UDP_REDIRECT: Failed to redirect URI device to UDP device in bootmgr.

�BL_LOG_ERROR_BM_FAILED_SVN_CHECK: Bootmgr SVN check failed.

�BL_LOG_ERROR_BM_FAILED_CHAINLOAD_SVN_CHECK: SVN check failed while chainloading bootmgr.

�BL_LOG_ERROR_OSL_REM_INTERN_APP_OPTS: OslpRemoveInternalApplicationOptions failed in osloader.

�BL_LOG_ERROR_OSL_GET_APP_OPT_DEVICE: BlGetApplicationOptionDevice failed for BCDE_OSLOADER_TYPE_OS_DEVICE in osloader.

�BL_LOG_ERROR_OSL_GET_SYSTEM_ROOT: Failed to get SystemRoot in osloader.

�BL_LOG_ERROR_OSL_FORCED_FAIL: OslpCheckForcedFailure failed implying a forced failure in osloader.

BL_LOG_ERROR_OSL_DISABLE_VGA: BlAppendApplicationOptionBoolean for BCDE_OSLOADER_TYPE_DISABLE_VGA_MODE failed in osloader.

�BL_LOG_ERROR_OSL_OPEN_OS_DEVICE: BlDeviceOpen failed for os device in osloader.

�BL_LOG_ERROR_OSL_LOAD_SYS_HIVE: OslpLoadSystemHive failed in osloader.

�BL_LOG_ERROR_OSL_CREATE_OS_LD_OPTS: AhCreateLoadOptionsString failed in osloader.

�BL_LOG_ERROR_OSL_DISPLAY_INIT: OslDisplayInitialize failed in osloader.

�BL_LOG_ERROR_OSL_PROCESS_SI_POLICY: OslpProcessSIPolicy failed in osloader.

�BL_LOG_ERROR_OSL_DISP_ADV_OPT: OslDisplayAdvancedOptionsProcess failed in osloader.

�BL_LOG_ERROR_OSL_ARCH_HV_SETUP: OslArchHypervisorSetup failed in osloader.

�BL_LOG_ERROR_OSL_ARCH_HYPERCALL_SETUP: OslArchHypercallSetup failed in osloader.

�BL_LOG_ERROR_OSL_INIT_RESUME_CONTEXT: OslInitializeResumeContext failed in osloader.

�BL_LOG_ERROR_OSL_INIT_LDR_BLOCK: OslInitializeLoaderBlock failed in osloader.

�BL_LOG_ERROR_OSL_PROC_INIT_MACH_CONFIG: OslpProcessInitialMachineConfiguration failed in osloader.

�BL_LOG_ERROR_OSL_ENUM_DISKS: OslEnumerateDisks failed for the loader block in osloader.

�BL_LOG_ERROR_OSL_REINIT_SYS_HIVE: OslpReinitializeSystemHive failed in osloader.

�BL_LOG_ERROR_OSL_INIT_CODE_INT: OslInitializeCodeIntegrity failed in osloader.

�BL_LOG_ERROR_OSL_INIT_CODE_INT_LD_BLOCK: OslBuildCodeIntegrityLoaderBlock failed in osloader.

�BL_LOG_ERROR_OSL_SECURE_BOOT_VARS: OslFwProtectSecureBootVariables failed in osloader.

�BL_LOG_ERROR_OSL_LD_MODULES: OslpLoadAllModules failed in osloader.

�BL_LOG_ERROR_OSL_LD_FW_DRIVERS: OslFwLoadFirmwareDrivers failed in osloader.

�BL_LOG_ERROR_OSL_VSM_CHK_ENCRYPT_KEY: BlVsmCheckSystemPolicy failed for master sncrupt key provisioning in osloader.

�BL_LOG_ERROR_OSL_VSM_PHASE_0: Fatal VSM Phase 0 initializatin failure in osloader.

�BL_LOG_ERROR_OSL_SET_SEIL_SIGN_POL: OslSetSeILSigningPolicy failed in osloader.

�BL_LOG_ERROR_OSL_CMS_PROV_IDK: BlVsmCheckSystemPolicy failed during VSM Idendity key work in osloader.

�BL_LOG_ERROR_OSL_ARCH_KERNEL_SETUP_0: OslArchKernelSetup failed for 0 in osloader.

