Mini Kabibi Habibi

Current Path : C:/Windows/System32/en-US/
Upload File :
Current File : C:/Windows/System32/en-US/microsoft-windows-system-events.dll.mui

MZ����@���	�!�L�!This program cannot be run in DOS mode.

$5�<�q�R�q�R�q�R�e���p�R�e�P�p�R�Richq�R�PEL�!V

��@ �R8.rdata�@@.rsrc` T@@f���
T88f���$��8.rdata8x.rdata$zzzdbg �.rsrc$01� �Q.rsrc$02 �b�0V���,���+0[�D�l��[f�����(�@�X�p�����	�	�	�� ���!�L��n$�MUI���4"(��T�)&-�I��[�PO .�ĀV9m	?����MUIen-US��,0(
36���X[����  ,%RVp%���&��,-���1���1��|2���2��@D���DL�E���u�}xx�}��$~@@p~���~
l�܀��Ȩ�	�	d���
̯h��X�d�
$�2	2	�a	d	d�r	r	l�

�\�x�  4�st��||H������|������������$�		����

���!"P�44����
��11X�|���
00X�11,�22@�:$:h�PP��UU��[[��	p
p�ssp�zzP������� ��������������`������� �����������8�����������l��	����t� �*�������������
�������x
�
� ����� ���	�	����  ��� ���� !�����&�����-�����.����<2�����3���4��$5!�-��51�3��>9�<��E>�>�LHI�K� IQ�Q��L�����M����@N�����N�����O����8P����TQ�����Q����TR����S�����S����tT����|W����DX����Y����hY�����Y��`[��<\���\#�$�(^2�3��^���i�� k���s�Q�`ve���(�����|��
�4��� �������޴I���J�
��J�Possible detection of CVE: %1%nAdditional Information: %2%n%nThis Event is generated when an attempt to exploit a known vulnerability (%1) is detected.%nThis Event is raised by a User mode process.%n

�Possible detection of CVE: %1%nAdditional Information: %2%n%nThis Event is generated when an attempt to exploit a known vulnerability (%1) is detected.%nThis Event is raised by a kernel mode driver.%n

PMicrosoft-Windows-Kernel-AppCompat

4Microsoft-Windows-AIT

TMicrosoft-Windows-Kernel-ApphelpCache

HMicrosoft-Windows-AeSwitchBack

\Microsoft-Windows-AeLookupServiceTrigger

%1

%1

%1

�The executable %2 received an access denied error when trying to modify the registry key %4.

LMicrosoft-Windows-Kernel-Network

 Data sent.

(Data received.

4Connection attempted.

0Disconnect issued.

0Data retransmitted.

4Connection accepted.

4Reconnect attempted.

HTCP connection attempt failed.

XProtocol copied data on behalf of user.

DData sent over UDP protocol.

LData received over UDP protocol.

HUDP connection attempt failed.

lTCPv4: %2 bytes transmitted from %4:%6 to %3:%5.

dTCPv4: %2 bytes received from %4:%6 to %3:%5.

tTCPv4: Connection attempted between %4:%6 and %3:%5.

lTCPv4: Connection closed between %4:%6 and %3:%5.

pTCPv4: %2 bytes retransmitted from %4:%6 to %3:%5.

xTCPv4: Connection established between %4:%6 and %3:%5.

lTCPv4: Reconnect attempt between %4:%6 and %3:%5.

tTCPv4: Connection attempt failed with error code %2.

�TCPv4: %2 bytes copied in protocol on behalf of user for connection between %4:%6 and %3:%5.

lUDPv4: %2 bytes transmitted from %4:%6 to %3:%5.

dUDPv4: %2 bytes received from %4:%6 to %3:%5.

tUDPv4: Connection attempt failed with error code %2.

lTCPv6: %2 bytes transmitted from %4:%6 to %3:%5.

dTCPv6: %2 bytes received from %4:%6 to %3:%5.

tTCPv6: Connection attempted between %4:%6 and %3:%5.

lTCPv6: Connection closed between %4:%6 and %3:%5.

pTCPv6: %2 bytes retransmitted from %4:%6 to %3:%5.

xTCPv6: Connection established between %4:%6 and %3:%5.

lTCPv6: Reconnect attempt between %4:%6 and %3:%5.

�TCPv6: %2 bytes copied in protocol on behalf of user for connection between %4:%6 and %3:%5.

lUDPv6: %2 bytes transmitted from %4:%6 to %3:%5.

dUDPv6: %2 bytes received from %4:%6 to %3:%5.

DMicrosoft-Windows-Kernel-Disk

L%3 bytes read from disk %1 at %5.

P%3 bytes written to disk %1 at %5.

@Buffers flushed to disk %1.

DMicrosoft-Windows-Kernel-Boot

LSystem was booted in %1x%2@%3bpp.

`BootUX screen was displayed in %1x%2@%3bpp.

`Video bit transfer rate is %1 bytes per ms.

�Boot library accessed file %2 on Device %1. Read %3 bytes and wrote %4 bytes.

�File IO for boot application %1: Total Bytes Read = %2, Total Bytes Written = %3.

�Image %1 failed IntegrityCheck reason is %3. Image flags are %2. Error ignored due to debugger %4.

TBootmgr duration is %1 milliseconds.

DImage %1 is not self-signed.

�A device (%1) that was enumerated by the BIOS was inaccessible to the boot environment.

|Variable %1 requires %2 bytes and was set with status %3.

hElement %2 of application %1 was not in policy.

pA Secure Boot Policy update resulted in status %1.

�A Secure Boot Revocation List update resulted in status %1.

lRetrieving the driver list took %1 milliseconds.

\Loading the drivers took %1 milliseconds.

TLoading hive %1 took %2 milliseconds.

XThe time elapsed loading %1 was %2 ms.

\The time elapsed executing %1 was %2 ms.

�Building chunk table for WIM compressed file %2 failed with status: %1

�Soft Restart failed to prepare target Operating System. Operation status: %1 failure point: %2

�Boot application failed to process persistent data with status: %1

DMicrosoft-Windows-Kernel-File

hError setting traits on Provider %1. Error: %2

�A registration for Provider %1 has joined Provider Group %2

 Enable Info

0Set Provider Traits

0Join Provider Group

TMicrosoft-Windows-Kernel-EventTracing

�Session "%1" failed to write to log file "%2" with the following error: %3

<The backing-file for the real-time session "%1" has reached its maximum size. As a result, new events will not be logged to this session until space becomes available. This error is often caused by starting a trace session in real-time mode without having any real-time consumers.

|Session "%1" failed to start with the following error: %3

pSession "%1" stopped due to the following error: %3

`The maximum file size for session "%1" has been reached. As a result, events might be lost (not logged) to file "%2". The maximum files size is currently set to %5 bytes.

�An error was encountered while tracing session "%2" was switching to the "%1" event log file. Error: %3

�Provider %1 was registered with Event Tracing for Windows.

�Provider %1 was unregistered from Event Tracing for Windows.

<Session "%3" was started.

<Session "%3" was stopped.

tThe configuration of session "%3" has been modified.

hThe events from session "%3" have been flushed.

dProvider %1 has been enabled to session "%2".

lProvider %1 is no longer enabled to session "%2".

�The security settings of provider %1 have been modified from %2 to %3.

�The security descriptor for session "%3" has been updated.

Provider

Session

Logging

Stop

Start

Disable

Enable

 Unregister

Register

Flush

Configure

$Write Buffer

 File Switch

Provider

Session

Stack correlation event. This event contains a call stack which is associated with a prior event which is correlated by the MatchId.

 Stack Trace

4User Mode Stack Trace

hMicrosoft-Windows-Kernel-EventTracing/Analytic

`Microsoft-Windows-Kernel-EventTracing/Admin

 Lost Event

 Lost Event

\Logger mode incompatible with Append mode

0OS version mismatch

4Pointer size mismatch

8Unsupported BufferSize

0BufferSize mismatch

lPreallocate mode is incompatible with Append mode

8File size query failed

<Maximum file size reached

LNumber of buffers written is zero

HNumberf of processors mismatch

xError saving soft restart persisted log "%1" Error: %5

 GUID Entry

4Provider Group Entry

LMicrosoft-Windows-Kernel-StoreMgr

dMicrosoft-Windows-Kernel-StoreMgr/Operational

�%5%n%nVirtual Address: %2%nPhysical Address: %3%nCorruption Window Size: %4

0A memory corruption was detected and handled. Memory diagnostics should be run on this machine and, if necessary, memory chips should be replaced.

�A data corruption was detected and handled in a ReadyBoost cache. This corruption was most likely caused by faulty hardware. While ReadyBoost will always detect and handle these errors, seeing a lot of these may mean that the ReadyBoost device has worn out which reduces its performance. You should consider replacing the ReadyBoost cache device.

tA ReadyBoost cache failed to persist across boot. This may happen if the cache device was modified on another computer or if this computer was booted into another operating system.

T%1%n%nDevice name: %4%nCache path: %6

�A ReadyBoost cache was deleted due to repeated data corruption instances on the associated device that have been detected and handled. While ReadyBoost will always detect and handle these errors, repeated corruption instances may mean that the ReadyBoost device has worn out which reduces its performance. You should consider replacing the ReadyBoost device.

�A ReadyBoost cache was deleted due to repeated I/O failures on the associated device. This typically happens when the device (e.g. an SD card) is removed, but it may also indicate faulty hardware.

hMicrosoft-Windows-LicensingStartServiceTrigger

hMicrosoft-Windows-WSServiceStartServiceTrigger

LMicrosoft-Windows-Kernel-LiveDump

`Microsoft-Windows-Kernel-LiveDump/Analytic

HLive Dump Capture Dump Data API

(Sizing Workflow

8Capture Pages Workflow

XLive Dump Write Deferred Dump Data API

\Live Dump Discard Deferred Dump Data API

PSizing Workflow: Mirroring started.

