1.2
低危

2073425680a0a7a374bc6ff4a5f4efc58bc8181435c5ccc2e6ed73a4e86d8fde

2073425680a0a7a374bc6ff4a5f4efc58bc8181435c5ccc2e6ed73a4e86d8fde.exe

分析耗时

194s

最近分析

377天前

文件大小

937.9KB
静态报毒 动态报毒 CVE FAMILY METATYPE PLATFORM TYPE UNKNOWN WIN32 TROJAN WORM DELF
鹰眼引擎
DACN 0.12
FACILE 1.00
IMCLNet 0.60
MFGraph 0.00
静态判定
反病毒引擎
查杀引擎 查杀结果 查杀时间 查杀版本
Alibaba None 20190527 0.3.0.5
Avast Win32:Delf-SVI [Trj] 20191023 18.4.3895.0
Baidu Win32.Virus.Lamer.f 20190318 1.0.0.2
CrowdStrike win/malicious_confidence_100% (D) 20190702 1.0
Kingsoft None 20191023 2013.8.14.323
McAfee W32/HLLP.11042.gen 20191023 6.0.6.653
Tencent Virus.Win32.Lamer.fh 20191023 1.0.0.1
行为判定
动态指标
可执行文件使用UPX压缩 (2 个事件)
section UPX0 description 节名称指示UPX
section UPX1 description 节名称指示UPX
网络通信
与未执行 DNS 查询的主机进行通信 (1 个事件)
host 114.114.114.114
文件已被 VirusTotal 上 60 个反病毒引擎识别为恶意 (50 out of 60 个事件)
ALYac Gen:Variant.Symmi.6015
APEX Malicious
AVG Win32:Delf-SVI [Trj]
Acronis suspicious
Ad-Aware Gen:Variant.Symmi.6015
AhnLab-V3 Worm/Win32.Delf.R234590
Antiy-AVL Worm[P2P]/Win32.Delf
Arcabit Trojan.Symmi.D177F
Avast Win32:Delf-SVI [Trj]
Avira DR/Delphi.Gen
Baidu Win32.Virus.Lamer.f
BitDefender Gen:Variant.Symmi.6015
Bkav W32.OverlayNT1.PE
CAT-QuickHeal W32.Lamer.VC8
CMC P2P-Worm.Win32.Delf!O
ClamAV Win.Malware.Delf-6737076-0
Comodo Packed.Win32.MUPX.Gen@24tbus
CrowdStrike win/malicious_confidence_100% (D)
Cybereason malicious.d9af13
Cylance Unsafe
Cyren W32/Trojan.FITT-6058
DrWeb Win32.HLLW.Kazaa.924
ESET-NOD32 Win32/Delf.NAY
Emsisoft Gen:Variant.Symmi.6015 (B)
Endgame malicious (high confidence)
F-Prot W32/Trojan3.AMWW
F-Secure Dropper.DR/Delphi.Gen
FireEye Generic.mg.af5556dd9af135a7
Fortinet W32/Aple.A
GData Gen:Variant.Symmi.6015
Ikarus P2P-Worm.Win32.Delf.aj
Invincea heuristic
Jiangmin Worm/Delf.xz
K7AntiVirus Trojan ( 004f00e31 )
K7GW Trojan ( 004f00e31 )
Kaspersky P2P-Worm.Win32.Delf.aj
MAX malware (ai score=86)
McAfee W32/HLLP.11042.gen
McAfee-GW-Edition BehavesLike.Win32.Generic.dm
MicroWorld-eScan Gen:Variant.Symmi.6015
Microsoft Worm:Win32/Xolxo.A
NANO-Antivirus Trojan.Win32.Delf.oxkq
Panda Trj/Genetic.gen
Qihoo-360 Harm.Win32.Baga.A
Rising Worm.Delf!1.64B1 (CLASSIC)
SentinelOne DFI - Malicious PE
Sophos W32/BagarBu-A
Symantec W32.SillyP2P
TACHYON Worm/W32.Delf
Tencent Virus.Win32.Lamer.fh
可视化分析
二进制图像
数据导入图像 288x288
数据导入图像 224x224
数据导入图像 192x192
数据导入图像 160x160
数据导入图像 128x128
数据导入图像 96x96
数据导入图像 64x64
数据导入图像 32x32
运行截图
暂无运行截图 该样本运行过程中未生成截图

👋 欢迎使用 ChatHawk

我是您的恶意软件分析助手,可以帮您分析和解读恶意软件报告。请随时向我提问!