�BL_LOG_ERROR_OSL_FW_KERNEL_SETUP: OslFwKernelSetup failed for 0 in osloader.

�BL_LOG_ERROR_OSL_PROC_EV_STORE: OslpProcessEVStore failed in osloader.

�BL_LOG_ERROR_OSL_COPY_BOOT_OPTS: BlCopyBootOptions failed in osloader.

�BL_LOG_ERROR_OSL_FVE_SEC_BOOT_REST_ONE: BlFveSecureBootRestrictToOne failed in osloader.

�BL_LOG_ERROR_OSL_NET_UNDI_CLOSE: BlNetUndiClose failed in osloader.

�BL_LOG_ERROR_OSL_PROC_APP_PDATA: OslProcessApplicationPersistentData failed in osloader.

�BL_LOG_ERROR_OSL_BLD_MEM_CACHE_REQ_LIST: OslFwBuildMemoryCachingRequirementsList failed in osloader.

�BL_LOG_ERROR_OSL_BLD_RT_MEM_MAP: OslFwBuildRuntimeMemoryMap failed in osloader.

�BL_LOG_ERROR_OSL_VSM_SETUP_1: OslVsmSetup failed for 1 in osloader.

�BL_LOG_ERROR_OSL_BLD_KERNEL_MEM_MAP: BlTraceBuildKernelMemoryMapStop failed in osloader.

�BL_LOG_ERROR_OSL_ARCH_KERNEL_SETUP_1: OslArchKernelSetup failed for 1 in osloader.

�BL_LOG_ERROR_OSL_SET_VSM_POL_SYS_HIVE: OslSetVsmPolicy failed in osloader.

�BL_LOG_ERROR_OSL_ENUM_ENCLAVE_PAGES: OslEnumerateEnclavePageRegions failed in osloader.

�BL_LOG_ERROR_OSL_GATHER_ENTROPY: OslGatherEntropy failed in osloader.

�BL_LOG_ERROR_OSL_VSM_SETUP_0: OslVsmSetup failed for 0 in osloader.

�BL_LOG_ERROR_OSL_VSM_CANNOT_BE_DISABLED_BY_KSR: VSM must not be disabled through KSR

lBL_LOG_ERROR_OSL_VSM_PHASE0_ALLOCATE_PAGES_FAILED

hBL_LOG_ERROR_OSL_VSM_PHASE0_LOAD_MODULES_FAILED

hBL_LOG_ERROR_OSL_VSM_PHASE0_LOAD_CIDATA_FAILED

lBL_LOG_ERROR_OSL_VSM_PHASE0_COPY_VSM_KEYS_FAILED

pBL_LOG_ERROR_OSL_VSM_PHASE0_COPY_ACPI_TABLES_FAILED

dBL_LOG_ERROR_OSL_VSM_PHASE0_ARCH_SETUP_FAILED

tBL_LOG_ERROR_OSL_VSM_PHASE0_BUILD_PAGE_TABLES_FAILED

�BL_LOG_ERROR_OSL_BUILD_BSD_LOCATION_FAILED: OslpBuildBsdLogLocation failed in osloader.

BL_LOG_ERROR_OSL_GET_APP_OPT_DEVICE_OSDATA: BlGetApplicationOptionDevice failed for BCDE_OSLOADER_TYPE_OS_DATA_DEVICE in osloader.

�BL_LOG_ERROR_OSL_OPEN_OSDATA_DEVICE: BlDeviceOpen failed for osdata device in osloader.

�BL_LOG_ERROR_OSL_ENUMERATE_PERSISTENT_MEMORY: OslEnumeratePersistentMemory failed in osloader.

�BL_LOG_ERROR_OSL_HVCI_CANNOT_BE_ENABLED_BY_KSR: HVCI must not be enabled through KSR

�BL_LOG_ERROR_OSL_PROCESS_PRESERVED_MEMORY: Error while processing preserved memory.

�BL_LOG_ERROR_OSL_LOAD_DEVICES_HIVE: OslpLoadDevicesHive failed in osloader.

�BL_LOG_ERROR_OSL_LOAD_OSBOOT_HIVE: OslpLoadOsBootHive failed in osloader.

