MZ@ !L!This program cannot be run in DOS mode. $}.....{fA..{fG..{fD..{f@..{fY..{fC..{fF..Rich.PELR!  fq;@t<09\s@.textef `.dataj@.idatal@@.rsrc0t@@.reloc4z@BsR.9-`ADVAPI32.dllGuidLevelFlagsCircularSizeWERDIAG: Verifier.dll loaded. Enabling Autoverifier. WERDIAG: ProcessStartupSettingsUpdate failed. NTSTATUS: %08X WERDIAG: FDR will be enabled WERDIAG: Stopping Autoverifier WERDIAG: Stopping FDR WERDIAG: AutoVerifier: Failed getting current user registry path. NTSTATUS: %08X WERDIAG: AutoVerifier: Path is: %S Software\Microsoft\Windows\Windows Error Reporting\Plugins\AutoverifierWERDIAG: AutoVerifier: Subkey is: %S WERDIAG: AutoVerifier: could not open settings key. NTSTATUS: %08X AutoverifierEnabledWERDIAG: AutoVerifier: could not read enabled flag. NTSTATUS: %08X WERDIAG: AutoVerifier: Enabled flag: %u \Registry\Machine\Software\Microsoft\Windows\Windows Error ReportingWERDIAG: Failed opening registry key. NTSTATUS: %08X ErrorPortWERDIAG: PluginsNtGetRegStringValue failed. NTSTATUS: %08X WERDIAG: SignalStartWerSvc failed NTSTATUS: %08X WERDIAG: NtQuerySysInfo(ErrorPortTimeouts) failed. NTSTATUS: %08X WERDIAG: WaitForWerSvc failed %08X. NTSTATUS: %08X WERDIAG: WaitForWerSvc timed out, failing the call with NTSTATUS: %08X WERDIAG: RtlAllocateAndInitializeSid failed. NTSTATUS: %08X WERDIAG: NtAlpcConnectPort failed. NTSTATUS: %08X WERDIAG: NtAlpcConnectPort timed out, failing the call with NTSTATUS %08X WERDIAG: NtAlpcSendWaitReceivePort failed. NTSTATUS: %08X WERDIAG: Service returned failure status. NTSTATUS: %08X WERDIAG: Failed getting current user registry path. NTSTATUS: %08X Software\Microsoft\Windows NT\CurrentVersion\Image File Execution OptionsWERDIAG: Handle to registry key is null WERDIAG: Failed getting process name. NTSTATUS: %08X AutoverifierAutoVerifierCountWERDIAG: Failed reading key value. NTSTATUS: %08X WERDIAG: Failed writing registry value. NTSTATUS: %08X OriginalBucketAutoVerifierTimeDurationWERDIAG: Failed creating timer thread. NTSTATUS: %08X WERDIAG: Failed deleting autovefier enabled flag. NTSTATUS: %08X WERDIAG: Failed writing key value \Registry\Machine\SYSTEM\CurrentControlSet\Control\Session ManagerImageExecutionOptionsWERDIAG: Not disabling HKCU IFEO look-up because its statically enabled. WERDIAG: Thread failed to wait for the specified time; Disabling autoverifier. NTSTATUS: %08X verifier.dllWERDIAG: Failed obtaining verifier.dll handle. NTSTATUS: %08X VerifierForceNormalHeapWERDIAG: Failed obtaining VerifierForceNormalHeap function address. NTSTATUS: %08X WERDIAG: Failed switching to normal heap mode. NTSTATUS: %08X WERDIAG: Verifier switched to light mode \KernelObjects\SystemErrorPortReadyu: AnT DWERDIAG: Invalid params WERDIAG: Arithmetic overflow WERDIAG: OOM WERDIAG: Failed creating FDR thread. NTSTATUS: %08X WERDIAG: GetTraceLoggerHandle failed WERDIAG: GetTraceEnableLevel failed WERDIAG: GetTraceEnableFlags failed WERDIAG: Internal provider enabled for Level %u, Flags %lu WERDIAG: Tracing disabled for internal provider WERDIAG: Provider not registered. RegisterTraceGuids failed with %d WERDIAG: Internal provider: FDR did not start yet; Message lost WERDIAG: Failed determining string length. HRESULT: %08X WERDIAG: Memory allocation for event failed. WERDIAG: Internal provider failed to log message. Win32 error: %08X WERDIAG: Internal log message WERDIAG: Failed reading the session settings of updating the process ID. HRESULT: %08X WERDIAG: Failed parsing settings string. HRESULT: %08X WERDIAG: Failed to enable logging. HRESULT: %08X FDR startedWERDIAG: Failed enabling trace provider. Win32 error: %08X FDR Tracing SessionWERDIAG: Invalid arguments: Log path cannot be null WERDIAG: Unable to allocate %d bytes for properties structure. WERDIAG: Failed copying string buffer. HRESULT: %08X WERDIAG: StartTrace failed for the internal provider. Win32 error: %08X WERDIAG: Failed enabling internal trace provider. Win32 error: %08X WERDIAG: Invalid args: The pair string cannot be null WERDIAG: Failed obtaining string length. HRESULT: %08X WERDIAG: Invalid format: expected '='. WERDIAG: Invalid args WERDIAG: Failed getting string length. HRESULT: %08X WERDIAG: Failed copying string. HRESULT: %08X WERDIAG: Invalid arguments: Buffer or separator character cannot be null WERDIAG: Invalid arguments: String buffer cannot be null WERDIAG: Failed obtaining the length of the input string. HRESULT: %08X WERDIAG: Out of resources allocating memory for string buffer WERDIAG: Failed making a copy of the original settings string. HRESULT: %08X WERDIAG: Failed copying characters to pair buffer. HRESULT: %08X WERDIAG: Invalid argument: GUID structure cannot be null WERDIAG: Invalid arguments: pointer to settings structure cannot be null WERDIAG: Invalid argument: settins string cannot be NULL WERDIAG: Failed extracting next token from settings string. HRESULT: %08X WERDIAG: Failed extracting next pair from the current token. HRESULT: %08X WERDIAG: Error parsing current pair; Ignoring pair and continuing parsing. HRESULT: %08X WERDIAG: Failed updating settings; Parsing continues. HRESULT: %08X WERDIAG: Log file size was not specified; Logging will not be enabled WERDIAG: Failed reading session settings, cannot delete log file. HRESULT: %08X %s_%dWERDIAG: Failed appending process ID to log file name. HRESULT: %08X WERDIAG: Failed deleting file. NTSTATUS: %08X WERDIAG: Session settings and/or FDR layer were not deleted successfuly. HRESULT: %08X Software\Microsoft\Windows\Windows Error Reporting\Plugins\FDR\CurrentSessionAppPathWERDIAG: Failed reading string value from registry. NTSTATUS: %08X Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LayersFDRWERDIAG: UtilRemoveAppCompatLayerFromList failed. HRESULT: %08X WERDIAG: PluginsNtSetRegStringValue failed. NTSTATUS: %08X WERDIAG: Failed opening session registry key. NTSTATUS: %08X WERDIAG: Invalid arguments; pointer to string buffer cannot be null SessionSettingsWERDIAG: Failed reading FDR settings value from registry. NTSTATUS: %08X LogPathWERDIAG: Failed reading log file path value from registry. NTSTATUS: %08X WERDIAG: Get current process ID failed ProcIDWERDIAG: Failed writing process ID to registry. NTSTATUS: %08X WERDIAG: StartFDR failed 0x%x FDR_FLUSH_MESSAGE%s-%dWERDIAG: Failed concatenating strings. HRESULT: %08X WERDIAG: Failed creating event. Win32 error: %08X WERDIAG: Failed setting event. Win32 