🔍 主要威胁分析
⚡ 行为特征
🛡️ 防护建议
🔧 技术手段
🎯 检测方法
🤖

PE Compile Time

1992-06-20 06:22:17

PE Imphash

9973fdd4b86d866b3faa39fa66cf7e0a

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
UPX0 0x00001000 0x0000a000 0x00008200 3.5176522058168964
UPX1 0x0000b000 0x00003000 0x00002400 4.355150921326428
.rsrc 0x0000e000 0x00001000 0x00000200 2.760203637112556
.imports 0x0000f000 0x00001000 0x00000400 4.0715912444404205

Resources

Name Offset Size Language Sub-language File type
RT_RCDATA 0x0000b0c0 0x00000044 LANG_NEUTRAL SUBLANG_NEUTRAL None
RT_RCDATA 0x0000b0c0 0x00000044 LANG_NEUTRAL SUBLANG_NEUTRAL None

Imports

Library KERNEL32.DLL:
0x4070f4 WriteFile
0x4070f8 ReadFile
0x407100 GetLastError
0x407104 FindNextFileA
0x407108 FindFirstFileA
0x40710c FindClose
0x407118 ExitProcess
0x40711c DeleteFileA
0x407120 CreateMutexA
0x407124 CreateFileA
0x407128 CopyFileA
0x40712c CloseHandle
Library KERNEL32.DLL:
0x407064 GetCurrentThreadId
0x407068 GetLastError
0x40706c ExitProcess
0x407070 WriteFile
0x407078 SetFilePointer
0x40707c SetEndOfFile
0x407080 RtlUnwind
0x407084 ReadFile
0x407088 RaiseException
0x40708c GetStdHandle
0x407090 GetFileSize
0x407094 GetFileType
0x407098 CreateFileA
0x40709c CloseHandle
0x4070a0 GetCommandLineA
0x4070a4 TlsSetValue
0x4070a8 TlsGetValue
0x4070ac LocalAlloc
0x4070b0 GetModuleHandleA
0x4070b4 GetModuleFileNameA
0x4070b8 FreeLibrary
0x4070bc HeapFree
0x4070c0 HeapReAlloc
0x4070c4 HeapAlloc
0x4070c8 GetProcessHeap
Library advapi32.dll:
0x4070d8 RegSetValueExA
0x4070dc RegQueryValueExA
0x4070e0 RegOpenKeyExA
0x4070e4 RegFlushKey
0x4070e8 RegCreateKeyExA
0x4070ec RegCloseKey
Library user32.dll:
0x4070d0 CharNextA