�BL_LOG_ERROR_OSL_LOAD_DRIVER_STORES: OslpLoadDriverStoreNodes failed in osloader.

�BL_LOG_ERROR_OSL_CMS_PROV_HBK: BlVsmCheckSystemPolicy failed during VSM Hibernation key work in osloader.

�BL_LOG_ERROR_OSL_ALLOC_LDR_BLOCK: OslAllocateLoaderBlock failed in osloader.

�BL_LOG_ERROR_OSL_ARCH_TCB_LAUNCH_0: OslTcbLaunch(0) failed in osloader.

�BL_LOG_ERROR_OSL_HVCI_CANNOT_BE_DISABLED_BY_KSR: HVCI must not be disabled through KSR

BL_LOG_ERROR_OSL_GET_APP_OPT_DEVICE_BSP: BlGetApplicationOptionDevice failed for BCDE_OSLOADER_TYPE_BSP_DEVICE in osloader.

�BL_LOG_ERROR_OSL_OPEN_BSP_DEVICE: BlDeviceOpen failed for bsp device in osloader.

�BL_LOG_ERROR_OSL_FVE_UNLOCK_DEVICE_OSDATA: Failed to unlock osdata device in osloader.

�BL_LOG_ERROR_OSL_FVE_UNLOCK_DEVICE_BSP: Failed to unlock bsp device in osloader.

�BL_LOG_ERROR_OSL_FVE_UNLOCK_DEVICE_COMPOSITE: Failed to unlock composite device in osloader.

�BL_LOG_ERROR_OSL_PROCESS_PRM_FIRMWARE: Failed to parse PRM firmware table.

�BL_LOG_ERROR_OSL_LOAD_PRM_UPDATES: Failed to load PRM updates.

xERROR_OSL_HOT_PATCH_FAILURE: Failed apply hot patches.

�BL_LOG_ERROR_OSL_SET_CIMFS_FAILURE: Failed to store CIMFS information.

�BL_LOG_ERROR_OSL_SET_COMPOSITEFS_FAILURE: Failed to store Compositefs information.

�BL_LOG_ERROR_OSL_TPM_SHUTDOWN: BlTpmShutdown failed in osloader.

�BL_LOG_ERROR_OSL_LOAD_DUMP_STACK: Failed to load dump stack.

�BL_LOG_ERROR_OSL_INIT_FUNC_OVERRIDE_CAPABILITIES: Failed to initialize function override capabilities.

�BL_LOG_ERROR_OSL_LOAD_MICROCODE_UPDATE: OslLoadMicrocodeUpdateDll failed in osloader.

�BL_LOG_ERROR_OSL_PRE_MICROCODE_UPDATE: OslPreMicrocodeUpdateControls failed in osloader.

�BL_LOG_ERROR_OSL_EXTRACT_MICROCODE_RECORD: OslpExtractMicrocodeRecord failed in osloader.

�BL_LOG_ERROR_OSL_PRELOAD_HYPERV: Failed to preload hypervisor.

|BL_LOG_ERROR_OSL_LOAD_HYPERV: Failed to load hypervisor.

|BL_LOG_ERROR_OSL_LOAD_HVLOADER: Failed to load hvloader.

pBL_LOG_ERROR_OSL_VSM_PHASE0_VBS_POLICY_NOT_PRESENT

�BL_LOG_ERROR_KSR_KSEG0: InitializeRebootAddressRange failed in SK extension.

�BL_LOG_ERROR_KSR_OUT_OF_MEMORY: Memory allocation failed in SK KSR extension.

�BL_LOG_ERROR_KSR_IMAGE_VALIDATION: Image validation failed in SK KSR extension.

�BL_LOG_ERROR_KSR_IMAGE_RELOCATION: Image relocation failed in SK KSR extension.

�BL_LOG_ERROR_KSR_BIND_IMPORT: Failed to bind imports to image in SK KSR extension.

�BL_LOG_ERROR_KSR_LOADER_ENTRY_POINT: SK loader entry point returned failure.

�BL_LOG_ERROR_KSR_RESERVE_EFI_RUNTIME: SK loader failed to reserve EFI runtime VA range.

�BL_LOG_ERROR_KSR_APPLY_FUNCTION_OVERRIDE: SK loader failed to apply function override fixups to osloader.

