Hacked By AnonymousFox

Current Path : C:/Windows/SysWOW64/
Upload File :
Current File : C:/Windows/SysWOW64/perfhost.exe

MZ@	!L!This program cannot be run in DOS mode.

$ցցցήց⢰ց⢰ց⢰ցրց⢰ց⢰ց⢰~ց⢰ցRichցPEL嬚h
&,.@@


@ dQ@`TP`.textd$& `.data@*@.idataP,@@.rsrc`8@@.relocP@B`@@@@"@`#@0%@3@3@3@@'@'@x@@
n`'@(@@@@@D;ơ}[Nko]+H`@|@@@@`Q@@u,@ ,@@/@P"`#0%P%`''' ,,...@/0p223
{|
N,5>
.p0%\0M\)T)T[0h2@FAph0L@@GCP!Dph08@DARpPerfpSetServiceStatePerfHostPerfpServiceMainwmainPerfpOpenProviderPerformanceLibraryOpenCloseQueryCollectLinkageExportPerfCollectDatancalrpcSOFTWARE\Microsoft\Windows NT\CurrentVersion\PerflibPerfpRpcIfCallbackPerfpCleanupServerPerfpGetClientAuthIdSYSTEM\CurrentControlSet\Services\%s\%s嬚h%	嬚h