error: %08X WERDIAG: Flushing done, done signal sent WERDIAG: Unexpected event response or failed waiting for event DFԓ@+f9vKtdgWERDIAG: AppRecorder: Failed creating AppRecorder thread. NTSTATUS: %08X Local\{DF2B7FCA-C5B0-4638-A4AD-59F7F76CE540}WERDIAG: AppRecorder: ProcessStartupSettingsUpdate failed. HRESULT: %08X %d-AppRecorderEnabledWERDIAG: AppRecorder: Failed creating apprecorder event name string. HRESULT: %08X WERDIAG: AppRecorder: Failed creating event. Win32 error: %08X WERDIAG: AppRecorder: Failed to get temp folder path. Win32 error: %08X WERWERDIAG: AppRecorder: Failed to get temp file name. Win32 error: %08X .AppRecorderData.xmlWERDIAG: AppRecorder: Failed to create temp file name. HRESULT: %08X WERDIAG: AppRecorder: Failed to create apprecorder temp file. Win32 error: %08X WERDIAG: AppRecorder: Failed to register the log file with WER. HRESULT: %08X WERDIAG: AppRecorder: Failed to get system folder path. Win32 error: %08X \psr.exeWERDIAG: AppRecorder: Failed to create UAR executable image path. HRESULT: %08X %s /start /output %s /gui 0 /recordpid %d /stopevent %s /sc 0 /noarc 1 /waitonpid 1WERDIAG: AppRecorder: Failed to create UAR process command line. HRESULT: %08X WERDIAG: AppRecorder: Failed to create UAR process. Win32 error: %08X WERDIAG: AppRecorder: Failed getting current user registry path. NTSTATUS: %08X Software\Microsoft\Windows\Windows Error Reporting\Plugins\AppRecorderWERDIAG: AppRecorder: AppRecorder settings key is not present. NTSTATUS: %08X AppRecorderEnabledWERDIAG: AppRecorder: AppRecorder enabled flag is not present. NTSTATUS: %08X AppRecorderCountWERDIAG: AppRecorder: Failed to get current process name. Win32 error: %08X WERDIAG: AppRecorder: Failed to open App Recorder layer key. NTSTATUS: %08X WERDIAG: AppRecorder: Failed to get application appcompat layers. NTSTATUS: %08X AppRecorderWERDIAG: AppRecorder: Failed to update application appcompat layers. NTSTATUS: %08X WERDIAG: AppRecorder: Failed to update App Recorder run count. NTSTATUS: %08X WERDIAG: Invalid parameters WERDIAG: SizeTAdd failed. NTSTATUS: %08X WERDIAG: Arithmetic operation failed. NTSTATUS: %08X WERDIAG: Insufficient resources %s\%sWERDIAG: Key: %S WERDIAG: Out of resources allocating memory for key information structure WERDIAG: Failed extracting registry value %S. NTSTATUS: %08X WERDIAG: Failed writing to value %S. NTSTATUS: %08X WERDIAG: Failed writing to value %S. NTSTATUS %08X WERDIAG: NtQueryInformationProcess failed. NTSTATUS: %08X WERDIAG: Invalid size returned. NTSTATUS: %08X WERDIAG: Registry value %S is not of type string WERDIAG: Failed determining string buffer length. HRESULT: %08X WERDIAG: Failed with integer overflow \RSDS)5_J@h|uYYuu YFhuYYuu YM3[^]̋U<3ʼnESVu3WM̍}j3]uĉ]؉]܉]YuhT%Sh W9td0=dhSp׉Eȅuh#Sh d0hSp׉EЅuh#Sh {9]"E܋Pj;^}e}e3td0SjpeEPj,M]؅tDuЋˋ}VWyPh0&EPEPVWyPh&jh}yujY}̋}̋uă>Eԅt:G3MVh%jh]؃2Vh%jhh&jh @td0S3Sp3ۃ}tud0Spud0SpEЅtPd0SpƋM_^3[<]̋U0S33VWMԍ}ثىMfMMM3fEEPEPyVh 'ShA::d0hjpd؅u!h#Ph }d}p Wht'hS]y Vh'SEPjjEPuEE3ɉE܍EԉMPE@MMEEPĐEyPh'jhuyVh'jh3td0Wjp}tud0jptd0Sjp_^[]̋U$SV33WfEލEuuPfu]u}ȐEP(PVujYy VhjMEP(]u̐EH)PjujY[xMEPyVh`뒍EPQM)yVh)jh}b}t 3f9tMWy Vh*$SEPEPu3?Vh)3Phy}t'SEPEPu}t u̐td0S3Sp}3ۋEtPd0Sp}td0WSp_^[]̋U3VWfE3E}P}f}ȐEP(PWu