�BL_LOG_ERROR_TCB_SI_POLICY_CHECK: Failed to validate and measure SI policy.

�BL_LOG_ERROR_TCB_LOAD_TCBLOADER: Failed to load tcbloader.dll.

tBL_LOG_ERROR_TCB_LOAD: Failed to perform load action.

|BL_LOG_ERROR_TCB_RESUME: Failed to perform resume action.

�BL_LOG_ERROR_TCB_INVALID_ATTRIBUTES: Invalid tcblaunch application attributes.

�BL_LOG_ERROR_TCB_REGISTER_EVENT_HANDLER: Failed to register launch notificaiton handler.

�BL_LOG_ERROR_TCB_OPEN_DEVICE: Failed to open application device.

�BL_LOG_ERROR_TCB_GET_DEVICE: Failed to query application device.

�BL_LOG_ERROR_GET_SYSTEM_ROOT: Failed to get SystemRoot value.

�BL_LOG_ERROR_OSL_PROCESS_BOOTSTAT_DATA: Failed to process bootstat data.

�BL_LOG_ERROR_OSL_VIRT_SETUP_0: Failed to perform virtual setup phase 0.

�BL_LOG_ERROR_OSL_VIRT_SETUP_1: Failed to perform virtual setup phase 1.

�BL_LOG_ERROR_OSL_PRELOAD_SI_POLICY: Failed to preload SI policies from OS volume.

�BL_LOG_ERROR_OSL_ARCH_TCB_LAUNCH_1: OslTcbLaunch(1) failed in osloader.

�ERROR_TCB_PLATORM_INIT: Failed to initialize TCB platform.

�BL_LOG_ERROR_OSL_INITIALIZE_FEATURE_CONFIGURATION: OslInitializeFeatureConfiguration failed in osloader.

�BL_LOG_ERROR_OSL_PROCESS_BOT_BCD: OslpProcessBootBcd failed in osloader.

�BL_LOG_ERROR_RES_OPEN_HIBERFILE: Failed to open the hiberfile.

�BL_LOG_ERROR_RES_INIT_DISPLAY: Failed to initialize display.

�BL_LOG_ERROR_RES_INVALID_PAGEFILE: Page file is invalide for hibernate resume.

�BL_LOG_ERROR_RES_HW_CHANGE: Hardware or firmware settings have changes since hibernate.

|BL_LOG_ERROR_RES_INVALID_HIBERFILE: Hiberfile is invalid.

�BL_LOG_ERROR_RES_GET_CONTEXT_FAILED: Failed to get the resume context.

�BL_LOG_ERROR_RES_INVALID_HBBOOT_MEM_MAP: The memory map has changed since associated cold boot.

�BL_LOG_ERROR_RES_FIRMWARE_PHASE_0: Failed phase 0 of firmware setup for resume.

�BL_LOG_ERROR_RES_USB_HANDOFF: Failed setup for legacy usb handoff.

pBL_LOG_ERROR_RES_SMBIOS: Failed to get SMBIOS data.

�BL_LOG_ERROR_RES_TCB_ALLOCATE: Failed to allocate space for TCB resume.

|BL_LOG_ERROR_RES_TCB_PREPARE: Failed to prepare TCB data.

�BL_LOG_ERROR_RES_INIT_PREALLOCATION: Failed to initialize the preallocation.

�BL_LOG_ERROR_RES_INIT_TRANSITION_SPACE: Failed to intialize transition space.

�BL_LOG_ERROR_RES_INIT_PAGE_ALLOCATOR: Failed to initialize the free page allocator.

�BL_LOG_ERROR_RES_RELOC_PROC_CONTEXT: Failed to relocate the processor context page.

�BL_LOG_ERROR_RES_LOAD_SECURE_DATA: Failed to load secure data from the hiberfile.

�BL_LOG_ERROR_RES_RESTORE_IMAGE: Failed to restore image from the hiberfile.

�BL_LOG_ERROR_RES_SECURE_DECRYPT_0: Failed phase 0 of secure data decryption.

�BL_LOG_ERROR_RES_FVE_RESTRICT: Failed to restrict bitlocker to resuming OS.

�BL_LOG_ERROR_RES_TCB_PREP_DATA: Failed to prepare data for TCB resume.