嬚hp2RSDSTg&<0[~dPerfHost.pdbGCTL.rdata$brc.CRT$XCA.CRT$XCAA.CRT$XCZ.CRT$XIA.CRT$XIAA.CRT$XIY.CRT$XIZP.gfids.rdata.rdata$sxdata.rdata$zzzdbg.text$mn4\.xdata$x@.data$brc@(.data0@.bssP`.idata$5`Q.00cfgdQ,.idata$2R.idata$3R`.idata$4T.idata$6``.rsrc$01`ap.rsrc$02UQVW|C@t$WTQ@E@@EW5@@ @@PQ@WLQ@h@@5C@P@WHQ@_^u*DP@jh@EEjPjhp@=E3]V
33VBVZ5C@5C@P@5C@^̋UVWC@WTQ@=C@tHEjZt+t
tjx^/33VV23C@VV5C@P@WPQ@_^]̋UQS3Sh@h@C@P@C@uzDP@Ejh@jEPjhp@"9C@tFVC@VTQ@VC@PQ@u3BS1C@C@^t
PP@C@[]SSjZExSSh@P@C@UENSjjZ멋UV3E@VVjVEP@uuLP@hC@VVh@DQ@E^uLEPP@u*DP@jh@EEjPjhp@
E5C@5C@@Q@3]ËV~0t3^WjjvXP@F4t7vP`P@F8t&v v4`P@F@tvv4`P@F<uDP@~4t
v4TP@f4F03_^ËUSVWO QAu+ʋW3ۉ]rff;u+֋w^ff;EuA+Pw UPwuPwjh @w@ `Q@֋w ENFu+O3ۍQff;u+ʋWZff;EuF+Pw MPwUPwEjPjh@p(3ۈ_1w4TP@_4_0_^[]ËUSVWME8G1tM;G(uA;G,|#Ee3Vu0P@EN_KCuW+ٍJff;uw+Nff;Eu+Ot&AEff;Eu+MMOEEul@CPwUPwuPwuQjhP@C
w8(w`Q@jZ@E
wNFuW+3ۍJff;u+ыOYff;EuF+PwUPwMPwEjPjh@	E(uEG(EG1G,3_^[]d0VW3vWpXQ@vd0WpXQ@vd0WpXQ@vd0WpXQ@v d0WpXQ@vd0WpXQ@d0VWpXQ@_^ËU$@@3ʼnESVWh@3Wh0@hPpyxDž3ۋύQff;u+MPWjPjh`@ttP@M_^3[l]ÍPjjPhP@gjDPd0p8Q@uDž@jDjV(F$PP@NF	
QP
NQP@
NQP$@
eN IQP,@?
t&QP4@
NKP@h<@Wh0@hP
yDž@@@@9tnjY)PjjPhP@uQFPQ~P@tt3ۉ2F035@@3wSV^~J;t_ЃW~$WTQ@~1t	.~0tv4TP@f4F0hC@TQ@thC@PQ@WPQ@_^[Ë9pu!N91uhC@HPQ@_^[jY)̋UQSVWC@VTQ@=@@@@jjujwP@t,?;u3}u&UM؅tVPQ@}.G֋}VPQ@w$VTQ@EVPQ@ttE83_^[]̋UESVW}3ۉ\$G$PTQ@D$tS0P@D$a_KCuw+3ҍNff;uW+Jff;D$u+}t*MAD$ff;D$u+L$MD$D$}Mul@C]PwuPwUPwjSt$4Qjh@Zw<E0uSPu`Q@jZ\@D$wNFuW+3ۍJff;u+ыOYff;D$uF+PwUPwMPwD$$jPjh@(|$tE3ɉG$PPQ@D$_^[]̋UVu&3^]̋USW3EWWPWEPu,P@E@u
}s*EjSjEPjh0@E_[]EPu(P@EuWWWEPWu$P@EEP P@9}uVjjujhp@P@EP P@^tEsu0P@E_EPhWh@hP@jZˉE9}/uP@3:UQSWj5C@h@P@E@p@tjWjEPjShC@P@jjh@P@EtjWjEPjS_[]ËW3Wj
hp@P@ubShP%@hj)WW@SP@uBVhC@P@WWu 5C@SP@thC@P@WWSP@3^[_ËUEP]̋Uud0jp8Q@]̋Uud0jpXQ@]U@@3ʼnESVW}9UwUt*ڍEfH&vFAFuፅPRW5C@5C@4Q@M_^3[]ËUQVWP@EtVWjEPjh@@Q_^]ËUH@@3ʼnEVWj0P@uhEPjjj0Q@jZ@y	V,Q@<EPj8EPj
u(Q@u$Q@xӃ}8sj
X
EȉẺG3M_3^]ËSVWً3ҍNff;ud0+4uVRp8Q@ujX
VWP
3_^[ËSVWًNFud0+FVjp8Q@ujX
VWPW
3_^[ËU@@3ʼnEVQVQyjzXAWQ3ff;uWh+ʍVQPW<Q@_y	P,Q@3M3^]ËUQSW3ۍEPSSS]hL@WP@tzuVd0VuSp8Q@ujX6EPVSShL@WP@td
0VSqXQ@E03^_[]UQQVuEPVEEPjh@QP@u4Er'3f;LFuEtuu	3^]UQQVuEPVEEPjRQP@u!Er|0u
EHw3^]UEVWt5S]3WxEPuWSQ@x;wu
z3f{_[^]ËUQVu+tftfu^uҁ3fz]>jH@@PP@
C@
C@YYP@
\@@Q@
P@@=@@uh0@P@Yl3̡X@@hL@@5T@@L@@h@@@h<@@h8@@Q@D@@jh4@93ۉ]dpC@3
t;u3FhP@3F95C@u
jY:9C@u,5C@h@h@YYtE54@@95C@uh@h@YYC@u	3C@=C@t#hC@YtSjS5C@`Q@5@@@5<@@58@@y0@@=H@@u6PQ@MEQP[YYËeE0@@=H@@uPP@=4@@uP@0@@EËUVu3;usWu>t
`Q@׃;ur_^]øMZf9@uU
<@@PEuC@f;tf;u(@v39@Ãt@v
39@3;
@@uUE8csmu+xu%@= t=!t="t=@uP@3]h.@@P@3%Q@jh(4@3ɋEtKtFMMZf9u2P<x+s#‰EPE#	3@Ëe3ɉMEUj\P@t PtH\jXf;t
u3@]ËE]%P@3̋UE3SVWH<AYt}p;r	H;r
B(;r3_^[]̋UjhH4@hp2@dPSVW@@1E3PEdeEh@ztTE-@Ph@Pt:@$ЃEMd
