HEX
Server: Apache/2.4.46 (Win64) OpenSSL/1.1.1j PHP/8.4.25
System: Windows NT DESKTOP-4TAV2RJ 10.0 build 19045 (Windows 10) AMD64
User: fred (0)
PHP: 8.4.25
Disabled: NONE
Upload Files
File: C:/Windows/System32/zh-TW/microsoft-windows-system-events.dll.mui
MZ����@���	�!�L�!This program cannot be run in DOS mode.

$5�<�q�R�q�R�q�R�e���p�R�e�P�p�R�Richq�R�PEL�!�

���@ ��8.rdata�@@.rsrc� �@@��F
T88��F$��8.rdata8x.rdata$zzzdbg �.rsrc$01� �a.rsrc$02 4�V�"h���.*f���܏v}����@&��F��(�@�X�p��������� ���!ػ�x��MUI���%O(,0���C�b���PO .�ĀV9m	?����MUIzh-TW�,0T36�	��
X[���  X#RV�#���$���'���+���+���,���,��0<���<L�=���j�oxxPp���p@@�p��$q
xql��r�����	�	���
��|�<�`� �
h�2	2	l�a	d	��r	r	Ԑ

�x���   �st`�||��������0���t���p���Ԗ�		l�8�

0�,�!"��44�(�
<�11��ĝ�
00��11t�22��:$:��PPĦUU�[[�	p
p�ss��zz`������0�������خ��$���h���̯��(�������ܰ��@�����������t��	�$���|� �*����������������4���|���D������
������������@�	�	��������������4�����x�����������T�����|���������@�����!�-�d�1�3�d�9�<���>�>��I�K�0�Q�Q��Y�Y�H����������`�����������������������������������������������8����@��������������������������L#�$��2�3�@2�3�������x���Q�0e����2�����?�
ѰE�ԜJ���hO�ޜ���Ĺ�
����S��uP,n0R CVE: %1%nvQ�Nnj
�: %2%n%nuP,n0R
\�]�w1_ޞ (%1) �v�c,nVf�Bf�g"uudk�N�N0%ndk�N�N/f1uO(u�!j_U�tz�^@b_|v0%n

��S��uP,n0R CVE: %1%nvQ�Nnj
�: %2%n%nuP,n0R
\�]�w1_ޞ (%1) �v�c,nVf�Bf�g"uudk�N�N0%ndk�N�N/f1u8h�_!j_E��Rz_@b_|v0%n

PMicrosoft-Windows-Kernel-AppCompat

4Microsoft-Windows-AIT

TMicrosoft-Windows-Kernel-ApphelpCache

HMicrosoft-Windows-AeSwitchBack

\Microsoft-Windows-AeLookupServiceTrigger

%1

%1

%1

�The executable %2 received an access denied error when trying to modify the registry key %4.

LMicrosoft-Windows-Kernel-Network

 Data sent.

(Data received.

4Connection attempted.

0Disconnect issued.

0Data retransmitted.

4Connection accepted.

4Reconnect attempted.

HTCP connection attempt failed.

XProtocol copied data on behalf of user.

DData sent over UDP protocol.

LData received over UDP protocol.

HUDP connection attempt failed.

lTCPv4: %2 bytes transmitted from %4:%6 to %3:%5.

dTCPv4: %2 bytes received from %4:%6 to %3:%5.

tTCPv4: Connection attempted between %4:%6 and %3:%5.

lTCPv4: Connection closed between %4:%6 and %3:%5.

pTCPv4: %2 bytes retransmitted from %4:%6 to %3:%5.

xTCPv4: Connection established between %4:%6 and %3:%5.

lTCPv4: Reconnect attempt between %4:%6 and %3:%5.

tTCPv4: Connection attempt failed with error code %2.

�TCPv4: %2 bytes copied in protocol on behalf of user for connection between %4:%6 and %3:%5.

lUDPv4: %2 bytes transmitted from %4:%6 to %3:%5.

dUDPv4: %2 bytes received from %4:%6 to %3:%5.

tUDPv4: Connection attempt failed with error code %2.

lTCPv6: %2 bytes transmitted from %4:%6 to %3:%5.

dTCPv6: %2 bytes received from %4:%6 to %3:%5.

tTCPv6: Connection attempted between %4:%6 and %3:%5.

lTCPv6: Connection closed between %4:%6 and %3:%5.

pTCPv6: %2 bytes retransmitted from %4:%6 to %3:%5.

xTCPv6: Connection established between %4:%6 and %3:%5.

lTCPv6: Reconnect attempt between %4:%6 and %3:%5.

�TCPv6: %2 bytes copied in protocol on behalf of user for connection between %4:%6 and %3:%5.

lUDPv6: %2 bytes transmitted from %4:%6 to %3:%5.

dUDPv6: %2 bytes received from %4:%6 to %3:%5.

DMicrosoft-Windows-Kernel-Disk

L%3 bytes read from disk %1 at %5.

P%3 bytes written to disk %1 at %5.

@Buffers flushed to disk %1.

DMicrosoft-Windows-Kernel-Boot

LSystem was booted in %1x%2@%3bpp.

`BootUX screen was displayed in %1x%2@%3bpp.

`Video bit transfer rate is %1 bytes per ms.

�Boot library accessed file %2 on Device %1. Read %3 bytes and wrote %4 bytes.

�File IO for boot application %1: Total Bytes Read = %2, Total Bytes Written = %3.

�Image %1 failed IntegrityCheck reason is %3. Image flags are %2. Error ignored due to debugger %4.

TBootmgr duration is %1 milliseconds.

DImage %1 is not self-signed.

�A device (%1) that was enumerated by the BIOS was inaccessible to the boot environment.

|Variable %1 requires %2 bytes and was set with status %3.

hElement %2 of application %1 was not in policy.

pA Secure Boot Policy update resulted in status %1.

�A Secure Boot Revocation List update resulted in status %1.

lRetrieving the driver list took %1 milliseconds.

\Loading the drivers took %1 milliseconds.

TLoading hive %1 took %2 milliseconds.

XThe time elapsed loading %1 was %2 ms.

\The time elapsed executing %1 was %2 ms.

�Building chunk table for WIM compressed file %2 failed with status: %1

�Soft Restart failed to prepare target Operating System. Operation status: %1 failure point: %2

�Boot application failed to process persistent data with status: %1

DMicrosoft-Windows-Kernel-File

<-��[�c�O� %1 
N�vyr�_Bf|vu/���0/���: %2

�A registration for Provider %1 has joined Provider Group %2

 Enable Info

0Set Provider Traits

0Join Provider Group

TMicrosoft-Windows-Kernel-EventTracing

L�]\O���k "%1" !q�l�[eQ���j "%2"�|vuNR/���: %3

�sSBf�]\O���k "%1" �v�P�c�jHh�]�}T�0R'Y\
NP�0�Vdk�(W�S�_�S(uzz��KNMR��e�N�N\
Ng��0R�P�]\O���k0�.z/���N,�/f(WsSBf!j_N_U�R��d��]\O���k�FO�l	g�NUOsSBfO(u�@b �b0

8�]\O���k "%1" !q�l_U�R�/����YN: %3

<�V�p�NN/�����]\O���k "%1" �]\Pbk: %3

��]�}T�0R�]\O���k "%1" �v�jHh'Y\
NP�0�Vdk��N�N�S��gz�1Y (*g��) 0R�jHh %20�jHh'Y\
NP��vMR-��[b %5 PMOCQD}0

X��d��]\O���k "%2" R�c� "%1" �N�N���jBf|vu/���0/���: %3

�Provider %1 was registered with Event Tracing for Windows.

�Provider %1 was unregistered from Event Tracing for Windows.

<Session "%3" was started.

<Session "%3" was stopped.

tThe configuration of session "%3" has been modified.

hThe events from session "%3" have been flushed.

dProvider %1 has been enabled to session "%2".

lProvider %1 is no longer enabled to session "%2".

@�c�O� %1 �v�[hQ'`-��[�]�_ %2 �O9eb %30

�The security descriptor for session "%3" has been updated.

Provider

Session

Logging

Stop

Start

Disable

Enable

 Unregister

Register

Flush

Configure

$Write Buffer

 File Switch

Provider

Session

|X�u�v�Nܕo��N�N0dk�N�NS+TNP|T�SX�u��Ndk|T�SX�u�HQMR�v�N�N (�N� MatchId �v�Nܕo�) �vܕo�0

 Stack Trace

4User Mode Stack Trace

hMicrosoft-Windows-Kernel-EventTracing/Analytic

`Microsoft-Windows-Kernel-EventTracing/Admin

 Lost Event

 Lost Event

\Logger mode incompatible with Append mode

0OS version mismatch

4Pointer size mismatch

8Unsupported BufferSize

0BufferSize mismatch

lPreallocate mode is incompatible with Append mode

8File size query failed

<Maximum file size reached

LNumber of buffers written is zero

HNumberf of processors mismatch

@2QX[ߎ��_j�OX[�� "%1" Bf|vu/���0/���: %5

 GUID Entry

4Provider Group Entry

LMicrosoft-Windows-Kernel-StoreMgr

dMicrosoft-Windows-Kernel-StoreMgr/Operational

T%5%n%n[��dMO@W: %2%n�[ԚMO@W: %3%n
d�k���z'Y\: %4

0A memory corruption was detected and handled. Memory diagnostics should be run on this machine and, if necessary, memory chips should be replaced.

�A data corruption was detected and handled in a ReadyBoost cache. This corruption was most likely caused by faulty hardware. While ReadyBoost will always detect and handle these errors, seeing a lot of these may mean that the ReadyBoost device has worn out which reduces its performance. You should consider replacing the ReadyBoost cache device.

�ReadyBoost �_�S!q�lc�~�e��_jKN��0��_�S݈n(WvQ�N��f�
N���O9e�b/fdk��f���_j�vQ�N\Omi�|q}��S��1\g|vudkOUL�0

<%1%n%n݈n
T1z: %4%n�_�S_: %6

�A ReadyBoost cache was deleted due to repeated data corruption instances on the associated device that have been detected and handled. While ReadyBoost will always detect and handle these errors, repeated corruption instances may mean that the ReadyBoost device has worn out which reduces its performance. You should consider replacing the ReadyBoost device.

�A ReadyBoost cache was deleted due to repeated I/O failures on the associated device. This typically happens when the device (e.g. an SD card) is removed, but it may also indicate faulty hardware.

hMicrosoft-Windows-LicensingStartServiceTrigger

hMicrosoft-Windows-WSServiceStartServiceTrigger

LMicrosoft-Windows-Kernel-LiveDump

`Microsoft-Windows-Kernel-LiveDump/Analytic

HLive Dump Capture Dump Data API

(Sizing Workflow

8Capture Pages Workflow

XLive Dump Write Deferred Dump Data API

\Live Dump Discard Deferred Dump Data API

PSizing Workflow: Mirroring started.

\Sizing Workflow: Mirroring Phase 0 ended.

\Sizing Workflow: Mirroring Phase 1 ended.

\Sizing Workflow: System Quiesce started.

XSizing Workflow: System Quiesce ended.

`Capture Pages Workflow: Mirroring started.

lCapture Pages Workflow: Mirroring Phase 0 ended.

lCapture Pages Workflow: Mirroring Phase 1 ended.

hCapture Pages Workflow: System Quiesce started.

dCapture Pages Workflow: System Quiesce ended.

pCapture Pages Workflow: Copy memory pages started.

lCapture Pages Workflow: Copy memory pages ended.

\Live Dump Capture Dump Data API started.

tLive Dump Capture Dump Data API ended. NT Status: %1.

@Writing dump file started.

�Writing dump file ended. NT Status: %1. Total %2 bytes (Header|Primary|Secondary: %3|%4|%5 bytes).

API Start

API End

4Dump File Write Start

0Dump File Write End

(Mirroring Start

4Mirroring Phase 0 End

4Mirroring Phase 1 End

4System Quiesce Start

0System Quiesce End

@Copying Memory Pages Start

<Copying Memory Pages End

hLive Dump Write Deferred Dump Data API started.

�Live Dump Write Deferred Dump Data API ended. NT Status: %1.

\Write deferred dump data to file started.

�Write deferred dump data to file ended. NT Status: %1. Total %2 bytes (Header|Primary|Secondary: %3|%4|%5 bytes).

lLive Dump Discard Deferred Dump Data API started.