�BL_LOG_ERROR_RES_SET_BGFX_OPTION: Failed to set BGFX option to preallocate progress frames.

�BL_LOG_ERROR_RES_CHECK_FILE_ARCH: Failed to verify hiberfile processor architecture.

�BL_LOG_ERROR_RES_GET_FADT_TBL: Failed to check the revision through FADT table.

�BL_LOG_ERROR_RES_MAP_FADT_TBL: Failed to check hardware configuration through FACS table.

�BL_LOG_ERROR_RES_HW_SIGNATURE_MISMATCH: Failed to resume due to hardware configuration changed.

�BL_LOG_ERROR_RES_SECURE_BOOT_MISMATCH: Failed to resume due to the state of secure boot.

�BL_LOG_ERROR_RES_PAGE_LEVEL_CHANGED: Failed to resume due to paging levels change.

�BL_LOG_ERROR_RES_ABANDON_HIBERNATION: Failed to resume due to user cancellation.

�BL_LOG_ERROR_RES_ALLOC_PAGE_PFN_ARRAY: Failed to allocate page for context parameters.

�BL_LOG_ERROR_RES_MAP_PAGE_PFN_ARRAY: Failed to map pages to transition space.

�BL_LOG_ERROR_RES_ALLOC_LIB_PAGES: Failed to allocate page for vresume library.

�BL_LOG_ERROR_RES_MMAP_RESUME_HEADER: Resume cancelled due to keystroke of the user.

�BL_LOG_ERROR_RES_BITLOCKER_MMAP_KEY_RING: Failed to memory map KeyRing.

�BL_LOG_ERROR_RES_BITLOCKER_ALLOC_PFN: Failed to allocate free pages as temporary storage.

�BL_LOG_ERROR_RES_BITLOCKER_MMAP_FREE_KEY_ADDR: Failed to memory map free keys.

�BL_LOG_ERROR_RES_IMAGE_ALLOC_SCRATCH_REGION: Failed to allocate memory for scratch region.

�BL_LOG_ERROR_RES_IMAGE_MAP_SCRATCH_REGION: Failed to memory map the scratch region.

�BL_LOG_ERROR_RES_IMAGE_RANGE_TBL_INVALID_READING: Failed to read hiber file.

�BL_LOG_ERROR_RES_IMAGE_RANGE_TBL_INVALID_HEADER: Failed to resume due to bad hiber table header.

�BL_LOG_ERROR_RES_IMAGE_RANGE_ARRAY_READING: Failed to read the range array.

�BL_LOG_ERROR_RES_IMAGE_ADD_DECOMPRESSION_PAGE: Failed to add page to decompression block.

�BL_LOG_ERROR_RES_IMAGE_PROCESS_DECOMPRESSION_PAGE: Failed to process the decompression block.

�BL_LOG_ERROR_RES_IMAGE_UNMAP_SCRATCH_REGION: Failed to unmap the scratch region.

�BL_LOG_ERROR_RES_IMAGE_FREE_SCRATCH_REGION: Failed to free scratch region.

�ERROR_RES_GET_HIBERFILE_DEVICE: Failed to get hiberfile device.

�ERROR_RES_GET_HIBERFILE_PATH: Failed to get hiberfile path.

�ERROR_RES_READ_HIBERFILE_HEADER: Failed to read hiberfile header.

tERROR_RES_EFI_GET_MEM_MAP: Failed to get memory map.

�ERROR_RES_FW_MEM_MAP_CHANGE: Firmware runtime regions are changed.

�ERROR_RES_EXIT_BOOT_SERVICE: Failed to terminate firmware boot services.

�BL_LOG_ERROR_RES_TPM_SHUTDOWN: Failed to shutdown TPM to resuming OS.

�ERROR_RES_RESUME_CONTEXT_PHASE_0: Failed to copy firmware resume context to OS.

�ERROR_RES_RESUME_CONTEXT_PHASE_1: Failed to copy firmware resume context to OS.

�BL_LOG_ERROR_IO_SPACE_ALLOCATION_FAILURE: Failed to apply Io Space configuration.

�ERROR_RES_ALLOCATE_LOG_PAGE: Failed to allocate pages for boot log.

