ElfFile%p AElfChnk%%TV6qrc!P/6^=f?mMF&V **X=  & \Dכ|ٖAM Eventjxmlns5http://schemas.microsoft.com/win/2004/08/events/eventoTSystemAY{Provider6F=KNameX)GuidAMzaEventID'X) Qualifiers " Version dLevelE{Task ?Opcode$fjKeywordsAP; TimeCreated'j<{ SystemTime .F EventRecordID A Correlation\FF ActivityIDmz5RelatedActivityID Am ExecutionHFF ProcessID9ThreadID "aChannelBF;nComputerWIN-00972SSK532AB.SecurityfLUserID !  <TK!=fBdMicrosoft-Windows-Crypto-DPAPI@NFMicrosoft-Windows-Crypto-DPAPI/Operational ⅖)⅖)ANDi6D EventDataAC^oData#= MasterKeyGUID A-^= UserStorage `D]ΌD˸O C:\Windows\system32\Microsoft\Protect\S-1-5-18\X**  &  <T!yCdMicrosoft-Windows-Crypto-DPAPI@NFMicrosoft-Windows-Crypto-DPAPI/Operational ⅖)` m2H"=lC:\Windows\system32\Microsoft\Protect\S-1-5-18\**  &  <T!yCdMicrosoft-Windows-Crypto-DPAPI@NFMicrosoft-Windows-Crypto-DPAPI/Operational ⅖)joSlN6XeC:\Windows\system32\Microsoft\Protect\S-1-5-18\User\**ḧ́(^ ioV iozZgAMsj5http://schemas.microsoft.com/win/2004/08/events/eventbAF=XAz      ? fA   AFFm AF  (FWIN-3PIMCL4OH3LA  !  <T!̈́(^0`Microsoft-Windows-Crypto-DPAPI@NFMicrosoft-Windows-Crypto-DPAPI/Operational ⅖)R\ DukC:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1242754773-2862960173-4029343502-500\h**XT,9 ioV   <T!T,9T8( Microsoft-Windows-Crypto-DPAPI@NFMicrosoft-Windows-Crypto-DPAPI/Operational ⅖).*-N:8 fC:\Users\Administrator\AppData\Roaming\Microsoft\Protect\S-1-5-21-1242754773-2862960173-4029343502-500\X**j*ZF#?C:\Windows\system32\Microsoft\Protect\S-1-5-18\**%  ioV   <T!  L(%Microsoft-Windows-Crypto-DPAPI@NFMicrosoft-Windows-Crypto-DPAPI/Operational ⅖)`6")M @-IC:\Windows\system32\Microsoft\Protect\S-1-5-18\