�Live Dump Discard Deferred Dump Data API ended. NT Status: %1.

�Sizing Workflow: Estimation. NT: %2 bytes (Minimum %1 bytes). Hypervisor: Primary %3 bytes. Secondary %4 bytes.

�Sizing Workflow: Allocation. NT: %1 bytes. Hypervisor: Primary %2 bytes. Secondary %3 bytes.

8Buffer Estimation Data

8Buffer Allocation Data

hSizing Workflow: RemovePages Callbacks started.

dSizing Workflow: RemovePages Callbacks ended.

lSizing Workflow: RemovePages Callback %1 started.

hSizing Workflow: RemovePages Callback %1 ended.

�Sizing Workflow: RemovePages Callback %1 failed. NT Status: %2.

8Remove Pages Callbacks

�Live Dump request aborted due to memory pressure on system

dMicrosoft-Windows-Kernel-LiveDump/Operational

��x�[�]\OAmz'Y\���M�n�v %1 �b���N�S�]M�n�v %2 �b�0P�6R�PpS�jHh'Y\�%30�PpS�jHh'Y\P�6R�%4 MOCQD}0�]T�0R�PpS�jHh'Y\P�6R�%50

|��te�]\OAmz'Y\��0O0NT�%2 MOCQD} (g\<P %1 MOCQD})0Hypervisor�;N�� %3 MOCQD}0!k�� %4 MOCQD}0SecureKernel�%5 CQD}0MemoryEstimationDuration�%6 �k�y0SystemQuiescedDuration�%7 �k�y0EndMirroringPhasesDuration�%8 �k�y0TotalMirrorPhysicalMemoryCallbackDuration�%9 �k�y0TotalMirrorPhysicalMemoryCallbackBytes�%10 MOCQD}0HvlCalculateLiveDumpSizeDuration�%11 �k�y

���te�]\OAmz'Y\�M�n0NT�%1 MOCQD}0Hypervisor�;N�� %2 MOCQD}0!k�� %3 MOCQD}0SecureKernel�%4 MOCQD}0AllocateDumpBuffersDuration�%5 �k�y0 AllocateExtraBuffersDuration�%6 �k�y0 HvlPrepareLivedumpDescriptorDuration�%7 �k�y0 

L.~>e�]\OAmz: �gb� Hvl �PpS'Y\1YWe0NT �rKa: %10

d.~>e�]\OAmz: !q�l��_U VM ��aԚ�x�xRrR0�}]�@SR>mM�n: %10NT �rKa: %2

l.~>e�]\OAmz: VM ��aԚ�x�xRrR�v�}]�@SM�n1YWe0�}]�@SR>mM�n: %10NT �rKa� %2

�Sizing Workflow: Capture processor context when the system is quiesced. Duration: %1ms.

�Sizing Workflow: Mark required dump data when system is quiesced. Duration: %1ms.

�Sizing Workflow: Mark important dump data when system is quiesced. Duration: %1ms.

(Sizing Workflow: Populate bitmap for dump when system is quiesced. PopulateBitmapForDumpDuration: %1ms. RemoveSystemCacheFromDumpDuration %2ms.

�Capture Pages Workflow: Capture processor context when the system is quiesced. Duration: %1ms.

�Capture Pages Workflow: Mark required dump data when system is quiesced. Duration: %1ms.

�Capture Pages Workflow: Mark important dump data when system is quiesced. Duration: %1ms.

8Capture Pages Workflow: Populate bitmap for dump when system is quiesced. PopulateBitmapForDumpDuration: %1ms. RemoveSystemCacheFromDumpDuration %2ms.

�Capture Pages Workflow: Collect Hvl dump when system is quiesced. Duration: %1ms.

�Capture Pages Workflow: Generate Ipt secondary data when system is quiesced. Duration: %1ms.

�Capture Pages Workflow: Initiate state change to copy contents of marked pages when system is quiesced. Duration: %1ms.

<Capture Processor Context

8Mark Required Dump Data

8Mark Important DumpData

<Populate Bitmap For Dump

4Hvl Collect LiveDump

@Generate Ipt Secondary Data

0Dump Data Buffering

tSizing Workflow: Corral processors to quiesce the system. CorralDuration: %1ms. DisableInterruptsDuration: %2ms. SaveSupervisorStateDuration: %3ms. SuspendClockTimerDuration: %4ms.

�Capture Pages Workflow: Corral processors to quiesce the system. CorralDuration: %1ms. DisableInterruptsDuration: %2ms. SaveSupervisorStateDuration: %3ms. SuspendClockTimerDuration: %4ms.

|Sizing Workflow: Uncorral processors to quiesce the system. UncorralDuration: %1ms. EnableInterruptsDuration: %2ms. RestoreSupervisorStateDuration: %3ms. ResumeClockTimerDuration: %4ms.

�Capture Pages Workflow: Uncorral processors to quiesce the system. UncorralDuration: %1ms. EnableInterruptsDuration: %2ms. RestoreSupervisorStateDuration: %3ms. ResumeClockTimerDuration: %4ms.

0�d�SR��]\OAmz: �d�S��aԚR�0MemoryCaptureDuration: %1 �k�y0SystemQuiescedDuration: %2 �k�y0EndMirroringPhasesDuration: %3 �k�y0TotalMirrorPhysicalMemoryCallbackDuration: %4 �k�y0TotalMirrorPhysicalMemoryCallbackBytes: %5 PMOCQD}0HvlCollectLivedumpDuration: %6 �k�y0DumpDataBufferingDuration: %7 �k�y0

,Corral Processors

0Uncorral Processors

4Capture Memory Pages

���te'Y\�]\OAmz: MmDuplicateMemory 1YWe0NT �rKa: %10MirrorInProgress: %20

��d�SR��]\OAmz: MmDuplicateMemory 1YWe0NT �rKa: %10MirrorInProgress: %20

<MmDuplicateMemory Failure

�Windows �]���YU�t�x�x@S�c�c��Bl0%n%n           �x�x@S GUID: %1%n           �x�x@S
T1z: %3%n

��]b�R0W�c�c�x�x@S0%n%n           �x�x@S GUID: %1%n           �x�x@S
T1z: %3%n

�Windows !q�l�c�c�x�x@S0%n%n           �rKa: %4%n           �x�x@S GUID: %1%n           �x�x@S
T1z: %3%n

@Microsoft-Windows-Kernel-IO

XMicrosoft-Windows-Kernel-IO/Operational

pWindows �]-��[�p\��
�Hr�jHh�|q}�{x�hV0%n%n           �{x�hV
T1z: %2%n

�
�Hr�jHh�|q}�{x�hV!q�lD��R0RMOCQD}�S�[@W�x�x@S0%n%n           �{x�hV
T1z: %2%n           �x�x@S
T1z: %4%n

�_jhV
N�]\P(u�PpS��V�p_U(u�PpS�R�[Bf|vu/���: %10

                %n�Y�	gܕ�PpS�R�[�vs�0}nj
��ˊ�S�� http://go.microsoft.com/fwlink/?LinkId=824149


@An internal error occurred

\Public Key or Thumbprint registry missing

0Invalid Public Key

@Unsupported Public Key Size

\Microsoft-Windows-Kernel-Audit-API-Calls

@Microsoft-Windows-Audit-CVE

LMicrosoft-Windows-User-Diagnostic

HMicrosoft-Windows-Heap-Snapshot

TMicrosoft-Windows-Threat-Intelligence

�Microsoft-Windows-Security-LessPrivilegedAppContainer/Operational

tMicrosoft-Windows-Security-LessPrivilegedAppContainer

h�]�bU}MO�e %1 �v�\yr�k
kP�KN�a(uz_�[hV
\nj�n�vX[�S (StackHash: %2)0

XMicrosoft-Windows-Security-Mitigations

8h�_!j_

O(u�!j_

L,g�O�ar��]�ybkU�t�^ '%2' (PID %5) "uu�RKaz_�x0

D�]�ybkU�t�^ '%2' (PID %5) "uu�RKaz_�x0

p,g�O�ar��]O(u}T�NR '%16' �ybkU�t�^ '%2' (PID %5) �^�zP[U�t�^ '%14'0

h�]O(u}T�NR '%16' �ybkU�t�^ '%2' (PID %5) �^�zP[U�t�^ '%14'0

`,g�O�ar��]�ybkU�t�^ '%2' (PID %5) 	�eQNO�[te'`�N2�MO�j '%14'0

X�]�ybkU�t�^ '%2' (PID %5) 	�eQNO�[te'`�N2�MO�j '%14'0

T,g�O�ar��]�ybkU�t�^ '%2' (PID %5) �_`��zqQ(u	�eQ�N2�MO�j0

L�]�ybkU�t�^ '%2' (PID %5) �_`��zqQ(u	�eQ�N2�MO�j0

d,g�O�ar��]�ybkU�t�^ '%2' (PID %5) 
\ Win32k.sys 2�L��|q}|T�S0

\�]�ybkU�t�^ '%2' (PID %5) 
\ Win32k.sys 2�L��|q}|T�S0

t,g�O�ar��]�ybkU�t�^ '%2' (PID %5) 	�eQ^� Microsoft =|r�v�N2�MO�j '%16'0

l�]�ybkU�t�^ '%2' (PID %5) 	�eQ^� Microsoft =|r�v�N2�MO�j '%16'0

`,g�O�ar��]�ybkU�t�^ '%2' (PID %3) X[�S!jD} '%8' �v/S�QMO@Wh�<h0

X�]�ybkU�t�^ '%2' (PID %3) X[�S!jD} '%8' �v/S�QMO@Wh�<h0

h,g�O�ar��]�ybkU�t�^ '%2' (PID %3) X[�S API '%10' �v/SeQMO@Wh�<h0

`�]�ybkU�t�^ '%2' (PID %3) X[�S API '%10' �v/SeQMO@Wh�<h0

�,g�O�ar��]�ybkU�t�^ '%2' (PID %3) |T�S API '%4'��V�p	gԏ�V\Tz_-�� (ROP) �v�`a�c"}�a�0

��]�ybkU�t�^ '%2' (PID %3) |T�S API '%4'��V�p	gԏ�V\Tz_-�� (ROP) �v�`a�c"}�a�0

�U�tz�^ ' %2 ' (PID %5) G�0Rp�q_X�u�P�VMO@W
N�v&{�v�`�l0�|q}\AQ1�U�tz�^|~�~�WL�0 %n%n�_!jD} ' %12 ' �P�V�WL��vc�N0%nVf�ԏ�V!jD} ' %14 '0 

�U�tz�^ ' %2 ' (PID %5) G�0Rp�q_X�u�P�VMO@W
N�v&{�v�`�l0\B}bkU�tz�^0 %n%n�_!jD} ' %12 ' �P�V�WL��vc�N0%nVf�ԏ�V!jD} ' %14 '0

�(W_U(uO(u�!j_p�q_X�uBf��S���]�ybkU�tz�^ ' %2 ' (PID %5) -��[gQ�[��V�p|vuc�NcjW�I�1YWe0

|(W_U(uO(u�!j_p�q_X�u�v�r�lN��]�ybkU�tz�^ '%2' (PID %5) -��[gQ�[��V�p|vuc�NcjW�I�1YWe0

�U�tz�^ ' %2 ' (PID %5) G�0Rp�q_X�u�P�VMO@W
N�v&{�v�`�l0�|q}\AQ1�U�tz�^|~�~�WL�0%nU�tz�^p�q_X�u�V<h!j_: %15%n%n�_!jD} '%12' �P�V�WL��vc�N0%nVf�ԏ�V!jD} '%14'0

�U�tz�^ ' %2 ' (PID %5) G�0Rp�q_X�u�P�VMO@W
N�v&{�v�`�l0\B}bkU�tz�^0 %nU�tz�^p�q_X�u�V<h!j_: %15%n%n�_!jD} ' %12 ' �P�V�WL��vc�N0%nVf�ԏ�V!jD} ' %14 '0

41u�e�N2�MO�p�q_X�u
N�v�[N/b:\�OY�r�lU�t�c�~nj�e��VdkU�tz�^ '%2' (PID %5) �]���ybk	�eQq_�P�N2�MO0%n U�tz�^��Bl�N2�MO_N�_�S+T�OY�r�lU�t�c�~nj�e: %15%n%n�N2�MO_: %12%n�N2�MO�p�q_X�u�v�[: %13%n�N2�MOS+T�OY�r�lU�t�c�~nj�e: %14%n