\Sizing Workflow: Mirroring Phase 0 ended.

\Sizing Workflow: Mirroring Phase 1 ended.

\Sizing Workflow: System Quiesce started.

XSizing Workflow: System Quiesce ended.

`Capture Pages Workflow: Mirroring started.

lCapture Pages Workflow: Mirroring Phase 0 ended.

lCapture Pages Workflow: Mirroring Phase 1 ended.

hCapture Pages Workflow: System Quiesce started.

dCapture Pages Workflow: System Quiesce ended.

pCapture Pages Workflow: Copy memory pages started.

lCapture Pages Workflow: Copy memory pages ended.

\Live Dump Capture Dump Data API started.

tLive Dump Capture Dump Data API ended. NT Status: %1.

@Writing dump file started.

�Writing dump file ended. NT Status: %1. Total %2 bytes (Header|Primary|Secondary: %3|%4|%5 bytes).

API Start

API End

4Dump File Write Start

0Dump File Write End

(Mirroring Start

4Mirroring Phase 0 End

4Mirroring Phase 1 End

4System Quiesce Start

0System Quiesce End

@Copying Memory Pages Start

<Copying Memory Pages End

hLive Dump Write Deferred Dump Data API started.

�Live Dump Write Deferred Dump Data API ended. NT Status: %1.

\Write deferred dump data to file started.

�Write deferred dump data to file ended. NT Status: %1. Total %2 bytes (Header|Primary|Secondary: %3|%4|%5 bytes).

lLive Dump Discard Deferred Dump Data API started.

�Live Dump Discard Deferred Dump Data API ended. NT Status: %1.

�Sizing Workflow: Estimation. NT: %2 bytes (Minimum %1 bytes). Hypervisor: Primary %3 bytes. Secondary %4 bytes.

�Sizing Workflow: Allocation. NT: %1 bytes. Hypervisor: Primary %2 bytes. Secondary %3 bytes.

8Buffer Estimation Data

8Buffer Allocation Data

hSizing Workflow: RemovePages Callbacks started.

dSizing Workflow: RemovePages Callbacks ended.

lSizing Workflow: RemovePages Callback %1 started.

hSizing Workflow: RemovePages Callback %1 ended.

�Sizing Workflow: RemovePages Callback %1 failed. NT Status: %2.

8Remove Pages Callbacks

�Live Dump request aborted due to memory pressure on system

dMicrosoft-Windows-Kernel-LiveDump/Operational

XSizing workflow: %1 pages estimated to be allocated and %2 pages allocated. Limit dump file size: %3. Dump file size limit: %4 bytes. Dump file size limit reached: %5.

�Sizing Workflow: Estimation. NT: %2 bytes (Minimum %1 bytes). Hypervisor: Primary %3 bytes. Secondary %4 bytes. SecureKernel: %5 bytes. MemoryEstimationDuration: %6ms. SystemQuiescedDuration: %7ms. EndMirroringPhasesDuration: %8ms. TotalMirrorPhysicalMemoryCallbackDuration: %9ms. TotalMirrorPhysicalMemoryCallbackBytes: %10 bytes. HvlCalculateLiveDumpSizeDuration: %11ms.

�Sizing Workflow: Allocation. NT: %1 bytes. Hypervisor: Primary %2 bytes. Secondary %3 bytes. SecureKernel: %4 bytes. AllocateDumpBuffersDuration: %5ms. AllocateExtraBuffersDuration: %6ms. HvlPrepareLivedumpDescriptorDuration: %7ms.

�Sizing Workflow: Query Hvl for dump size failed. NT Status: %1.

�Sizing Workflow: Open VM memory partition failed. Buffer allocation scheme: %1. NT Status: %2

�Sizing Workflow: Buffer allocation from the VM memory partition failed. Buffer allocation scheme: %1. NT Status: %2

�Sizing Workflow: Capture processor context when the system is quiesced. Duration: %1ms.

�Sizing Workflow: Mark required dump data when system is quiesced. Duration: %1ms.

�Sizing Workflow: Mark important dump data when system is quiesced. Duration: %1ms.

(Sizing Workflow: Populate bitmap for dump when system is quiesced. PopulateBitmapForDumpDuration: %1ms. RemoveSystemCacheFromDumpDuration %2ms.

�Capture Pages Workflow: Capture processor context when the system is quiesced. Duration: %1ms.

�Capture Pages Workflow: Mark required dump data when system is quiesced. Duration: %1ms.

�Capture Pages Workflow: Mark important dump data when system is quiesced. Duration: %1ms.

8Capture Pages Workflow: Populate bitmap for dump when system is quiesced. PopulateBitmapForDumpDuration: %1ms. RemoveSystemCacheFromDumpDuration %2ms.

�Capture Pages Workflow: Collect Hvl dump when system is quiesced. Duration: %1ms.

�Capture Pages Workflow: Generate Ipt secondary data when system is quiesced. Duration: %1ms.

�Capture Pages Workflow: Initiate state change to copy contents of marked pages when system is quiesced. Duration: %1ms.

<Capture Processor Context

8Mark Required Dump Data

8Mark Important DumpData

<Populate Bitmap For Dump

4Hvl Collect LiveDump

@Generate Ipt Secondary Data

0Dump Data Buffering

tSizing Workflow: Corral processors to quiesce the system. CorralDuration: %1ms. DisableInterruptsDuration: %2ms. SaveSupervisorStateDuration: %3ms. SuspendClockTimerDuration: %4ms.

�Capture Pages Workflow: Corral processors to quiesce the system. CorralDuration: %1ms. DisableInterruptsDuration: %2ms. SaveSupervisorStateDuration: %3ms. SuspendClockTimerDuration: %4ms.

|Sizing Workflow: Uncorral processors to quiesce the system. UncorralDuration: %1ms. EnableInterruptsDuration: %2ms. RestoreSupervisorStateDuration: %3ms. ResumeClockTimerDuration: %4ms.

�Capture Pages Workflow: Uncorral processors to quiesce the system. UncorralDuration: %1ms. EnableInterruptsDuration: %2ms. RestoreSupervisorStateDuration: %3ms. ResumeClockTimerDuration: %4ms.

lCapture Pages Workflow: Capture memory pages. MemoryCaptureDuration: %1ms. SystemQuiescedDuration: %2ms. EndMirroringPhasesDuration: %3ms. TotalMirrorPhysicalMemoryCallbackDuration: %4ms. TotalMirrorPhysicalMemoryCallbackBytes: %5 bytes. HvlCollectLivedumpDuration: %6ms. DumpDataBufferingDuration: %7ms.

,Corral Processors

0Uncorral Processors

4Capture Memory Pages

�Sizing Workflow: MmDuplicateMemory failed. NT Status: %1. MirrorInProgress: %2.

�Capture Pages Workflow: MmDuplicateMemory failed. NT Status: %1. MirrorInProgress: %2.

<MmDuplicateMemory Failure

�Windows has started processing the volume mount request.%n%n           Volume GUID: %1%n           Volume Name: %3%n

�The volume has been successfully mounted.%n%n           Volume GUID: %1%n           Volume Name: %3%n

�Windows failed to mount the volume.%n%n           Status: %4%n           Volume GUID: %1%n           Volume Name: %3%n

@Microsoft-Windows-Kernel-IO

XMicrosoft-Windows-Kernel-IO/Operational

�Windows is configured to block legacy file system filters.%n%n           Filter name: %2%n

Legacy file system filters cannot attach to byte addressable volumes.%n%n           Filter name: %2%n           Volume name: %4%n

�Dumps are disabled on the machine since there was an error enabling dump encryption: %1.

                 %nSee http://go.microsoft.com/fwlink/?LinkId=824149 for more information on dump encryption

@An internal error occurred

\Public Key or Thumbprint registry missing

0Invalid Public Key

@Unsupported Public Key Size

\Microsoft-Windows-Kernel-Audit-API-Calls

@Microsoft-Windows-Audit-CVE

LMicrosoft-Windows-User-Diagnostic

HMicrosoft-Windows-Heap-Snapshot

TMicrosoft-Windows-Threat-Intelligence

�Microsoft-Windows-Security-LessPrivilegedAppContainer/Operational

tMicrosoft-Windows-Security-LessPrivilegedAppContainer

�Access to the a resource has been denied for a less privileged app container at %1 (StackHash: %2).

XMicrosoft-Windows-Security-Mitigations

 Kernel Mode

User Mode

�Process '%2' (PID %5) would have been blocked from generating dynamic code.

�Process '%2' (PID %5) was blocked from generating dynamic code.

�Process '%2' (PID %5) would have been blocked from creating a child process '%14' with command line '%16'.

�Process '%2' (PID %5) was blocked from creating a child process '%14' with command line '%16'.

�Process '%2' (PID %5) would have been blocked from loading the low-integrity binary '%14'.

�Process '%2' (PID %5) was blocked from loading the low-integrity binary '%14'.

�Process '%2' (PID %5) would have been blocking from loading a binary from a remote share.

�Process '%2' (PID %5) was blocked from loading a binary from a remote share.

�Process '%2' (PID %5) would have been blocked from making system calls to Win32k.sys.

�Process '%2' (PID %5) was blocked from making system calls to Win32k.sys.

�Process '%2' (PID %5) would have been blocked from loading the non-Microsoft-signed binary '%16'.

�Process '%2' (PID %5) was blocked from loading the non-Microsoft-signed binary '%16'.

�Process '%2' (PID %3) would have been blocked from accessing the Export Address Table for module '%8'.

�Process '%2' (PID %3) was blocked from accessing the Export Address Table for module '%8'.

�Process '%2' (PID %3) would have been blocked from accessing the Import Address Table for API '%10'.

�Process '%2' (PID %3) was blocked from accessing the Import Address Table for API '%10'.

Process '%2' (PID %3) would have been blocked from calling the API '%4' due to return-oriented programming (ROP) exploit indications.