L!This program must be run under Win32
.imports
StringX
TObject%p@
[RP@P@
gW9tSVW
t1|9,9t:VW
_^SVWU
< v;"u
3C<"u1S
>3Q<"u8S
< w]_^[
Ht Ht.g
RPFHPS
6Huv=L
1^6GfF
53E?E3s
3EE_^[Y]
f=r/f=w)f%f=u
f=v)f=w#j
RPCHPt$
-CGL$
Iu9u_^[
PRQQTj
YZXtpH
S1VWUd
SPRQT$(j
SVWUc@
SVWUc@
^s]_^[
PQ}ZXSVW
,ISVWRP1L
JZ_^[X$
thtkFW)w
9uXJt
8uAJt
t7JIt1S
PHXHI|
St-Xt&J|
t0JN|*9}&~")9~
t@t1SVW
1Z)_^[
U3Uh])@
U3Uh)@
3U3Uh*@
TRegistry
E2EPEPj
MU3ZYYd
SVWUQ3
jZ]_^[Q
UQSVWM
P_^[Y]
UQSVW3EE
U3Uh/@
v3ZYYd
BFKu_^[
d0d EEPEPt,P3
EU3ZYYd
UQSEEh3Uhe1@
UxSVW3
x|UEEd@
d0d UP@
EPEPEP
U|FPx5@
Ux"P3ZYYd
EE_^[]
BagarBubba
TFileName5@
TSearchRecX
uEPC,P
PEPC8C
[b[UQ6
IuMSMUEE_EWEO
3UhN;@
d0d E@U|
u?8.t4uhh;@
uU*P0
>u|U0|tP
upUpXhP^
hldl;@
ludU^d\P
4\``;@
uXUXPP
*3ZYYd
3Uh4<@
M3Uh<@
d0d uE
U3ZYYd
x[Y]Uj
SV3Uh=@
B3ZYYd
EU^[Y],
Windows\CurrentVersion\Uninstall\eDonkey2000
UninstallString
uninstall
\incoming
SV3Uh>@
E1^[Y]-
Windows\CurrentVersion\Uninstall\Morpheus 2.0
UninstallString
UNWISE.EXE
\My Shared Folder
U3QQQQS3UhX@@
u63h@@
\software\Xolox
shareddirs
Drivers
Drivers\
U3QQQQQSVW
=3ZYYd
\software\kazaa\Localcontent
Drivers
012345:
DisableSharing
\software\Shareaza\Shareaza\Transfers
DownloadsPath
S3Uh/C@
\software\LimeWire
InstallDir
\Shared
U3QQQQQQ3UhD@
C:\My Downloads
\software\LimeWire
\software\shareaza
\software\Kazaa
\software\Xolox
\software\morpheus
\software\Windows\CurrentVersion\Uninstall\eDonkey2000
U3Uh-F@
d0d e@
t3UhF@
d0d hF@
v3ZYYd
BagarBubba
UTypes
System
SysInit
RegUnit
KWindows
WriteFile
ReadFile
GetWindowsDirectoryA
GetLastError
FindNextFileA
FindFirstFileA
FindClose
FileTimeToLocalFileTime
FileTimeToDosDateTime
ExitProcess
DeleteFileA
CreateMutexA
CreateFileA
CopyFileA
CloseHandle
GetCurrentThreadId
GetLastError
ExitProcess
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
GetCommandLineA
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
GetModuleFileNameA
FreeLibrary
HeapFree
HeapReAlloc
HeapAlloc
GetProcessHeap
RegSetValueExA
RegQueryValueExA
RegOpenKeyExA
RegFlushKey
RegCreateKeyExA
RegCloseKey
CharNextA
.idata
.rdata
P.reloc
P.rsrc
|FFFF}FFFUf
5YhQn3O;Y
PGWoG9&p
-!W6?7
7S|d+|#xzKxJ
Baga]s
rBubba[-R
FFileName
TSe-ntchcX(+
WkX"g9,w
Pf`N;6X|
8.t4uh\eW>`
oFfOE*S
d{v0!phd
||tKF.@tx
dlld@.
@d\KF.\``
X;5wIl
`h!ltx
iv~dOr
*.*exe
$Oscrcompif
t#Gc&I_O
7BNR"=o+
,Windows\CurrentVersion\Un
stall\e
-Morpheus 2.0
NWISE.EXE
My Sha_d Foldb
S.G2X@
-8dHv!@_LL2H#<
softw\X
3)U>n,@A
BWJwh"g!XH
_kazQjaa\LocB
012345:+
BGL["%d%
9{K_Tra[f
n3adsPh
yVkj/C
DCM`C^!
BtC6CJA
ZLimeQ
\,te30f
HH,-$!
=$!4FJ@f
W=$c_t
Oi;&=O8
UTypes
System
Wp;`Writeo
ZUGet&?%(oryA
LastErr
F Next1A
ClosM{
m;ExPccess#De]fTC%Mu
v4HanddIU"Th8dId
UnhLd
1SePop;
E)OfOt@(l:wiZRai
{,YHStd\
TlsViue
c6ModulGA
veVbra
w;OnKey
dChI}APEL
{eR/pj0YuS6
`DATA,
<BSSvd
`>.I7idap'
ODrS2w
DPNxl'e|Ks
F'sr&G|]J'
KERNEL32.DLL
advapi32.dll
user32.dll
LoadLibraryA
GetProcAddress
ExitProcess
RegFlushKey
CharNextA
KERNEL32.DLL
WriteFile