41u�e�N2�MO�p�q_X�u
N�v�[N/b:\�OY�r�lU�t�c�~nj�e��VdkU�tz�^ '%2' (PID %5) ���ybk	�eQq_�P�N2�MO0%n U�tz�^��Bl�N2�MO_N�_�S+T�OY�r�lU�t�c�~nj�e: %15%n%n�N2�MO_: %12%n�N2�MO�p�q_X�u�v�[: %13%n�N2�MOS+T�OY�r�lU�t�c�~nj�e: %14%n

�U�t8^_ '%2' (PID %5) �S���]���ybk��d�*g�S�O�N�v͑�e\T: %n%n�N2�MO_: %2%n_xe: %4%n͑�e\T^��W: %11%n�d\O_: %13%n!j�d: %14%n

�U�t8^_ '%2' (PID %5) �]���ybk��d�*g�S�O�N�v͑�e\T: %n%n�N2�MO_: %2%n_xe: %4%n͑�e\T^��W: %11%n�d\O_: %13%n!j�d: %14%n

�U�tz�^ '%2' (PID %5) �S��g�V�pO(u�!j_p�q_X�u�]_U(u�!q�l-��[gQ�[0%nU�tz�^ƖgQ�[W�I��V<h!j_: %13%n-��[gQ�[^��W: %14%n%n-��[gQ�[�vj!jD} '%12'0

�(W_U(uO(u�!j_p�q_X�uBf�1u�ec�NcjW�I�1YWe��Vdk�]�ybkU�tz�^ '%2' (PID %5) -��[gQ�[0 %nU�tz�^ƖgQ�[W�I��V<h!j_: %13%n-��[gQ�[^��W: %14%n%n-��[gQ�[�vj!jD} '%12'0

<Exception handling unwind

`Context resumption without unwind semantics

(Longjump unwind

0Set thread context

@Unknown redirection type%n

0NTFS mount point%n

(NTFS symlink%n

d�]�ybk2�z '%2' (PID %5) 2�L� NtFsControlFile �|q}|T�S0

d�]�ybk2�z '%2' (PID %5) 2�L� NtFsControlFile �|q}|T�S0

lMicrosoft-Windows-Security-Adminless/Operational

TMicrosoft-Windows-Security-Adminless

h�Y�g(W %1 �c!q�|q}�{t�TP�6R�O�WL��GRX[�Snj�n\g���bU} (StackHash: %2)0

H{Remote Registy Service} Access Denied to key: %2 under parent key: %4 as the parent is mentioned under AllowedExactPaths and hence subkey cannot be accessed.

t�|q}Bf���]���f�]�_ %2 �p%10%n%n ���f�S�V�%30%n U�tz�^�'%4' (PID %5)0

$uP,n0R�c
k�SGR�_�S
d�k0

$�]�O�_�c
k�SGR�_�S
d�k0

<�c
k�SGR�_�S�]0Rg��V�p�[�l	g(W�g�vg��gQ�f�e0

d{{v�@S�]�O�_} {v�@S (�jHh): '%3' �S�]
d�k��s�]�O�_0�g�Nnj�e�S���]z�1Y0

\1u{v�@bw��Y�v I/O �d\O!q�l���S0{v�!q�l�cn{v�@S (�jHh): '%3'0

t{v�@S %2 (TM: %3�RM: %4) �v TxR R�YS���k�]�[b�P}�g=%5 (gQ萼x=%6)0

0\Omi�|q}�]�}(W�|q}Bf�� %7 _U�R0

0\Omi�|q}�]�}(W�|q}Bf�� %1 ܕ��0

\{v�@S %2 �]͑�eD}T~�p���Y'Y\�p %3 PMOCQD}NP}_g'Y\�p %4 PMOCQD}0

d�]nd�{v�@S %2 -N�vX[�Swkz����f�e�N %3 P_j�x&N�^�z�N %4 P�O9e�v�b�0

$\Omi�|q}ck�eߎ��_j�__U�R0

d���yM�n�]�f�e%n�Sxe�%1%n�]_U(u���y�%2%n�e���y�xe�%3%n
����y�xe�%4

0!q�l�_;��Qh��f�e���yxe�d��S�V�%1

,Bf@SOP�]�]�_ %1 ���f� %20

H�V�p��Q�S�V %1��]͑�etetBf@Snj
�0�vMRBf@SOP�]�p %20

@%3 Vf�	�eQ�v�O'` %2 Bf�P�V/����rKa�x %10

�
NAQ1��_�vMR�v�v�	�eQ�v�O'` %2 (�dk�R\O/f1u %1 Vf�)0|v�s�SNP DLL: %30�Y�s�0}nj
��ˊ�S�� http://go.microsoft.com/fwlink/?LinkId=7181360

�
NAQ1��_�vMR�v�v�	�eQ�v�O'` %2 (�dk�R\O/f1u %1 Vf�)0~b
N0R�NUOvQ�N DLL�N�v�O'`㉐g1YWe0�Y�s�0}nj
��ˊ�S�� http://go.microsoft.com/fwlink/?LinkId=7181360

4
\ %1 �vX[�S/f1u�SGR��GR %2 �v��0

L�|q}�{t�T�Ogq�-��vߎԚP�6R�SGRd\}��]�}P�6R�N
\ %1 �vX[�S0

`�|q}�{t�T�Ogq>en�e_ %3 �v�SGR��GR %2 �vMOn��]�}P�6R�N
\ %1 �vX[�S0

D�|q}�{t�T�OgqߎԚ|vL���SGR��]�}P�6R�N
\ %1 �vX[�S0

D�|q}�{t�T�Ogq�SGR��GR %2��]�}P�6R�N
\ %1 �vX[�S0

D�|q}�{t�T�Ogq�SGR��GR %2��]�}P�6R�N
\ %1 �vX[�S0

`�|q}̗Ԛ�]M�nHQMR��$R�[�p
N�S`��v��aԚ@S�W0�#j�S��g �b�|q}
Niz�[�T/bnj�e
d�k0

<Windows !q�l�_O wb`�_�/����rKa�p %10

4�]o�:y��_j�{tz_Y͑ OS x��dkub�0

(dk�|q}
N	g %1 P��_jx��0

,dk�|q}
N	g %1 P��_j�]wQx��0

D
N!kܕ_j�vb�R�rKa�p %10
N!k��_j�vb�R�rKa�p %20

L�]o�:y OS 	�eQhV2���x���R��h���NO(u��]x��Sx�� %10

0�]o�:y OS 	�eQhV�}/�x���R��h�0

0��_jg��	cN�N Windows u�0

$��_jg��	cN�N F8 u�0

$��_j�R��h��SGR�p %10

,dk��_jg��O(u�NN!k'`��_j��^0

��_j^��W�p %10

@Windows !q�l�WL��_�_U�R�/����rKa�p %10

$̗Ԛ�]�V1X��_ja�ϑj�n0

@bootmgr ���N %1 �k�y�vBf��I{PO(u�8�eQ0

(ߎ͑�e��_j�]���Y�S�m: %1

(ߎ͑�e��_j�]�[b�S�m: %10

H[��dS�W�[hQ'`_U(u�SGR�j�g�e���k %1 1YWe��rKa�p: %2

8[��dS�W�[hQ'` (�SGR: %3) /f %20

D[��dS�W�[hQ'` (�SGR: %3) /f %2��rKa�p: %1

<ߎ͑�e��_j�]���Y�n�P (�[te�v��Blxe: %1)0

(ߎ͑�e��_j�]�[b�n�P %10

$ߎ͑�e��_j�]���Y�[te�n�P0

,ߎ͑�e��_j�]�[b�[te�n�P: %10

H
\ %1 �vߎ͑�e��_j|T�S1YWe: %2 (�j�gޞ: %3)0

8�|q}E��Rz_����f�eMb��/e�c VBS _U�R0

,SMM -��[W�I�1YWe0�S�V�%1

4EFI Bf@SOP�]: %10�eIQ�ej: %2

dBootmgr �[hQ'`Hr,g_��x�j�g1YWe0Svn <P� %1�HQMR�v SVN <P� %2.

��a(uz_ %1 �]B}bk�/����p %2��S�V/f Windows �N2�MO�jHh %3 |vuOUL�0��S��/f�V�pr��N2�MO�jHh*g�}=|r0S+T
N�S�O�N�v=|�z0�]
d�kb�]m��z9e0ˊ͑�etet�`�v��f��N�OckdkOUL�0

,Structured State

0Unstructured Reset

$Out Of Memory

$Apiset Error

WinRT

@Low-level Data Store Error

<!q�l	�eQWY�N %1 �v�a(uz_-��[0/����x: %2

<!q�l���SWY�N %1 �v�a(uz_-��[0/����x: %2

<!q�l�[eQWY�N %1 �v�a(uz_-��[0/����x: %2

H!q�lݑ
\WY�N %2 \2QX[nj�e>Y %1 wQ�sS�/����x: %3

D�]��|v�O�_��V�pWY�N %2 �v\Omi %1 |vu/��� %30

T�pWY�N %2 �v\Omi %1 �WL��O�_Bf|vu/��� %3��P�V/����x: %4

@nj�e>Y_ %1 !q�l�N�X[�S�j�g: /����x: %2

L�]��|v�O�_�rKaMOn��V�pWY�N %2 �v\Omi %1 |vu/��� %30

X
\WY�N %2 �v\Omi %1 2�L��rKaMOn�O�_Bf�P�V/��� %30/����x: %4

8Verbose context events

8Scenario trigger events

SQM

Time

(Deprecated dlls

DFatal user callback exception

4A dll failed to load.

<Launch 16bit application

DWindows component on demand.

TThe Loader encountered a fatal error.

�V�aBf��

<Deprecated COM interfaces

Process

$AppContainer

0DesktopAppXProcess

4DesktopAppXContainer

�Scenario start enables context providers to the WDI context logger.

�Scenario end disables context providers to the WDI context logger.

�When a scenario has remained in-flight beyond the maximum time window it is automatically terminated by the SEM.

`A scenario start attempt failed in the SEM.

\A scenario end attempt failed in the SEM.

�The SEM received a request to start a new scenario, but the maximum number of scenarios were already in-flight.

�There is an invalid configuration parameter in the SEM registry namespace.

�The SEM is configured with more scenarios than the maximum allowed count.

�The SEM is configured with a scenario with too many context providers.

�The SEM is configured with a scenario that has too many end events.

�The number of providers specified across all scenarios is above the maximum allowed amount.

nj
�

���Y

\Pbk

Start

<Invoke callback function

0Disable live cache

HUpdate resource cache manifest

4Build resource cache

Start

End

/���

f�JT

nj
�

͑'Y

s�0}nj
�

8SEM Scenario Lifecycle

0SEM Initialization

�This group of events tracks the performance of mounting hives from existing files.

�This group of events tracks the performance of unloading hives.

�This group of events tracks the performance of flushing hives.

�This group of events tracks the performance of registry shutdown.

�This group of events tracks the performance of loading hives.

�This group of events tracks the performance of restoring hives.

�This group of events tracks the performance of exporting hives.

HMUI NotifyUILanguageChange task

@MUI resource cache builder

DMicrosoft-Windows-Kernel-WDI

TMicrosoft-Windows-Kernel-WDI/Analytic

PMicrosoft-Windows-Kernel-WDI/Debug

\Microsoft-Windows-Kernel-WDI/Operational

LMicrosoft-Windows-AppModel-State

XMicrosoft-Windows-AppModel-State/Debug

`Microsoft-Windows-AppModel-State/Diagnostic

LMicrosoft-Windows-Kernel-General

�|q}

LMicrosoft-Windows-Kernel-Process

LMicrosoft-Windows-Kernel-Registry

DMicrosoft-Windows-Kernel-Acpi

DMicrosoft-Windows-User-Loader

 Application

\Microsoft-Windows-Kernel-BootDiagnostics

4Microsoft-Windows-UAC

LMicrosoft-Windows-UAC/Operational

4Microsoft-Windows-COM

dMicrosoft-Windows-SoftwareRestrictionPolicies

4Microsoft-Windows-MUI

LMicrosoft-Windows-MUI/Operational

@Microsoft-Windows-MUI/Admin

HMicrosoft-Windows-MUI/Analytic

@Microsoft-Windows-MUI/Debug

4Microsoft-Windows-PCI

PMicrosoft-Windows-Kernel-ShimEngine

hMicrosoft-Windows-Kernel-ShimEngine/Operational

PMicrosoft-Windows-AppModel-Runtime

`Microsoft-Windows-AppModel-Runtime/Analytic

dError while deleting file: %1. Error Code: %2

pError while deleting directory: %1. Error Code: %2

DError while allocating memory

lApiSet Function: %1 returned with Error Code: %2

�Low-level data store access error. Function: %1 returned with Error Code: %2

�Cleanup of temporary state has been skipped due to low disk usage.