�Process '%2' (PID %3) was blocked from calling the API '%4' due to return-oriented programming (ROP) exploit indications.

�Process '%2' (PID %5) has encountered a shadow stack return address mismatch. The process will be allowed to continue execution.%n%nReturn instruction executed from module '%12'.%nAttempting to return to module '%14'.

�Process '%2' (PID %5) has encountered a shadow stack return address mismatch. The process will be terminated.%n%nReturn instruction executed from module '%12'.%nAttempting to return to module '%14'.

<Process '%2' (PID %5) would have been blocked from setting context due to instruction pointer validation failure when user-mode shadow stack is enabled.

$Process '%2' (PID %5) was blocked from setting context due to instruction pointer validation failure when user-mode shadow stack is enabled.

Process '%2' (PID %5) has encountered a shadow stack return address mismatch. The process will be allowed to continue execution.%nProcess shadow stack strict mode: %15%n%nReturn instruction executed from module '%12'.%nAttempting to return to module '%14'.

�Process '%2' (PID %5) has encountered a shadow stack return address mismatch. The process will be terminated.%nProcess shadow stack strict mode: %15%n%nReturn instruction executed from module '%12'.%nAttempting to return to module '%14'.

 Process '%2' (PID %5) would have been blocked from loading an image binary due to the binary not being compatible with shadow stacks and/or missing exception handling continuation data.%nProcess requires binaries to also contain exception handling continuation data: %15%n%nBinary path: %12%nBinary compatible with shadow stacks: %13%nBinary contains exception handling continuation data: %14%n

Process '%2' (PID %5) was blocked from loading an image binary due to the binary not being compatible with shadow stacks and/or missing exception handling continuation data.%nProcess requires binaries to also contain exception handling continuation data: %15%n%nBinary path: %12%nBinary compatible with shadow stacks: %13%nBinary contains exception handling continuation data: %14%n

�Process '%2' (PID %5) would have been blocked from following an untrusted redirection: %n%nBinary path: %2%nArguments: %4%nRedirection Type: %11%nOperation Path: %13%nImpersonating: %14%n

hProcess '%2' (PID %5) was blocked from following an untrusted redirection: %n%nBinary path: %2%nArguments: %4%nRedirection Type: %11%nOperation Path: %13%nImpersonating: %14%n

Process '%2' (PID %5) would have been blocked from setting context due to instruction pointer validation failure when user-mode shadow stack is enabled.%nProcess set context validation strict mode: %13%nSet context type: %14%n%nSet context target module '%12'.

�Process '%2' (PID %5) was blocked from setting context due to instruction pointer validation failure when user-mode shadow stack is enabled.%nProcess set context validation strict mode: %13%nSet context type: %14%n%nSet context target module '%12'.

<Exception handling unwind

`Context resumption without unwind semantics

(Longjump unwind

0Set thread context

@Unknown redirection type%n

0NTFS mount point%n

(NTFS symlink%n

�Process '%2' (PID %5) would have been blocked from making the NtFsControlFile system call.

�Process '%2' (PID %5) was blocked from making the NtFsControlFile system call.

lMicrosoft-Windows-Security-Adminless/Operational

TMicrosoft-Windows-Security-Adminless

�Access to a resource would have been denied if run with the adminless restriction at %1 (StackHash: %2).

H{Remote Registy Service} Access Denied to key: %2 under parent key: %4 as the parent is mentioned under AllowedExactPaths and hence subkey cannot be accessed.

�The system time has changed to %1 from %2.%n%nChange Reason: %3.%nProcess: '%4' (PID %5).

\License policy-cache corruption detected.

hLicense policy-cache corruption has been fixed.

�License policy-cache has expired because it was not updated within expected duration.

{Registry Hive Recovered} Registry hive (file): '%3' was corrupted and it has been recovered. Some data might have been lost.

�An I/O operation initiated by the Registry failed unrecoverably.The Registry could not flush hive (file): '%3'.

�TxR init phase for hive %2 (TM: %3, RM: %4) finished with result=%5 (Internal code=%6).

hThe operating system started at system time %7.

|The operating system is shutting down at system time %1.

�Hive %2 was reorganized with a starting size of %3 bytes and an ending size of %4 bytes.

�The access history in hive %2 was cleared updating %3 keys and creating %4 modified pages.

tThe operating system is starting after soft restart.

 The leap second configuration has been updated.%nReason: %1%nLeap seconds enabled: %2%nNew leap second count: %3%nOld leap second count: %4

�Failed to update leap second data from the registry. Reason: %1

dThe time zone bias has changed to %1 from %2.

�The time zone information was refreshed with exit reason %1. Current time zone bias is %2.

�Error status code %1 returned when %3 attempted to load dependency %2.

�Loading dependency %2 from the current directory was not allowed when attempted by %1. Another DLL was found: %3. For more information, see http://go.microsoft.com/fwlink/?LinkId=718136.

�Loading dependency %2 from the current directory was not allowed when attempted by %1. No other DLL was found and the dependency resolution failed. For more information, see http://go.microsoft.com/fwlink/?LinkId=718136.

dAccess to %1 is monitored by policy rule %2.

�Access to %1 has been restricted by your Administrator by the default software restriction policy level.

�Access to %1 has been restricted by your Administrator by location with policy rule %2 placed on path %3.

�Access to %1 has been restricted by your Administrator by software publisher policy.

�Access to %1 has been restricted by your Administrator by policy rule %2.

�Access to %1 has been restricted by your Administrator by policy rule %2.

TThe system firmware has allocated a memory region previously determined to be unreliable. This has the potential to cause system instability and/or data corruption.

�Windows failed to resume from hibernate with error status %1.

|The boot manager multi OS selection screen was displayed.

\There are %1 boot options on this system.

hThere are %1 boot tool options on this system.

�The last shutdown's success status was %1. The last boot's success status was %2.

�The OS loader advanced options menu was displayed and the user selected option %1.

hThe OS loader edit options menu was displayed.

\The Windows key was pressed during boot.

PThe F8 key was pressed during boot.

DThe boot menu policy was %1.

pA one-time boot sequence was used during this boot.

4The boot type was %1.

lWindows failed fast startup with error status %1.

PThe firmware reported boot metrics.

hThe bootmgr spent %1 ms waiting for user input.

TSoft reboot cancellation started: %1

XSoft reboot cancellation finished: %1.

�The virtualization-based security enablement policy check at phase %1 failed with status: %2

pVirtualization-based security (policies: %3) is %2.

�Virtualization-based security (policies: %3) is %2 with status: %1

tSoft reboot prepare started (complete requested: %1).

LSoft reboot prepare finished: %1.

TSoft reboot complete prepare started.

`Soft reboot complete prepare finished: %1.

pSoft reboot call to %1 failed: %2 (checkpoint: %3).

lSystem drivers need update to support VBS launch.

hSMM configuration failed validation. Reason: %1

`EFI time zone bias: %1. Daylight flags: %2

�Bootmgr Security Version Number check failed. Svn Value: %1, Previous SVN Value: %2.

�App %1 was terminated with error %2 because of an issue with Windows binary %3. This could be because the binary is unsigned, contains an untrusted signature, or has been corrupted or tampered with. Refresh your PC to fix this issue.

,Structured State

0Unstructured Reset

$Out Of Memory

$Apiset Error

WinRT

@Low-level Data Store Error

�Failure to load the application settings for package %1. Error Code: %2

�Failure to read an application setting for package %1. Error Code: %2

�Failure to write an application setting for package %1. Error Code: %2

�Failure to instantiate storage folder %1 for package %2 with Error Code: %3

�Triggered repair because operation %1 against package %2 hit error %3.

�Repair for operation %1 against package %2 with error %3 returned Error Code: %4

pFolder path %1 failed access check: Error Code: %2

�Triggered repair of state locations because operation %1 against package %2 hit error %3.

�Repair of state locations for operation %1 against package %2 with error %3 returned Error Code: %4

8Verbose context events

8Scenario trigger events

SQM

Time

(Deprecated dlls

DFatal user callback exception

4A dll failed to load.

<Launch 16bit application

DWindows component on demand.

TThe Loader encountered a fatal error.

$Response Time

<Deprecated COM interfaces

Process

$AppContainer

0DesktopAppXProcess

4DesktopAppXContainer

�Scenario start enables context providers to the WDI context logger.

�Scenario end disables context providers to the WDI context logger.

�When a scenario has remained in-flight beyond the maximum time window it is automatically terminated by the SEM.

`A scenario start attempt failed in the SEM.

\A scenario end attempt failed in the SEM.

�The SEM received a request to start a new scenario, but the maximum number of scenarios were already in-flight.

�There is an invalid configuration parameter in the SEM registry namespace.

�The SEM is configured with more scenarios than the maximum allowed count.

�The SEM is configured with a scenario with too many context providers.

�The SEM is configured with a scenario that has too many end events.

�The number of providers specified across all scenarios is above the maximum allowed amount.

Info

Start

Stop

Start

<Invoke callback function

0Disable live cache

HUpdate resource cache manifest

4Build resource cache

Start

End

Error

Warning

 Information

Critical

Verbose

8SEM Scenario Lifecycle

0SEM Initialization

�This group of events tracks the performance of mounting hives from existing files.

�This group of events tracks the performance of unloading hives.

�This group of events tracks the performance of flushing hives.

�This group of events tracks the performance of registry shutdown.

�This group of events tracks the performance of loading hives.

�This group of events tracks the performance of restoring hives.

�This group of events tracks the performance of exporting hives.