yVhX*Wh uP9}t u̐_^]̋UV3W3fE}}f}9E9E EPȐEP(PWujYI yVh~uM*yVh+`u ML+wyVh`+Bd@ uh+Wh @3M+PyVh+Wh9}t u̐h*Wh W_^]̋U<3ĉ$8SVWL$yVh(,jhhd3hSp d0pduh#Sh $VhH,hl,hW*yVhx,ShWSSS8u<Ph,tL$ÅtT$09u@Iu4%HP(=uWL$3ɅɁwQVӅuV0u><Ph,3Sh@2hH-3Sh@h-3Sh d0WSp$D_^[3]̋UE V3t=vWx7S]3WxEPuWS|x;wu z3f{_[ tM3f^]̋U3tvWx} vWu uQ t3f]̋UW3t'E SVu+tft fNJu^[uz3f_] ̋U3tvWxhuQ t3f]̋UES3ۅt3VWˋf9tNuuWt x+8_^Wyt[]̋U W3}}}tRVEPEPWh_WWWWWjxyVh-Wh9}t uD^_]̋U 3ĉ$ SVW3D$$j@VPމt$,Q3t$|$ 3-f$WVhfD$tf$f$f$,8WjVVӅu @=yPhX.Vh׃dp $h.hPyVh.jh׃n$3PVVVӋ؅u35<Ph(/Sh׃֋4&$Ph(u5<Phh/D$hPVh/$P$u5<Ph/vD$hP h0L$ly Vh@0jhjjjh@$Pu5<Ph0PDjjD$pPy Vh0$xVPu5<Ph01h1֍$|nyVh1I$P PPD$pP$Ph1$hP0yVh2jh׃D$D$ DP3D$$PVVVVVV$P$Pu-5<Ph2jh׃֋~3(9t$tt$Dt$9t$tt$Dt$t ySD$ _^[3w ]̋UV3W3fEE}P}f}ȐyPh03tLtZtGetTraceLoggerHandleGetTraceEnableLevelGetTraceEnableFlagsRegisterTraceGuidsWTraceEventEnableTraceStartTraceWjRtttt"Ex_ItuuWerDiagController.dllQueryOriginalBucketStartAppRecorderStartFDRN@D,ȇkrrrrrrrD2ؕʕvfVB4ʖ 4FZtĔҔ ēlP.Ȓlht^<*P<ZD2ؕʕvfVB4ʖ 4FZtĔҔ ēlP.Ȓlht^<hLdrDisableThreadCalloutsForDll"DbgPrintExBNtTerminateProcess2RtlUnhandledExceptionFilterNtCloseRtlFormatCurrentUserKeyPathRtlFreeUnicodeStringRtlInitUnicodeString?EtwEventWriteNoRegistrationZwUpdateWnfStateData%ZwQueryWnfStateNameInformationNtQuerySystemInformation[NtWaitForSingleObjectyNtOpenEventRtlAllocateAndInitializeSidNtAlpcConnectPortNtAlpcSendWaitReceivePortRtlFreeHeapRtlFreeSidRtlCreateUserThread(NtDeleteKey#NtDelayExecutionrLdrGetDllHandleRtlInitAnsiStringyLdrGetProcedureAddressRtlAllocateHeap_wcsnicmpgwcschrRtlGUIDFromString_wcsicmp_wtoi_vsnwprintfBRtlDosPathNameToNtPathName_U'NtDeleteFile+NtDeleteValueKey#isspace7memmoventdll.dllCloseHandleRReadProcessMemoryPGetLastErrorCreateEventWWaitForSingleObjectSetEventOpenEventWGetTempPathWGetTempFileNameW DeleteFileWCreateFileWWerRegisterFileGetSystemDirectoryWGetProcessId GetCurrentProcessCreateProcessWcGetModuleFileNameWKERNEL32.dll~NtOpenKeyNtQueryValueKey4NtSetValueKeyNtQueryInformationProcessDelayLoadFailureHookResolveDelayLoadedAPI5memcpy9memset0 H`4VS_VERSION_INFO@%@%?.StringFileInfo 040904B0LCompanyNameMicrosoft Corporation\FileDescriptionWER Diagnostic Controllerr)FileVersion6.3.9600.16384 (winblue_rtm.130821-1623)TInternalNameWER Diagnostic Controller.LegalCopyright Microsoft Corporation. All rights reserved.TOriginalFilenameWERDiagController.dllj%ProductNameMicrosoft Windows Operating SystemBProductVersion6.3.9600.16384DVarFileInfo$Translation 0H0L0099M:R:`:l:r:z:::::::::::;;;#;);2;:;G;^;;;;;;< <<>0><>>>???????@d0,0G0y000000000 11-1@1P1k111111122#2B2K2P2U2b2h2n2z222222293E3O3h3t33333333444(4d4j4t44444444445.5D5M5d5n5a6666677%7>7D7777X8_888888-9@9L9X999999999999999::":G:a:g:p:z:::::::::;#;<;T;u;{;;;;;; <9p>}>>>>>>>>>?T?a?r?????P<00)060I0V00000000 141A1W1z1111 2)292F2h2u222/3;3R3_3333333333434e4q444444G55555666&636R6o6667 727=7I7k77777777 8868P8f888889 979R9_999999999:0:H:|::::::;;5;B;S;`;q;;;;;;;;;<:?????`<080j0x0000011H1R1Z1j1x1111111111 2212;2C2M2g2w2~22222343H3[3333333344)4F44444445(525:5F5n555556"6766666757D7w7777788@9K9W9r99999999999:E:k:t:::::;;=;J;_;h;t;;;;;;3>>>J>n>{>>>>>???8?E?\?i?????ph"0(0.040:0@0G0N0U0\0c0j0q0y000000000000011)141;1V2b2l2~22222222233$3l3x30@0D0H0L0P0T0X0