\Cleanup of temporary state has completed.

�Cleanup of temporary state was unable to enumerate the user profiles.  Object: %1, Error Code: %2.

tCleanup of temporary state has aborted unexpectedly.

�Need to update state locations of package %1 for user %2 because the schema is not found. Error Code: %3

�Need to update state locations of package %1 for user %2 because the package is not found. Error Code: %3

�Need to update state locations of package %1 for user %2 because the package full name has changed. Error Code: %3

�Need to update state locations of package %1 for user %2 because the schema version has changed. Error Code: %3

lSucceeded to fix state locations for package %1.

�Failure to fix state locations for package %1. Error Code: %2

4The Scenario Event Mapper started a scenario for provider %1 (event ID %2) with %4 context providers.  The context logger dropped event count was %3.

4The Scenario Event Mapper stopped a scenario for provider %1 (event ID %2) with %4 context providers.  The context logger dropped event count was %3.

An in-flight scenario from provider %1 (event ID %2) timed out and was stopped automatically by the Scenario Event Mapper.

<The Scenario Event Mapper was unable to start a new scenario for provider %1 (event ID %2) because the maximum number of scenarios are already in flight.

�The Scenario Event Mapper was unable to start a scenario for provider %1 (event ID %2).  The error code was %3.

�The Scenario Event Mapper was unable to stop a scenario for provider %1 (event ID %2).  The error code was %3.

h�r�l�N�N
\�az_@b-��[�v�r�lxe�v��N�
NP�0\�_eu�c�O� %1 (�N�NX�%R�x %2) �v�r�l0

x�r�l�N�N
\�az_�pwQ	g�c�O� %1 (�N�NX�%R�x %2) �v�r�l@b-��[�vgQ�[�c�O�xe�v��N�
NP�0\�_eur��r�l0

x�r�l�N�N
\�az_�pwQ	g�c�O� %1 (�N�NX�%R�x %2) �v�r�l@b-��[�vP}_g�N�Nxe�v��N�
NP�0\�_eur��r�l0

L�r�l�N�N
\�az_@b-��[�v�c�O�xe�v��N�
NP�0\�_eu�c�O� %10

x�r�l�N�N
\�az_@b-��[�v�r�l
N�S/e�c0�c�O� %1 (�N�NX�%R�x %2) �v�r�l|vu/����x %3�\���_eu0

,�|q}Bf���]�_ %2 ���f�p %10

H�|q}Bf���]�_ %2 ���f�p %10%n%n ���f�S�V�%30

�Process %1 started at time %2 by parent %3 running in session %4 with name %5.

�Process %1 (which started at time %3) stopped at time %4 with exit code %5.

PThread %2 (in Process %1) started.

PThread %2 (in Process %1) stopped.

dProcess %3 had an image loaded with name %7.

hProcess %3 had an image unloaded with name %7.

�Base CPU priority of thread %2 in process %1 was changed from %3 to %4.

�CPU priority of thread %2 in process %1 was changed from %3 to %4.

�Page priority of thread %2 in process %1 was changed from %3 to %4.

�I/O priority of thread %2 in process %1 was changed from %3 to %4.

hExecution of the process %1 has been suspended.

dExecution of the process %1 has been resumed.

PJob %1 started with status code %2.

XJob %1 terminated with status code %2.

�Enumerated process %1 had started at time %2 by parent %3 running in session %4 with name %6.

�Process %1 started at time %2 by parent %3 running in session %4 with name %6.

�Process %1 (which started at time %2) stopped at time %3 with exit code %4.

�Enumerated process %1 had started at time %3 by parent %4 running in session %6 with name %11.

�Process %1 started at time %2 by parent %3 running in session %4 with name %6.

�Process %1 started at time %3 by parent %4 running in session %6 with name %11.

xA memory range descriptor has been marked as reserved.

�Unexpected GPE event was fired on GPE bits that should be disabled.

�A temperature change notification (Notify(thermal_zone, 0x80)) for ACPI thermal zone %2 has been received.             %n_TMP = %3K             %n_PSV = %4K             %n_AC0 = %5K             %n_AC1 = %6K             %n_AC2 = %7K             %n_AC3 = %8K             %n_AC4 = %9K             %n_AC5 = %10K             %n_AC6 = %11K             %n_AC7 = %12K             %n_AC8 = %13K             %n_AC9 = %14K             %n_HOT = %15K             %n_CRT = %16K

�A trip point change notification (Notify(thermal_zone, 0x81)) for ACPI thermal zone %2 has been received.             %n_TMP = %3K             %n_PSV = %4K             %n_AC0 = %5K             %n_AC1 = %6K             %n_AC2 = %7K             %n_AC3 = %8K             %n_AC4 = %9K             %n_AC5 = %10K             %n_AC6 = %11K             %n_AC7 = %12K             %n_AC8 = %13K             %n_AC9 = %14K             %n_HOT = %15K             %n_CRT = %16K

lThe active cooling device %6 has been turned %8.             %nThermal zone device instance: %2             %nActive cooling package: _AC%3             %nNamespace object: _AL%4

lThe active cooling device %6 has been turned %7.             %nThermal zone device instance: %2             %nActive cooling package: _AC%3             %nNamespace object: _AL%4

LACPI method %2 evaluation has %3.

lThe active cooling device %2 has been turned %3.

�The passive cooling device %2 throttle has changed to %3 percent.

�The device %2 has the following cooling state.             %nActive cooling: %3             %nPassive cooling: %4 percent

`ACPI device %2 is undergoing %3. Status %4.

<ACPI device OverRide - %1

�Error occured while interpreting AML code: scope %1, object %2. Status %3.

TACPI method %2 has high frequency %3.

4Deprecated module %1.

xProcess %2 encountered a fatal user callback exception.

XThe process launches a 16 bit process.

HWindows component on demand %1.

�The Loader encountered a fatal error while loading a thread from process image name %1.

lA fatal error occured during initalization of %1.

�The Loader encountered a fatal error running process image name %1.

dU�tz�^(W�^�zP[U�tz�^Bf�!q�lU�t ERROR_ELEVATION_REQUIRED0

<Deprecated COM CLSID %1.

<MUI ��w�d\O1YWe��rKa�x�p %10*g�S(u�V|T0

x�jHh %1 �v MUI �V|T1YWe��V�p!q�l	�eQ�[0傁��Ockdk/����ˊ�f�cdk�jHhb�O�_ Windows �[݈0

�;��Q�p^��W %2 KN�jHh %1 �v MUI �V|T1YWe��V�p DLL -N�l	g %3 �Q_0傁��Ockdk/����ˊ�f�cdk�jHhb�O�_{v���v0

��jHh %1 �v MUI �V|T1YWe��V�pr��jHh&N^�1u Microsoft =|r0傁��Ockdk/����ˊ\r��jHh�f�cbdk Windows �[݈��D��v�S�Y�j0

`~b
N0R MUI �V|T�jHh %10傁��Ockdk/����ˊ�O�_{v�b\r��jHh���0Rc�[�vMOn0

<!q�l\P(u Wow ͑�e\T0\
Ng�^n�enj�n�_�S0

@!q�l(W�S�[eQ!j_N��_Unj�n�_�S0\
Ng�^n�enj�n�_�S0

 !q�l\P(usSBfnj�n�_�S0

H!q�l�_ MUI API �b�S���-��[0\
Ng�^n�enj�n�_�S0

�!q�lVR�g�S�_�S�v�jHhn�Ub�[eQnj�n�_�Snj
�n�U0��N}T�NR�Sxe�e_c�[-��[�j�ˊ�x��r��jHhX[(W�N<h_ck�x0\
Ng�^n�enj�n�_�S0

L
\nj�n�_�Snj
�n�U@bZP�v���f!q�l�[eQ�x�x0\
Ng�^n�enj�n�_�S0

81u�e|vugQ�/����!q�l�^n�enj�n�_�S: %10

,!q�l(W�|q}
N�[݈�e�^n�vnj�n�_�S0

<!q�l�^�znj�n�_�Snj
�n�U0\
Ng�^n�enj�n�_�S0

��]�S(u UI ������f�v MUI ��w�N�ej-��p %1��e���-��p %2��
����GR-��p %30�^8O�ej�]-��p %4

T%1 -N�v MUI ��w�V|T API %2 �]�P�V�WL�P}�g��N�x�p %30

@�]O(u�NN�Sxe|T�S MUI nj�n�_�S�^�zhV: %10

�MUI resource cache manifest entry for file %1 has been updated. Affinity: '%2', Sequence: %3, and Priority: %4

Start: %1

End: %1

x�]�^n�enj�n�_�S&N�[݈(W�|q}
N0�e�_�S"}_�p %1�sSBf�_�S"}_�p %2 � config �]-��[�p %30

�Resource file %1 will not be cached since it is not used frequently in the system.

\�|q}�v RAM0=~�x�xzz��b�S(u�x�xzz��	gP��@b�N\
Ng�}w� MUI nj�n�_�S0

�Unable to parse configuration parameters. The configuration parameters will be ignored.

�The time elapsed before Bootmgr, based on the TSC, is %1 ms.

�Initialization of the firmware crypto hash provider resulted in status %1.

�The firmware update capsule (%1) failed to load with status %2.

�The PE/COFF image firmware update capsule (%1) failed to load with status %2.

�The Efi UpdateCapsule failed to apply updates with status %1.

�Firmware update supported status is %3. The BitLocker device flags are %1 and the PCR bitmap is %2.

�The firmware update capsule (%1) code integrity check failed with status %2.

HWindows !q�l	�eQ�_���v�|q}�j %1�/����rKa�p %20

HWindows !q�l	�eQ�|q}{v��j %1�/����rKa�p %20

DWindows !q�lR�YS ACPI�/����rKa�p %10

8Windows !q�l	�eQ�/����rKa�p %10

PWindows !q�l	�eQ�_ %1 /SeQ�v f�P %2�/����rKa�p %30

LWindows !q�l�_ f�P %1 /SeQ %2�/����rKa�p %30

�Windows !q�lHO�^ VSM X�%Rёp�0�d��[\�_�S�v�,g�rKa: %10�e�vёp�"uu�rKa: %20,nϑ PCR �rKa: %30�[\��_�S�rKa: %40

�VSM X�%Rёp�HO�^0�d��[\�_�S�v�,g�rKa: %10�e�vёp�"uu�rKa: %20,nϑ PCR �rKa: %30�[\��_�S�rKa: %40

\Windows �|q}�[te'`�SGR
NAQ1�	�eQ����v�|q}�jHh %1�/����rKa�p %20

�Windows !q�lHO�^ VSM ;N���R�[ёp�0O(u�]�_�S�v�,g�rKa: %10��[�]�_�S�v�,g�rKa: %20�e�vёp�"uu�rKa: %30�R�[�rKa: %40TPM PCR n�i: %501u�Ow�݈nTS�R�v��[�rKa: %601u�Ow�݈nTS�R�v͑�e�R�[�rKa: %70�Ow�݈n�f�e�rKa: %80TPM �xehVW�I��rKa: %90TPM �xehV�^�z�rKa: %100O(u�P�N\݈ blob: %110

lVSM ;N���R�[ёp�HO�^0O(u�]�_�S�v�,g�rKa: %10��[�]�_�S�v�,g�rKa: %20�e�vёp�"uu�rKa: %30�R�[�rKa: %40TPM PCR n�i: %501u�Ow�݈nTS�R�v��[�rKa: %601u�Ow�݈nTS�R�v��[�rKa: %70�Ow�݈n�f�e�rKa: %80TPM �xehVW�I��rKa: %90TPM �xehV�^�z�rKa: %100O(u�P�N\݈ blob: %110

