Hacked By AnonymousFox

Current Path : C:/Windows/System32/
Upload File :
Current File : C:/Windows/System32/werdiagcontroller.dll

MZ@	!L!This program cannot be run in DOS mode.

$\W222ɡ212623ñ23222;2202Rich2PELX?!
l"pq


\@Ayh0p9T.text
jl `.datap@.idatar@@.rsrc0@@.reloc@BH49u`oFF@IIS`S0e`opqtw@wGuidLevelFlagsCircularSizeu:AWERDIAG: Verifier.dll loaded. Enabling Autoverifier.
WERDIAG: ProcessStartupSettingsUpdate failed. NTSTATUS: %08X
WERDIAG: FDR will be enabled
WERDIAG: Stopping Autoverifier
WERDIAG: Stopping FDR
WERDIAG: AutoVerifier: Failed getting current user registry path. NTSTATUS: %08X
WERDIAG: AutoVerifier: Path is: %S
Software\Microsoft\Windows\Windows Error Reporting\Plugins\AutoverifierWERDIAG: AutoVerifier: Subkey is: %S
WERDIAG: AutoVerifier: could not open settings key. NTSTATUS: %08X
AutoverifierEnabledWERDIAG: AutoVerifier: could not read enabled flag. NTSTATUS: %08X
WERDIAG: AutoVerifier: Enabled flag: %u
\Registry\Machine\Software\Microsoft\Windows\Windows Error ReportingWERDIAG: Failed opening registry key. NTSTATUS: %08X
ErrorPortWERDIAG: PluginsNtGetRegStringValue failed. NTSTATUS: %08X
WERDIAG: SignalStartWerSvc failed NTSTATUS: %08X
WERDIAG: NtQuerySysInfo(ErrorPortTimeouts) failed. NTSTATUS: %08X
WERDIAG: WaitForWerSvc failed. NTSTATUS: %08X
WERDIAG: WaitForWerSvc timed out, failing the call with NTSTATUS: %08X
WERDIAG: RtlAllocateAndInitializeSid failed. NTSTATUS: %08X
WERDIAG: NtAlpcConnectPort failed. NTSTATUS: %08X
WERDIAG: NtAlpcConnectPort timed out, failing the call with NTSTATUS %08X
WERDIAG: NtAlpcSendWaitReceivePort failed. NTSTATUS: %08X
WERDIAG: Service returned failure status. NTSTATUS: %08X
WERDIAG: Failed getting current user registry path. NTSTATUS: %08X
Software\Microsoft\Windows NT\CurrentVersion\Image File Execution OptionsWERDIAG: Handle to registry key is null
WERDIAG: Failed getting process name. NTSTATUS: %08X
AutoverifierAutoVerifierCountWERDIAG: Failed reading key value. NTSTATUS: %08X
WERDIAG: Failed writing registry value. NTSTATUS: %08X
OriginalBucketAutoVerifierTimeDurationWERDIAG: Failed creating timer thread. NTSTATUS: %08X
WERDIAG: Failed deleting autovefier enabled flag. NTSTATUS: %08X
WERDIAG: Failed writing key value
\Registry\Machine\SYSTEM\CurrentControlSet\Control\Session ManagerImageExecutionOptionsWERDIAG: Not disabling HKCU IFEO look-up because its statically enabled.