HMUI NotifyUILanguageChange task

@MUI resource cache builder

DMicrosoft-Windows-Kernel-WDI

TMicrosoft-Windows-Kernel-WDI/Analytic

PMicrosoft-Windows-Kernel-WDI/Debug

\Microsoft-Windows-Kernel-WDI/Operational

LMicrosoft-Windows-AppModel-State

XMicrosoft-Windows-AppModel-State/Debug

`Microsoft-Windows-AppModel-State/Diagnostic

LMicrosoft-Windows-Kernel-General

System

LMicrosoft-Windows-Kernel-Process

LMicrosoft-Windows-Kernel-Registry

DMicrosoft-Windows-Kernel-Acpi

DMicrosoft-Windows-User-Loader

 Application

\Microsoft-Windows-Kernel-BootDiagnostics

4Microsoft-Windows-UAC

LMicrosoft-Windows-UAC/Operational

4Microsoft-Windows-COM

dMicrosoft-Windows-SoftwareRestrictionPolicies

4Microsoft-Windows-MUI

LMicrosoft-Windows-MUI/Operational

@Microsoft-Windows-MUI/Admin

HMicrosoft-Windows-MUI/Analytic

@Microsoft-Windows-MUI/Debug

4Microsoft-Windows-PCI

PMicrosoft-Windows-Kernel-ShimEngine

hMicrosoft-Windows-Kernel-ShimEngine/Operational

PMicrosoft-Windows-AppModel-Runtime

`Microsoft-Windows-AppModel-Runtime/Analytic

dError while deleting file: %1. Error Code: %2

pError while deleting directory: %1. Error Code: %2

DError while allocating memory

lApiSet Function: %1 returned with Error Code: %2

�Low-level data store access error. Function: %1 returned with Error Code: %2

�Cleanup of temporary state has been skipped due to low disk usage.

\Cleanup of temporary state has completed.

�Cleanup of temporary state was unable to enumerate the user profiles.  Object: %1, Error Code: %2.

tCleanup of temporary state has aborted unexpectedly.

�Need to update state locations of package %1 for user %2 because the schema is not found. Error Code: %3

�Need to update state locations of package %1 for user %2 because the package is not found. Error Code: %3

�Need to update state locations of package %1 for user %2 because the package full name has changed. Error Code: %3

�Need to update state locations of package %1 for user %2 because the schema version has changed. Error Code: %3

lSucceeded to fix state locations for package %1.

�Failure to fix state locations for package %1. Error Code: %2

4The Scenario Event Mapper started a scenario for provider %1 (event ID %2) with %4 context providers.  The context logger dropped event count was %3.

4The Scenario Event Mapper stopped a scenario for provider %1 (event ID %2) with %4 context providers.  The context logger dropped event count was %3.

An in-flight scenario from provider %1 (event ID %2) timed out and was stopped automatically by the Scenario Event Mapper.

<The Scenario Event Mapper was unable to start a new scenario for provider %1 (event ID %2) because the maximum number of scenarios are already in flight.

�The Scenario Event Mapper was unable to start a scenario for provider %1 (event ID %2).  The error code was %3.

�The Scenario Event Mapper was unable to stop a scenario for provider %1 (event ID %2).  The error code was %3.

4The Scenario Event Mapper is configured with more than the maximum number of scenarios.  The scenario for provider %1 (event ID %2) will be ignored.

hThe Scenario Event Mapper is configured with more than the maximum number of context providers for the scenario with provider %1 (event ID %2).  The scenario will be ignored.

XThe Scenario Event Mapper is configured with more than the maximum number of end events for the scenario with provider %1 (event ID %2).  The scenario will be ignored.

�The Scenario Event Mapper is configured with more than the maximum number of providers.  The provider %1 will be ignored.

HThe Scenario Event Mapper is configured with an unsupported scenario. The scenario for provider %1 (event ID %2) encountered error code %3 and will be ignored.

`The system time has changed to %1 from %2.

�The system time has changed to %1 from %2.%n%nChange Reason: %3.

�Process %1 started at time %2 by parent %3 running in session %4 with name %5.

�Process %1 (which started at time %3) stopped at time %4 with exit code %5.

PThread %2 (in Process %1) started.

PThread %2 (in Process %1) stopped.

dProcess %3 had an image loaded with name %7.

hProcess %3 had an image unloaded with name %7.

�Base CPU priority of thread %2 in process %1 was changed from %3 to %4.

�CPU priority of thread %2 in process %1 was changed from %3 to %4.

�Page priority of thread %2 in process %1 was changed from %3 to %4.

�I/O priority of thread %2 in process %1 was changed from %3 to %4.

hExecution of the process %1 has been suspended.

dExecution of the process %1 has been resumed.

PJob %1 started with status code %2.

XJob %1 terminated with status code %2.

�Enumerated process %1 had started at time %2 by parent %3 running in session %4 with name %6.

�Process %1 started at time %2 by parent %3 running in session %4 with name %6.

�Process %1 (which started at time %2) stopped at time %3 with exit code %4.

�Enumerated process %1 had started at time %3 by parent %4 running in session %6 with name %11.

�Process %1 started at time %2 by parent %3 running in session %4 with name %6.

�Process %1 started at time %3 by parent %4 running in session %6 with name %11.

xA memory range descriptor has been marked as reserved.

�Unexpected GPE event was fired on GPE bits that should be disabled.

�A temperature change notification (Notify(thermal_zone, 0x80)) for ACPI thermal zone %2 has been received.             %n_TMP = %3K             %n_PSV = %4K             %n_AC0 = %5K             %n_AC1 = %6K             %n_AC2 = %7K             %n_AC3 = %8K             %n_AC4 = %9K             %n_AC5 = %10K             %n_AC6 = %11K             %n_AC7 = %12K             %n_AC8 = %13K             %n_AC9 = %14K             %n_HOT = %15K             %n_CRT = %16K

�A trip point change notification (Notify(thermal_zone, 0x81)) for ACPI thermal zone %2 has been received.             %n_TMP = %3K             %n_PSV = %4K             %n_AC0 = %5K             %n_AC1 = %6K             %n_AC2 = %7K             %n_AC3 = %8K             %n_AC4 = %9K             %n_AC5 = %10K             %n_AC6 = %11K             %n_AC7 = %12K             %n_AC8 = %13K             %n_AC9 = %14K             %n_HOT = %15K             %n_CRT = %16K

lThe active cooling device %6 has been turned %8.             %nThermal zone device instance: %2             %nActive cooling package: _AC%3             %nNamespace object: _AL%4

lThe active cooling device %6 has been turned %7.             %nThermal zone device instance: %2             %nActive cooling package: _AC%3             %nNamespace object: _AL%4

LACPI method %2 evaluation has %3.

lThe active cooling device %2 has been turned %3.

�The passive cooling device %2 throttle has changed to %3 percent.

�The device %2 has the following cooling state.             %nActive cooling: %3             %nPassive cooling: %4 percent

`ACPI device %2 is undergoing %3. Status %4.

<ACPI device OverRide - %1

�Error occured while interpreting AML code: scope %1, object %2. Status %3.

TACPI method %2 has high frequency %3.

4Deprecated module %1.

xProcess %2 encountered a fatal user callback exception.

XThe process launches a 16 bit process.

HWindows component on demand %1.

�The Loader encountered a fatal error while loading a thread from process image name %1.

lA fatal error occured during initalization of %1.

�The Loader encountered a fatal error running process image name %1.

�The process failed to handle ERROR_ELEVATION_REQUIRED during the creation of a child process.

<Deprecated COM CLSID %1.

�MUI notify operation failed with status code %1. No callbacks were invoked.

 MUI Callback failed for file %1 because it can not be loaded. To correct this error, replace this file or repair your Windows installation.

`MUI Callback failed for file %1 registered as type %2 because the function %3 does not exist in the dll. To correct this error, replace the file or fix the registry entry.

XMUI Callback failed for file %1 because it is not signed by Microsoft. To correct this error, replace with the original file that came with this Windows installation.

MUI Callback file %1 cannot be found. To correct this error, repair the registry or copy the file to the specified location.

�Wow redirection could not be disabled. New resource cache will not be built.

�Resource cache cannot be opened in writable mode. New resource cache will not be built.

`Live resource cache could not be disabled.

�Unable to retrieve language settings from MUI API. New resource cache will not be built.

�Unable to parse the cacheable file list or write to the resource cache manifest. If configuration file was specified as command-line parameter, check that file exists and has correct format.  New resource cache will not be built.

�Changes made to resource cache manifest cannot be written to disk. New resource cache will not be built.

�New resource cache could not be built due to internal error: %1.

�Newly built resource cache could not be installed on the system.

�Resource cache manifest could not be created. New resource cache will not be built.

pMUI notification for UI Language change has been invoked with flags set to %1 and the new languages set to %2 and the previous languages set to %3. The extended flags is set to %4

�MUI notification callback API %2 in %1 returned with code %3.

�MUI resource cache builder has been called with the following parameters: %1.

�MUI resource cache manifest entry for file %1 has been updated. Affinity: '%2', Sequence: %3, and Priority: %4

Start: %1

End: %1

�New resource cache built and installed on system. New cache index is %1, live cache index is %2 and config is set to %3.

�Resource file %1 will not be cached since it is not used frequently in the system.

�The system is constrained in RAM, total disk space or free disk space, so the MUI resource cache will not be maintained.

�Unable to parse configuration parameters. The configuration parameters will be ignored.

�The time elapsed before Bootmgr, based on the TSC, is %1 ms.

�Initialization of the firmware crypto hash provider resulted in status %1.

�The firmware update capsule (%1) failed to load with status %2.

�The PE/COFF image firmware update capsule (%1) failed to load with status %2.

�The Efi UpdateCapsule failed to apply updates with status %1.

�Firmware update supported status is %3. The BitLocker device flags are %1 and the PCR bitmap is %2.

�The firmware update capsule (%1) code integrity check failed with status %2.

�Windows failed to load the required system file %1 with error status %2.

�Windows failed to load the system registry file %1 with error status %2.

�Windows failed to initialize the ACPI with error status %1.

dWindows failed to load with error status %1.

�Windows failed to load image %2 imported from %1 with error status %3.

�Windows failed to import %2 from image %1 with error status %3.