LWindows !q�lHO�^ TPM 2QX[9hёp��/����rKa�p: %10

\Windows �]�)RHO�^ TPM 2QX[9hёp�0dk\Omi���N %1 �k�y�vBf���[b0

LWindows !q�lHO�^ TPM k~P}nj
��/����rKa�p: %10

8NFIT ACPI h�<h<h_
Nck�x�!q�lVR�g0

PVf��WL�0,nϑ_U�R�t�X
0BfuP,n0RHQMR�v/���0TXT /����x: %10

8̗Ԛ�c�O�v SINIT ACM *gO(u0%1

�Windows !q�lHO�^ DRTM �}�[�v VSM ;N���R�[ёp�0O(u�}X[oR,g�rKa�%10�e�vёp�ub�rKa�%20�[\�rKa�%30�c�Of}�[hQ8h�_�rKa�v UEFI ёp��%40

�Windows b�RHO�^ DRTM �}�[�v VSM ;N���R�[ёp�0O(u�}X[oR,g�rKa�%10�e�vёp�ub�rKa�%20�[\�rKa�%30�c�Of}�[hQ8h�_�rKa�v UEFI ёp��%40

pWindows �]euN�HO�^ TPM 2QX[9hёp���V�p NoAutoProvision {veQ<P�]-��[0

��^�z\݈�v�R�[ёp��rKa%n%n�rKa: %1%nPcrMask: %2%nUnsealPolicyPdGuid: %3%nSealingProtectorFixedBufferSize: %4%nSealingProtectorUsedBufferSize: %5%nSealedSecretBufferSize: %6%nPcrInfoArrayElCount: %7%n%n��[�SGR%n%nHr,g: %8%nVarDataOffset: %9%nStructureSize: %10%nPolicyVersion: %11%nPolicyHashLength: %12%nWinloadSVN: %13%nWinresumeSVN: %14%nBootmgrSVN: %15%nLKeyPkgId: %16%n

Hߎ��_j!q�l�[b��rKa�p: %1��V�p %2 P�_U�t*g��BlM�n

<ߎ��_j!q�l���S��aԚ�x�xRrR %1��rKa�p: %2

D0ߎ��_j
0!q�lO(u0ߎ��_j
0�^8O!jD}�O;��Q0Hr,g
N�v�[0

<ߎ��_j!q�lO(u�[hQ	�eQ�O�^�z#��}��rKa�p: %1

<0��_j�SGR�yI�
0�]O(u�]W�I��v��xe0�rKa: %1

<0��_j�SGR�yI�
0�]O(u*gW�I��v��xe0�rKa: %1

$nj
�: %1 �rKa: %2

$/���: %1 �rKa: %2

<ߎ��_jE��Rz_!q�l\ꁫ�;��Q�p�rKa�%1

 �v�{x�hV�A command was submitted to the TPM.%nCommand code: %1.%nResponse code: %2.%nElapsed time: %3ms.

�A command could not be submitted to the TPM.%nCommand code: %1.%nError code: %2.%nElapsed time: %3ms.

�The TPM was found not to be useable for BitLocker. Flags: %1.

�Measured Boot library was initialized. Phase: %1, StatusCode: %2.

�,nϑ��_jz_�^|vu1YWe�N2�eQ
N�[hQ�rKa0InitState: %1�StatusCode: %2�1YWeMO@W: %3��SgqMO@W: %4��S�V: %50

�DRTM �[hQ'`Hr,g_��x�j�g1YWe0SvnCounterId: %1�StatusCode: %2�Svn <P: %3�
NNP SVN <P: %40

@Intel TXT SENTER Bf��: %1 �k�y0

`File modification detected after load: %1.

hRegistry modification detected after load: %1.

LIntel TXT �n�P�[b0ACM �eg: %2/%1/%30

0�|q}2�w��]_U(u�FO
N/e�c0�S�V: %1

8VBS �]-��[�p
NAQ1� trustlets0

,��_j�R��h��BfhV�V	cu��R\O��S�m0

lWindows ��_j�t�X!q�l\ TPM ݈nR�YS0StatusCode: %1�MOn: %20

,SMM ���I{}n\0�S�V: %1

@
N/e�clxԚ��aԚ��P0MirrorStatus�%1

P/e�c TPR�Vf��WL�0,nϑ_U�R�t�X
0Bf�\g��Bl TPR �[݈z_0

<BCD x��'%1'*gWY(u��V�pck(W_U(u�[hQ��_j0

D�]WY(u Windows ��_j�{tz_�d���SGRHr,g %10

P~b
N0R Windows ��_j�{tz_�d���SGRHr,g%10�^p�͑�e�r0

0�]b�R�f�e FW.

 -N�v SBAT <P0!q�l�f�e FW.

 -N�v SBAT <P�Windows HO�^ VSM ;N���R�[ёp�1YWe0O(u�_�S�v����rKa: %10;N�� Blob �\�rKa: %20�P�N Blob �\�rKa: %30�V��P�N Blob �\�rKa: %40�P�N Blob 	gHe'`�j�g�rKa: %50�P�N Blob 	gHe'`�j�gP}�g: %60�V��P�N Blob 	gHe'`�j�g�rKa: %70�V��P�N Blob 	gHe'`�j�gP}�g: %80;N�� Blob ͑�ed\�rKa: %90�P�N Blob ͑�e\݈�rKa: %100�V��P�N Blob ͑�e\݈�rKa: %110�e�vёp�"uu�rKa: %120\݈�rKa: %130TPM PCR n�i: %140Tpm �xehVW�I��rKa: %150Tpm �xehV�^�z�rKa: %160�]O(u�P�N�[\�v Blob: %170�V��P�N\݈�v Blob nd��_GS}�rKa: %180

�VSM ;N���R�[ёp�HO�^0O(u�_�S�v����rKa: %10;N�� Blob �\�rKa: %20�P�N Blob �\�rKa: %30�V��P�N Blob �\�rKa: %40�P�N Blob 	gHe'`�j�g�rKa: %50�P�N Blob 	gHe'`�j�gP}�g: %60�V��P�N Blob 	gHe'`�j�g�rKa: %70�V��P�N Blob 	gHe'`�j�gP}�g: %80;N�� Blob ͑�ed\�rKa: %90�P�N Blob ͑�e\݈�rKa: %100�V��P�N Blob ͑�e\݈�rKa: %110�e�vёp�"uu�rKa: %120\݈�rKa: %130TPM PCR n�i: %140Tpm �xehVW�I��rKa: %150Tpm �xehV�^�z�rKa: %160�]O(u�P�N�[\�v Blob: %170�V��P�N\݈�v Blob nd��_GS}�rKa: %180

�Windows HO�^ VSM ;N���R�[ёp�1YWe0O(u�_�S�v����rKa: %10;N�� Blob ��[�rKa: %20�P�N Blob ��[�rKa: %30�V��P�N Blob ��[�rKa: %40LostOemPk �Ow�݈n��[�rKa: %50�P�N Blob W�I��j�g�rKa: %60�P�N Blob W�I��j�gP}�g: %70�V��P�N Blob W�I��j�g�rKa: %80�V��P�N Blob W�I��j�gP}�g: %90;N�� Blob ͑�e\݈�rKa: %100�P�N Blob ͑�e\݈�rKa: %110�V��P�N Blob ͑�e\݈�rKa: %120�e�vёp�"uu�rKa: %130\݈�rKa: %140TPM PCR n�i: %150Tpm �xehVW�I��rKa: %160Tpm �xehV�^�z�rKa: %170�]O(u�P�N�[\�v Blob: %180�V��P�N�[\�v Blob nd��_GS}�rKa: %190

�VSM ;N���R�[ёp�HO�^0O(u�_�S�v����rKa: %10;N�� Blob ��[�rKa: %20�P�N Blob ��[�rKa: %30�V��P�N Blob ��[�rKa: %40LostOemPk �Ow�݈n��[�rKa: %50�P�N Blob W�I��j�g�rKa: %60�P�N Blob W�I��j�gP}�g: %70�V��P�N Blob W�I��j�g�rKa: %80�V��P�N Blob W�I��j�gP}�g: %90;N�� Blob ͑�e\݈�rKa: %100�P�N Blob ͑�e\݈�rKa: %110�V��P�N Blob ͑�e\݈�rKa: %120�e�vёp�"uu�rKa: %130\݈�rKa: %140TPM PCR n�i: %150Tpm �xehVW�I��rKa: %160Tpm �xehV�^�z�rKa: %170�]O(u�P�N�[\�v Blob: %180�V��P�N�[\�v Blob nd��_GS}�rKa: %190

p%3 kXEQ�x�]WY(u�E��Rz_ [%1]0%n%nkXEQ�x�O�n: %20%n%nkXEQ�x GUID: %40

`�ej [%4] �]WY(u�݈n [%1] - ^�%R [%2]0%n%n�ej�O�n: %30

�Process %1 started at time %2 by parent %3 running as package %4 with executable %5 is application %6.

D%2: !q�l�pWY�N %1 �^�zU�tz�^��V�p|vu/���0%3

T%2: !q�l�pWY�N %1 �^�zU�tz�^��V�p�gb��_��_�SBf|vu/���0%3

X%2: !q�l�pWY�N %1 �^�zU�tz�^��V�p�n�P�a(uz_��I�Bf|vu/���0%3

\%2: !q�l�pWY�N %1 �^�zU�tz�^��V�p�j�gO(u�d\}WY�N�rKaBf|vu/���0%3

\%2: !q�l�pWY�N %1 �^�zU�tz�^��V�p�j�g_jhVd\}WY�N�rKaBf|vu/���0%3

X%2: !q�l�pWY�N %1 �^�zU�tz�^��V�pW�I��a(uz_��I�Bf|vu/���0%3

��a(uz_ %1 �]B}bk�/����p %2��S�V/f�a(uz_�N2�MO�jHh %3 |vuOUL�0��S��/f�V�pr��N2�MO�jHh*g�}=|r0S+T
N�S�O�N�v=|�z0�]
d�kb�]m��z9e0ˊ͑�e�[݈�a(uz_�N�OckdkOUL�0

��a(uz_ %1 !q�l	�eQ"uu�v�N2�MO�jHh %3��V�p|vu/��� %20��S��/f�V�pr��N2�MO�jHh*g�}=|r0S+T
N�S�O�N�v=|�z0�]
d�kb�]m��z9e0

��a(uz_!q�l	�eQ�N2�MO�jHh��V�p|vu/��� %10��S��/f�V�pr��N2�MO�jHh*g�}=|r0S+T
N�S�O�N�v=|�z0�]
d�kb�]m��z9e0

�%2: WY�N�WL����knj
� %1 �]
d�k (MO@W=%5�'Y\=%3�MO�y=%4�@S�k=%6�U�tz�^X�%R�x=%7)0ˊ͑�e�[݈r�WY�N�N�OckdkOUL�0

�%2: WY�N�WL����knj
� %1 z�1Y�g�vnj�e (MO@W=%4�'Y\=%3�@S�k=%5�U�tz�^X�%R�x=%6)0ˊ͑�e�[݈r�WY�N�N�OckdkOUL�0

�%2: WY�N�WL����knj
� %1 S+T]��z�vnj�e (MO@W=%5�'Y\=%3�MO�y=%4�@S�k=%6�U�tz�^X�%R�x=%7)0ˊ͑�e�[݈r�WY�N�N�OckdkOUL�0

�%2: WY�N�WL����knj
� %1 S+T*g�g�vnj�e (MO@W=%5�'Y\=%3�MO�y=%4�@S�k=%6�U�tz�^X�%R�x=%7)0ˊ͑�e�[݈r�WY�N�N�OckdkOUL�0