None

@Processor is not supported.

4VMX is not supported.

4SMX is not supported.

pTXT is disabled by the BIOS in MSR_FEATURE_CONTROL.

lRequired GETSEC[CAPABILITIES] are not available.

<TPM 2.0 is not available.

dMemory Attributes Table (MAT) not available.

|No SINIT ACM module type found at the SINIT base address.

dThe ACM UUID does not match well known value.

xThe ACM client/server flags do not match the BIOS data.

`The ACM debug flag does not match platform.

TThe ACM does not support the chipset.

XThe ACM does not support the processor.

lA more up to date ACM is available on the system.

XNo compatible ACM found on the system.

�The system does not support DMA remapping in the DMAR table.

dTPM does not meet provisioning requirements.

�System does not meet required configuration to validate SMM.

HA VMX failure was encountered.

\Call to retrieve SMM information failed.

TSMM has access to OS memory regions.

TSMM signature is missing or corrupt.

@SMM signature check failed.

�SMM has access to a MSR that is not allowed by policy level.

�SMM has access to an IO port that is not allowed by policy level.

PSMM has access to IOMMU structures.

8ACM layout corruption.

dSKINIT instruction not supported by platform.

`The required platform module was not found.

HThe platform module is invalid.

\The platform module failed to initialize.

�The platform does not have required capabilities or features.

LSMM has access to CPU state save.

hSMM has access to a restricted platform range.

0Not started at EL2.

dThe platform firmware does not support SMCCC.

pFailed to query the platform for its DRTM version.

�The DRTM version provided by this platform is not supported.

�Failed to query the platform's DRTM capabilities or features.

�The platform's DRTM implementation is not supported by this version of Windows.

|The platform's firmware does not properly implement DRTM.

�The hash algorithm in use is not supported by this version of Windows.

�The PCR schema in use is not supported by this version of Windows.

dThe DMA protection feature is not supported.

pNot running on the correct processor core for DRTM.

XThe ACM on the system has been revoked.

dFailed to read the SVN from the AUX NV index.

None

8Using 2k PPAM manifest.

8Using PPAM 3k manifest

XPPAM 3k manifest system table missing.

None.

DFailed to reserve scratch VA.

TFailed to get connection parameters.

HDebugging blocked by BitLocker.

dFailed to initialize debug device descriptor.

LFailed to setup debugging device.

TFailed to initialize debug transport.

DFailed to setup debug traps.

\Failed to load debugger transport module.

PFailed to allocate scratch buffer.

lFailed to get debugger transport extension name.

|Failed to establish connection with isolated hypervisor.

�Pluton-Windows firmware upgrade not supported for this CPUID.

XFailed to load Pluton firmware package.

PPluton firmware package is invalid.

LPluton firmware binary not found.

<Failed to apply firmware.

(truncatememory

(avoidlowmemory

 testsigning

,nointegritychecks

undefined

Undefined

Available

Applied

Rejected

NotFound

Low

High

Base

End

<applied through registry

Xapplied through compatibility database

<applied through registry

Xapplied through compatibility database

PackageId

None

XHSP Shadow Stacks in compatibility mode

LHSP Shadow Stacks in strict mode

tHSP Shadow Stacks in compatibility mode (audit mode)

dHSP Shadow Stacks in strict mode (audit mode)

None

 VBS Enabled

$VSM Required

 Secure Boot

,Iommu Protection

Mmio Nx

4Strong MSR Filtering

Mandatory

Hvci

 Hvci Strict

HBoot Chain Signer Soft Enforced

HBoot Chain Signer Hard Enforced

(Measured Launch

$4VS_VERSION_INFO��
k�e
k�e?�StringFileInfo`040904B0LCompanyNameMicrosoft Corporation|*FileDescriptionMicrosoft-Windows-System-Events Resourcesn'FileVersion10.0.26100.7019 (WinBuild.160101.0800)h$InternalNamemicrosoft-windows-system-events.dll�.LegalCopyright� Microsoft Corporation. All rights reserved.x(OriginalFilenamemicrosoft-windows-system-events.dll.muij%ProductNameMicrosoft� Windows� Operating SystemDProductVersion10.0.26100.7019DVarFileInfo$Translation	�PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX

Anon7 - 2021