`Windows failed to provision VSM Identity Key. Unsealing cached copy status: %1. New key generation status: %2. Measuring to PCR status: %3. Sealing and caching status: %4.

DVSM Identity Key Provisioning. Unsealing cached copy status: %1. New key generation status: %2. Measuring to PCR status: %3. Sealing and caching status: %4.

�Windows system integrity policy does not allow to load the required system file %1 with error status %2.

Windows failed to provision VSM Master Encryption Key. Using cached copy status: %1. Unsealing cached copy status: %2. New key generation status: %3. Sealing status: %4. TPM PCR mask: %5. Protector-assisted unseal status: %6. Protector-assisted re-seal status: %7. Protector update status: %8. Tpm Counter validation status: %9. Tpm Counter creation status: %10. Backup sealed blob used: %11.

�VSM Master Encryption Key Provisioning. Using cached copy status: %1. Unsealing cached copy status: %2. New key generation status: %3. Sealing status: %4. TPM PCR mask: %5. Protector-assisted unseal status: %6. Protector-assisted re-seal status: %7. Protector update status: %8. Tpm Counter validation status: %9. Tpm Counter creation status: %10. Backup sealed blob used: %11.

�Windows failed to provision the TPM Storage Root Key with error status:%1.

�Windows successfully provisioned the TPM Storage Root Key. This operation took %1 milliseconds.

�Windows failed to provision TPM binding information with error status:%1.

�NFIT ACPI table is not properly formed, and could not be parsed.

�Previous error detected while attempting to execute Measured Launch Environment. TXT error code: %1.

\Firmware provided SINIT ACM not used. %1

�Windows failed to provision DRTM-bound VSM Master Encryption Key . Using cached copy status: %1. New key generation status: %2. Sealing status: %3. UEFI keys provided to Secure Kernel status: %4.

�Windows successfully provisioned DRTM-bound VSM Master Encryption Key. Using cached copy status: %1. New key generation status: %2. Sealing status: %3. UEFI keys provided to Secure Kernel status: %4.

�Windows skipped provisioning the TPM Storage Root Key because the NoAutoProvision registry value was set.

�Soft Restart failed to complete with status: %1 due to %2 outstanding unclaimed allocations

�Soft Restart failed to restore memory partition %1 with status: %2

�Soft Restart failed to register with Soft Restart extension. The versions are not compatible.

�Soft Restart failed to establish connection with secure load with status: %1

�Boot Policy Migration used an authenticated variable.  Status: %1

�Boot Policy Migration used an unauthenticated variable.  Status: %1

0Info: %1 Status: %2

4Error: %1 Status: %2

�Soft Restart driver failed to register itself as a filter with status: %1

�A command was submitted to the TPM.%nCommand code: %1.%nResponse code: %2.%nElapsed time: %3ms.

�A command could not be submitted to the TPM.%nCommand code: %1.%nError code: %2.%nElapsed time: %3ms.

�The TPM was found not to be useable for BitLocker. Flags: %1.

�Measured Boot library was initialized. Phase: %1, StatusCode: %2.

HMeasured Boot library encountered a failure and entered insecure state. InitState: %1, StatusCode: %2, Failure Address: %3, Reference Address: %4, Reason: %5.

�DRTM Security Version Number check failed. SvnCounterId: %1, StatusCode: %2, Svn Value: %3, Previous SVN Value: %4.

DIntel TXT SENTER time: %1 ms.

`File modification detected after load: %1.

hRegistry modification detected after load: %1.

XIntel TXT prepared. ACM date: %2/%1/%3.

pSystem Guard enabled but not supported. Reason: %1

\VBS is configured to disallow trustlets.

`Boot menu timer canceled due to key press.

�Windows boot environment failed to initialize TPM device. StatusCode: %1, Position: %2.

\SMM isolation level decreased. Reason: %1

�Hardware memory mirroring is not supported. MirrorStatus: %1

�TPRs are supported, TPR setup will be requested while attempting to execute Measured Launch Environment.

�BCD Option '%1' was not applied due to Secure Boot being enabled.

�Windows boot manager revocation policy version %1 is applied.

�Windows boot manager revocation policy version %1 was not found. It is recommended that it be redeployed.

`Succeeded in updating the SBAT value in FW.

XFailed to update the SBAT value in FW.

�Windows failed to provision VSM Master Encryption Key. Using cached copy status: %1. Primary Blob Unseal Status: %2. Backup Blob Unseal Status: %3. Kickback Backup Blob Unseal Status: %4. Backup Blob Validity Check Status: %5. Backup Blob Validity Check Result: %6. Kickback Backup Blob Validity Check Status: %7. Kickback Backup Blob Validity Check Result: %8. Primary Blob Reseal Status: %9. Backup Blob Reseal Status: %10. Kickback Backup Blob Reseal Status: %11. New key generation status: %12. Sealing status: %13. TPM PCR mask: %14. Tpm Counter validation status: %15. Tpm Counter creation status: %16. Backup sealed blob used: %17. Kickback Backup sealed blob cleaned up post upgrade status: %18.

lVSM Master Encryption Key Provisioning. Using cached copy status: %1. Primary Blob Unseal Status: %2. Backup Blob Unseal Status: %3. Kickback Backup Blob Unseal Status: %4. Backup Blob Validity Check Status: %5. Backup Blob Validity Check Result: %6. Kickback Backup Blob Validity Check Status: %7. Kickback Backup Blob Validity Check Result: %8. Primary Blob Reseal Status: %9. Backup Blob Reseal Status: %10. Kickback Backup Blob Reseal Status: %11. New key generation status: %12. Sealing status: %13. TPM PCR mask: %14. Tpm Counter validation status: %15. Tpm Counter creation status: %16. Backup sealed blob used: %17. Kickback Backup sealed blob cleaned up post upgrade status: %18.

�%3 shim(s) were applied to driver [%1].%n%nShim(s) source: %2.%n%nShim GUID(s): %4.

�Flags [%4] were applied to device [%1] - class [%2].%n%nFlags source: %3.

�Process %1 started at time %2 by parent %3 running as package %4 with executable %5 is application %6.

�%2: Cannot create the process for package %1 because an error was encountered. %3

�%2: Cannot create the process for package %1 because an error was encountered while querying the fast cache. %3

�%2: Cannot create the process for package %1 because an error was encountered while preparing the App credentials. %3

%2: Cannot create the process for package %1 because an error was encountered while checking the user-level package status. %3

%2: Cannot create the process for package %1 because an error was encountered while checking the machine-level package status. %3

�%2: Cannot create the process for package %1 because an error was encountered while verifying the App credentials. %3

�App %1 was terminated with error %2 because of an issue with application binary %3. This could be because the binary is unsigned, contains an untrusted signature, or has been corrupted or tampered with. Reinstall the application to fix this issue.

|App %1 prevented the load of generated binary %3 due to error %2. This could be because the binary is unsigned, contains an untrusted signature, or has been corrupted or tampered with.

dAn app prevented the load of a binary due to error %1. This could be because the binary is unsigned, contains an untrusted signature, or has been corrupted or tampered with.

4%2: Package runtime information %1 is corrupted (address=%5, size=%3, offset=%4, section=%6, processid=%7). Reinstall the package to fix this issue.

4%2: Package runtime information %1 is missing expected data (address=%4, size=%3, section=%5, processid=%6). Reinstall the package to fix this issue.

L%2: Package runtime information %1 contains conflicting data (address=%5, size=%3, offset=%4, section=%6, processid=%7). Reinstall the package to fix this issue.

L%2: Package runtime information %1 contains unexpected data (address=%5, size=%3, offset=%4, section=%6, processid=%7). Reinstall the package to fix this issue.

�%2: Package runtime information %1 failed to load (processid=%3).

�Package runtime information %1 failed to load because exception %2 occurred.

�%2: Cannot create the process for package %1 because an error was encountered while loading the runtime information. %3

�CreateAppContainerProfile failed for AppContainer %2 with error %1.

�DeleteAppContainerProfile failed for AppContainer %2 with error %1.

�UpdateAppContainerProfile failed for AppContainer %2 with error %1.

�CreateAppContainerProfile failed with error %1 because it was unable to create registry key %2.

�CreateAppContainerProfile failed with error %1 because it was unable to set security on registry key %2.

�AppContainer profile failed with error %1 because it was unable to delete registry key %2.

�CreateAppContainerProfile failed with error %1 because it was unable to create folder %2.

�CreateAppContainerProfile failed with error %1 because it was unable to set attributes on folder %2.

�CreateAppContainerProfile failed with error %1 because it was unable to verify the existence of registry key %2.

�CreateAppContainerProfile failed with error %1 because it was unable to verify the existence of folder %2.

�CreateAppContainerProfile failed with error %1 because it was unable to find the users local app data folder.

�AppContainer profile failed with error %1 because it was unable to delete folder %2 or its contents.

�AppContainer profile failed with error %1 because it was unable to look up the AppContainer name.

�AppContainer profile failed with error %1 because it was unable to look up the AppContainer display name.

�CreateAppContainerProfile failed with error %1 because it was unable to register with the firewall.

�DeleteAppContainerProfile failed with error %1 because it was unable to unregister with the firewall.

�App Container profile failed with error %1 because it was unable to register the AppContainer SID.

�DeleteAppContainerProfile failed with error %1 because it was unable to unregister the AppContainer SID.

TSuccessfully created AppContainer %1.

�AppContainer %1 was not created because it already exists.

TSuccessfully deleted AppContainer %1.

TSuccessfully updated AppContainer %1.

4%2: Package runtime information %1 is missing expected data (address=%4, size=%3, section=%5, processid=%6). Reinstall the package to fix this issue.

�%2: Application identity not accessible while loading package runtime information %1 (address=%4, size=%3, processid=%5).

�Failed with %1 while retrieving AppContainer %2 information during interaction with Restricted AppContainer.

�Failed with %1 while retrieving AppContainer information during interaction with Restricted AppContainer.