P%2: WY�N�WL����knj
� %1 !q�l	�eQ (U�tz�^X�%R�x=%3)0

DWY�N�WL����knj
� %1 !q�l	�eQ��V�p|vu�OY�r�l %20

X%2: !q�l�^�zWY�N %1 �vU�tz�^��V�p	�eQ�WL����knj
�Bf|vu/���0%3

xAppContainer %2 �v CreateAppContainerProfile 1YWe�/����p %10

xAppContainer %2 �v DeleteAppContainerProfile 1YWe�/����p %10

xAppContainer %2 �v UpdateAppContainerProfile 1YWe�/����p %10

tCreateAppContainerProfile 1YWe (/����p %1)��V�p�[!q�l�^�z{v�_j�x %20

�CreateAppContainerProfile 1YWe (/����p %1)��V�p�[!q�l(W{v�_j�x %2 
N-��[�[hQ'`0

`AppContainer -��[�j1YWe (/����p %1)��V�p�[!q�l*Rd�{v�_j�x %20

tCreateAppContainerProfile 1YWe (/����p %1)��V�p�[!q�l�^�znj�e>Y %20

|CreateAppContainerProfile 1YWe (/����p %1)��V�p�[!q�l(Wnj�e>Y %2 
N-��[l\'`0

�CreateAppContainerProfile 1YWe (/����p %1)��V�p�[!q�lW�I�{v�_j�x %2 /f&TX[(W0

|CreateAppContainerProfile 1YWe (/����p %1)��V�p�[!q�lW�I�nj�e>Y %2 /f&TX[(W0

�CreateAppContainerProfile 1YWe (/����p %1)��V�p�[~b
N0RO(u��v,g_j�a(uz_nj�enj�e>Y0

hAppContainer -��[�j1YWe (/����p %1)��V�p�[!q�l*Rd�nj�e>Y %2 bvQgQ�[0

tAppContainer -��[�j1YWe (/����p %1)��V�p�[!q�l�gb� AppContainer 
T1z0

xAppContainer -��[�j1YWe (/����p %1)��V�p�[!q�l�gb� AppContainer o�:y
T1z0

pCreateAppContainerProfile 1YWe (/����p %1)��V�p�[!q�lT2�kpFr{v�0

tDeleteAppContainerProfile 1YWe (/����p %1)��V�p�[!q�lT2�kpFr�d�{v�0

h�a(uz_�[hV-��[�j1YWe (/����p %1)��V�p�[!q�l{v� AppContainer SID0

�DeleteAppContainerProfile 1YWe (/����p %1)��V�p�[!q�l�d�{v� AppContainer SID0

8�]�)R�^�z AppContainer %10

@*g�^�z AppContainer %1��V�p�[�]X[(W0

8�]�)R*Rd� AppContainer %10

8�]�)R�f�e AppContainer %10

�%2: WY�N�WL����knj
� %1 z�1Y�g�vnj�e (MO@W=%4�'Y\=%3�@S�k=%5�U�tz�^X�%R�x=%6)0ˊ͑�e�[݈r�WY�N�N�OckdkOUL�0

�%2: ck(W	�eQWY�N�WL����knj
� %1 (MO@W=%4�'Y\=%3�U�tz�^X�%R�x=%5) Bf�!q�lX[�S�a(uz_��RX�%R0

x(W��SP��v AppContainer �N�Rg���b�S AppContainer %2 nj
�1YWe�/����p %10

p(W��SP��v AppContainer �N�Rg���b�S AppContainer nj
�1YWe�/����p %10

`�b�S AppContainer nj
�1YWe�/����p %10�O�dkU�tz�^^��W�v|T�S!qHe0

\!q�l�p�SP��v AppContainer %2 �^�zqQ(u
NN�eir�N�/����p %10

H!q�l_U(u�SP��v AppContainer %2�/����p %10

d�^�z�SP��v AppContainer %2 1YWe (/����p %1)��V�pc�[�v�R��!qHe0

l��_U�s	g�SP��v AppContainer %2 1YWe (/����p %1)��V�p!q�l���S�R��X[>e@S<P0

X!q�l�p�SP��v AppContainer %2 �^�z�R��X[>e@S<P�/����p %10

 WY�N %1 ���W�I�0

(uP,n0RWY�N %1 -N|vu�O9e0

,!q�lB}bkWY�N�p %1 �v�a(uz_0

0�]�)RW�I�WY�N�p %1 �v�a(uz_0

@�b�SWY�N %2 nj�e>Y�v�O�N�rKa1YWe��rKa�p %10

Hck(W�j�g %2 Bf�0�a(uz_�[te'`
0�j�g1YWe�/����p %10

L0�a(uz_�[te'`
0�]B}bk�a(uz_0%2 �v�[te'`�j�g�P�V %10

0%1 �v0�a(uz_�[te'`
0�j�g>�Bf0

T%2: !q�l�^�zWY�N %1 �vU�tz�^��V�p�WL��[te'`�j�gBf|vu/���0%3

@WY�N %1 �v�r:O
ghV�[te'`�j�g1YWe��rKa�p %20

L�b�S0AppModel �WL����k
0�D}�SGR<P1YWe�/����p %10

LW�I�0AppModel �WL����k
0�D}�SGR<P1YWe�/����p %10

P�b�S\݈ %20AppModel �WL����k
0�rKa1YWe�/����p %10

\�b�SO(u� %3 \݈ %20AppModel �WL����k
0�rKa1YWe�/����p %10

|�O9e\݈ %20AppModel �WL����k
0�rKa1YWe�/����p %1 (�vMR�rKa = %4�@b��v�rKa = %3)0

d\݈ %10AppModel �WL����k
0�rKa�]b�R0W�f�e�p %2 (HQMR�rKa = %3)0

��O9eO(u� %3 \݈ %20AppModel �WL����k
0�rKa1YWe�/����p %1 (�vMR�rKa = %5�@b��v�rKa = %4)0

tO(u� %2 \݈ %10AppModel �WL����k
0�rKa�]b�R0W�f�e�p %3 (HQMR�rKa = %4)0

\�O9e0AppModel �WL����k
0�rKaHr,g1YWe�/����p %1 (gQ�[ = %2)0

tAppModel Runtime status version successfully updated.

X%2: !q�l�^�zWY�N %1 �vU�tz�^��V�p�^�z�a(uz_nj�eBf|vu/���0%3

X!q�l͑�etetWY�N�WL����knj
� %1��V�p\Omi^��W %3 -N|vuNR/��� %20

`/���%2: !q�l{v�%1WY�N��V�pSb�� HKEY O(u�{v�_j�xBf|vuNR/���:

 
`/���%4: !q�l{v�%1WY�N��V�pR	��N�yd�%2\%3WY�N�|R{v�_j�xBf|vuNR/���:

\/���%4: !q�l{v�%1WY�N��V�puR�^%2\%3WY�N�|R{v�_j�xBf|vuNR/���: 

`/���%4: !q�l{v�%1WY�N��V�p�yd�%2\%3WY�N�|R{v�_j�xBf|vuNR/���: 


H%2: WY�N�|R %1 �WL����knj
�
d�k0ck(WVf��OckdkOUL�0

H%2: WY�N�|R %1 �WL����knj
�
d�k�FO/f�vMR!q�l�O�_0

�!q�l�_WY�N %2 �v�rKaX[>e�^�_�S�S�_ IsPackageStageInPlace nj
��%10�a(uz_\g�-�����[te'`�j�g0

<Creating AppContainer %1.

`Finished creating AppContainer %2 with %1.

<Deleting AppContainer %1.

`Finished deleting AppContainer %2 with %1.

<Updating AppContainer %1.

`Finished updating AppContainer %2 with %1.

dCreating firewall rules for AppContainer %1.

�Finished creating firewall rules for AppContainer %2 with %1.

dDeleting firewall rules for AppContainer %1.

�Finished deleting firewall rules for AppContainer %2 with %1.

TCreating Restricted AppContainer %1.

tFinished creating Restricted AppContainer %2 with %1.

TDeleting Restricted AppContainer %1.

tFinished deleting Restricted AppContainer %2 with %1.

POpening Restricted AppContainer %1.

tFinished opening Restricted AppContainer %2 with %1.

lEnumerating all Restricted AppContainers for %1.

�Finished enumerating all Restricted AppContainers for AppContainer %2 with %1.

lLaunching process in Restricted AppContainer %1.

�Finished launching process in Restricted AppContainer %2 with %1.

|Terminating all processes in Restricted AppContainer %1.

�Finished terminating all processes in Restricted AppContainer %2 with %1.

HChecking package graph for %1.

dPackage graph check for %2 finished with %1.

hPerforming app integrity check for package %1.

tApp integrity check for package %2 finished with %1.

xPerforming runtime app integrity check for package %1.

�Runtime app integrity check for package %2 finished with %1.

�Firewall Service not running. Skipping creation of firewall rules for AppContainer %1.

lUpdating Restricted AppContainer Capabilities %1.

�Finished Updating Restricted AppContainer Capabilities %2 with %1.

H�](WWY�N %2 -N�^�z�a(uz_ %4 �vU�tz�^ %10%5

H%4: �V�p|vu/����@b�N!q�l�^�zWY�N %1 �vU�tz�^0%5

T%4: �V�p�n�P_U(uBf|vu/����@b�N!q�l�^�zWY�N %1 �vU�tz�^0%5

T%4: �V�pU�0O
kVgBf|vu/����@b�N!q�l�^�zWY�N %1 �vU�tz�^0%5

l%4: �V�pLhb� AppX U�tz�^
N/e�c UI X[�S�@b�N!q�l�^�zWY�N %1 �vU�tz�^0%5

T%4: �V�p��te
kVgBf|vu/����@b�N!q�l�^�zWY�N %1 �vU�tz�^0%5

P%4: �V�p_U�RBf|vu/����@b�N!q�l�^�zWY�N %1 �vU�tz�^0%5

X%4: �V�p-��[�WL����kBf|vu/����@b�N!q�l�^�zWY�N %1 �vU�tz�^0%5

X%4: �V�p|~�~2�L��WL��}Bf|vu/����@b�N!q�l�^�zWY�N %1 �vU�tz�^0%5

<�]�^�zWY�N %1 �vLhb� AppX �[hV %30

P�]\U�tz�^ %1 �e�X�WY�N %2 �vLhb� AppX �[hV %30

l%1: �V�p|vu/����@b�N!q�l\U�tz�^ %2 �e�X�WY�N %3 �vLhb� AppX �[hV %40

\%1: �V�p�^�z�]\OBf|vu/����@b�N!q�l�^�zWY�N %2 �vLhb� AppX �[hV0

\%1: �V�p�^�z�c�Bf|vu/����@b�N!q�l�^�zWY�N %2 �vLhb� AppX �[hV0

\%1: �V�pI��c�]\OBf|vu/����@b�N!q�l�^�zWY�N %2 �vLhb� AppX �[hV0

`%1: �V�p-��[�WL����kBf|vu/����@b�N!q�l�^�zWY�N %2 �vLhb� AppX �[hV0

<�]B}P}WY�N %1 �vLhb� AppX �[hV %20

<!q�lB}P}WY�N %1 �vLhb� AppX �[hV %20

PSystem time initialized during boot

pAn application or system component changed the time

lSystem time synchronized with the hardware clock

\System time adjusted to the new time zone

xLeap second data initialized from registry during boot

XLeap second data updated from registry

TRegistry value invalid format or size

4Too many leap seconds

�Cannot decrease the number of leap seconds while the system is running

LAn invalid leap second was found

tThe list of leap seconds must be strictly increasing

�Cannot modify the existing leap seconds while the system is running

$Other reason

on

off

started

finished

@Platform-level Device Reset

@Function-level Device Reset

LAcpi Override attribute - MpSleep

PAcpi Override attribute - DisableS1

PAcpi Override attribute - DisableS2

PAcpi Override attribute - DisableS3

hAcpi Override attribute - DellMaxUlongBugcheck

lAcpi Override attribute - PciBusNumberTranslation

pAcpi Override attribute - RunRegMethodOnPciDevices

lAcpi Override attribute - RescanPostDependencies

�Acpi Override attribute - PlatformCheckD3ColdOnSurpriseRemoval

�Acpi Override attribute - PlatformCheckFailResetOnOpenHandles

disabled

Hdisabled due to HyperV opt-out

Tdisabled due to opt-out UEFI variable

`disabled due to secure boot being disabled

ldisabled due to DMA protection being unavailable

ldisabled due to the hypervisor being unavailable

`disabled due to VBS initialization failure

pdisabled due to VBS anti-rollback policy is missing

\enabled due to VBS registry configuration

4enabled due to HyperV

Xenabled due to VBS locked configuration

Tenabled due to Code Integrity policy

8enabled due to Velocity

@BL_LOG_INFO_NONE: Info none

�BL_LOG_INFO_BLI_IO_INITED: IO initialized in boot library initialization.

�BL_LOG_INFO_BLI_FINISHED: Finished in boot library initialization.

�BL_LOG_INFO_BM_BL_INITED: The boot library has been initialized for bootmgr.

�BL_LOG_INFO_BM_GET_BOOT_SEQ: Getting boot sequence in bootmgr.

�BL_LOG_INFO_BM_LAUNCH_ENTRY: Launching boot entry in bootmgr.