Y_^[]ËE3Ɂ8ËeE3Md
Y_^[]̋UMMZf9uA<8PEuf9Hu]3]ËUee@@VWN@;tudEPP@E3EEtP@1EpP@1EP@3EM3EEP|P@E3E3E;t5@@uO@ȉ
@@_@@^]hhP@YY%P@hp2@d5D$l$l$+SVW@@1E3PeuEEEEdËMd
Y__^[]Q̋Uuuuuh.@h@@M]Uj@P@u<P@h	lP@PhP@]ËU$`A@
\A@XA@TA@5PA@=LA@fxA@f
lA@fHA@fDA@f%@A@f-<A@pA@EdA@EhA@EtA@@@hA@l@@`@@	d@@p@@jXkǀt@@jX
@@t@@jX
@@t@@jXk
@@LjX
@@Lh@]%Q@%4P@%Q@%Q@-@-@/@/@0@0@@@@@N@D6W`WNWWWVVVVVzV^VFV4VWW~WW(X6XZXHXBY.YYYYXXXXYYZXZrZZZZ[&[F[PT|TrTjT0TTTTTT TbTT[>TT[VUUUUUVvUbUHU.UUTU2@STPS*V$QRrWPRW<PRXLPRnXTP(SXPSVYhP SY|P<SYPDSZPLS6ZPTSZP`SZPpSd[P6W`WNWWWVVVVVzV^VFV4VWW~WW(X6XZXHXBY.YYYYXXXXYYZXZrZZZZ[&[F[PT|TrTjT0TTTTTT TbTT[>TT[VUUUUUVvUbUHU.UUTU_vsnwprintfo_XcptFilter__p__commode_amsg_exit__wgetmainargs__set_app_typeexits_exit$_cexit__p__fmode__setusermatherr_inittermmsvcrt.dll5?terminate@@YAXXZ7_controlfpj_except_handler4_commonRtlAcquireSRWLockExclusive3RtlReleaseSRWLockExclusiveRtlAcquireSRWLockShared4RtlReleaseSRWLockShared;EtwEventRegister=EtwEventUnregisterRtlFreeHeapRtlAllocateHeap>EtwEventWriteNtOpenThreadTokenRtlNtStatusToDosErrorNtQueryInformationTokenNtCloseRtlExpandEnvironmentStringsntdll.dll+NdrServerCall2RpcImpersonateClientsRpcBindingInqAuthClientWRpcBindingToStringBindingWRpcStringBindingParseW
RpcStringFreeWRpcEpUnregisterRpcBindingVectorFreeRpcServerUnregisterIfRpcServerUseProtseqWRpcServerRegisterIfExRpcServerInqBindingsRpcEpRegisterWRpcRevertToSelfRPCRT4.dllGetLastErrorSetUnhandledExceptionFilterUnhandledExceptionFilterapi-ms-win-core-errorhandling-l1-1-0.dll
HeapSetInformationapi-ms-win-core-heap-l1-1-0.dllFreeLibraryLoadLibraryExWGetProcAddressGetModuleHandleWapi-ms-win-core-libraryloader-l1-2-0.dllRegCloseKeyRegOpenKeyExW%RegQueryValueExW$RegQueryValueExAapi-ms-win-core-registry-l1-1-0.dll
GetCurrentProcessIdGetCurrentThreadIdGetCurrentProcessMTerminateProcessapi-ms-win-core-processthreads-l1-1-0.dllQueryPerformanceCounterapi-ms-win-core-profile-l1-1-0.dllCompareStringOrdinalapi-ms-win-core-string-l1-1-0.dllInitializeSRWLock-Sleepapi-ms-win-core-synch-l1-1-0.dllapi-ms-win-core-synch-l1-2-0.dllGetSystemTimeAsFileTimeGetTickCountapi-ms-win-core-sysinfo-l1-1-0.dllCloseThreadpoolWorkSubmitThreadpoolWorkCreateThreadpoolWorkapi-ms-win-core-threadpool-l1-2-0.dllSetServiceStatusRegisterServiceCtrlHandlerExW	StartServiceCtrlDispatcherWapi-ms-win-service-core-l1-1-0.dll	memcpy
memsetL00H`x				 ugd`a
WEVT_TEMPLATEMUI<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
    version="5.1.0.0"
    processorArchitecture="x86"
    name="Microsoft.Windows.Diagnosis.PerfHost"
    type="win32"
/>
<description>Performance Counter DLL Host</description>