WERDIAG: Thread failed to wait for the specified time; Disabling autoverifier. NTSTATUS: %08X
verifier.dllWERDIAG: Failed obtaining verifier.dll handle. NTSTATUS: %08X
VerifierForceNormalHeapWERDIAG: Failed obtaining VerifierForceNormalHeap function address. NTSTATUS: %08X
WERDIAG: Failed switching to normal heap mode. NTSTATUS: %08X
WERDIAG: Verifier switched to light mode
\KernelObjects\SystemErrorPortReadynTDWERDIAG: AppRecorder: Failed creating AppRecorder thread. NTSTATUS: %08X
Local\{DF2B7FCA-C5B0-4638-A4AD-59F7F76CE540}WERDIAG: AppRecorder: ProcessStartupSettingsUpdate failed. HRESULT: %08X
%d-AppRecorderEnabledWERDIAG: AppRecorder: Failed creating apprecorder event name string. HRESULT: %08X
WERDIAG: AppRecorder: Failed creating event. Win32 error: %08X
WERDIAG: AppRecorder: Failed to get temp folder path. Win32 error: %08X
WERWERDIAG: AppRecorder: Failed to get temp file name. Win32 error: %08X
.AppRecorderData.xmlWERDIAG: AppRecorder: Failed to create temp file name. HRESULT: %08X
WERDIAG: AppRecorder: Failed to create apprecorder temp file. Win32 error: %08X
WERDIAG: AppRecorder: Failed to register the log file with WER. HRESULT: %08X
WERDIAG: AppRecorder: Failed to get system folder path. Win32 error: %08X
\psr.exeWERDIAG: AppRecorder: Failed to create UAR executable image path. HRESULT: %08X
%s /start /output %s /gui 0 /recordpid %d /stopevent %s /sc 0 /noarc 1 /waitonpid 1WERDIAG: AppRecorder: Failed to create UAR process command line. HRESULT: %08X
WERDIAG: AppRecorder: Failed to create UAR process. Win32 error: %08X
WERDIAG: AppRecorder: Failed getting current user registry path. NTSTATUS: %08X
Software\Microsoft\Windows\Windows Error Reporting\Plugins\AppRecorderWERDIAG: AppRecorder: AppRecorder settings key is not present. NTSTATUS: %08X
AppRecorderEnabledWERDIAG: AppRecorder: AppRecorder enabled flag is not present. NTSTATUS: %08X
AppRecorderCountWERDIAG: AppRecorder: Failed to get current process name. Win32 error: %08X
Software\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\LayersWERDIAG: AppRecorder: Failed to open App Recorder layer key. NTSTATUS: %08X
WERDIAG: AppRecorder: Failed to get application appcompat layers. NTSTATUS: %08X
AppRecorderWERDIAG: AppRecorder: Failed to update application appcompat layers. NTSTATUS: %08X
WERDIAG: AppRecorder: Failed to update App Recorder run count. NTSTATUS: %08X
WERDIAG: Invalid params
WERDIAG: Failed creating FDR thread. NTSTATUS: %08X
WERDIAG: GetTraceLoggerHandle failed
WERDIAG: GetTraceEnableLevel failed
WERDIAG: GetTraceEnableFlags failed
WERDIAG: Internal provider enabled for Level %u, Flags %lu
WERDIAG: Tracing disabled for internal provider
WERDIAG: Provider not registered. RegisterTraceGuids failed with %d
WERDIAG: Internal provider: FDR did not start yet; Message lost
WERDIAG: Failed determining string length. HRESULT: %08X
WERDIAG: Memory allocation for event failed.
WERDIAG: Internal provider failed to log message. Win32 error: %08X
WERDIAG: Internal log message
WERDIAG: Failed reading the session settings of updating the process ID. HRESULT: %08X
WERDIAG: Failed parsing settings string. HRESULT: %08X
WERDIAG: Failed to enable logging. HRESULT: %08X
FDR startedWERDIAG: Failed enabling trace provider. Win32 error: %08X
FDR Tracing SessionWERDIAG: Invalid arguments: Log path cannot be null
WERDIAG: Unable to allocate %d bytes for properties structure.
WERDIAG: Failed copying string buffer. HRESULT: %08X
WERDIAG: StartTrace failed for the internal provider. Win32 error: %08X
WERDIAG: Failed enabling internal trace provider. Win32 error: %08X
WERDIAG: Invalid args: The pair string cannot be null
WERDIAG: Failed obtaining string length. HRESULT: %08X
WERDIAG: Invalid format: expected '='.
WERDIAG: Invalid args
WERDIAG: Failed getting string length. HRESULT: %08X
WERDIAG: Failed copying string. HRESULT: %08X
WERDIAG: Invalid arguments: Buffer or separator character cannot be null
WERDIAG: Invalid arguments: String buffer cannot be null
WERDIAG: Failed obtaining the length of the input string. HRESULT: %08X
WERDIAG: Out of resources allocating memory for string buffer
WERDIAG: Failed making a copy of the original settings string. HRESULT: %08X
WERDIAG: Failed copying characters to pair buffer. HRESULT: %08X
WERDIAG: Invalid argument: GUID structure cannot be null
WERDIAG: Invalid argument: settins string cannot be NULL
WERDIAG: Failed extracting next token from settings string. HRESULT: %08X
WERDIAG: Failed extracting next pair from the current token. HRESULT: %08X
WERDIAG: Error parsing current pair; Ignoring pair and continuing parsing. HRESULT: %08X
WERDIAG: Failed updating settings; Parsing continues. HRESULT: %08X
WERDIAG: Log file size was not specified; Logging will not be enabled
WERDIAG: Failed reading session settings, cannot delete log file. HRESULT: %08X
%s_%dWERDIAG: Failed appending process ID to log file name. HRESULT: %08X
WERDIAG: Failed deleting file. NTSTATUS: %08X
WERDIAG: Session settings and/or FDR layer were not deleted successfuly. HRESULT: %08X
Software\Microsoft\Windows\Windows Error Reporting\Plugins\FDR\CurrentSessionAppPathWERDIAG: Failed reading string value from registry. NTSTATUS: %08X
WERDIAG: UtilRemoveAppCompatLayerFromList failed. HRESULT: %08X
WERDIAG: Failed opening session registry key. NTSTATUS: %08X
WERDIAG: Invalid arguments; pointer to string buffer cannot be null
SessionSettingsWERDIAG: Failed reading FDR settings value from registry. NTSTATUS: %08X
LogPathWERDIAG: Failed reading log file path value from registry. NTSTATUS: %08X
WERDIAG: Get current process ID failed
ProcIDWERDIAG: Failed writing process ID to registry. NTSTATUS: %08X
WERDIAG: StartFDR failed 0x%x
FDR_FLUSH_MESSAGE%s-%dWERDIAG: Failed concatenating strings. HRESULT: %08X
WERDIAG: Failed creating event. Win32 error: %08X
WERDIAG: Failed setting event. Win32 error: %08X
WERDIAG: Flushing done, done signal sent
WERDIAG: Unexpected event response or failed waiting for event
DFԓ@+f9vKtdgWERDIAG: Invalid parameters
WERDIAG: SizeTAdd failed. NTSTATUS: %08X
WERDIAG: Arithmetic operation failed. NTSTATUS: %08X
WERDIAG: Insufficient resources
%s\%sWERDIAG: Key: %S
WERDIAG: Out of resources allocating memory for key information structure
WERDIAG: Failed extracting registry value %S. NTSTATUS: %08X
WERDIAG: Failed writing to value %S. NTSTATUS: %08X
WERDIAG: Failed writing to value %S. NTSTATUS %08X
WERDIAG: NtQueryInformationProcess failed. NTSTATUS: %08X
WERDIAG: Invalid size returned. NTSTATUS: %08X
WERDIAG: Registry value %S is not of type string
WERDIAG: Failed determining string buffer length. HRESULT: %08X
WERDIAG: Failed with integer overflow
X?.9-X?
:.X?wRSDS{m`K֚:&WerDiagController.pdbGCTL.rdata$brc.CRT$XCA.CRT$XCZ.CRT$XIA.CRT$XIAA.CRT$XIZ@.gfids(.rdata9.rdata$sxdata9.rdata$zzzdbg;<.text$mnx.xdata$xy.edata0.data$brc0.data@.bss.idata$5.00cfgT.idata$2ܒ.idata$3.idata$4t2.idata$6`.rsrc$01`.rsrc$02UV3FW;QxpuVx0ȡp
t
t=xtDhHjW<tyPhjW<5phjh<%x%luZ95xu.hjh<tBP%2=tu)hjh<YYo#u	M_^]UV3F}ujVj9uu=uuVuI75uUM^]USV3ۍEWP]]]yPhSuhljh<Wh jh< E3ɋAPSuL*yPhH묋MEPE]P]J,yPh녃}u3FVhjh<9]t	u9]tEPSEP_^[]ËU,43ʼnES3fEVWPS3ɉS(A]`)PyVhSh<~P.y
Vhj%	yVh<3WjPjsyVhpyVhuSPhSPPWWWWWWWjjEP(yVh0{Džtꉅ#3WPPPPhPPPP,yVhpuSPhhP jPC8@hDž PhDž8PjP8DžPhhW3WPPW Ph0x3t+9}h0Wh<VhWh<td0S3Sp43ۃt8tt(M_^3[2]ËUDS33VWhSh]]]]]ĉ]]]f6EPyVhpSh<QE3PSu亸A%EPyVh뿋EuhLSh<f9u)yVhx{EMQPS^%xEPuSA%uMEPE]P]A'yVh}v,MEPG]P]'yVh$MEP\)]xF+tftfuu3ft
1CVAMEȃe|ePEP&yVhjh<}vQjhig3Vu4EPhhhFVVVVVj5|yVh딃w1u@u@hyPhjh<3td0Sjp4}t	u}t	u}t	u_^[]ËU VW3EP}}}}}yVhpWh<EPWujY#yVhɋMEPW}}%yh,Wh<YE3PWWPA"x;MEPE}P}$x9}thjh<9}t	u9}t	u9}tEPWEP_^]̋U SVWu3W}}}}DyPhXWS<hEPEPEPWWHyVhWS<ahEPLEPWEPuPyVh0uuj֋yVhhWS<_^[]̋U43ʼnEEM-VuWRWRPQ8u~B
89t+)1CVAt
UPg
M_3^,]Ut+EVW+t<ftf9Nu_^uҁ3f]U3tv
xQuQ	t3f]U0VWjFXjHfE3XfEEEE؍EPhEEP}ԉ}܉}}$x6tƹEUFE#VWu u_^]ËU43ʼnESVWjE3PSj@Wx9]tSSSSSSWxF3}SSEPh8uFM3;_3%?^[O+]̋UW3}}}tRVEPEPWhIWWWWWj|yVhHWh<9}t	u(^_]̋U
43ĉ$
SVWjD3ۍD$$SP.3|$V33f$WhfD$tf$f$f$dVjWWlu
@yPhWS<dp $hDhPyVhpWS<x$PWWWl؅u9PhWh<6($Ph u9PhWh<D$hPWhT$PuPh`먍D$hPhL$lyVhWh<`WhjWjh@$PuPh( 6P(jjD$pPyVh 딾$xVPuPh h !֍$|yVh8!G$PLPHPD$pP$Ph!$hPyVh8"D$D$ DPD$$PWWWWWW$P$PTuPh"49|$tt$(|$9|$tt$(|$tyS($
_^[3@']ËUVW3EP}}}yPh"Wh<QE3PWu(#AyPh#΋MEPE}P$}yPh0$맃}u3F9}t	u9}tEPWEP_^]ËUL43ʼnESV3@W3fPyPh"Wh<n(#PWyPh#ËPP$xyPh0$덋@hPW0u9Ph$Wh<؅ہ$PWjYyPh%Py Ph%Wh<>3ҋOff;u+jXjh$&PĐuC9tD0P̐Yt$0P̐Yu13f90t#O@;w^뀋ɍB#ȍB;r3fN6+t}P}PPNP(3f9>PPPT߃tttd0VWp4tPWPM_^3[&#]ËPV[Ph@&QHP$_#Ph&Ut+EVW+t<ftf9Nu_^uҁ3fz]USVW3WtvxBt
f98tu+ǁ#xQu+QyM_^[]UEV3t=vWx7S]3WxEPuWSȐx;wu
z3f{_[tM3f^]̋UVW3EPE}PWh0eWWWWWj}}|yVh'Wh<_^]̋UEth'P uuh<'jh<^SRP؄uhd'55uh'jh<PPh'jh<[3]UQQVW(E6P3@WW8xEPjh6Wh`S}tPh((Wh<_^]ËUQSVWuhp(jh<EL*PyPh(jh<EE6d0WjpX؅uh(WjS#E{f36C,EPC4hL*PCC0s#S55tPh )jV<hh)jV<d0Sjp4_^3[]USV3W]h SW](, $"]E]MPEP]yVh)jh<?EPyVh)ՋSyVh*QQ 3td0Sjp4}tud0jp4_^[]ËUQS3V3EW9v[{uG$G P7wj3GtQhd*jh<FE@E;r_@^[]ËUSVW3E ;{9}uh*Wh<WMEPXyVh(Wh<jE*P*xҋEEE=MAPEd0WpX}uuh+P뛋uVjW ׋MEx2zB,6uB(}JlB@Bpx@bDB<B0URByVh@+jh<}Wh*StPhx+jh<@Os3h6jjjt)Vh+jh<~x봋M3d0Wjp4_^[]UQ}W}VEPyVhH,jh<j=WYYuh,Ph<WS+Ct|9EtwEP*yPh,jh<@buMV*
xMSW
yVh,jh<3h,jh<W[^h,jh<W_]U}Wuh(-jh<Wuht-VEP9
yVh-jh<ESEPEd0jpX؅uh-Ph<E7EPyVh@.jh<AuSYY7+EMpd0uuk3Vp4ud0V7pXMuh-Vh<USRVh.Vjp4'}E;sV+ƉEEPd0jpXȉuh-jtEUPBryVh,uv06Pd0jpXMtu֋S
A3d0Sjp4[^_]U 43ʼnEVWэujY}}u!Efufu3|u@rkzjYuM_3^]UQQ3EE9Euh.Ph<WuEPuEP\
]UhuАYYu
uuohuАYYuuԐYMAIhuАYYuuԐYMA#h$uАYYuuԐYM3]U<43ʼnESVu3WMԍ}j3uĉU܉U؉UYuh/Rh<W)39>uh/Wd0hWpXE̅uh-Wh<d0hWpXEȅuh-Wh<z]9>(E؋Pj;y}}3}}૫3td0SWp4}܍EPj,M.]܅tGuȋˋ}VWyPh/MԍEPEPVWyPhP0jh<}vujY}ԋ}ԋuă>t!3Vh/Wh<]܃BEЅt G32VhP/Wh<3h0Wh<@td0SWp4}tud0Wp4ud0Wp4EȅtPd0Wp4ƋM_^3[]U8SVWjY3}3}߉}}}E}PE}PMVy"Vh0Wh<}d0hWpX؅uh-Wh<d}p Wh41hS`yVh@1jh<SEPjjEPu`EE3ɉEԍẺMPE@M܉MdEEPEyPh1jh<uyVh1d3td0Wjp4}tud0jp4td0Sjp4_^[]US3ۍEVW]P]]}]E2PSujYyVhMEP2
}xttpuE$PSujYlxMEPZ
yVh6h&SS<WVh3jS<3Vh2Sh<}}t'WEPEPuT}t	utd0WSp4}tud
0Sq4_^[]ËUVW3EP}}}E2PWubyVhL3Wh<u@9}t	u_^]ËUS3VW]9]uh3Sh<WuVE2PSvjYy VhSh<M3WyVh3uMD4zyVhX4d@ uh4Sh<@+M]QM4P]$yVh4[9]t	u_^[]̋U<43ĉ$8SVWL$XyVh 5jh<ed3hSp d0pXuh-Sh<!Vh@5hd5hWyVhp5Sh<WSSSlu%Ph5Sh<@L$ÅtT$09u@u%HP%=uEL$83ɅIwQVhuVpu)Ph5sh@6Sh<@h6Sh<d0WSp4$D_^[3
]ËU3tvWx}vWuuQ	t3f]Ut)EVu+Wt<ftf9Nu_^uҁ3fz]U3tvWxhuQ	t3f]UUS3ۅt:VWf9tu%Wtt+:_^Wyt[]U0SV3MډuuuuWE09u;MEPYy$VhH,jh<EP$xˋEE;EH;r;jYr	d0VjpXuh$7Ph<SuhH7VW^y$Vhp5jh<WEP3:Ph6Ph6jh<SEPu컖hT7jS<EEԍEE؍EEPuE@uuuhyVhjS<3td0Wjp4h6Vh<
_^[]UQSVW3}څuh6Wh<
ESu8d0jWpXuhh7Ph<TEPjWjuVlxuM3GVSh7jh<d0Wjp4_^[]UVWuh6Qh<
AWujEPjjuVpyVWh7jh<3_^]UQSVWthutaWue΍Qff;Eu+MPVj3PuSp3yVWh,8Ph<h6jh<
_^[]U43ʼnEVWV3WP}WVPj+jtyVh`8Wh<f;v
Vh83ҋfHF\t/t:t;wRyPh,gM_3^b]ËUSV3ۋW]]]]WEPd0hSpX؅uhh7Ph<=EPhSjEPVlyVWh7jh<{t Wh8jh<UMQKy$Vh9jh<Ex;rod0WjpXȋEuh-Qh<QWtQCPQ?yVh,m3hD9jh<d0Sjp4h6Sh<
_^[]UV3ƅt1t
f91tu+ЁW#WUtx2^]hćYu@Ã 3ËU}SVW@dH3ۣ@ȇd]PʉU33G;thxU3u}=̇t
jY\ćEth5u;r:MtUć
;uE9Mt͋‰MEP3YćGȇ̇9]33G9}d3ۉ]ȇPU;thxU3u}9̇j[t	j5hh=̇AYYt3XhhẎ}Yu3=Їt&hЇYtu5ЇSu@_^[]̋U}u] Ucsm9Eu
uP	YY]3]j,hxE3uEw0}u=@uu9Et	=ԇtNE}u
Duuu׉EMEQPIYYËe3uu}EuuuEMEQPYYËe3uu}EuuujEMEQPYYËe3uu}}EVVu!MEQP}YYËe3uEVVu]MEQPNYYËe3u=ԇt4EVVuMEQPYYËe3uEt	EuuuEMEQPYYËe3uu=ԇtG=Dt>Euuu׉EMEQPyYYËe3uuEE}w
0ËUVu3;usWu>t
׃;ur_^];
4uU}ue3@]%%̋UE3SVWH<AYt}p;r	H;r
B(;r3_^[]̋UjhXyhwdPSVW41E3PEdeEhztTE-PhPt:@$ЃEMd
Y_^[]ËE3Ɂ8ËeE3Md
Y_^[]̋UMMZf9uA<8PEuf9Hu]3]ËUee4VWN@;tudEPE3EED1E@1E3EM3EEP\E3E3E;t54uO@ȉ
4_8^]%hwd5D$l$l$+SVW41E3PeuEEEEdËMd
Y__^[]Q̋Uuuuuhth4M]Ujuh	LPP]ËU$H
D@<58=4f`f
Tf0f,f%(f-$XELEPE\PTH	LXjXkǀ\jX
4\jX
8\jXk
4LjX
8Lh]%̋D$L$ȋL$u	D$S؋D$d$؋D$[%ؐ%ܐ%2t,r@rorrrrrs's;sesysssstuuX?yyyyF@ISyyzWerDiagController.dllQueryOriginalBucketStartAppRecorderStartFDR,N@DxhLʗؗVdܔԔ"<4bxL̙tޖЖ

(@Xv̚$@Nrԛ.>J\l\@whx Е0L\0@pHlƖ$̘((8Td2 RrڙxhLʗؗVdܔԔ"<4bxL̙tޖЖ

(@Xv̚$@Nrԛ.>J\l\o_XcptFilter_amsg_exitfreemalloc_inittermmsvcrt.dllj_except_handler4_common-SleepQueryPerformanceCounter
GetCurrentProcessIdGetCurrentThreadIdGetSystemTimeAsFileTimeGetTickCountUnhandledExceptionFilterSetUnhandledExceptionFilterGetCurrentProcessMTerminateProcessapi-ms-win-core-synch-l1-2-0.dllapi-ms-win-core-libraryloader-l1-2-0.dllapi-ms-win-core-profile-l1-1-0.dllapi-ms-win-core-processthreads-l1-1-0.dllapi-ms-win-core-sysinfo-l1-1-0.dllapi-ms-win-core-errorhandling-l1-1-0.dlloLdrDisableThreadCalloutsForDll#DbgPrintExntdll.dll_vsnwprintf_wcsnicmpisspacepwcschr
_wcsicmp_wtoiWerRegisterFileapi-ms-win-core-windowserrorreporting-l1-1-0.dllCloseHandleReadProcessMemoryGetLastErrorOpenEventWCreateEventW>GetTempPathW<GetTempFileNameW	DeleteFileWCreateFileWGetSystemDirectoryWGetProcessIdCreateProcessWGetModuleFileNameWGetTraceLoggerHandleGetTraceEnableLevelGetTraceEnableFlagsRegisterTraceGuidsWTraceEventStartTraceW6WaitForSingleObject)SetEventapi-ms-win-core-handle-l1-1-0.dllapi-ms-win-core-memory-l1-1-0.dllapi-ms-win-core-synch-l1-1-0.dllapi-ms-win-core-file-l1-2-0.dllapi-ms-win-core-file-l1-1-0.dllapi-ms-win-eventing-classicprovider-l1-1-0.dllapi-ms-win-eventing-controller-l1-1-0.dllEnableTraceapi-ms-win-eventing-legacy-l1-1-0.dllNtCloseRtlFormatCurrentUserKeyPathRtlFreeUnicodeStringGRtlInitUnicodeStringBEtwEventWriteNoRegistrationTZwUpdateWnfStateDataZwQueryWnfStateNameInformationNtQuerySystemInformationNtWaitForSingleObjectNtOpenEventRtlAllocateAndInitializeSidNtAlpcConnectPortNtAlpcSendWaitReceivePortRtlFreeHeapRtlFreeSidJRtlCreateUserThreadENtDeleteKey@NtDelayExecutionzLdrGetDllHandle<RtlInitAnsiStringLdrGetProcedureAddressHNtDeleteValueKeyRtlAllocateHeapRtlGUIDFromStringRtlDosPathNameToNtPathName_UDNtDeleteFileNtOpenKeyNtQueryValueKeybNtSetValueKeyNtQueryInformationProcess	memcpymemmove
memset0	H`4VS_VERSION_INFO
"cE
"cE?&StringFileInfo040904B0LCompanyNameMicrosoft Corporation\FileDescriptionWER Diagnostic Controllerl&FileVersion10.0.17763.802 (WinBuild.160101.0800)TInternalNameWER Diagnostic Controller.LegalCopyright Microsoft Corporation. All rights reserved.TOriginalFilenameWERDiagController.dllj%ProductNameMicrosoft Windows Operating SystemBProductVersion10.0.17763.802DVarFileInfo$Translation	00D0H0P0X000|;;<<<%<+<;<I<[<d<m<<<<<<<<<<<<<	=4=I=~=========>>>0>?>J>c>>>>>>?*?@?L?h?????@xJ0V0p001+1=1I1c1|1111122!2-2D2V2`2n2z2222223,3@3Q3b3333334444$4*464F4O4^4k44444444	5"515G5S5e555555556.666>6H6X6d6l6v6666666667727<7?8h888888899h9u9999992:E:g:o:::::::::;;$;0;9;\;j;t;z;;;;;;;;;<<&<0<6<@<Z<m<t<<<<<<==)=a=k=w========
>X>b>n>>>>>>?
???(?K?e?????PD0$00001#191G111123,383D3w3|3333333333333344.4H4N4W4a4m4444444445565W5]5c5r5{5555
6666S6t66666B7N7s777778P8]8h8o8y8888888/9<9M9Z9f99999::#:0:U:b:z::::::	;;(;T;i;w;;;;;; <B<q<<=
=$=1=F=O=g=p=========>>7>O>[>g>>>>?;?Y?f???????`L0(0;0S000001171D1W1h111111122N2V2o2222222223303=3L3a3{33333334&4=4E4^4j4444444445?5`5m555555555666{666666666r88889#999F9b9q9~99999999:$:0:\:h::::::::;*;6;J;^;k;x;;;;;<<3<e<q<}<<<=V=k=v=======	>>C>S>_>>>>>>>g?l?q??????p0010:0@0a0i0p0v0|0000000
111/171J1V1^111112!2E3]3333:4b444455/5M5a5g5646C6L6U6j6666666"7'7L7U7`7g7y77777777777777777778
88$848:8E8K8W8g8p8888888899999 9(9,94989@9D9L9P9l9p901

Hacked By AnonymousFox1.0, Coded By AnonymousFox