exytral
> **Note:** This issue was diagnosed and written by Claude (Anthropic). ## Summary SecureUxTheme v4.0.0 installs successfully (MSI returns 0 or 3010, DLL is placed in System32) but the hook never loads and unsigned themes silently fall back to Aero with no error surfaced to the user. The root cause is that Windows blocks LSA notification package registration for unsigned DLLs when LSA protection (enforced via HVCI) is active. This is not a new Windows feature — LSA protected process has existed since Windows 8.1 — but Microsoft began enabling HVCI automatically on clean installs of Windows 11 meeting specific hardware criteria starting with Windows 11 22H2 (late 2022), and has continued doing so on subsequent releases. Auto-enablement applies only to clean installs, not in-place upgrades; the hardware criteria require Intel 8th generation or later (or AMD Zen 2+), at least 8 GB RAM, an SSD, HVCI-compatible drivers, and virtualization enabled in BIOS. This means previously working SecureUxTheme installs on machines that did receive auto-enablement can break silently after a routine update with no indication of what changed. The symptoms match issue #267 (March 2026, Win10 LTSC) and likely explain other intermittent reports going back further. ## Steps to reproduce 1. Have LSA protection enabled — either via a clean install of Windows 11 22H2 or later on hardware meeting Microsoft's auto-enablement criteria (Intel 8th gen+, 8 GB+ RAM, SSD, compatible drivers, virtualization enabled in BIOS), or by manually enabling HVCI. No user notification is involved in the automatic case. 2. Install SecureUxTheme 4.0.0, reboot when prompted. 3. Apply any custom unsigned .msstyles theme. 4. Observe that Windows silently falls back to Aero.msstyles. The partial application — some colors applying correctly while graphical theme elements revert to Aero defaults — is the key symptom. ## Diagnostic evidence `SecureUxTheme4.dll` is present in System32 (43896 bytes) but is not loaded in the Themes svchost process: ```powershell # Run in elevated PowerShell $themes = Get-Process -Name svchost | Where-Object { $_.Modules | Where-Object { $_.ModuleName -like "*theme*" } } $themes | ForEach-Object { $_.Modules | Where-Object { $_.ModuleName -like "*SecureUx*" -or $_.ModuleName -like "*theme*" } } | Select-Object ModuleName, FileName # Result: only themeservice.dll and uxtheme.dll — SecureUxTheme4.dll absent ``` `GetCurrentThemeName` returns `Aero.msstyles` despite a custom theme being selected: ```powershell Add-Type -TypeDefinition @" using System; using System.Runtime.InteropServices; public class UxTheme { [DllImport("uxtheme.dll", CharSet = CharSet.Unicode)] public static extern int GetCurrentThemeName(System.Text.StringBuilder a, int b, System.Text.StringBuilder c, int d, System.Text.StringBuilder e, int f); } "@ $t = New-Object System.Text.StringBuilder 260 $c = New-Object System.Text.StringBuilder 260 $s = New-Object System.Text.StringBuilder 260 [UxTheme]::GetCurrentThemeName($t, 260, $c, 260, $s, 260) $t.ToString() # Returns: C:\WINDOWS\Resources\Themes\Aero\Aero.msstyles ``` LSA notification packages show no SecureUxTheme registration: ```powershell # Run in elevated PowerShell Get-ItemProperty "HKLM:\SYSTEM\CurrentControlSet\Control\Lsa" | Select-Object "Authentication Packages", "Security Packages", "Notification Packages" # Returns only default Windows entries — no SecureUxTheme4 ``` No registration found in AppInit_DLLs, Winlogon notify, AppCertDlls, KnownDLLs, or Session Manager BootExecute. The DLL is on disk with no active load mechanism anywhere. HVCI / LSA protection confirmed enabled: ```powershell # Run in elevated PowerShell Get-ItemProperty "HKLM:\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity" | Select-Object Enabled # Enabled: 1 ``` Disabling HVCI and rebooting resolved the issue — `GetCurrentThemeName` returned the correct `.msstyles` path, `SecureUxTheme4.dll` appeared in the Themes svchost module list, and themes applied and persisted across reboots correctly after reapplying the custom theme. ## Root cause SecureUxTheme v4 registers itself as an LSA notification package to receive `LdrRegisterDllNotification` callbacks, which allows it to hook `themeui.dll`, `themeservice.dll`, `uxinit.dll`, and `uxtheme.dll` at load time. When LSA protected process is active, Windows enforces that all LSA packages must be Microsoft-signed. `SecureUxTheme4.dll` is not Microsoft-signed, so Windows silently refuses to load it as an LSA package at boot. The MSI install itself succeeds and the DLL is written to disk, but the registration never takes effect. ## Why this is difficult to diagnose - The MSI install completes with exit code 0 or 3010 — no failure indication. - `SecureUxTheme4.dll` is present on disk at the expected path and size. - Windows does not surface any error when it refuses to load an unsigned LSA package. - Theme application silently falls back to Aero with no user-facing error. - The security configuration change (LSA protection being enabled) can happen without the user's knowledge and with no notification — there is no indication anything changed between a working and broken state. - The `uxtheme.dll` version string (`FileVersion` resource) may not match the actual binary version (`FileVersionRaw`), making version-based diagnosis unreliable. ## Workaround > ⚠️ **Security and compatibility notice:** Disabling HVCI reduces kernel-level protection against unsigned and malicious code. Some anti-cheat systems — notably Valorant (Vanguard) — will refuse to launch with HVCI disabled. Consider this tradeoff before proceeding. > > **Windows edition note:** The Group Policy method below requires Windows 11 Pro, Enterprise, or Education. Windows Home does not include Group Policy Editor (`gpedit.msc`). Home users can disable HVCI via the registry key alone but have no supported way to prevent Windows Update from re-enabling it via policy — the registry-only block may not survive future updates. Run the following in an **elevated (Administrator) PowerShell**: ```powershell # Disable HVCI Set-ItemProperty "HKLM:\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios\HypervisorEnforcedCodeIntegrity" -Name "Enabled" -Value 0 # Pro/Enterprise/Education only — lock via Group Policy to prevent Windows Update from re-enabling it New-Item "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" -Force -ErrorAction SilentlyContinue Set-ItemProperty "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" -Name "EnableVirtualizationBasedSecurity" -Value 0 Set-ItemProperty "HKLM:\SOFTWARE\Policies\Microsoft\Windows\DeviceGuard" -Name "HypervisorEnforcedCodeIntegrity" -Value 0 ``` Reboot. SecureUxTheme v4 will load correctly after the reboot, but the custom theme will not apply automatically — Windows fell back to Aero at the previous boot and will not reapply the selection. Reopen the theme settings and reselect your theme after rebooting. ## Suggested improvements 1. **Detection at install time**: check whether LSA protection / HVCI is enabled during MSI install and surface a clear warning that SecureUxTheme will not function until it is disabled. A single registry read at install time would make this immediately diagnosable. 2. **README documentation**: note that LSA protection must be disabled for v4 to function, that Windows 11 22H2+ enables it automatically on qualifying clean installs, and that the setting can also be enabled manually or by OEM configuration. 3. **Possible fix direction**: a signed kernel driver loading the hook would bypass the LSA package restriction entirely, though this requires an EV code signing certificate. Alternatively, a file-patching fallback mode (similar to UltraUXThemePatcher) when LSA protection is detected, at the cost of requiring repatching after system file updates.