<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
    <security>
        <requestedPrivileges>
            <requestedExecutionLevel
                level="asInvoker"
                uiAccess="false"
            />
        </requestedPrivileges>
    </security>
</trustInfo>
</assembly>
4VS_VERSION_INFO
cE
cE?StringFileInfo040904B0LCompanyNameMicrosoft CorporationbFileDescriptionx86 Performance Counter Hosth$FileVersion10.0.17763.1 (WinBuild.160101.0800):
InternalNameperfhost.exe.LegalCopyright Microsoft Corporation. All rights reserved.B
OriginalFilenameperfhost.exej%ProductNameMicrosoft Windows Operating System>
ProductVersion10.0.17763.1DVarFileInfo$Translation	CRIM{|
N,5>$WEVT
t
hCHAN|`Microsoft-Windows-Diagnosis-Perfhost/AnalyticTTBL
TEMP=Z_BWzT@ECD	EventDataA5oDataKNameError
A;oData#KNameFunction
ErrorFunctionTEMP,>DYPdXdD	EventDataA5oDataKNameError
ACoData+KNameProviderName
$Error ProviderNameTEMP6E{^
A.D	EventDataAAoData)KNameReturnValue
A;oData#KNameProvider
AAoData)KNameProviderDll
A;oData#KNameFunction
,HReturnValueProviderProviderDllFunctionTEMP$4ybDY%*$νR`2D	EventDataAEoData-KName
FirstArgument
A;oData#KNameProvider
AAoData)KNameProviderDll
A;oData#KNameFunction
8Pl FirstArgumentProviderProviderDllFunctionTEMP`	a1rIS'	J1\D	EventDataA5oDataKNameQuery
A3oDataKNameSize
A;oData#KNameProvider
AAoData)KNameProviderDll
A;oData#KNameFunction
x					QuerySizeProviderProviderDllFunctionTEMPn/~\@Y!ED	EventDataA;oData#KNameProvider
AAoData)KNameProviderDll
A;oData#KNameFunction
<TpProviderProviderDllFunctionPRVA`Microsoft-Windows-Diagnosis-PerfHostOPCOLEVLTASKKEYWX8
LerrorscalloutsEVNT



D`

	((((D/n]]qW$r5t%CWHoQ*WEVT_TEMPLATEMUIMUIen-US00000000(0,00080H0x0|0000000,10181@1111888(8-838:8?8E8K8T8`8g8w88888888!91979>9[9`9f9l9q9{999999999999
:::Q:]:i:n:u:{:::::::::;;';4;E;;;D<Z<<I=q====@>S>f>y>>>>>>>5?]???? \L0000-12181_1d1111292F2L2Z2`2g22222222233+333+4Z4x4445l5t55555556656@6_6v6{66666666666777#71787C7I7R77778$8*8M8c8~8888888B999::>:E:b:y:::::9;;(<4<:<A<J<P<X<^<k<s<y<<<<<<<<<<<<=
=='=,=1=S=Y=`=e=r=============>
>>>!>Q>k>s>y>>>>>>>)?A?G?P?W???0h0m00000f11111111112	2&222222222222223333!3(30383@3L3U3Z3`3j3t33333333333334 4<4@4\4`4@00P`1

Hacked By AnonymousFox1.0, Coded By AnonymousFox