MZ@ !L!This program cannot be run in DOS mode. $|/////1f%//1f //1f#//1f$//1f=//1f'//1f"//Rich/PEd/R"  t"P=}2` <04 ;́@.textst `.data x@.pdataz@@.idatal ~@@.rsrc0@@.reloc@B~/R.;/@ADVAPI32.dllGuidLevelFlagsCircularSizeWERDIAG: Verifier.dll loaded. Enabling Autoverifier. WERDIAG: ProcessStartupSettingsUpdate failed. NTSTATUS: %08X WERDIAG: FDR will be enabled WERDIAG: Stopping Autoverifier WERDIAG: Stopping FDR WERDIAG: AutoVerifier: Failed getting current user registry path. NTSTATUS: %08X WERDIAG: AutoVerifier: Path is: %S Software\Microsoft\Windows\Windows Error Reporting\Plugins\AutoverifierWERDIAG: AutoVerifier: Subkey is: %S WERDIAG: AutoVerifier: could not open settings key. NTSTATUS: %08X AutoverifierEnabledWERDIAG: AutoVerifier: could not read enabled flag. NTSTATUS: %08X WERDIAG: AutoVerifier: Enabled flag: %u \Registry\Machine\Software\Microsoft\Windows\Windows Error ReportingWERDIAG: Failed opening registry key. NTSTATUS: %08X ErrorPortWERDIAG: PluginsNtGetRegStringValue failed. NTSTATUS: %08X WERDIAG: SignalStartWerSvc failed NTSTATUS: %08X WERDIAG: NtQuerySysInfo(ErrorPortTimeouts) failed. NTSTATUS: %08X WERDIAG: WaitForWerSvc failed %08X. NTSTATUS: %08X WERDIAG: WaitForWerSvc timed out, failing the call with NTSTATUS: %08X WERDIAG: RtlAllocateAndInitializeSid failed. NTSTATUS: %08X WERDIAG: NtAlpcConnectPort failed. NTSTATUS: %08X WERDIAG: NtAlpcConnectPort timed out, failing the call with NTSTATUS %08X WERDIAG: NtAlpcSendWaitReceivePort failed. NTSTATUS: %08X WERDIAG: Service returned failure status. NTSTATUS: %08X WERDIAG: Failed getting current user registry path. NTSTATUS: %08X Software\Microsoft\Windows NT\CurrentVersion\Image File Execution OptionsWERDIAG: Handle to registry key is null WERDIAG: Failed getting process name. NTSTATUS: %08X AutoverifierAutoVerifierCountWERDIAG: Failed reading key value. NTSTATUS: %08X WERDIAG: Failed writing registry value. NTSTATUS: %08X OriginalBucketAutoVerifierTimeDurationWERDIAG: Failed creating timer thread. NTSTATUS: %08X WERDIAG: Failed deleting autovefier enabled flag. NTSTATUS: %08X WERDIAG: Failed writing key value \Registry\Machine\SYSTEM\CurrentControlSet\Control\Session ManagerImageExecutionOptionsWERDIAG: Not disabling HKCU IFEO look-up because its statically enabled. WERDIAG: Thread failed to wait for the