�BL_LOG_INFO_OSL_PREPARE_ENTERED: Reached prepare target within osloader.

�BL_LOG_INFO_OSL_OPEN_DEVICE: Preparing to open OS device in osloader.

�BL_LOG_INFO_OSL_LAUNCH_HYPERV: Preparing to launch hyper-v if specified within osloader.

�BL_LOG_INFO_OSL_LOAD_MODULES: Preparing to load OS modules within osloader.

�BL_LOG_INFO_OSL_KERNEL_SETUP: Setting up kernel within osloader.

�BL_LOG_INFO_OSL_PRELOAD_HYPERV: Preloading hyper-v if specified within osloader.

pBL_LOG_INFO_OSL_BOOT_CANCELLED: Boot was cancelled.

�BL_LOG_INFO_TCB_LAUNCH_HYPERV: Preparing to launch hyper-v.

@BL_LOG_ERROR: Generic Error

�BL_LOG_ERROR_BLI_NET_INIT: BlNetInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_UTL_INIT: BlUtlInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_SEC_BOOT_INIT: BlSecureBootInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_PDATA_INIT: BlpPdInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_RES_INIT: BlpResourceInitialize failed in BL initialization.

�BL_LOG_ERROR_BLI_SEC_LAUNCH_INIT: BlpTcbLaunchInitialize failed in BL initialization.

�BL_LOG_ERROR_BM_INIT_MACH_POL: BmSecureBootInitializeMachinePolicy failed in bootmgr.

�BL_LOG_ERROR_BM_FW_REG_SYSINT: BmFwRegisterSystemIntegrityPolicies failed in bootmgr.

�BL_LOG_ERROR_BM_RES_FIND_HTML: BlResourceFindHtml failed to find BOOTMGR.XSL in bootmgr.

�BL_LOG_ERROR_BM_XMI_INIT: BlXmiInitialize failed in bootmgr.

�BL_LOG_ERROR_BM_OPEN_DATA_STORE: BmOpenDataStore failed in bootmgr.

�BL_LOG_ERROR_BM_SELF_INT_CHK: BmpSelfIntegrityCheck failed in bootmgr.

�BL_LOG_ERROR_BM_FW_REG_REV_LIST: BmFwRegisterRevocationList failed in bootmgr.

�BL_LOG_ERROR_BM_RESUME_HIBER: BmResumeFromHibernate failed in bootmgr.

�BL_LOG_ERROR_BM_PURGE_OPT_START_SEQ: BL_ERROR_BM_PURGE_OPT_START_SEQ failed in bootmgr.

�BL_LOG_ERROR_BM_PURGE_OPT_BOOT_SEQ: BmPurgeOption failed for BCDE_BOOTMGR_TYPE_BOOT_SEQUENCE in bootmgr.

�BL_LOG_ERROR_BM_REOPEN_DATA_STORE: BmOpenDataStore failed on reopen in bootmgr.

�BL_LOG_ERROR_BM_UPDATE_APP_OPTS: BmpUpdateApplicationOptions failed in bootmgr.

�BL_LOG_ERROR_BM_LAUNCH_BOOT_ENTRY: BmpLaunchBootEntry failed in bootmgr.

�BL_LOG_ERROR_BM_CREATE_DEVICES: BmpCreateDevices failed in bootmgr.

�BL_LOG_ERROR_BM_LAUNCH_FLIGHT_BM: BmFwLaunchFlightedBootmgr failed in bootmgr.

�BL_LOG_ERROR_BM_FE_BOOTAPP_LD: Fatal error: failure to load boot app in bootmgr.

�BL_LOG_ERROR_BM_FE_CONFIG_DATA: Fatal error: failure attempting to read boot config file in bootmgr.

�BL_LOG_ERROR_BM_FE_NO_VALID_OS_ENTRY: Fatal error: no valid os entires found in bootmgr.

�BL_LOG_ERROR_BM_FE_NO_VALID_PXE_ENTRY: Fatal error: no valid entries found from PXE server in bootmgr.

�BL_LOG_ERROR_BM_FE_FAILURE_STATUS: Fatal error: failure status in bootmgr.

�BL_LOG_ERROR_BM_FE_BOOT_DEVICE: Fatal error: boot device inaccessible in bootmgr.

�BL_LOG_ERROR_BM_FE_RAMDISK_MEM: Fatal error: ramdisk device creation had insufficient memory in bootmgr.

�BL_LOG_ERROR_BM_FE_INVALID_BCD_STORE: Fatal error: BCD is invalid in bootmgr.

�BL_LOG_ERROR_BM_FE_INVALID_BCD_ENTRY: Fatal error: Invalid BCD entry in bootmgr.

�BL_LOG_ERROR_BM_FE_NO_SECUREBOOT_POL: Fatal error: Default Secure Boot policy not found in bootmgr.

�BL_LOG_ERROR_BM_FE_NO_PAE_SUPPORT: Fatal error: CPU does not support PAE in bootmgr.

�BL_LOG_ERROR_BM_FE_UNSEAL_NOT_POS: Fatal error: Cannot unseal sensitive data in bootmgr.

�BL_LOG_ERROR_BM_FE_GENERIC: Fatal error: Generic failure in bootmgr.

�BL_LOG_ERROR_BM_FAILED_SVN_CHECK: Bootmgr SVN check failed.

�BL_LOG_ERROR_BM_FAILED_CHAINLOAD_SVN_CHECK: SVN check failed while chainloading bootmgr.

BL_LOG_ERROR_BM_PURGE_OPT_DISABLE_TRUSTED_WIM_BOOT: bootmgr -N BCDE_OSLOADER_TYPE_DISABLE_TRUSTED_WIM_BOOT �v BmPurgeOption 1YWe0

�BL_LOG_ERROR_OSL_REM_INTERN_APP_OPTS: osloader -N�v OslpRemoveInternalApplicationOptions 1YWe0

�BL_LOG_ERROR_OSL_GET_APP_OPT_DEVICE: (W osloader -N�BCDE_OSLOADER_TYPE_OS_DEVICE �v BlGetApplicationOptionDevice 1YWe0

�BL_LOG_ERROR_OSL_GET_SYSTEM_ROOT: !q�l(W osloader -N�S�_ SystemRoot0

�BL_LOG_ERROR_OSL_FORCED_FAIL: osloader -N�v OslpCheckForcedFailure 1YWe�h�:y7_6R1YWe0

�BL_LOG_ERROR_OSL_DISABLE_VGA: (W osloader -N�BCDE_OSLOADER_TYPE_DISABLE_VGA_MODE �v BlAppendApplicationOptionBoolean 1YWe0

�BL_LOG_ERROR_OSL_OPEN_OS_DEVICE: osloader -N OS ݈n�v BlDeviceOpen 1YWe0

�BL_LOG_ERROR_OSL_LOAD_SYS_HIVE: osloader -N�v OslpLoadSystemHive 1YWe0

�BL_LOG_ERROR_OSL_CREATE_OS_LD_OPTS: osloader -N�v AhCreateLoadOptionsString 1YWe0

�BL_LOG_ERROR_OSL_DISPLAY_INIT: osloader -N�v OslDisplayInitialize 1YWe0

�BL_LOG_ERROR_OSL_PROCESS_SI_POLICY: osloader -N�v OslpProcessSIPolicy 1YWe0

�BL_LOG_ERROR_OSL_DISP_ADV_OPT: osloader -N�v OslDisplayAdvancedOptionsProcess 1YWe0

�BL_LOG_ERROR_OSL_ARCH_HV_SETUP: osloader -N�v OslArchHypervisorSetup 1YWe0

�BL_LOG_ERROR_OSL_ARCH_HYPERCALL_SETUP: osloader -N�v OslArchHypercallSetup 1YWe0

�BL_LOG_ERROR_OSL_INIT_RESUME_CONTEXT: osloader -N�v OslInitializeResumeContext 1YWe0

�BL_LOG_ERROR_OSL_INIT_LDR_BLOCK: osloader -N�v OslInitializeLoaderBlock 1YWe0

�BL_LOG_ERROR_OSL_PROC_INIT_MACH_CONFIG: osloader -N�v OslpProcessInitialMachineConfiguration 1YWe0

�BL_LOG_ERROR_OSL_ENUM_DISKS: osloader -N	�eQhV@SJX�v OslEnumerateDisks 1YWe0

�BL_LOG_ERROR_OSL_REINIT_SYS_HIVE: osloader -N�v OslpReinitializeSystemHive 1YWe0

�BL_LOG_ERROR_OSL_INIT_CODE_INT: osloader -N�v OslInitializeCodeIntegrity 1YWe0

�BL_LOG_ERROR_OSL_INIT_CODE_INT_LD_BLOCK: osloader -N�v OslBuildCodeIntegrityLoaderBlock 1YWe0

�BL_LOG_ERROR_OSL_SECURE_BOOT_VARS: osloader -N�v OslFwProtectSecureBootVariables 1YWe0

�BL_LOG_ERROR_OSL_LD_MODULES: osloader -N�v OslpLoadAllModules 1YWe0

�BL_LOG_ERROR_OSL_LD_FW_DRIVERS: osloader -N�v OslFwLoadFirmwareDrivers 1YWe0

�BL_LOG_ERROR_OSL_VSM_CHK_ENCRYPT_KEY: osloader -N;N�� sncrupt ёp�HO�^�v BlVsmCheckSystemPolicy 1YWe0

�BL_LOG_ERROR_OSL_VSM_PHASE_0: osloader -N�V͑�v VSM ���k 0 R�YS1YWe0

�BL_LOG_ERROR_OSL_SET_SEIL_SIGN_POL: osloader -N�v OslSetSeILSigningPolicy 1YWe0

�BL_LOG_ERROR_OSL_CMS_PROV_IDK: osloader -N�v BlVsmCheckSystemPolicy (W VSM ��RX�%R_j�x�]\Og��1YWe0

�BL_LOG_ERROR_OSL_ARCH_KERNEL_SETUP_0: osloader -Nݑ
\ 0 �v OslArchKernelSetup 1YWe0

�BL_LOG_ERROR_OSL_FW_KERNEL_SETUP: osloader -Nݑ
\ 0 �v OslFwKernelSetup 1YWe0

�BL_LOG_ERROR_OSL_PROC_EV_STORE: osloader -N�v OslpProcessEVStore 1YWe0

�BL_LOG_ERROR_OSL_COPY_BOOT_OPTS: osloader -N�v BlCopyBootOptions 1YWe0

�BL_LOG_ERROR_OSL_FVE_SEC_BOOT_REST_ONE: osloader -N�v BlFveSecureBootRestrictToOne 1YWe0

�BL_LOG_ERROR_OSL_NET_UNDI_CLOSE: osloader -N�v BlNetUndiClose 1YWe0

�BL_LOG_ERROR_OSL_PROC_APP_PDATA: osloader -N�v OslProcessApplicationPersistentData 1YWe0

�BL_LOG_ERROR_OSL_BLD_MEM_CACHE_REQ_LIST: osloader -N�v OslFwBuildMemoryCachingRequirementsList 1YWe0

�BL_LOG_ERROR_OSL_BLD_RT_MEM_MAP: osloader -N�v OslFwBuildRuntimeMemoryMap 1YWe0

�BL_LOG_ERROR_OSL_VSM_SETUP_1: osloader -Nݑ
\ 1 �v OslVsmSetup 1YWe0

�BL_LOG_ERROR_OSL_BLD_KERNEL_MEM_MAP: osloader -N�v BlTraceBuildKernelMemoryMapStop 1YWe0

�BL_LOG_ERROR_OSL_ARCH_KERNEL_SETUP_1: osloader -Nݑ
\ 1 �v OslArchKernelSetup 1YWe0

�BL_LOG_ERROR_OSL_SET_VSM_POL_SYS_HIVE: osloader -N�v OslSetVsmPolicy 1YWe0

�BL_LOG_ERROR_OSL_ENUM_ENCLAVE_PAGES: osloader -N�v OslEnumerateEnclavePageRegions 1YWe0