�Failed with %1 while retrieving AppContainer information. Call invalid from this process type.

�Failed to create shared context object for Restricted AppContainer %2 with %1.

xFailed to activate Restricted AppContainer %2 with %1.

�Creation of Restricted AppContainer %2 failed with %1 because an invalid capability was specified.

�Opening existing Restricted AppContainer %2 failed with %1 because the capabilities storage value could not be read.

�Failed to create the capabilities storage value for Restricted AppContainer %2 with %1.

PThe package %1 requires validation.

\Modification was detected in package %1.

\Failed to terminate app with package %1.

lValidation of app with package %1 was successful.

�Failed with %1 to retrieve the trust state of the package %2 folder.

tApp Integrity check failed with %1 while checking %2.

�App Integrity terminated an application. Integrity check for %2 returned %1.

TApp Integrity check for %1 timed out.

�%2: Cannot create the process for package %1 because an error was encountered while performing the integrity check. %3

�Deployment server integrity check of package %1 failed with %2.

�Failed with %1 retrieving AppModel Runtime group policy values.

�Failed with %1 validating AppModel Runtime group policy values.

�Failed with %1 retrieving AppModel Runtime status for package %2.

�Failed with %1 retrieving AppModel Runtime status for package %2 for user %3.

�Failed with %1 modifying AppModel Runtime status for package %2 (current status = %4, desired status = %3).

�AppModel Runtime status for package %1 successfully updated to %2 (previous status = %3).

�Failed with %1 modifying AppModel Runtime status for package %2 for user %3 (current status = %5, desired status = %4).

�AppModel Runtime status for package %1 for user %2 successfully updated to %3 (previous status = %4).

�Failed with %1 modifying AppModel Runtime status version (context = %2).

tAppModel Runtime status version successfully updated.

�%2: Cannot create the process for package %1 because an error was encountered while performing the app data creation. %3

�Package runtime information %1 failed to refresh because the following error %2 occurred in operation type %3.

error %2: Cannot register the %1 package because the following error was encountered while opening the HKEY_USERS registry key

8error %4: Cannot register the %1 package because the following error was encountered while enumerating to remove the %2\%3 package family registry key

 error %4 : Cannot register the %1 package because the following error was encountered while creating the %2\%3 package family registry key

error %4: Cannot register the %1 package because the following error was encountered while removing the %2\%3 package family registry key

�%2: Package family %1 runtime information is corrupted. Attempting to correct the issue.

�%2: Package family %1 runtime information is corrupted but we cannot repair it at this time.

$Failed with %1 to get IsPackageStageInPlace info from State Repository cache for package %2. The app will by default require integrity check.

<Creating AppContainer %1.

`Finished creating AppContainer %2 with %1.

<Deleting AppContainer %1.

`Finished deleting AppContainer %2 with %1.

<Updating AppContainer %1.

`Finished updating AppContainer %2 with %1.

dCreating firewall rules for AppContainer %1.

�Finished creating firewall rules for AppContainer %2 with %1.

dDeleting firewall rules for AppContainer %1.

�Finished deleting firewall rules for AppContainer %2 with %1.

TCreating Restricted AppContainer %1.

tFinished creating Restricted AppContainer %2 with %1.

TDeleting Restricted AppContainer %1.

tFinished deleting Restricted AppContainer %2 with %1.

POpening Restricted AppContainer %1.

tFinished opening Restricted AppContainer %2 with %1.

lEnumerating all Restricted AppContainers for %1.

�Finished enumerating all Restricted AppContainers for AppContainer %2 with %1.

lLaunching process in Restricted AppContainer %1.

�Finished launching process in Restricted AppContainer %2 with %1.

|Terminating all processes in Restricted AppContainer %1.

�Finished terminating all processes in Restricted AppContainer %2 with %1.

HChecking package graph for %1.

dPackage graph check for %2 finished with %1.

hPerforming app integrity check for package %1.

tApp integrity check for package %2 finished with %1.

xPerforming runtime app integrity check for package %1.

�Runtime app integrity check for package %2 finished with %1.

�Firewall Service not running. Skipping creation of firewall rules for AppContainer %1.

lUpdating Restricted AppContainer Capabilities %1.

�Finished Updating Restricted AppContainer Capabilities %2 with %1.

xCreated process %1 for application %4 in package %2. %5

�%4: Cannot create the process for package %1 because an error was encountered. %5

�%4: Cannot create the process for package %1 because an error was encountered while preparing for activation. %5

�%4: Cannot create the process for package %1 because an error was encountered while elevating the token. %5

�%4: Cannot create the process for package %1 because UI Access is not supported for Desktop AppX processes. %5

�%4: Cannot create the process for package %1 because an error was encountered while adjusting the token. %5

�%4: Cannot create the process for package %1 because an error was encountered while launching. %5

�%4: Cannot create the process for package %1 because an error was encountered while configuring runtime. %5

�%4: Cannot create the process for package %1 because an error was encountered while resuming the thread. %5

lCreated Desktop AppX container %3 for package %1.

�Added process %1 to Desktop AppX container %3 for package %2.

�%1: Cannot add process %2 to Desktop AppX container %4 for package %3 because an error was encountered.

�%1: Cannot create the Desktop AppX container for package %2 because an error was encountered creating the job.

�%1: Cannot create the Desktop AppX container for package %2 because an error was encountered creating the description.

�%1: Cannot create the Desktop AppX container for package %2 because an error was encountered converting the job.

�%1: Cannot create the Desktop AppX container for package %2 because an error was encountered configuring the runtime.

pDestroyed Desktop AppX container %2 for package %1.

|Cannot destroy Desktop AppX container %2 for package %1.

PSystem time initialized during boot

pAn application or system component changed the time

lSystem time synchronized with the hardware clock

\System time adjusted to the new time zone

xLeap second data initialized from registry during boot

XLeap second data updated from registry

TRegistry value invalid format or size

4Too many leap seconds

�Cannot decrease the number of leap seconds while the system is running

LAn invalid leap second was found

tThe list of leap seconds must be strictly increasing

�Cannot modify the existing leap seconds while the system is running

$Other reason

on

off

started

finished

@Platform-level Device Reset

@Function-level Device Reset

LAcpi Override attribute - MpSleep

PAcpi Override attribute - DisableS1

PAcpi Override attribute - DisableS2

PAcpi Override attribute - DisableS3

hAcpi Override attribute - DellMaxUlongBugcheck

lAcpi Override attribute - PciBusNumberTranslation

pAcpi Override attribute - RunRegMethodOnPciDevices

lAcpi Override attribute - RescanPostDependencies

�Acpi Override attribute - PlatformCheckD3ColdOnSurpriseRemoval

�Acpi Override attribute - PlatformCheckFailResetOnOpenHandles

disabled

Hdisabled due to HyperV opt-out

Tdisabled due to opt-out UEFI variable

`disabled due to secure boot being disabled

ldisabled due to DMA protection being unavailable

ldisabled due to the hypervisor being unavailable

`disabled due to VBS initialization failure

pdisabled due to VBS anti-rollback policy is missing

\enabled due to VBS registry configuration

4enabled due to HyperV

Xenabled due to VBS locked configuration

Tenabled due to Code Integrity policy

8enabled due to Velocity

@BL_LOG_INFO_NONE: Info none

�BL_LOG_INFO_BLI_IO_INITED: IO initialized in boot library initialization.

�BL_LOG_INFO_BLI_FINISHED: Finished in boot library initialization.

�BL_LOG_INFO_BM_BL_INITED: The boot library has been initialized for bootmgr.

�BL_LOG_INFO_BM_GET_BOOT_SEQ: Getting boot sequence in bootmgr.

�BL_LOG_INFO_BM_LAUNCH_ENTRY: Launching boot entry in bootmgr.

�BL_LOG_INFO_OSL_PREPARE_ENTERED: Reached prepare target within osloader.

�BL_LOG_INFO_OSL_OPEN_DEVICE: Preparing to open OS device in osloader.

�BL_LOG_INFO_OSL_LAUNCH_HYPERV: Preparing to launch hyper-v if specified within osloader.

�BL_LOG_INFO_OSL_LOAD_MODULES: Preparing to load OS modules within osloader.

�BL_LOG_INFO_OSL_KERNEL_SETUP: Setting up kernel within osloader.

�BL_LOG_INFO_OSL_PRELOAD_HYPERV: Preloading hyper-v if specified within osloader.

pBL_LOG_INFO_OSL_BOOT_CANCELLED: Boot was cancelled.

�BL_LOG_INFO_TCB_LAUNCH_HYPERV: Preparing to launch hyper-v.

@BL_LOG_ERROR: Generic Error

�BL_LOG_ERROR_BLI_NET_INIT: BlNetInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_UTL_INIT: BlUtlInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_SEC_BOOT_INIT: BlSecureBootInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_PDATA_INIT: BlpPdInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_RES_INIT: BlpResourceInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_SEC_LAUNCH_INIT: BlpTcbLaunchInitialize failed in BL initialization.

�BL_LOG_ERROR_BM_INIT_MACH_POL: BmSecureBootInitializeMachinePolicy failed in bootmgr.

�BL_LOG_ERROR_BM_FW_REG_SYSINT: BmFwRegisterSystemIntegrityPolicies failed in bootmgr.

�BL_LOG_ERROR_BM_RES_FIND_HTML: BlResourceFindHtml failed to find BOOTMGR.XSL in bootmgr.

�BL_LOG_ERROR_BM_XMI_INIT: BlXmiInitialize failed in bootmgr.

�BL_LOG_ERROR_BM_OPEN_DATA_STORE: BmOpenDataStore failed in bootmgr.

�BL_LOG_ERROR_BM_SELF_INT_CHK: BmpSelfIntegrityCheck failed in bootmgr.

�BL_LOG_ERROR_BM_FW_REG_REV_LIST: BmFwRegisterRevocationList failed in bootmgr.

�BL_LOG_ERROR_BM_RESUME_HIBER: BmResumeFromHibernate failed in bootmgr.

�BL_LOG_ERROR_BM_PURGE_OPT_START_SEQ: BL_ERROR_BM_PURGE_OPT_START_SEQ failed in bootmgr.

�BL_LOG_ERROR_BM_PURGE_OPT_BOOT_SEQ: BmPurgeOption failed for BCDE_BOOTMGR_TYPE_BOOT_SEQUENCE in bootmgr.

�BL_LOG_ERROR_BM_REOPEN_DATA_STORE: BmOpenDataStore failed on reopen in bootmgr.

�BL_LOG_ERROR_BM_UPDATE_APP_OPTS: BmpUpdateApplicationOptions failed in bootmgr.

�BL_LOG_ERROR_BM_LAUNCH_BOOT_ENTRY: BmpLaunchBootEntry failed in bootmgr.

�BL_LOG_ERROR_BM_CREATE_DEVICES: BmpCreateDevices failed in bootmgr.

�BL_LOG_ERROR_BM_LAUNCH_FLIGHT_BM: BmFwLaunchFlightedBootmgr failed in bootmgr.

�BL_LOG_ERROR_BM_FE_BOOTAPP_LD: Fatal error: failure to load boot app in bootmgr.

�BL_LOG_ERROR_BM_FE_CONFIG_DATA: Fatal error: failure attempting to read boot config file in bootmgr.

�BL_LOG_ERROR_BM_FE_NO_VALID_OS_ENTRY: Fatal error: no valid os entires found in bootmgr.

�BL_LOG_ERROR_BM_FE_NO_VALID_PXE_ENTRY: Fatal error: no valid entries found from PXE server in bootmgr.

�BL_LOG_ERROR_BM_FE_FAILURE_STATUS: Fatal error: failure status in bootmgr.

�BL_LOG_ERROR_BM_FE_BOOT_DEVICE: Fatal error: boot device inaccessible in bootmgr.

�BL_LOG_ERROR_BM_FE_RAMDISK_MEM: Fatal error: ramdisk device creation had insufficient memory in bootmgr.

�BL_LOG_ERROR_BM_FE_INVALID_BCD_STORE: Fatal error: BCD is invalid in bootmgr.

�BL_LOG_ERROR_BM_FE_INVALID_BCD_ENTRY: Fatal error: Invalid BCD entry in bootmgr.

�BL_LOG_ERROR_BM_FE_NO_SECUREBOOT_POL: Fatal error: Default Secure Boot policy not found in bootmgr.

�BL_LOG_ERROR_BM_FE_NO_PAE_SUPPORT: Fatal error: CPU does not support PAE in bootmgr.

�BL_LOG_ERROR_BM_FE_UNSEAL_NOT_POS: Fatal error: Cannot unseal sensitive data in bootmgr.

�BL_LOG_ERROR_BM_FE_GENERIC: Fatal error: Generic failure in bootmgr.

�BL_LOG_ERROR_BM_FAILED_SVN_CHECK: Bootmgr SVN check failed.

�BL_LOG_ERROR_BM_FAILED_CHAINLOAD_SVN_CHECK: SVN check failed while chainloading bootmgr.

�BL_LOG_ERROR_OSL_REM_INTERN_APP_OPTS: OslpRemoveInternalApplicationOptions failed in osloader.

�BL_LOG_ERROR_OSL_GET_APP_OPT_DEVICE: BlGetApplicationOptionDevice failed for BCDE_OSLOADER_TYPE_OS_DEVICE in osloader.

�BL_LOG_ERROR_OSL_GET_SYSTEM_ROOT: Failed to get SystemRoot in osloader.

�BL_LOG_ERROR_OSL_FORCED_FAIL: OslpCheckForcedFailure failed implying a forced failure in osloader.

BL_LOG_ERROR_OSL_DISABLE_VGA: BlAppendApplicationOptionBoolean for BCDE_OSLOADER_TYPE_DISABLE_VGA_MODE failed in osloader.

�BL_LOG_ERROR_OSL_OPEN_OS_DEVICE: BlDeviceOpen failed for os device in osloader.

�BL_LOG_ERROR_OSL_LOAD_SYS_HIVE: OslpLoadSystemHive failed in osloader.

�BL_LOG_ERROR_OSL_CREATE_OS_LD_OPTS: AhCreateLoadOptionsString failed in osloader.

�BL_LOG_ERROR_OSL_DISPLAY_INIT: OslDisplayInitialize failed in osloader.

�BL_LOG_ERROR_OSL_PROCESS_SI_POLICY: OslpProcessSIPolicy failed in osloader.

�BL_LOG_ERROR_OSL_DISP_ADV_OPT: OslDisplayAdvancedOptionsProcess failed in osloader.

�BL_LOG_ERROR_OSL_ARCH_HV_SETUP: OslArchHypervisorSetup failed in osloader.

�BL_LOG_ERROR_OSL_ARCH_HYPERCALL_SETUP: OslArchHypercallSetup failed in osloader.

�BL_LOG_ERROR_OSL_INIT_RESUME_CONTEXT: OslInitializeResumeContext failed in osloader.

�BL_LOG_ERROR_OSL_INIT_LDR_BLOCK: OslInitializeLoaderBlock failed in osloader.

�BL_LOG_ERROR_OSL_PROC_INIT_MACH_CONFIG: OslpProcessInitialMachineConfiguration failed in osloader.

�BL_LOG_ERROR_OSL_ENUM_DISKS: OslEnumerateDisks failed for the loader block in osloader.

�BL_LOG_ERROR_OSL_REINIT_SYS_HIVE: OslpReinitializeSystemHive failed in osloader.

�BL_LOG_ERROR_OSL_INIT_CODE_INT: OslInitializeCodeIntegrity failed in osloader.

�BL_LOG_ERROR_OSL_INIT_CODE_INT_LD_BLOCK: OslBuildCodeIntegrityLoaderBlock failed in osloader.

�BL_LOG_ERROR_OSL_SECURE_BOOT_VARS: OslFwProtectSecureBootVariables failed in osloader.

�BL_LOG_ERROR_OSL_LD_MODULES: OslpLoadAllModules failed in osloader.

�BL_LOG_ERROR_OSL_LD_FW_DRIVERS: OslFwLoadFirmwareDrivers failed in osloader.

�BL_LOG_ERROR_OSL_VSM_CHK_ENCRYPT_KEY: BlVsmCheckSystemPolicy failed for master sncrupt key provisioning in osloader.

�BL_LOG_ERROR_OSL_VSM_PHASE_0: Fatal VSM Phase 0 initializatin failure in osloader.

�BL_LOG_ERROR_OSL_SET_SEIL_SIGN_POL: OslSetSeILSigningPolicy failed in osloader.

�BL_LOG_ERROR_OSL_CMS_PROV_IDK: BlVsmCheckSystemPolicy failed during VSM Idendity key work in osloader.

�BL_LOG_ERROR_OSL_ARCH_KERNEL_SETUP_0: OslArchKernelSetup failed for 0 in osloader.

�BL_LOG_ERROR_OSL_FW_KERNEL_SETUP: OslFwKernelSetup failed for 0 in osloader.

�BL_LOG_ERROR_OSL_PROC_EV_STORE: OslpProcessEVStore failed in osloader.

�BL_LOG_ERROR_OSL_COPY_BOOT_OPTS: BlCopyBootOptions failed in osloader.

�BL_LOG_ERROR_OSL_FVE_SEC_BOOT_REST_ONE: BlFveSecureBootRestrictToOne failed in osloader.

�BL_LOG_ERROR_OSL_NET_UNDI_CLOSE: BlNetUndiClose failed in osloader.

�BL_LOG_ERROR_OSL_PROC_APP_PDATA: OslProcessApplicationPersistentData failed in osloader.

�BL_LOG_ERROR_OSL_BLD_MEM_CACHE_REQ_LIST: OslFwBuildMemoryCachingRequirementsList failed in osloader.

�BL_LOG_ERROR_OSL_BLD_RT_MEM_MAP: OslFwBuildRuntimeMemoryMap failed in osloader.

�BL_LOG_ERROR_OSL_VSM_SETUP_1: OslVsmSetup failed for 1 in osloader.

�BL_LOG_ERROR_OSL_BLD_KERNEL_MEM_MAP: BlTraceBuildKernelMemoryMapStop failed in osloader.

�BL_LOG_ERROR_OSL_ARCH_KERNEL_SETUP_1: OslArchKernelSetup failed for 1 in osloader.

�BL_LOG_ERROR_OSL_SET_VSM_POL_SYS_HIVE: OslSetVsmPolicy failed in osloader.

�BL_LOG_ERROR_OSL_ENUM_ENCLAVE_PAGES: OslEnumerateEnclavePageRegions failed in osloader.

�BL_LOG_ERROR_OSL_GATHER_ENTROPY: OslGatherEntropy failed in osloader.

�BL_LOG_ERROR_OSL_VSM_SETUP_0: OslVsmSetup failed for 0 in osloader.

�BL_LOG_ERROR_OSL_VSM_CANNOT_BE_DISABLED_BY_KSR: VSM must not be disabled through KSR

lBL_LOG_ERROR_OSL_VSM_PHASE0_ALLOCATE_PAGES_FAILED

hBL_LOG_ERROR_OSL_VSM_PHASE0_LOAD_MODULES_FAILED

hBL_LOG_ERROR_OSL_VSM_PHASE0_LOAD_CIDATA_FAILED

lBL_LOG_ERROR_OSL_VSM_PHASE0_COPY_VSM_KEYS_FAILED

pBL_LOG_ERROR_OSL_VSM_PHASE0_COPY_ACPI_TABLES_FAILED

dBL_LOG_ERROR_OSL_VSM_PHASE0_ARCH_SETUP_FAILED

tBL_LOG_ERROR_OSL_VSM_PHASE0_BUILD_PAGE_TABLES_FAILED

�BL_LOG_ERROR_OSL_BUILD_BSD_LOCATION_FAILED: OslpBuildBsdLogLocation failed in osloader.