specified time; Disabling autoverifier. NTSTATUS: %08X verifier.dllWERDIAG: Failed obtaining verifier.dll handle. NTSTATUS: %08X VerifierForceNormalHeapWERDIAG: Failed obtaining VerifierForceNormalHeap function address. NTSTATUS: %08X WERDIAG: Failed switching to normal heap mode. NTSTATUS: %08X WERDIAG: Verifier switched to light mode \KernelObjects\SystemErrorPortReadyu: AnT DWERDIAG: Invalid params WERDIAG: Arithmetic overflow WERDIAG: OOM WERDIAG: Failed creating FDR thread. NTSTATUS: %08X WERDIAG: GetTraceLoggerHandle failed WERDIAG: GetTraceEnableLevel failed WERDIAG: GetTraceEnableFlags failed WERDIAG: Internal provider enabled for Level %u, Flags %lu WERDIAG: Tracing disabled for internal provider WERDIAG: Provider not registered. RegisterTraceGuids failed with %d WERDIAG: Internal provider: FDR did not start yet; Message lost WERDIAG: Failed determining string length. HRESULT: %08X WERDIAG: Memory allocation for event failed. WERDIAG: Internal provider failed to log message. Win32 error: %08X WERDIAG: Internal log message WERDIAG: Failed reading the session settings of updating the process ID. HRESULT: %08X WERDIAG: Failed parsing settings string. HRESULT: %08X WERDIAG: Failed to enable logging. HRESULT: %08X FDR startedWERDIAG: Failed enabling trace provider. Win32 error: %08X FDR Tracing SessionWERDIAG: Invalid arguments: Log path cannot be null WERDIAG: Unable to allocate %d bytes for properties structure. WERDIAG: Failed copying string buffer. HRESULT: %08X WERDIAG: StartTrace failed for the internal provider. Win32 error: %08X WERDIAG: Failed enabling internal trace provider. Win32 error: %08X WERDIAG: Invalid args: The pair string cannot be null WERDIAG: Failed obtaining string length. HRESULT: %08X WERDIAG: Invalid format: expected '='. WERDIAG: Invalid args WERDIAG: Failed getting string length. HRESULT: %08X WERDIAG: Failed copying string. HRESULT: %08X WERDIAG: Invalid arguments: Buffer or separator character cannot be null WERDIAG: Invalid arguments: String buffer cannot be null WERDIAG: Failed obtaining the length of the input string. HRESULT: %08X WERDIAG: Out of resources allocating memory for string buffer WERDIAG: Failed making a copy of the original settings string. HRESULT: %08X WERDIAG: Failed copying characters to pair buffer. HRESULT: %08X WERDIAG: Invalid argument: settins string cannot be NULL WERDIAG: Failed extracting next token from settings string. HRESULT: %08X WERDIAG: Failed extracting next pair from the current token. HRESULT: %08X WERDIAG: Error parsing current pair; Ignoring pair and continuing parsing. HRESULT: %08X WERDIAG: Failed updating settings; Parsing continues. HRESULT: %08X WERDIAG: Log file size was not specified; Logging will not be enabled WERDIAG: Failed reading session settings, cannot delete log file. HRESULT: %08X %s_%dWERDIAG: Failed appending process ID to log file name. HRESULT: %08X WERDIAG: Failed deleting file. NTSTATUS: %08X WERDIAG: Session settings and/or FDR layer were not deleted successfuly. HRESULT: %08X Software\Microsoft\Windows\Windows Error Reporting\Plugins\FDR\CurrentSessionAppPathWERDIAG: Failed reading string value from registry. NTSTATUS: %08X Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LayersFDRWERDIAG: UtilRemoveAppCompatLayerFromList failed. HRESULT: %08X WERDIAG: PluginsNtSetRegStringValue failed. NTSTATUS: %08X WERDIAG: Failed opening session registry key. NTSTATUS: %08X WERDIAG: Invalid arguments; pointer to string buffer cannot be null SessionSettingsWERDIAG: Failed reading FDR settings value from registry. NTSTATUS: %08X LogPathWERDIAG: Failed reading log file path value from registry. NTSTATUS: %08X WERDIAG: Get current process ID failed ProcIDWERDIAG: Failed writing process ID to registry. NTSTATUS: %08X WERDIAG: StartFDR failed 0x%x FDR_FLUSH_MESSAGE%s-%dWERDIAG: Failed concatenating strings. HRESULT: %08X WERDIAG: Failed creating event. Win32 error: %08X WERDIAG: Failed setting event. Win32 error: %08X WERDIAG: Flushing done, done signal sent WERDIAG: Unexpected event response or failed waiting for event DFԓ@+f9vKtdgWERDIAG: AppRecorder: Failed creating AppRecorder thread. NTSTATUS: %08X Local\{DF2B7FCA-C5B0-4638-A4AD-59F7F76CE540}WERDIAG: AppRecorder: ProcessStartupSettingsUpdate failed. HRESULT: %08X %d-AppRecorderEnabledWERDIAG: AppRecorder: Failed creating apprecorder event name string. HRESULT: %08X WERDIAG: AppRecorder: Failed creating event. Win32 error: %08X WERDIAG: AppRecorder: Failed to get temp folder path. Win32 error: %08X WERWERDIAG: AppRecorder: Failed to get temp file name. Win32 error: %08X .AppRecorderData.xmlWERDIAG: AppRecorder: Failed to create temp file name. HRESULT: %08X WERDIAG: AppRecorder: Failed to create apprecorder temp file. Win32 error: %08X WERDIAG: AppRecorder: Failed to register the log file with WER. HRESULT: %08X WERDIAG: AppRecorder: Failed to get system folder path. Win32 error: %08X \psr.exeWERDIAG: AppRecorder: Failed to create UAR executable image path. HRESULT: %08X %s /start /output %s /gui 0 /recordpid %d /stopevent %s /sc 0 /noarc 1 /waitonpid 1WERDIAG: AppRecorder: Failed to create UAR process command line. HRESULT: %08X WERDIAG: AppRecorder: Failed to create UAR process. Win32 error: %08X WERDIAG: AppRecorder: Failed getting current user registry path. NTSTATUS: %08X Software\Microsoft\Windows\Windows Error Reporting\Plugins\AppRecorderWERDIAG: AppRecorder: AppRecorder settings key is not present. NTSTATUS: %08X AppRecorderEnabledWERDIAG: AppRecorder: AppRecorder enabled flag is not present. NTSTATUS: %08X AppRecorderCountWERDIAG: AppRecorder: Failed to get current process name. Win32 error: %08X WERDIAG: AppRecorder: Failed to open App Recorder layer key. NTSTATUS: %08X WERDIAG: AppRecorder: Failed to get application appcompat layers. NTSTATUS: %08X AppRecorderWERDIAG: AppRecorder: Failed to update application appcompat layers. NTSTATUS: %08X WERDIAG: AppRecorder: Failed to update App Recorder run count. NTSTATUS: %08X WERDIAG: Invalid parameters WERDIAG: SizeTAdd failed. NTSTATUS: %08X WERDIAG: Arithmetic operation failed. NTSTATUS: %08X WERDIAG: Insufficient resources %s\%sWERDIAG: Key: %S WERDIAG: Out of resources allocating memory for key information structure WERDIAG: Failed extracting registry value %S. NTSTATUS: %08X WERDIAG: Failed writing to value %S. NTSTATUS: %08X WERDIAG: Failed writing to value %S. NTSTATUS %08X WERDIAG: NtQueryInformationProcess failed. NTSTATUS: %08X WERDIAG: Invalid size returned. NTSTATUS: %08X WERDIAG: Registry value %S is not of type string WERDIAG: Failed determining string buffer length. HRESULT: %08X WERDIAG: Failed with integer overflow RSDS[G!rMWerDiagController.pdbH(u YuY/ YYY=YtLQLdyuLyLD3ҹYuYLP-u%fY!vuc=TYu3LtH D[HtFtH%1[6=Yu-Lgtu H RIH(Hl$Ht$WH IHuE33u= ]u<\LƋHHl$0Ht$8H _WH\$UVAVHH@33HMHu(fuHEEfEsy LLMLsL LsLEE3EqHE(HAHD$ 3yL~$HM(LE H_5yLD3PsD9u LADD1sHM(HtrH9utHMrHM3rH\$pH@A^^]HHXHxL`Lp UHHp HPH3H` E33HHEEfEHEEt$E3E3ALd$`Ld$hLeLd$pDe@fEDLefDeHD$ 1HMqyLD3ҹ=rHMLD$`H/8؅y LKLMH vE3AAD$ oqx0D9et*Dd$0H IE3E33Dd$(Ld$ IqAI3HUHH &E3E3HEHHEP*quAAE܅yDLE3HT$xEAAIsp؅y LHc\$xHiLEHEHEHMEFHE0HELeDeLe Le(lpx7„u HiHMHMLEME3CpHMwp߅yDLGuASLeAHT$`HM0pHD$pE3HD$PDd$HDd$@Dd$8Dd$0EAHM@ADd$(Dd$ o؅y LMr|$|E0LeDeLeLeLeuHcD$|HiHMHD$pH}IELEHU0H|$PLd$HLd$@Ld$8Ld$0HD$(HL$hE3D$ o؅y L=uASLAAxHM`3Er<HE3E`PxDžDI<HL$hH|$8HELd$0HD$(HLE`E3ɺDžPxHD$ LuWn؅x4=t-DEyL3ҹnALD3ҹnL9d$`teH %`LD$`3HI0mHL$pHt =mLd$pHL$hHt  nLd$hHMHtlH` H36L$p I[I{Mc Ms(I]HL$USWAVHl$HE33H ^T3ALuLuLuwLu'HE/fDuHEE!fE%LufD5RL5T:HM`m؅yLD3ҹmLEE3HEAIH(HD$ ,HM my DLLMMuL3ҹ=mDfD95sQu1؅y LgLMHEHKQE3HD$ e,؅yDLMHEwHE3HD$ 9,؅xHMwLEgHx.؅y L}gv&HMwDGHJ/؅y LHMwLEHc2xbLEH RL+EHHtAft fHHuHu HAfD1ZREɹ1CVAIIRHMwLEoHb-؅y LrEot}HiȀigHE'E3HD$HHQH THD$@HSE3HD$8HC3HD$0HLt$(Lt$ L5Q)j؅yLD3ҹLk<w4HMwjHMiyLD3ҹkAL9uteH %`LE3HI0iHMHtjHMHtjHMwHtrjHĈA^_[]HL$USWHH@33HMH}0H}(f}HEEfE} j؅y L-LEE3HE0AIHHD$ )؅yLD3ҹ)jHM0HYE3A-؅yLD3ҹi`E3HE(HOAIE3HD$ J)x6HM(LE H+x9} tLiHM(Ht6iHM0Ht'iH9}tHMiHM3hH@_[]H\$UVWHH@33H3fuHEEfEfuHEEfEgyLtD3ҋhHHMvhLM(LE33g؅y L3ҋQHHMgHM(LM0HUE3{g؅y LHU(HU03ҋϋ؅yLD_hLFPhދH\$`H@_^]@SVWH`H>FH3H$PH,IAH+H\NLD$@HHD$0AHD$ ~f3ujf NH|$0t+~|$@1CVAt mHGAI;A HAGɅx@΅t/LL$DL+L+IHtAft fHHuHuHtf3H$PH3/H`_^[H\$Hl$Ht$WATAUAVAWH E3IHLEAH`HHfD9,AuJH;HH;eH %`D3HI0D~eHHHuLD3ҹofM3HV3f Dvf;uEAEHf93ttfD9+t f7AHHAHduHCfuI;t v fD9kuHftHfHEfufD/A9L[3ҹeLMteH %`3HI0dL.L3ҹieWH\$PHl$XHt$`H A_A^A]A\_LSH`IcIc3ICICE3ICICE3ICIcHICIcIc3Hc؅yLD3ҹd3ۋH`[@SH0tH%ML^ICHLHuL3ҹjdNHB؄u LH LB3ҹu LLDˉD$ d3H0[HHXHhHp HPWH 3H9-SLuL:3ҹc!H f9)t HHuHeH %`H+3HI0H\$8ffDqbHHu LRL3Ha0LD$8fG,HO4HGNEGG00H KHAtLD3ҹbLP3ҹbeH %`LHI03aLbAW3ҹbH\$0Hl$@Ht$H3H _H\$Hl$Ht$WH033H91vbHk|+ uOH DD+T+LKHD$ L@3ɅL+ tLD3ҹb;;rH\$@Hl$HHt$P%@H0_H\$Hl$Ht$ WATAUAVAWH0E3H LLLHuL}aWIAًfD9 t HHuHu WIHH+HL$`yDL3ҹGaHLAfE9t IHuHu WIH+…xI=L$E3A,LeH %`HI0DD_HHuDL{M3H-HT$`/G,AL$xo(M5OpG@GtxHGAFgDH‰GtLD3ҹ`@bHL AՋHD$ >؅t3LD3ҹ_ˁN˻@Iˋ I'3eH %`L3HI0^H\$hHl$pHt$xH0A_A^A]A\_H\$Hl$Ht$WATAUAVAWH E3ILHMLt$pMAHAAfD9!t HHuWHuIIH+y LK?=I]HHu La;HI+HHHH;Ht ILEfE9 t IHuHu)IDEy&LH3ҹk^@IH+AAzI;v;AAI+HItB2ft fAIIuMuIAfE&xKHQI;v6AL+HBHtA?ft fHHuHuHAfD'yLD3ҹ]ALI3ҹ]ދL3ҹj]WH\$PHl$XHt$`H A_A^A]A\_H\$UVWATAUAVAWH0E3MLMuLL3ҹ]WHHu LvغA܋fD9 t HHuWHuIHH+IHH$yLmD3ҹ\/eH %`HE3HI0LH$X[HHuLq3ҹL\L$MHMeI ؅yDLpH[eH %`MHI0H3H+HD$ HHHuQZeH %`L$HI0E33M.ZIHLIH؅yDoZIu8E3M.AeH %`L3HI0qZH\$pH0A_A^A]A\_^]H$E3M.H;sReH %`H+3HI0L]ZIHtXLD$ HSHI؅yDLH_eH %`L?3HI0YHIHuL3ҹZ HAHWGޅxQHvIAHt-LH+L+H:HtAft fHHuHu HzfD) HtfD(DL3ҹ ZH\$Hl$Ht$WH0HHrIHIY3u33HL$ Hfl$ HD$"D$*fD$.BYHL$ HXhH3HYuHXFFH!HpYuHsXF$HHNYuHQXHL$`H\$@Hl$HHt$P3H0_H\$UVWATAUAVAWHl$HH 7H3HE3LLHMDC3H]H]]lj]%MuL3ҹXWI9teH %`3AHI0rWLHuL3ҹfXeH %`3AHI01WLHuLJ3ҹ%XHuI9LE;I؅3H9]DDCHM3H]$HteH %`LE3HI0VH]LEHM,[؅ Hu3HtPMHLd$ y LC&HELMMIIHD$ NyL{D3ҋ6WH9]]MEEEf~EMׅu/HMHH fuH0fuHE8u Hr?AHkBT9EBD9 EBD9EBD9EBD9E BD9EBD9 AI9EDžt6AGFL D3ҋtVHu,LD3ҋZVL3ҋGV@3HteH %`LE3HI02UH9}teH %`LE3HI0UeH %`M3HI0TMteH %`M3HI0THMH3(H$HĠA_A^A]A\_^]H\$Ht$ HL$UWAVHHpE3HM3EF(Duj"3fDuHE‰EfELu Lu0ALE HU0؅y!LD3ҹ U eH %`3HI0ASHHuL3ҹTeH%0LM LH@L$ H ؅yDLHMHTHMHUE3E3SHEHMHEE0LuE@LuLuvSHMSyLD3ҹTyDL3ҹSAL9u teH %`LE 3HI0RL9u0teH %`LE03HI0RHteH %`L3HI0RL\$pI[(Is8IA^_]HL$USVWAVAWHHXE33HML}8fD}HEډEfEAL}PEL}@AL}HRLEHE8HMAOE3HD$ ؅y L7HM8LEPHHuP؅HHM8}RLEE3HE8AIHHD$ !؅xHM8LE@H؅y LRD3ҹzRLu@Lu@MtHUHMIEH}HLҽ3ҹ=RWyLD3ҹRdHt$fD9?tHM8LH؅y$L'HMH}QHM8HUQA@LD3ҹQy!L9}8t*HMH8QHM8HUPHM8Ht3QHt!eH %`LEP3HI0uPLu@H}HMteH %`LE@3HI0OPH}HHteH %`LEH3HI0-PHXA_A^_^[]LI[IKWH@33IKf|$0ICD$:fD$>I{|PLD$8HD$PHE3ɹHD$ %؅yLD3ҹP HL$PKOHL$PHt!PH\$XH@_H\$Ht$HL$UWAVHH@3E3IHLu fDuHEEfEHMHMOLEHE H ANE3HD$ [؅y LRHM HL؅y LlHM HL؅y LJeH%0D@@EuL 3ҹkO@6HM H)؅yL/D3ҹ7OAHM HtNL3ҹOWH\$hHt$pH@A^_]HHXHpHxUHXHH,H3HHd$@Hd$HHHHL$`3A LD$HHT$@ Ht$H؅yLHT$@HL$`=3ҋ؅yL"Hd$XHHHD$PHLHD$8Hd$0Hd$(HD$PH ;AHD$ r,tLںD3ҋMHL$`H؅yLü3DȋM3HteH %`LD$H3HI0LH|$@teH %`LD$@3HI0dLyLqD3ҋDHt*L+L+IHtAft fHHuHuHAzHtfH\$A@SH`Hd$pHd$P3HD$Xt{HD$PE3E3HD$HHD$p3HD$@Hd$8HaHD$0Hd$(Hd$ HH؅yLD3ҹ J3HL$pHtHH`[HHXHpHxUAVAWHH@ H'H3H0 3HL$x3DF`t$p3L3ҹHt$PHD$XHD$`ffuff fGH1L HDF33GHu @!:AyLuD3AHeH%0ALDH@HAN؅yLD3AHLE333*GHHu4$GL3DAH G؁NdH AFuFLLMH H E3FuFLHM]FL6HM؅y LKHt$0HMDCE3ɺ@D$(\$ FHu6FLW6H1FHMAE؅y LHAEuELLHI؅y LRLEHKEHLHL$0D$(HEL)HIHD$ U؅yLD3AFHD$PHHHD$HHD$pE3HD$@Ht$8Ht$0E3t$(D$pht$ Du1DLD3AVFD؁N,HL$PHt DHt$PHL$XHt DHt$XHt y HDH0 H3YL$@ I[ Is(I{0IA_A^]H\$UVWHH@33HMH}(f}HEEfEBEy LNLEE3HE(AqH_HD$ y LHM(LE H>yL7D3ҹ/E9u DHM(HtDH9}tHMDHM3DH\$pH@_^]HHXHpHxUATAUAVAWHHHH"H3HE33HL$PALl$0Ll$@Dl$8fDl$PHD$RH\$HD$ZfD$^A@fDl$pDy LLD$XHD$0H-E3ɹHD$ y LHL$0LD$8HZy LDD$8HL$0AZBHT$pA3Au9VBL73DȹC9BDADNULD$XE3HD$@AIHHD$ y L.HL$@LD$HHT$pY y!LZD3ҹ2CH\$HH\$HHHfD9,su ADfHlA H CAu0tG CBtG D CBufF9,{t A;wF명OG D;rfD,K.+ׅtDFH H K DFH HHSMAHT$pfD9+HL$`AHL$@HT$`yAEHL$0HtAHL$@HtAHteH %`LD$H3HI0AL9l$XtHL$PAHL$P3xAAHH36 L$I[0Is8I{@IA_A^A]A\]HL$@LWLHA7LYD3ҹaAH\$H|$3HBLH=WDDGILEx)IDMtf99t HHuHtML+DLExQIK CDI+t5HI+MLH+Mt ftfIHHuHu HAzf9H\$H|$AH\$Ht$H|$UATAUAVAWHHp3ME3MLDfDMAHE‰EfEHHuPHLMIЋfD9 t HHuHxLIL+HfD9 t HHuHTH+JI;2HHH;HHHeH %`LHI0>HHuLK3ҹ~?$HLRMHHLt$ ؅y%LʺD3ҹ:?ہHHM>LML ?HeHeHELEAHE0LeHEE@>؅y[L;D3ҹ>DAL,A!ALAWLٯD3ҹq>3HteH %`L3HI0`=L}3ҹ8> L\$pI[0Is8I{@IA_A^A]A\]LI[IkVWAVH@33Mfl$0ICHD$:fD$>Hىl$hHHIKA(O=eH %`DEHI03<HHuL3ҹ=rHD$hHT$0LHD$(AHD$ :=؅xu G ALL3ҹD$ !=eH %`L3HI0<L63ҹ< H\$`Hl$pH@A^_^LI[IsECWH@33Hft$0ICHىD$:fD$>Ht\HtWIK$<DNHD$`DL$(HT$0E3HHD$ X<؅yLL3ҹD$ G<ދLp3ҹ+< H\$PHt$XH@_LI[IkIsWH@33Ifl$0ICHD$:fD$>HHtqHtlHtgIK\;HHf9,CuEHT$0AD$(E3HH\$ ;؅yLcL3ҹD$ o;݋L3ҹS; H\$PHl$XHt$`H@_H\$WH`H4H3H$PHL$233Af|$0LD$0W+AHH|$ :؅y Lf9D$0vL D~L$0HD$8Hf>C C5GD ʴ޸ &pXbXи(n\N@,̷ܷ@drжV2:Hhx:&ƵnV> ʴ޸ &pXbfLdrDisableThreadCalloutsForDll"DbgPrintExANtTerminateProcessRtlCaptureContext]RtlLookupFunctionEntryiRtlVirtualUnwind8RtlUnhandledExceptionFilterNtCloseRtlFormatCurrentUserKeyPathRtlFreeUnicodeStringRtlInitUnicodeString?EtwEventWriteNoRegistrationZwUpdateWnfStateData5ZwQueryWnfStateNameInformationNtQuerySystemInformationZNtWaitForSingleObjectxNtOpenEventRtlAllocateAndInitializeSidNtAlpcConnectPortNtAlpcSendWaitReceivePortRtlFreeHeapRtlFreeSidRtlCreateUserThread'NtDeleteKey"NtDelayExecutionpLdrGetDllHandleRtlInitAnsiStringxLdrGetProcedureAddressRtlAllocateHeap_wcsnicmpfwcschrRtlGUIDFromString_wcsicmp _wtoi_vsnwprintfJRtlDosPathNameToNtPathName_U&NtDeleteFile*NtDeleteValueKey!isspace6memmoventdll.dllCloseHandleVReadProcessMemoryVGetLastErrorCreateEventWWaitForSingleObjectSetEventOpenEventWGetTempPathWGetTempFileNameW DeleteFileWCreateFileWWerRegisterFileGetSystemDirectoryWGetProcessIdGetCurrentProcessCreateProcessWiGetModuleFileNameWKERNEL32.dll}NtOpenKeyNtQueryValueKey3NtSetValueKeyNtQueryInformationProcessDelayLoadFailureHookResolveDelayLoadedAPI4memcpy8memset0 H`4VS_VERSION_INFO@%@%?.StringFileInfo 040904B0LCompanyNameMicrosoft Corporation\FileDescriptionWER Diagnostic Controllerr)FileVersion6.3.9600.16384 (winblue_rtm.130821-1623)TInternalNameWER Diagnostic Controller.LegalCopyright Microsoft Corporation. All rights reserved.TOriginalFilenameWERDiagController.dllj%ProductNameMicrosoft Windows Operating SystemBProductVersion6.3.9600.16384DVarFileInfo$Translation HP0 x`hpx