�BL_LOG_ERROR_OSL_GATHER_ENTROPY: osloader -N�v OslGatherEntropy 1YWe0

�BL_LOG_ERROR_OSL_VSM_SETUP_0: osloader -Nݑ
\ 0 �v OslVsmSetup 1YWe0

�BL_LOG_ERROR_OSL_VSM_CANNOT_BE_DISABLED_BY_KSR: VSM 
N�S�N� KSR \P(u

lBL_LOG_ERROR_OSL_VSM_PHASE0_ALLOCATE_PAGES_FAILED

hBL_LOG_ERROR_OSL_VSM_PHASE0_LOAD_MODULES_FAILED

hBL_LOG_ERROR_OSL_VSM_PHASE0_LOAD_CIDATA_FAILED

lBL_LOG_ERROR_OSL_VSM_PHASE0_COPY_VSM_KEYS_FAILED

pBL_LOG_ERROR_OSL_VSM_PHASE0_COPY_ACPI_TABLES_FAILED

dBL_LOG_ERROR_OSL_VSM_PHASE0_ARCH_SETUP_FAILED

tBL_LOG_ERROR_OSL_VSM_PHASE0_BUILD_PAGE_TABLES_FAILED

�BL_LOG_ERROR_OSL_BUILD_BSD_LOCATION_FAILED: osloader -N�v OslpBuildBsdLogLocation 1YWe0

BL_LOG_ERROR_OSL_GET_APP_OPT_DEVICE_OSDATA: (W osloader -N�BCDE_OSLOADER_TYPE_OS_DATA_DEVICE �v BlGetApplicationOptionDevice 1YWe0

�BL_LOG_ERROR_OSL_OPEN_OSDATA_DEVICE: (W osloader -N osdata ݈n�v BlDeviceOpen 1YWe0

�BL_LOG_ERROR_OSL_ENUMERATE_PERSISTENT_MEMORY: osloader -N�v OslEnumeratePersistentMemory 1YWe0

�BL_LOG_ERROR_OSL_HVCI_CANNOT_BE_ENABLED_BY_KSR: HVCI 
N�S�N� KSR _U(u

|BL_LOG_ERROR_OSL_PROCESS_PRESERVED_MEMORY: U�t�OYu��aԚBf|vu/���0

�BL_LOG_ERROR_OSL_LOAD_DEVICES_HIVE: osloader -N OslpLoadDevicesHive 1YWe0

�BL_LOG_ERROR_OSL_LOAD_OSBOOT_HIVE: osloader -N OslpLoadOsBootHive 1YWe0

�BL_LOG_ERROR_OSL_LOAD_DRIVER_STORES: osloader -N OslpLoadDriverStoreNodes 1YWe0

�BL_LOG_ERROR_OSL_CMS_PROV_HBK: osloader -N VSM O w_j�x�]\Og�� BlVsmCheckSystemPolicy 1YWe0

�BL_LOG_ERROR_OSL_ALLOC_LDR_BLOCK: osloader -N�v OslAllocateLoaderBlock 1YWe0

�BL_LOG_ERROR_OSL_ARCH_TCB_LAUNCH_0: osloader -N�v OslTcbLaunch(0) 1YWe0

�BL_LOG_ERROR_OSL_HVCI_CANNOT_BE_DISABLED_BY_KSR: HVCI 
N�S�N� KSR \P(u

�BL_LOG_ERROR_OSL_GET_APP_OPT_DEVICE_BSP: osloader -N BCDE_OSLOADER_TYPE_BSP_DEVICE �v BlGetApplicationOptionDevice 1YWe0

�BL_LOG_ERROR_OSL_OPEN_BSP_DEVICE: osloader -N bsp ݈n�v BlDeviceOpen 1YWe0

pBL_LOG_ERROR_OSL_VSM_PHASE0_VBS_POLICY_NOT_PRESENT

�BL_LOG_ERROR_KSR_KSEG0: SK �^8O!jD}-N�v InitializeRebootAddressRange 1YWe0

pBL_LOG_ERROR_KSR_OUT_OF_MEMORY: SK KSR �^8O-N�v��aԚM�n1YWe0

tBL_LOG_ERROR_KSR_IMAGE_VALIDATION: SK KSR �^8O-N�v f�PW�I�1YWe0

xBL_LOG_ERROR_KSR_IMAGE_RELOCATION: SK KSR �^8O-N�v f�P͑�e�[MO1YWe0

tBL_LOG_ERROR_KSR_BIND_IMPORT: !q�l\/SeQk~P}� SK KSR �^8O-N�v f�P0

pBL_LOG_ERROR_KSR_LOADER_ENTRY_POINT: SK 	�eQhV2�eQޞ�P�V1YWe0

�BL_LOG_ERROR_KSR_RESERVE_EFI_RUNTIME: SK 	�eQhV!q�l�OYu EFI �WL����k VA �{
W0

lBL_LOG_ERROR_TCB_SI_POLICY_CHECK: !q�lW�I��S,nϑ SI �SGR0

tBL_LOG_ERROR_TCB_LOAD_TCBLOADER: !q�l	�eQ tcbloader.dll0

LBL_LOG_ERROR_TCB_LOAD: !q�l�WL�	�eQ�R\O0

PBL_LOG_ERROR_TCB_RESUME: !q�l�WL�|~�~�R\O0

|BL_LOG_ERROR_TCB_INVALID_ATTRIBUTES: tcblaunch �a(uz_l\'`!qHe0

xBL_LOG_ERROR_TCB_REGISTER_EVENT_HANDLER: !q�l;��Q_U�R��wU�t8^_0

\BL_LOG_ERROR_TCB_OPEN_DEVICE: !q�l��_U�a(uz_݈n0

\BL_LOG_ERROR_TCB_GET_DEVICE: !q�l�gb��a(uz_݈n0

lBL_LOG_ERROR_GET_SYSTEM_ROOT: !q�l�S�_ SystemRoot <P0

|BL_LOG_ERROR_OSL_PROCESS_BOOTSTAT_DATA: !q�lU�t bootstat nj�e0

`BL_LOG_ERROR_OSL_VIRT_SETUP_0�!q�l�WL�[��d�[݈���k 0.

`BL_LOG_ERROR_OSL_VIRT_SETUP_1�!q�l�WL�[��d�[݈���k 1.

|BL_LOG_ERROR_OSL_PRELOAD_SI_POLICY� !q�l�_ OS �x�x@S�HQ	�eQ SI �SGR0

�BL_LOG_ERROR_OSL_ARCH_TCB_LAUNCH_1: osloader -N�v OslTcbLaunch(1) 1YWe0

XERROR_TCB_PLATORM_INIT: !q�l\ TCB s^�SR�YS0

�BL_LOG_ERROR_OSL_INITIALIZE_FEATURE_CONFIGURATION: OslInitializeFeatureConfiguration (W osloader -N1YWe0

lBL_LOG_ERROR_RES_OPEN_HIBERFILE: !q�l��_U Hiberfile0

XBL_LOG_ERROR_RES_INIT_DISPLAY: !q�lR�YSo�:y0

pBL_LOG_ERROR_RES_INVALID_PAGEFILE: R��jHh(W2�L�O w|~�~Bf!qHe0

dBL_LOG_ERROR_RES_HW_CHANGE: �O ww��vlxԚb̗Ԛ-��[�]���f0

lBL_LOG_ERROR_RES_INVALID_HIBERFILE: Hiberfile !qHe0

hBL_LOG_ERROR_RES_GET_CONTEXT_FAILED: !q�l�S�_|~�~�vgQ�[0

tBL_LOG_ERROR_RES_INVALID_MEM_MAP: �ܕo��v�Q��_jw���]���f��aԚM�nW0

pBL_LOG_ERROR_RES_FIRMWARE_PHASE_0: |~�~̗Ԛ-��[�v���k 0 1YWe0

dBL_LOG_ERROR_RES_USB_HANDOFF: 
�Hr USB ^��N-��[1YWe0

\BL_LOG_ERROR_RES_SMBIOS: !q�l�S�_ SMBIOS nj�e0

lBL_LOG_ERROR_RES_TCB_ALLOCATE: !q�lM�n(u�e TCB |~�~�vzz��0

`BL_LOG_ERROR_RES_TCB_PREPARE: !q�l�n�P TCB nj�e0

hBL_LOG_ERROR_RES_INIT_PREALLOCATION: !q�lR�YS�HQM�n0

pBL_LOG_ERROR_RES_INIT_TRANSITION_SPACE: !q�lR�YSI��czz��0

pBL_LOG_ERROR_RES_INIT_PAGE_ALLOCATOR: !q�lR�YS�S(u�b�M�nhV0

pBL_LOG_ERROR_RES_RELOC_PROC_CONTEXT: !q�l͑�e>enU�thVgQ�[�b�0

|BL_LOG_ERROR_RES_LOAD_SECURE_DATA: !q�l�_ Hiberfile 	�eQ�[hQ�vnj�e0

pBL_LOG_ERROR_RES_RESTORE_IMAGE: !q�l�_ Hiberfile ���Sq_�P0

pBL_LOG_ERROR_RES_SECURE_DECRYPT_0: �[hQnj�e��[�v���k 0 1YWe0

tBL_LOG_ERROR_RES_FVE_RESTRICT: !q�lP�6R BitLocker |~�~ OS0

lBL_LOG_ERROR_RES_TCB_PREP_DATA: !q�l�n�P(u�e TCB |~�~�vnj�e0

!q


N/e�cU�thV0


N/e�c VMX0


N/e�c SMX0

X(W MSR_FEATURE_CONTROL -N�TXT �]�� BIOS \P(u0

H�_���v GETSEC[CAPABILITIES] !q�lO(u0

$TPM 2.0 !q�lO(u0

0��aԚl\'`h�<h (MAT) !q�lO(u0

L(W SINIT �W�^MO@W~b
N0R SINIT ACM �v!jD}^��W0

0ACM UUID ��w
T�v<P
N�v&{0

@ACM (u6b�z/:O
ghV�e_^� BIOS nj�e
N�v&{0

(ACM uP/��ej�s^�S
N�v&{0

$ACM 
N/e�cdkvfGrƖ0

$ACM 
N/e�cdkU�thV0

(�|q}
N	g�f�eHr,g�v ACM0 

,(W�|q}
N~b
N0R�NUO�v�[�v ACM0

@�|q}
N/e�c(W DMAR nj�eh�-N DMA ͑�e
\�a0

$TPM 
N&{THO�^�Bl0

0�|q}
N&{TW�I� SMM @b��v-��[0 

 |vu VMX �v/���0

(�d�S SMM nj
��v|T�S1YWe0

0SMM �S�NX[�S OS ��aԚ@S�W0

$SMM =|�z�]z�1Yb
d�k0

 SMM =|�z�j�g1YWe0

4SMM wQ	gX[�S�SGRd\}
NAQ1��v MSR0

<SMM wQ	gX[�S�SGRd\}
NAQ1��v IO #��c�W0

0SMM 	g
kP�X[�S IOMMU P}�i0

ACM M�n
d�X0

!q0

 !q�l�OYu�Bf VA0

!q�l�S�_#��}�Sxe0

,BitLocker \���NuP/�0

$!q�lR�YSuP/�݈n�c�0

!q�l-��[uP/�݈n0

 !q�lR�YSuP/��P8�0

!q�l-��[uP/�-�w�0

$!q�l	�eQuP/��]wQ�P8�!jD}0

 !q�lM�n�Bf�}]�@S0

(!q�l�S�_uP/��]wQ�P8��dEQ
T1z0

(truncatememory

(avoidlowmemory

,nf�=|r

,nointegritychecks

*g�[�

�S(u

�]WY(u

�]�bU}

NotFound

<applied through registry

Xapplied through compatibility database

<applied through registry

Xapplied through compatibility database

PackageId

None

 VBS Enabled

$VSM Required

 Secure Boot

,Iommu Protection

Mmio Nx

4Strong MSR Filtering

Mandatory

Hvci

 Hvci Strict

HBoot Chain Signer Soft Enforced

HBoot Chain Signer Hard Enforced

(Measured Launch

4VS_VERSION_INFO��
{aJ
{aJ?xStringFileInfoT040404B0LCompanyNameMicrosoft Corporationn#FileDescriptionMicrosoft-Windows-System-Events nj�nn'FileVersion10.0.19041.7291 (WinBuild.160101.0800)h$InternalNamemicrosoft-windows-system-events.dll�.LegalCopyright� Microsoft Corporation. All rights reserved.x(OriginalFilenamemicrosoft-windows-system-events.dll.muij%ProductNameMicrosoft� Windows� Operating SystemDProductVersion10.0.19041.7291DVarFileInfo$Translation�PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDING