MZ@ !L!This program cannot be run in DOS mode. $L```\`*`*```*`*`*`*0`*`Rich`PELD! n$`t $c@A|h0:T.textjmn `.data r@.idata t@@.rsrc0@@.reloc@BH4: u:@rGHKKTTg@r`twPz{GuidLevelFlagsCircularSizeu: AWERDIAG: Verifier.dll loaded. Enabling Autoverifier. WERDIAG: ProcessStartupSettingsUpdate failed. NTSTATUS: %08X WERDIAG: FDR will be enabled WERDIAG: Stopping Autoverifier WERDIAG: Stopping FDR WERDIAG: AutoVerifier: Failed getting current user registry path. NTSTATUS: %08X WERDIAG: AutoVerifier: Path is: %S Software\Microsoft\Windows\Windows Error Reporting\Plugins\AutoverifierWERDIAG: AutoVerifier: Subkey is: %S WERDIAG: AutoVerifier: could not open settings key. NTSTATUS: %08X AutoverifierEnabledWERDIAG: AutoVerifier: could not read enabled flag. NTSTATUS: %08X WERDIAG: AutoVerifier: Enabled flag: %u \Registry\Machine\Software\Microsoft\Windows\Windows Error ReportingWERDIAG: Failed opening registry key. NTSTATUS: %08X ErrorPortWERDIAG: PluginsNtGetRegStringValue failed. NTSTATUS: %08X WERDIAG: SignalStartWerSvc failed NTSTATUS: %08X WERDIAG: NtQuerySysInfo(ErrorPortTimeouts) failed. NTSTATUS: %08X WERDIAG: WaitForWerSvc failed. NTSTATUS: %08X WERDIAG: WaitForWerSvc timed out, failing the call with NTSTATUS: %08X WERDIAG: RtlAllocateAndInitializeSid failed. NTSTATUS: %08X WERDIAG: NtAlpcConnectPort failed. NTSTATUS: %08X WERDIAG: NtAlpcConnectPort timed out, failing the call with NTSTATUS %08X WERDIAG: NtAlpcSendWaitReceivePort failed. NTSTATUS: %08X WERDIAG: Service returned failure status. NTSTATUS: %08X WERDIAG: Failed getting current user registry path. NTSTATUS: %08X Software\Microsoft\Windows NT\CurrentVersion\Image File Execution OptionsWERDIAG: Handle to registry key is null WERDIAG: Failed getting process name. NTSTATUS: %08X AutoverifierAutoVerifierCountWERDIAG: Failed reading key value. NTSTATUS: %08X WERDIAG: Failed writing registry value. NTSTATUS: %08X OriginalBucketAutoVerifierTimeDurationWERDIAG: Failed creating timer thread. NTSTATUS: %08X WERDIAG: Failed deleting autovefier enabled flag. NTSTATUS: %08X WERDIAG: Failed writing key value \Registry\Machine\SYSTEM\CurrentControlSet\Control\Session ManagerImageExecutionOptionsWERDIAG: Not disabling HKCU IFEO look-up because its statically enabled. WERDIAG: Thread failed to wait for the specified time; Disabling autoverifier. NTSTATUS: %08X verifier.dllWERDIAG: Failed obtaining verifier.dll handle. NTSTATUS: %08X VerifierForceNormalHeapWERDIAG: Failed obtaining VerifierForceNormalHeap function address. NTSTATUS: %08X WERDIAG: Failed switching to normal heap mode. NTSTATUS: %08X WERDIAG: Verifier switched to light mode \KernelObjects\SystemErrorPortReadynT DWERDIAG: AppRecorder: Failed creating AppRecorder thread. NTSTATUS: %08X Local\{DF2B7FCA-C5B0-4638-A4AD-59F7F76CE540}WERDIAG: AppRecorder: ProcessStartupSettingsUpdate failed. HRESULT: %08X %d-AppRecorderEnabledWERDIAG: AppRecorder: Failed creating apprecorder event name string. HRESULT: %08X WERDIAG: AppRecorder: Failed creating event. Win32 error: %08X WERDIAG: AppRecorder: Failed to get temp folder path. Win32 error: %08X WERWERDIAG: AppRecorder: Failed to get temp file name. Win32 error: %08X .AppRecorderData.xmlWERDIAG: AppRecorder: Failed to create temp file name. HRESULT: %08X WERDIAG: AppRecorder: Failed to create apprecorder temp file. Win32 error: %08X WERDIAG: AppRecorder: Failed to register the log file with WER. HRESULT: %08X WERDIAG: AppRecorder: Failed to get system folder path. Win32 error: %08X \psr.exeWERDIAG: AppRecorder: Failed to create UAR executable image path. HRESULT: %08X %s /start /output %s /gui 0 /recordpid %d /stopevent %s /sc 0 /noarc 1 /waitonpid 1WERDIAG: AppRecorder: Failed to create UAR process command line. HRESULT: %08X WERDIAG: AppRecorder: Failed to create UAR process. Win32 error: %08X WERDIAG: AppRecorder: Failed getting current user registry path. NTSTATUS: %08X Software\Microsoft\Windows\Windows Error Reporting\Plugins\AppRecorderWERDIAG: AppRecorder: AppRecorder settings key is not present. NTSTATUS: %08X AppRecorderEnabledWERDIAG: AppRecorder: AppRecorder enabled flag is not present. NTSTATUS: %08X AppRecorderCountWERDIAG: AppRecorder: Failed to get current process name. Win32 error: %08X Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LayersWERDIAG: AppRecorder: Failed to open App Recorder layer key. NTSTATUS: %08X WERDIAG: AppRecorder: Failed to get application appcompat layers. NTSTATUS: %08X AppRecorderWERDIAG: AppRecorder: Failed to update application appcompat layers. NTSTATUS: %08X WERDIAG: AppRecorder: Failed to update App Recorder run count. NTSTATUS: %08X WERDIAG: Invalid params WERDIAG: Failed creating FDR thread. NTSTATUS: %08X WERDIAG: GetTraceLoggerHandle failed WERDIAG: GetTraceEnableLevel failed WERDIAG: GetTraceEnableFlags failed WERDIAG: Internal provider enabled for Level %u, Flags %lu WERDIAG: Tracing disabled for internal provider WERDIAG: Provider not registered. RegisterTraceGuids failed with %d WERDIAG: Internal provider: FDR did not start yet; Message lost WERDIAG: Failed determining string length. HRESULT: %08X WERDIAG: Memory allocation for event failed. WERDIAG: Internal provider failed to log message. Win32 error: %08X WERDIAG: Internal log message WERDIAG: Failed reading the session settings of updating the process ID. HRESULT: %08X WERDIAG: Failed parsing settings string. HRESULT: %08X WERDIAG: Failed to enable logging. HRESULT: %08X FDR startedWERDIAG: Failed enabling trace provider. Win32 error: %08X FDR Tracing SessionWERDIAG: Invalid arguments: Log path cannot be null WERDIAG: Unable to allocate %d bytes for properties structure. WERDIAG: Failed copying string buffer. HRESULT: %08X WERDIAG: StartTrace failed for the internal provider. Win32 error: %08X WERDIAG: Failed enabling internal trace provider. Win32 error: %08X WERDIAG: Invalid args: The pair string cannot be null WERDIAG: Failed obtaining string length. HRESULT: %08X WERDIAG: Invalid format: expected '='. WERDIAG: Invalid args WERDIAG: Failed getting string length. HRESULT: %08X WERDIAG: Failed copying string. HRESULT: %08X WERDIAG: Invalid arguments: Buffer or separator character cannot be null WERDIAG: Invalid arguments: String buffer cannot be null WERDIAG: Failed obtaining the length of the input string. HRESULT: %08X WERDIAG: Out of resources allocating memory for string buffer WERDIAG: Failed making a copy of the original settings string. HRESULT: %08X WERDIAG: Failed copying characters to pair buffer. HRESULT: %08X WERDIAG: Invalid argument: GUID structure cannot be null WERDIAG: Invalid arguments: pointer to settings structure cannot be null WERDIAG: Invalid argument: settins string cannot be NULL WERDIAG: Failed extracting next token from settings string. HRESULT: %08X WERDIAG: Failed extracting next pair from the current token. HRESULT: %08X WERDIAG: Error parsing current pair; Ignoring pair and continuing parsing. HRESULT: %08X WERDIAG: Failed updating settings; Parsing continues. HRESULT: %08X WERDIAG: Log file size was not specified; Logging will not be enabled WERDIAG: Failed reading session settings, cannot delete log file. HRESULT: %08X %s_%dWERDIAG: Failed appending process ID to log file name. HRESULT: %08X WERDIAG: Failed deleting file. NTSTATUS: %08X WERDIAG: Session settings and/or FDR layer were not deleted successfuly. HRESULT: %08X Software\Microsoft\Windows\Windows Error Reporting\Plugins\FDR\CurrentSessionAppPathWERDIAG: Failed reading string value from registry. NTSTATUS: %08X WERDIAG: UtilRemoveAppCompatLayerFromList failed. HRESULT: %08X WERDIAG: Failed opening session registry key. NTSTATUS: %08X WERDIAG: Invalid arguments; pointer to string buffer cannot be null SessionSettingsWERDIAG: Failed reading FDR settings value from registry. NTSTATUS: %08X LogPathWERDIAG: Failed reading log file path value from registry. NTSTATUS: %08X WERDIAG: Get current process ID failed ProcIDWERDIAG: Failed writing process ID to registry. NTSTATUS: %08X WERDIAG: StartFDR failed 0x%x FDR_FLUSH_MESSAGE%s-%dWERDIAG: Failed concatenating strings. HRESULT: %08X WERDIAG: Failed creating event. Win32 error: %08X WERDIAG: Failed setting event. Win32 error: %08X WERDIAG: Flushing done, done signal sent WERDIAG: Unexpected event response or failed waiting for event DFԓ@+f9vKtdgWERDIAG: Invalid parameters WERDIAG: Failed obtaining string length. NTSTATUS: %08X WERDIAG: RtlSizeTAdd failed. NTSTATUS: %08X WERDIAG: RtlSizeTAdd operation failed. NTSTATUS: %08X WERDIAG: RtlSizeTMult operation failed. NTSTATUS: %08X WERDIAG: Insufficient resources %s\%sWERDIAG: Failed concatenating strings. NTSTATUS: %08X WERDIAG: Key: %S WERDIAG: Out of resources allocating memory for key information structure WERDIAG: Failed extracting registry value %S. NTSTATUS: %08X WERDIAG: Failed writing to value %S. NTSTATUS: %08X WERDIAG: Failed writing to value %S. NTSTATUS %08X WERDIAG: NtQueryInformationProcess failed. NTSTATUS: %08X WERDIAG: Invalid size returned. NTSTATUS: %08X WERDIAG: Failed copying string. NTSTATUS: %08X WERDIAG: Registry value %S is not of type string WERDIAG: Failed determining string buffer length. NTSTATUS: %08X ntdll.dllMicrosoftTelemetryAssertTriggeredUMD.p;p/D ;/D$=1Pz;$8;8r`ssstt>w{{)= :wPzo{8|RSDS|.text$mn8|.xdata$x|.edata0.data$brc0.data@.bss.idata$5.00cfgT.idata$2.idata$3.idata$4Z.idata$6`.rsrc$01`.rsrc$02 |.̋UVWt'E +t<ft f9Nuu_ҁ3f^] ̋Utw QuQ t3f]̋U0VWjFXjHfE3XfEEEE؍EPhEEP}ԉ}܉}}$x6tƹEUFE#VWu u_^̋U43ʼnESVWjE3PSjXWx9]tSSSSSSWxF3}SSEPhPuFM3;_3%?^[,̋U W3}}}tRVEPEPWhKWWWWWjxyVh`Wh|9}t u(^_̋U 43ĉ$ SVWjD3ۍD$$SPt03|$ VSh3f$fD$tf$f$f$xVjSStu @yPhSW|dp $h\hPyVhSW|i$PSSStu9PhSh|'$Ph uPh D$hPShl$PuPhxlD$hPhL$lgy VhShjSjh@$PuPh8  P(jjD$pPy Vh $xVPuPh h,!֍$|yVh@!I$PHPXPD$pP$Ph!$hPyVh@"Sh|fD$D$ DPD$$PSSSSSS$P$PPu=Ph"Sh|~ y/W(&9\$tt$(\$9\$t t$($ _^[3(]̋UVW3EP}}}<yPh"Wh|GE3PWu0#AyPh#΋MEP$yPh8$뱃}u3F9}t u9}tEPWEP _^̋U443ʼnESV3@W3fP<yPh"Wh|[0#PWyPh#ËP$yPh8$렋@hPW8u9Ph$Wh|؅ہ%PWjYy Ph% P"y Ph%Wh|>3ҋOff;u+ jXj h,&Pؐ uC9tD0PԐYt$0PԐYu13f9 0t#O@;w^뀋ɍB#ȍB ;r3fN6+t}P}PPNP) 3f9>PP PT߃t t td0VWp4tPWP M_^3[$ËVpPhH&HP$KPh&̋UVWt'E +t<ft f9Nuu_ҁ3f^z] ̋UWtMwEVf8tu΋+#ȋ%W^tQu+Q OSW_]̋UE Vt>=w7S]3WxEPuWSܐx;wu z3f{_[WtM3f^]̋U VW3EPE}PWhgWWWWWj}}xyVh 'Wh|_^̋UEth'P uuhD'jh| ^SRP؄uhl'55uh'jh| PPh'jh|[3]̋UQQVW(E6P3@WW8xEPjh6WhT}tPh0(Wh|_^̋UQ SVWuhx(jh| ET*PWyPh(jh|EE6d0WjpX؅uh(WjS%E{f36C,EPC4hT*PCC0/%S55tPh()jV|hp)jV| d0Sjp4_^3[̋UQQV3WEh PWE(, $$ EPEPMyVh)jh|AEP yVh)ՋuyVh *QQ(3}tud0jp4}tud0jp4_^̋UQS3V3EW9v[{uG$G P7wj3GtQhl*jh|FE@E;r_@^[̋USVW3E ;{9}uh*Wh| WMEPyVh(Wh|jE*PyxҋE EE=MAPEd0WpX}u uh+P뛋uVjW"׋MEx 2zB,6uB(}JlB@Bpx@bDBd0hWpXE̅uh.Wh| d0hWpXEȅuh.Wh| x]9>&EPj;V\}}3}}૫3td0SWp4}܍EPj,EP]܅tEuȋ}QVQWSyPh@0EPEPVWyPh0jh|}wujY}ԋ}ԋuă>t!3Vh/Wh|]܃BEЅt G32Vh/Wh|3h0Wh| @td0SWp4}tud0Wp4ud0Wp4EȅtPd0Wp4hd/Wh| WM_^3[C̋U0SVWj3ۍ}Y3]]]]EPEPTy"Vh01Sh|]d0hSpXuh.Sh| d]p Sh1hW yVh1jh|~WEP 3EVVPu`EEE܍EPuE@uudEPy)Vh1jh|} Vh2r3td0Sjp4}tud0jp4td0Wjp4_^[̋US3ۍEVW]P]]}]<E`2PSujYy VhMEP2 }xttpuE%PSujYxMEP yVh6h&SS| WVhX3jS|3Vh3Sh|}}t'WEP EPuT}t utd0WSp4}tud 0Sq4_^[̋UVW3EP}}}<E`2PWuxyVh3Wh| u@9}t u_^̋UVW3}}}9}9} EP<E`2PWujYy VhWh|uM(4yVhH4u M4yVh4d@ uh4Wh| @!M5PVy Vh05c9}t uh3Wh| W_^̋U<43ĉ$8SVWL$yVhp5jh|ed3hSp d0pXuh.Sh| !Vh5h5hWdyVh5Sh|WSSStu%Ph5Sh|@L$ÅtT$09u@u%HP%=uEL$3ɅIwQVpuVlu)Ph,6sh6Sh|@h`6Sh| d0WSp4$D_^[3]̋Ut&w} vWu uQWt3f]̋UVWt%E u+t<ft f9Nuu_ҁ3f^z] ̋UtwhuQWt3f]̋US3Vut_u Wt^[]̋U0SV3MډuuuuWE09u*MEPyVh7jh||EPxҋEE;EH;jYrw{d0VjpXuh7Ph| Suh8VWyVh8jh|WEP 3APh7Ph|7PhL7SEP u컖hT8jS|E EԍEE؍EEPuE@uuuhyVhjS|3td0Wjp4h6Vh| _^[ ̋USVW3ډ}}}ES8EP d0jWpXuhh8Ph| UEPjWjEPVlxu M3G VSh8jh|d0Wjp4h6Wh| _^[̋USVW3ۋ]]tGtCWEP jEPjSEPVpyVWh8Sh|h6Sh| _^[̋USV3WEEEtjtfut_WEP ΍Qff;Eu+MPVj3PEPSp3yVWh,9Ph|h6Ph| _^[̋U43ʼnEVWV3WP WVPj+jtyVh`9Wh|f;vf;v Vh93ҋfHF\t/t :t;wRxy Vh9^M_3^D̋USV3ۋW]]]qiWEP d0hSpX؅uhh8Ph| !EPhSjEPVlyVWh8jh|{tWh9e{ UEPDEp;rad0VjpXȋEuh.Qh| Su QWQyPh93*VhL7 Ph0:jh|d0Sjp4h6Sh| _^[̋UE Vt>=w7S]3WxEPuWSܐx;wu 3f{_[ tM3f^]̋UVW3t f99tuM%? t t+19_^]̋U$eEVPht:j4tP}tJh:u0t6ME܃eMMMPE EEE^hYu@à 3̋U} SVW@dH3ۣ@d]PʉU33G;thU3u}=ćt jY\Eth5u;r:MtU ;uE9Mt͋‰MEP3YGć9]33G9} d3ۉ]PU;thU3u}9ćj[t j5hh=ćgYYt3XhhYć}Yu3=ȇt&hȇ Ytu5ȇSu@_^[ ̋U} u],̋Ucsm9Eu u P/YY]3]j,h8|:E3uE w0} u=@uu9E t =̇tNE} u Duu u׉EMEQPCYYËe3uu}Euu uEMEQPYYËe3uu}Euu uJEMEQPYYËe3uu} }EVVuMEQPwYYËe3uEVVuGMEQPHYYËe3u=̇t4EVVuMEQP YYËe3uE t Euu uEMEQPYYËe3uu=̇tG=Dt>Euu u׉EMEQPsYYËe3uuEEMd Y_^[ } w 0̋UVu3;u sWu>t ׃;u r_^]; 4u ̋U} u3@] %Ȑ%̋UE3SVWH<AYt} p ;r H;r B(;r3_^[]̋Ujh|hPzdPSVW41E3PEdeEhtTE-PhPt:@$ЃEMd Y_^[]ËE3Ɂ8ËeE3Md Y_^[]̋UMMZf9uA<8PEu f9Hu]3]̋Uee4VWN@;tudEPE3EET1E\1E3EM3EEPdE3E3E;t54uO@ȉ 4_8^%hPzd5D$l$l$+SVW41E3PeuEEEEdËMd Y__^[]Q̋Uuuu uhwh4O]̋Ujuh HPL]̋U$H D@<58=4f`f Tf0f,f%(f-$XELEPE\PTH LXjXkǀ\jX 4\jX 8\jXk 4LjX 8Lh%̋D$L$ ȋL$ u D$S؋D$d$؋D$[%%%8w(uNZl|lȖ{Ȑx(0\ d@.HX|֖4 ܘ(8@d lB bx\ڗƗf.t И2L"\rDܙʜʔԜ8Phܚ 4P^ʛ >NZl|lȖt_XcptFilter_amsg_exitfreemalloc_inittermmsvcrt.dlls_except_handler4_common-SleepQueryPerformanceCounter GetCurrentProcessIdGetCurrentThreadIdGetSystemTimeAsFileTimeGetTickCountUnhandledExceptionFilterSetUnhandledExceptionFilter GetCurrentProcessTTerminateProcessapi-ms-win-core-synch-l1-2-0.dllapi-ms-win-core-libraryloader-l1-2-0.dllapi-ms-win-core-profile-l1-1-0.dllapi-ms-win-core-processthreads-l1-1-0.dllapi-ms-win-core-sysinfo-l1-1-0.dllapi-ms-win-core-errorhandling-l1-1-0.dlloLdrDisableThreadCalloutsForDll#DbgPrintExntdll.dll_vsnwprintf"_wcsnicmpisspace{wcschr_wcsicmp_wtoi WerRegisterFileapi-ms-win-core-windowserrorreporting-l1-1-0.dllCloseHandle ReadProcessMemoryGetLastErrorOpenEventWCreateEventW?GetTempPath2W=GetTempFileNameW DeleteFileWCreateFileWGetSystemDirectoryWGetProcessIdCreateProcessWGetModuleFileNameWGetTraceLoggerHandleGetTraceEnableLevelGetTraceEnableFlagsRegisterTraceGuidsWTraceEventStartTraceW6WaitForSingleObject)SetEventapi-ms-win-core-handle-l1-1-0.dllapi-ms-win-core-memory-l1-1-0.dllapi-ms-win-core-synch-l1-1-0.dllapi-ms-win-core-file-l1-2-4.dllapi-ms-win-core-file-l1-1-0.dllapi-ms-win-eventing-classicprovider-l1-1-0.dllapi-ms-win-eventing-controller-l1-1-0.dllEnableTraceapi-ms-win-eventing-legacy-l1-1-0.dllNtCloseRtlFormatCurrentUserKeyPathRtlFreeUnicodeStringhRtlInitUnicodeStringBEtwEventWriteNoRegistrationZwUpdateWnfStateDataZwQueryWnfStateNameInformationNtQuerySystemInformationNtWaitForSingleObjectNtOpenEventRtlAllocateAndInitializeSidNtAlpcConnectPortNtAlpcSendWaitReceivePortRtlFreeHeapRtlFreeSid`RtlCreateUserThreadQNtDeleteKeyLNtDelayExecutionzLdrGetDllHandle[RtlInitAnsiStringLdrGetProcedureAddressTNtDeleteValueKeyRtlAllocateHeapRtlGUIDFromStringRtlDosPathNameToNtPathName_UPNtDeleteFileNtOpenKey NtQueryValueKeysNtSetValueKeyNtQueryInformationProcessGetModuleHandleExAGetProcAddressmemcpymemmovememset0 H`4VS_VERSION_INFO ! |O ! |O?,StringFileInfo040904B0LCompanyNameMicrosoft Corporation\FileDescriptionWER Diagnostic Controllern'FileVersion10.0.20348.2849 (WinBuild.160101.0800)TInternalNameWER Diagnostic Controller.LegalCopyright Microsoft Corporation. All rights reserved.TOriginalFilenameWERDiagController.dllj%ProductNameMicrosoft Windows Operating SystemDProductVersion10.0.20348.2849DVarFileInfo$Translation 00D0H0P0X0000X======>>>1>:>C>U>b>h>}>>>>>>>>>>?%?`?j?u??????????@t000<0h00000011%1A1[1n111#2/2I2233%313K3d3333334 4404B4L4Z4f4z44444455)5:5x55555555555666+686S6b6q6666666677,7B7U7b7|7777777788$8,868@8R8^8p8~88888888 :2:_:j:::::::8;E;Q;];x;;;<<5<=>!>B>N>>>>>>>>>&?0?6N6^6k66666666 777&7;77777 8$8l8888899,9b9s9999: ::#:7:C:O:\:::::;;K;X;;;;;;;<3<@>*>J>>>>>?#?5?>?T?]?l?w???????`H0)050W0c0o00 1%121p1|111111122(2422222223&363G3n3z3333333&4.4G4X4s4{4444444455$595S55555556606<6U6f6s6666666667@7M7u77777777777[8f8p8v888888k:x::::;;);<;M;_;q;;;;;;;;<<`>'>3>X>>>>>"?3????????p(0T0d0p000000006111112+2G2L2Q2~22222223 3&3G3O3V3\3b33333333344404<4D4444455A6Y6666@7n777788=8O8m888L9j9y999999999:b:g:::::::::::::::::;;;;*;3;8;>;H;R;b;r;x;;;;;;;<(<4