BL_LOG_ERROR_OSL_GET_APP_OPT_DEVICE_OSDATA: BlGetApplicationOptionDevice failed for BCDE_OSLOADER_TYPE_OS_DATA_DEVICE in osloader.

�BL_LOG_ERROR_OSL_OPEN_OSDATA_DEVICE: BlDeviceOpen failed for osdata device in osloader.

�BL_LOG_ERROR_OSL_ENUMERATE_PERSISTENT_MEMORY: OslEnumeratePersistentMemory failed in osloader.

�BL_LOG_ERROR_OSL_HVCI_CANNOT_BE_ENABLED_BY_KSR: HVCI must not be enabled through KSR

�BL_LOG_ERROR_OSL_PROCESS_PRESERVED_MEMORY: Error while processing preserved memory.

�BL_LOG_ERROR_OSL_LOAD_DEVICES_HIVE: OslpLoadDevicesHive failed in osloader.

�BL_LOG_ERROR_OSL_LOAD_OSBOOT_HIVE: OslpLoadOsBootHive failed in osloader.

�BL_LOG_ERROR_OSL_LOAD_DRIVER_STORES: OslpLoadDriverStoreNodes failed in osloader.

�BL_LOG_ERROR_OSL_CMS_PROV_HBK: BlVsmCheckSystemPolicy failed during VSM Hibernation key work in osloader.

�BL_LOG_ERROR_OSL_ALLOC_LDR_BLOCK: OslAllocateLoaderBlock failed in osloader.

�BL_LOG_ERROR_OSL_ARCH_TCB_LAUNCH_0: OslTcbLaunch(0) failed in osloader.

�BL_LOG_ERROR_OSL_HVCI_CANNOT_BE_DISABLED_BY_KSR: HVCI must not be disabled through KSR

BL_LOG_ERROR_OSL_GET_APP_OPT_DEVICE_BSP: BlGetApplicationOptionDevice failed for BCDE_OSLOADER_TYPE_BSP_DEVICE in osloader.

�BL_LOG_ERROR_OSL_OPEN_BSP_DEVICE: BlDeviceOpen failed for bsp device in osloader.

pBL_LOG_ERROR_OSL_VSM_PHASE0_VBS_POLICY_NOT_PRESENT

�BL_LOG_ERROR_KSR_KSEG0: InitializeRebootAddressRange failed in SK extension.

�BL_LOG_ERROR_KSR_OUT_OF_MEMORY: Memory allocation failed in SK KSR extension.

�BL_LOG_ERROR_KSR_IMAGE_VALIDATION: Image validation failed in SK KSR extension.

�BL_LOG_ERROR_KSR_IMAGE_RELOCATION: Image relocation failed in SK KSR extension.

�BL_LOG_ERROR_KSR_BIND_IMPORT: Failed to bind imports to image in SK KSR extension.

�BL_LOG_ERROR_KSR_LOADER_ENTRY_POINT: SK loader entry point returned failure.

�BL_LOG_ERROR_KSR_RESERVE_EFI_RUNTIME: SK loader failed to reserve EFI runtime VA range.

�BL_LOG_ERROR_TCB_SI_POLICY_CHECK: Failed to validate and measure SI policy.

�BL_LOG_ERROR_TCB_LOAD_TCBLOADER: Failed to load tcbloader.dll.

tBL_LOG_ERROR_TCB_LOAD: Failed to perform load action.

|BL_LOG_ERROR_TCB_RESUME: Failed to perform resume action.

�BL_LOG_ERROR_TCB_INVALID_ATTRIBUTES: Invalid tcblaunch application attributes.

�BL_LOG_ERROR_TCB_REGISTER_EVENT_HANDLER: Failed to register launch notificaiton handler.

�BL_LOG_ERROR_TCB_OPEN_DEVICE: Failed to open application device.

�BL_LOG_ERROR_TCB_GET_DEVICE: Failed to query application device.

�BL_LOG_ERROR_GET_SYSTEM_ROOT: Failed to get SystemRoot value.

�BL_LOG_ERROR_OSL_PROCESS_BOOTSTAT_DATA: Failed to process bootstat data.

�BL_LOG_ERROR_OSL_VIRT_SETUP_0: Failed to perform virtual setup phase 0.

�BL_LOG_ERROR_OSL_VIRT_SETUP_1: Failed to perform virtual setup phase 1.

�BL_LOG_ERROR_OSL_PRELOAD_SI_POLICY: Failed to preload SI policies from OS volume.

�BL_LOG_ERROR_OSL_ARCH_TCB_LAUNCH_1: OslTcbLaunch(1) failed in osloader.

�ERROR_TCB_PLATORM_INIT: Failed to initialize TCB platform.

�BL_LOG_ERROR_OSL_INITIALIZE_FEATURE_CONFIGURATION: OslInitializeFeatureConfiguration failed in osloader.

�BL_LOG_ERROR_RES_OPEN_HIBERFILE: Failed to open the hiberfile.

�BL_LOG_ERROR_RES_INIT_DISPLAY: Failed to initialize display.

�BL_LOG_ERROR_RES_INVALID_PAGEFILE: Page file is invalide for hibernate resume.

�BL_LOG_ERROR_RES_HW_CHANGE: Hardware or firmware settings have changes since hibernate.

|BL_LOG_ERROR_RES_INVALID_HIBERFILE: Hiberfile is invalid.

�BL_LOG_ERROR_RES_GET_CONTEXT_FAILED: Failed to get the resume context.

�BL_LOG_ERROR_RES_INVALID_MEM_MAP: The memory map has changed since associated cold boot.

�BL_LOG_ERROR_RES_FIRMWARE_PHASE_0: Failed phase 0 of firmware setup for resume.

�BL_LOG_ERROR_RES_USB_HANDOFF: Failed setup for legacy usb handoff.

pBL_LOG_ERROR_RES_SMBIOS: Failed to get SMBIOS data.

�BL_LOG_ERROR_RES_TCB_ALLOCATE: Failed to allocate space for TCB resume.

|BL_LOG_ERROR_RES_TCB_PREPARE: Failed to prepare TCB data.

�BL_LOG_ERROR_RES_INIT_PREALLOCATION: Failed to initialize the preallocation.

�BL_LOG_ERROR_RES_INIT_TRANSITION_SPACE: Failed to intialize transition space.

�BL_LOG_ERROR_RES_INIT_PAGE_ALLOCATOR: Failed to initialize the free page allocator.

�BL_LOG_ERROR_RES_RELOC_PROC_CONTEXT: Failed to relocate the processor context page.

�BL_LOG_ERROR_RES_LOAD_SECURE_DATA: Failed to load secure data from the hiberfile.

�BL_LOG_ERROR_RES_RESTORE_IMAGE: Failed to restore image from the hiberfile.

�BL_LOG_ERROR_RES_SECURE_DECRYPT_0: Failed phase 0 of secure data decryption.

�BL_LOG_ERROR_RES_FVE_RESTRICT: Failed to restrict bitlocker to resuming OS.

�BL_LOG_ERROR_RES_TCB_PREP_DATA: Failed to prepare data for TCB resume.

None

@Processor is not supported.

4VMX is not supported.

4SMX is not supported.

pTXT is disabled by the BIOS in MSR_FEATURE_CONTROL.

lRequired GETSEC[CAPABILITIES] are not available.

<TPM 2.0 is not available.

dMemory Attributes Table (MAT) not available.

|No SINIT ACM module type found at the SINIT base address.

dThe ACM UUID does not match well known value.

xThe ACM client/server flags do not match the bios data.

`The ACM debug flag does not match platform.

TThe ACM does not support the chipset.

XThe ACM does not support the processor.

lA more up to date ACM is available on the system.

XNo compatible ACM found on the system.

�The system does not support DMA remapping in the DMAR table.

dTPM does not meet provisioning requirements.

�System does not meet required configuration to validate SMM.

HA VMX failure was encountered.

\Call to retrieve SMM information failed.

TSMM has access to OS memory regions.

TSMM signature is missing or corrupt.

@SMM signature check failed.

�SMM has access to a MSR that is not allowed by policy level.

�SMM has access to an IO port that is not allowed by policy level.

PSMM has access to IOMMU structures.

8ACM layout corruption.

None.

DFailed to reserve scratch VA.

TFailed to get connection parameters.

HDebugging blocked by BitLocker.

dFailed to initialize debug device descriptor.

LFailed to setup debugging device.

TFailed to initialize debug transport.

DFailed to setup debug traps.

\Failed to load debugger transport module.

PFailed to allocate scratch buffer.

lFailed to get debugger transport extension name.

(truncatememory

(avoidlowmemory

 testsigning

,nointegritychecks

Undefined

Available

Applied

Rejected

NotFound

<applied through registry

Xapplied through compatibility database

<applied through registry

Xapplied through compatibility database

PackageId

None

 VBS Enabled

$VSM Required

 Secure Boot

,Iommu Protection

Mmio Nx

4Strong MSR Filtering

Mandatory

Hvci

 Hvci Strict

HBoot Chain Signer Soft Enforced

HBoot Chain Signer Hard Enforced

(Measured Launch

$4VS_VERSION_INFO��
iaJ
iaJ?�StringFileInfo`040904B0LCompanyNameMicrosoft Corporation|*FileDescriptionMicrosoft-Windows-System-Events Resourcesn'FileVersion10.0.19041.5737 (WinBuild.160101.0800)h$InternalNamemicrosoft-windows-system-events.dll�.LegalCopyright� Microsoft Corporation. All rights reserved.x(OriginalFilenamemicrosoft-windows-system-events.dll.muij%ProductNameMicrosoft� Windows� Operating SystemDProductVersion10.0.19041.5737DVarFileInfo$Translation	�PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD