MZ@ !L!This program cannot be run in DOS mode. $]?QQQQtRQtUQPRQtPQtQQtXQtQtSQRichQPELiW! f < I@Etd@8(98`.textJef `.dataj@.idata l@@.rsrc8x@@.reloc(~@B@0` 5<EFHpITT0gtGuidLevelFlagsCircularSizeu: AWERDIAG: Verifier.dll loaded. Enabling Autoverifier. WERDIAG: ProcessStartupSettingsUpdate failed. NTSTATUS: %08X WERDIAG: FDR will be enabled WERDIAG: Stopping Autoverifier WERDIAG: Stopping FDR WERDIAG: AutoVerifier: Failed getting current user registry path. NTSTATUS: %08X WERDIAG: AutoVerifier: Path is: %S Software\Microsoft\Windows\Windows Error Reporting\Plugins\AutoverifierWERDIAG: AutoVerifier: Subkey is: %S WERDIAG: AutoVerifier: could not open settings key. NTSTATUS: %08X AutoverifierEnabledWERDIAG: AutoVerifier: could not read enabled flag. NTSTATUS: %08X WERDIAG: AutoVerifier: Enabled flag: %u \Registry\Machine\Software\Microsoft\Windows\Windows Error ReportingWERDIAG: Failed opening registry key. NTSTATUS: %08X ErrorPortWERDIAG: PluginsNtGetRegStringValue failed. NTSTATUS: %08X WERDIAG: SignalStartWerSvc failed NTSTATUS: %08X WERDIAG: NtQuerySysInfo(ErrorPortTimeouts) failed. NTSTATUS: %08X WERDIAG: WaitForWerSvc failed. NTSTATUS: %08X WERDIAG: WaitForWerSvc timed out, failing the call with NTSTATUS: %08X WERDIAG: RtlAllocateAndInitializeSid failed. NTSTATUS: %08X WERDIAG: NtAlpcConnectPort failed. NTSTATUS: %08X WERDIAG: NtAlpcConnectPort timed out, failing the call with NTSTATUS %08X WERDIAG: NtAlpcSendWaitReceivePort failed. NTSTATUS: %08X WERDIAG: Service returned failure status. NTSTATUS: %08X WERDIAG: Failed getting current user registry path. NTSTATUS: %08X Software\Microsoft\Windows NT\CurrentVersion\Image File Execution OptionsWERDIAG: Handle to registry key is null WERDIAG: Failed getting process name. NTSTATUS: %08X AutoverifierAutoVerifierCountWERDIAG: Failed reading key value. NTSTATUS: %08X WERDIAG: Failed writing registry value. NTSTATUS: %08X OriginalBucketAutoVerifierTimeDurationWERDIAG: Failed creating timer thread. NTSTATUS: %08X WERDIAG: Failed deleting autovefier enabled flag. NTSTATUS: %08X WERDIAG: Failed writing key value \Registry\Machine\SYSTEM\CurrentControlSet\Control\Session ManagerImageExecutionOptionsWERDIAG: Not disabling HKCU IFEO look-up because its statically enabled. WERDIAG: Thread failed to wait for the specified time; Disabling autoverifier. NTSTATUS: %08X verifier.dllWERDIAG: Failed obtaining verifier.dll handle. NTSTATUS: %08X VerifierForceNormalHeapWERDIAG: Failed obtaining VerifierForceNormalHeap function address. NTSTATUS: %08X WERDIAG: Failed switching to normal heap mode. NTSTATUS: %08X WERDIAG: Verifier switched to light mode \KernelObjects\SystemErrorPortReadynT DWERDIAG: AppRecorder: Failed creating AppRecorder thread. NTSTATUS: %08X Local\{DF2B7FCA-C5B0-4638-A4AD-59F7F76CE540}WERDIAG: AppRecorder: ProcessStartupSettingsUpdate failed. HRESULT: %08X %d-AppRecorderEnabledWERDIAG: AppRecorder: Failed creating apprecorder event name string. HRESULT: %08X WERDIAG: AppRecorder: Failed creating event. Win32 error: %08X WERDIAG: AppRecorder: Failed to get temp folder path. Win32 error: %08X WERWERDIAG: AppRecorder: Failed to get temp file name. Win32 error: %08X .AppRecorderData.xmlWERDIAG: AppRecorder: Failed to create temp file name. HRESULT: %08X WERDIAG: AppRecorder: Failed to create apprecorder temp file. Win32 error: %08X WERDIAG: AppRecorder: Failed to register the log file with WER. HRESULT: %08X WERDIAG: AppRecorder: Failed to get system folder path. Win32 error: %08X \psr.exeWERDIAG: AppRecorder: Failed to create UAR executable image path. HRESULT: %08X %s /start /output %s /gui 0 /recordpid %d /stopevent %s /sc 0 /noarc 1 /waitonpid 1WERDIAG: AppRecorder: Failed to create UAR process command line. HRESULT: %08X WERDIAG: AppRecorder: Failed to create UAR process. Win32 error: %08X WERDIAG: AppRecorder: Failed getting current user registry path. NTSTATUS: %08X Software\Microsoft\Windows\Windows Error Reporting\Plugins\AppRecorderWERDIAG: AppRecorder: AppRecorder settings key is not present. NTSTATUS: %08X AppRecorderEnabledWERDIAG: AppRecorder: AppRecorder enabled flag is not present. NTSTATUS: %08X AppRecorderCountWERDIAG: AppRecorder: Failed to get current process name. Win32 error: %08X Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LayersWERDIAG: AppRecorder: Failed to open App Recorder layer key. NTSTATUS: %08X WERDIAG: AppRecorder: Failed to get application appcompat layers. NTSTATUS: %08X AppRecorderWERDIAG: AppRecorder: Failed to update application appcompat layers. NTSTATUS: %08X WERDIAG: AppRecorder: Failed to update App Recorder run count. NTSTATUS: %08X WERDIAG: Invalid params WERDIAG: Arithmetic overflow WERDIAG: OOM WERDIAG: Failed creating FDR thread. NTSTATUS: %08X WERDIAG: GetTraceLoggerHandle failed WERDIAG: GetTraceEnableLevel failed WERDIAG: GetTraceEnableFlags failed WERDIAG: Internal provider enabled for Level %u, Flags %lu WERDIAG: Tracing disabled for internal provider WERDIAG: Provider not registered. RegisterTraceGuids failed with %d WERDIAG: Internal provider: FDR did not start yet; Message lost WERDIAG: Failed determining string length. HRESULT: %08X WERDIAG: Memory allocation for event failed. WERDIAG: Internal provider failed to log message. Win32 error: %08X WERDIAG: Internal log message WERDIAG: Failed reading the session settings of updating the process ID. HRESULT: %08X WERDIAG: Failed parsing settings string. HRESULT: %08X WERDIAG: Failed to enable logging. HRESULT: %08X FDR startedWERDIAG: Failed enabling trace provider. Win32 error: %08X FDR Tracing SessionWERDIAG: Invalid arguments: Log path cannot be null WERDIAG: Unable to allocate %d bytes for properties structure. WERDIAG: Failed copying string buffer. HRESULT: %08X WERDIAG: StartTrace failed for the internal provider. Win32 error: %08X WERDIAG: Failed enabling internal trace provider. Win32 error: %08X WERDIAG: Invalid args: The pair string cannot be null WERDIAG: Failed obtaining string length. HRESULT: %08X WERDIAG: Invalid format: expected '='. WERDIAG: Invalid args WERDIAG: Failed getting string length. HRESULT: %08X WERDIAG: Failed copying string. HRESULT: %08X WERDIAG: Invalid arguments: Buffer or separator character cannot be null WERDIAG: Invalid arguments: String buffer cannot be null WERDIAG: Failed obtaining the length of the input string. HRESULT: %08X WERDIAG: Out of resources allocating memory for string buffer WERDIAG: Failed making a copy of the original settings string. HRESULT: %08X WERDIAG: Failed copying characters to pair buffer. HRESULT: %08X WERDIAG: Invalid argument: GUID structure cannot be null WERDIAG: Invalid arguments: pointer to settings structure cannot be null WERDIAG: Invalid argument: settins string cannot be NULL WERDIAG: Failed extracting next token from settings string. HRESULT: %08X WERDIAG: Failed extracting next pair from the current token. HRESULT: %08X WERDIAG: Error parsing current pair; Ignoring pair and continuing parsing. HRESULT: %08X WERDIAG: Failed updating settings; Parsing continues. HRESULT: %08X WERDIAG: Log file size was not specified; Logging will not be enabled WERDIAG: Failed reading session settings, cannot delete log file. HRESULT: %08X %s_%dWERDIAG: Failed appending process ID to log file name. HRESULT: %08X WERDIAG: Failed deleting file. NTSTATUS: %08X WERDIAG: Session settings and/or FDR layer were not deleted successfuly. HRESULT: %08X Software\Microsoft\Windows\Windows Error Reporting\Plugins\FDR\CurrentSessionAppPathWERDIAG: Failed reading string value from registry. NTSTATUS: %08X FDRWERDIAG: UtilRemoveAppCompatLayerFromList failed. HRESULT: %08X WERDIAG: PluginsNtSetRegStringValue failed. NTSTATUS: %08X WERDIAG: Failed opening session registry key. NTSTATUS: %08X WERDIAG: Invalid arguments; pointer to string buffer cannot be null SessionSettingsWERDIAG: Failed reading FDR settings value from registry. NTSTATUS: %08X LogPathWERDIAG: Failed reading log file path value from registry. NTSTATUS: %08X WERDIAG: Get current process ID failed ProcIDWERDIAG: Failed writing process ID to registry. NTSTATUS: %08X WERDIAG: StartFDR failed 0x%x FDR_FLUSH_MESSAGE%s-%dWERDIAG: Failed concatenating strings. HRESULT: %08X WERDIAG: Failed creating event. Win32 error: %08X WERDIAG: Failed setting event. Win32 error: %08X WERDIAG: Flushing done, done signal sent WERDIAG: Unexpected event response or failed waiting for event DFԓ@+f9vKtdgWERDIAG: Invalid parameters WERDIAG: SizeTAdd failed. NTSTATUS: %08X WERDIAG: Arithmetic operation failed. NTSTATUS: %08X WERDIAG: Insufficient resources %s\%sWERDIAG: Key: %S WERDIAG: Out of resources allocating memory for key information structure WERDIAG: Failed extracting registry value %S. NTSTATUS: %08X WERDIAG: Failed writing to value %S. NTSTATUS: %08X WERDIAG: Failed writing to value %S. NTSTATUS %08X WERDIAG: NtQueryInformationProcess failed. NTSTATUS: %08X WERDIAG: Invalid size returned. NTSTATUS: %08X WERDIAG: Registry value %S is not of type string WERDIAG: Failed determining string buffer length. HRESULT: %08X WERDIAG: Failed with integer overflow iW.:.iW HH:H.RSDSރ=:HGd=WerDiagController.pdbGCTL.rdata$brc(.cfguardh).rdata:x.rdata$zzzdbg;09.text$mnt.edata0.data$brc0.data@p.bss`.idata$5`.00cfgd,.idata$2.idata$3`.idata$4.idata$6`.rsrc$01`.rsrc$02UV3FW;Qܐ`uoh3ȡ` d d=htDhjW yPh0jW5`hpjh%h B'luZ95hu.hjhx tBP%x2=du)hjhYY%u M_^]̋UV3F} ujVj9u u=uuVu755uU Mq^] ̋USV33fEWE]P]f]y PhS|uhjh@Whjh E3ɋAPSu,yPh믋MEP<.yPhh뒃}u3FVhjh9]t u9]tEPSEP_^[]̋U, 03ʼnES3fEV3Wf3ɍPSSA] f+PyVhdShP0y Vhj'b yVh3WjPjsy Vh y VhduSPhSPPWWWWWWWjjEPy Vh}Džuꉅ #3WPPPPhPPPP y Vh uSPhXhP jP04@ hDž PhDž8PjP3 DžPhhW3WPPW Phx3t+9}hWhVhWhtd0S3Sp3ۃttt $M_^3[0]̋U,S33VWhSh]]]]؉]fE]f]]fpx2 EPyVh Sh E3PSuhA(EPyVhd뿋EuhSh f9pu,y Vh({EMpQPS'xE`PuSt'uMEP|})y Vh}v"MGP|G*y VhMEP p,]xS x 1CVAMEP,(yVhjh}vQjhig3Vu0EPhxhhEVVVVVj5xyVh`딃w1u u myPhjh3td0Sjp}t u}t u}t u_^[]̋U3VW3fEE}P}}f}}yVh WhE@PWujYu%yVhdɋM<Wq(yhWh OE3PWWA*%x1MEP9'x9}thjh 9}t u9}t u9}tEPWEP_^]̋U 03ʼnESVWu33WfE}f}fE}f}$yPhWShhEPEPEPWW(yVhWSahEP,EPWEPu0yVhuuj`֋yVh4htWS M_^3[+]̋U 03ʼnEE M-VuWRWRPQ4u~B 89t+)1CVAt UP M_3^*]̋UV3tv x?3t/S]W++ٍt ft fu_[ut3f^]̋U0VWjFXjHfE3XfEEEE؍EPhEEP}ԉ}܉}}x?uƺEUM#PWuXu_^]̋U03ʼnESVWjE3PSjWx9]tSSSSSSWxF3}SSEPhuFM3;_3%?^[R)]̋U W3}}}tRVEPEPWhpIWWWWWjyVhWh9}t u$^_]̋U 03ĉ$ SVWjD3ۍD$$SP*!\$|$ 3 HV33f$WhfD$tf$f$f$`VjWWlu @yPhWSdp $hhPyVh WSx$PWWWl؅u9PhxWh6($Phu9PhWhD$hPWh$PuPh먍D$hPh`L$lyVhWh`WhjWjh@$PuPh6P$jjD$pPyVh0 딾$xVP|uPh h ֍$|Cy Vh G$PDPPPD$pP$Ph@!$hPy Vh!D$D$ DPD$$PWWWWWW$P$P@uPh8"49|$tt$$|$9|$tt$$|$t yS$$ _^[3?%]̋UV3W3fEE}P}f}yPh"WhGE3PWu"AyPhh#΋MEP#yPh#뱃}u3F9}t u9}tEPWEP_^]̋U403ʼnES33VWff@PfyPh"Sh3"PSyPhh#ËP0$yPh#렋 hPS,u9PhX$Sh|$PSjY(y Ph0% Pd y Ph%ShNff;u+ Gj h%P uRt@PԐYt8PԐY3Ʌu f9utKS ;r%3fOLCN;{/+tuPWPOPBuPWPW 3f9PPP4t t td0WSptPSPM_^3[Q!]ËWnPh%Sh@QHP0$5PhH&̋UQSVډM3ҋWWtvx(Ëtf9tut+MxFӍ yj^+t-+Ë]+مt< ft f9Huuz3f_^[]̋UE V3t=vWx7S]3WxEPuWSĐx;wu z3f{_[ tM3f^]̋USVW3}_] TQff;u+<A;jYE;r Pd0Wp8;uh&Whu3PW!3Ƀ f9 j ZtEf9t}tf9t jXfMjh,3V u"Fftj Zf;u;t v 3f9Fu3ftfjX3@j Zf9u3f3h&Wh ;t3d 0Wq;h&WhW _^[]̋U VW3EPE}PWh0gWWWWWj}}yVh&Wh_^]̋UEth'P uuh'jh ^SRP؄uhD'55uhl'jh PPh'jh[3]̋UQQVW(E6P3@WW8xEPjh6WhT}tPh(Wh_^]̋UQ SVWuhP(jh E,*PyPh(jhEE6d0Wjp8؅uh(WjSXE{f36C,EPC4h,*PCC0S55tPh)jVhH)jV d0Sjp_^3[]̋UQQV3WEh PWE(, $ EPEPyVhh)jhAEPyVh)ՋuyVh)QQ'3}tud0jp}tud0jp_^]̋UQS3V3EW9v[{uG$G P7wj3GtQhD*jhFE@E;r_@^[]̋USVW3E ;{9}uh*Wh WMEP:yVh(WhjE*P xҋE EE=MAPEd0Wp8}u uh*P뛋uVjW}׋MEx 2zB,6uB(}JlB@Bpx@bDBuhE؋Pj;I}}3}}૫3td0SWp}܍EPj,Mx|]܅tDuȋˋ}VWyPh0EPEPVWyPhx0jh}uujY}ԋ}ԋuă>t!3&Vh/Wh]܃BEЅt G32Vhx/Wh3h0Wh @td0SWp}tud0Wpud0WpEȅtPd0WpƋM_^3[l]̋U0S33VWMԍ}ثىMfMMM3fEEPEPy"Vh1ShD}7d0hjp8؅uh-Ph d}p Wh\1hSbyVhh1jhSEPjjEPu@EE3ɉE܍EԉMPE@MMDEEPEyPh1jhuy Vh1d3td0Wjp}tud0jptd0Sjp_^[]̋U$SV33WfEލEuuPfu]u}E82PVujYWy VhdjMEP2 ]uE$PjujYxMEPN yVh뒍EPQMyVh83jh}b}t 3f9tMW> y Vh|3$SEPEPu43?Vh23Phy}t'SEPEPu4}t utd0S3Sp}3ۋEtPd0Sp}td0WSp_^[]̋U3VWfE3E}P}f}E82PWuyVh3Wh u 9}t u_^]̋UV3W3fE}}f}9E9E EPE82PWujYy VhdWhuM@4 yVh`4u M4yVh4d@ uh 5Wh @!M45Pmy VhH5c9}t uh3Wh W_^]̋U<03ĉ$8SVWL$yVh5jhhd3hSp d0p8uh-Sh $Vh5h5hW"yVh5ShWSSSlu%Ph6Sh@L$ÅtT$09u@u%HP(=uHL$c3ɅɁwQVduVhu)PhD6ph6Sh@hx6Sh d0WSp$D_^[3> ]̋U3tvWx} vWu uQ t3f]̋UW3t)E SVu+tft fNu^[uz3f_] ̋U3tvWxhuQ t3f]̋UES3ۅt5VWˋf9tuuWt x+8_^Wyt[]̋U0SV3Mډu3fufEuuWE09u.MEPNy$Vh(,jh~EPxˋUU;UB;jYr d0Vjp8uh7Ph Suh7VWy$Vh5jhWEP3:PhT7 Ph(7jhSEPu컖h7jSE EԍEE؍EEPuE@uuuHyVhdjS3td0Wjph7Vh _^[] ̋USVW33}fEf}}ES8EPd0jWp8uh7Ph UEPjWjEPVLxu M3G VSh8jhd0Wjph7Wh _^[]̋USVW3ۋ3]fEf]tGtCWEPjEPjSEPVPyVWh\8Shh7Sh _^[]̋USV3WfEEEfEtjtfut_WEP΍Qff;Eu+MPVj3PEPSP3yVWh8Phh7Ph _^[]̋U03ʼnEVWV3WP WVPj+jTyVh8Whf;v Vh93ҋfHB\t/t :t;wPp2yPh,cM_3^]̋USV33WfE]f]]]ldWEPd0hSp8؅uh7Ph EPhSjEPVLyVWh8jh{t Wh49jhUE{ PIy!Vhh9jhsEp;rOd0Vjp8Muh-Ph3W֋iyVh,3h9jh d0Sjph7Sh _^[]̋UVj^tvWx?3t/S]W++ٍt ft fu_[uzt3f^]̋USW3ۋÅt0w(Vtf9tut+W^WUt x_[]; 0uP̋U} uP3@] ̋Ujuh DPH]̋U$@ <8450=,fXf Lf(f$f% f-PEDEHETHL@ DPjXkǀTjX 0TjX 4TjXk 0LjX 4Lh]̋Uee0VWN@;t t У4jEPxE3EEL1E<1Et3EM3EEPXE3EM3;t50uO@ 0щ 4_^]̋D$L$ ȋL$ u D$S؋D$d$؋D$[%Ȑ%̐WWuttuFHTu0uAuWerDiagController.dllQueryOriginalBucketStartAppRecorderStartFDR,N@D Җ–r:(>RfƗܗƔ.~PhȘ֕$<Tr <JXn|К *:FXhștВ֔,*<TXxt̕ܐX"(@Ȓ$ؒ 4,`N0nHP֘ Җ–r:(>RfƗܗƔ.~PhȘ֕$<Tr <JXn|К *:FXhșUnhandledExceptionFilterSetUnhandledExceptionFilter GetCurrentProcessMTerminateProcessQueryPerformanceCounter GetCurrentProcessIdGetCurrentThreadIdGetSystemTimeAsFileTimeGetTickCountapi-ms-win-core-libraryloader-l1-2-0.dllapi-ms-win-core-errorhandling-l1-1-1.dllapi-ms-win-core-processthreads-l1-1-2.dllapi-ms-win-core-profile-l1-1-0.dllapi-ms-win-core-sysinfo-l1-2-1.dlliLdrDisableThreadCalloutsForDll"DbgPrintExntdll.dll_vsnwprintf_wcsnicmpisspace memmovepwcschr _wcsicmp_wtoimsvcrt.dllWerRegisterFileapi-ms-win-core-windowserrorreporting-l1-1-0.dllCloseHandleReadProcessMemoryGetLastErrorOpenEventWCreateEventW<GetTempPathW:GetTempFileNameW DeleteFileWCreateFileWGetSystemDirectoryWGetProcessIdCreateProcessWGetModuleFileNameWGetTraceLoggerHandleGetTraceEnableLevelGetTraceEnableFlagsRegisterTraceGuidsWTraceEventStartTraceW6WaitForSingleObject)SetEventapi-ms-win-core-handle-l1-1-0.dllapi-ms-win-core-memory-l1-1-2.dllapi-ms-win-core-synch-l1-2-0.dllapi-ms-win-core-file-l1-2-1.dllapi-ms-win-eventing-classicprovider-l1-1-0.dllapi-ms-win-eventing-controller-l1-1-0.dllEnableTraceapi-ms-win-eventing-legacy-l1-1-0.dllNtCloseRtlFormatCurrentUserKeyPathRtlFreeUnicodeStringRtlInitUnicodeString@EtwEventWriteNoRegistration ZwUpdateWnfStateDataZwQueryWnfStateNameInformationNtQuerySystemInformationnNtWaitForSingleObjectNtOpenEventRtlAllocateAndInitializeSidNtAlpcConnectPortNtAlpcSendWaitReceivePortRtlFreeHeapRtlFreeSid)RtlCreateUserThread0NtDeleteKey+NtDelayExecutiontLdrGetDllHandleRtlInitAnsiString{LdrGetProcedureAddress3NtDeleteValueKeyRtlAllocateHeapRtlGUIDFromString^RtlDosPathNameToNtPathName_U/NtDeleteFileNtOpenKeyNtQueryValueKeyGNtSetValueKeyNtQueryInformationProcess memcpy memset0 H`4VS_VERSION_INFO 98 98?&StringFileInfo040904B0LCompanyNameMicrosoft Corporation\FileDescriptionWER Diagnostic Controllern'FileVersion10.0.14393.0 (rs1_release.160715-1616)TInternalNameWER Diagnostic Controller.LegalCopyright Microsoft Corporation. All rights reserved.TOriginalFilenameWERDiagController.dllj%ProductNameMicrosoft Windows Operating System> ProductVersion10.0.14393.0DVarFileInfo$Translation 00D0P0X00|;;;;;;;;;<<"<4>0>e>>>>>>??#???Y?l???@|#0/0I00011"1<1U1p11111122'292C2Q2]2q22222223 373F3V3g3t3333333333334!404?4N44444444455+585R5`5o5z55555555 666&686D6V6d6k6s6666667 8?8J8d8|888889%919=9X99999:":::T:\:u::::::::::;;';-;:;?;Y;e;;;;;;;;;;; < <'<:<[<<<<<<< =*=6=J=Z=h=w=====>$>0>C>_>s>>>>>>>>>?;?G?????PD40V0i0000001 1'1:1)2222I3P333333)4<4H4T4444444444444455!5.5S5m5s5|5555555555$6/6H6`666666666.7;7W7v77778!8r8~888889499999999999!:d:q::::::;+;9;F;Y;f;;;;;;< <K>b>o>>>>>>>>>> ???,?L?~???????`80 0k000011.1:1F1R1o11112&2Q2\2h222222233353R3l3333334%4S4n4{444444455-5L5d55555550686Q6]6v66666666677?7`7m777777777888~888888888::;;;3;I;V;r;;;;;;;;<<+<4<@<<<<<<< ==(=4={======>A>P>\>l>x>>>>> ?\?t????p0$010>0R0d000000011)121>142l2u2222222222222222223333%3/393I3Y3_3j3p3|3333333344*474?444 0 `1