ReadFile
GetWindowsDirectoryA
GetLastError
FindNextFileA
FindFirstFileA
FindClose
FileTimeToLocalFileTime
FileTimeToDosDateTime
ExitProcess
DeleteFileA
CreateMutexA
CreateFileA
CopyFileA
CloseHandle
KERNEL32.DLL
GetCurrentThreadId
GetLastError
ExitProcess
WriteFile
UnhandledExceptionFilter
SetFilePointer
SetEndOfFile
RtlUnwind
ReadFile
RaiseException
GetStdHandle
GetFileSize
GetFileType
CreateFileA
CloseHandle
GetCommandLineA
TlsSetValue
TlsGetValue
LocalAlloc
GetModuleHandleA
GetModuleFileNameA
FreeLibrary
HeapFree
HeapReAlloc
HeapAlloc
GetProcessHeap
advapi32.dll
RegSetValueExA
RegQueryValueExA
RegOpenKeyExA
RegFlushKey
RegCreateKeyExA
RegCloseKey
user32.dll
CharNextA
C:\WINNT\system32\actmovie.exe
L!This program cannot be run in DOS mode.
`.data
MSVCRT.dll
ADVAPI32.dll
KERNEL32.dll
USER32.dll
SHELL32.dll
ole32.dll
wYwwwwbwTwwM}w
w2wVwb_w
w0wDwww`swxmw4swwKVw#wzewTwvw9~wLwswqw$w
w$Jw+ww
7[w[wZw([w
DllUnregisterServer
DllRegisterServer
msdxm.ocx
IsInstalled
Software\Microsoft\Active Setup\Installed Components\{22d6f312-b0f6-11d0-94ab-0080c74c7e95}
audio/wav
audio/x-wav
SoundRec
midi/rmi
midi/mid
audio/midi
MPlayer
MIDFile
audio/basic
AUFile
video/quicktime
MOVFile
video/avi
video/x-msvideo
AVIFile
AIFFFile
audio/aiff
audio/x-aiff
video/mpeg
MPEGFile
BinaryFile
%s\Command
\Command
MPEGVideo
.Backup
MCI Extensions
/NewUser
ZAM1.0 QT PlugIn patch
rundll32 advpack.dll,DelNodeRunDLL32 %s
AM1.0 QT PlugIn patch
regedit -s %s
Software\Microsoft\Windows\CurrentVersion\RunOnceEx\920
[HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\audio/x-aiff]
[HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\audio/aiff]
[HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aiff]
[HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aifc]
[HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.aif]
[HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\MIME\video/quicktime]
[HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.qt]
[HKEY_CLASSES_ROOT\CLSID\{05589FA1-C356-11CE-BF01-00AA0055595A}\EnablePlugin\.mov]
REGEDIT4
/Remove
MPEGFILE\CLSID
MOVFILE\CLSID
AUFILE\CLSID
{00022601-0000-0000-C000-000000000046}
AIFFFILE\CLSID
PostExeSetup
RunSetupCommand
\dxmedia.inf
urlmon.dll
ddrawex.dll
danim.dll
{DC38CC31-4E3B-11d1-9071-0060081840BC}
{DC38CC30-4E3B-11d1-9071-0060081840BC}
quartz.dll
ActiveMovie Control
ActiveMovie File Types
\exx86.inf
\dxddex.cab
\mini.inf
\dxmini.cab
\exaxp.inf
\dxminiax.cab
ExecuteCab
advpack.dll
dxmedia.inf
mciqtz32.dll
mciqtz.drv
SYSTEM.INI
MCI.Support
MIME\Database\Content Type\audio/x-wav
Extensions\.mid
MediaType.Icon.bak
Extensions\.avi
CLSID\{2179C5D3-EBFF-11CF-B6FD-00AA00B4E220}
/Backup
/MPInstall
/Install
amovie.ocx,RunDll
InstallINF
MediaType.Open.Bak
Software\Microsoft\Multimedia\DirectXMedia\Extensions\.wav
Software\Microsoft\Multimedia\DirectXMedia
%s%s.lnk
amovie.ocx
%sActiveMovie Control.lnk
F.Owner
Software\Microsoft\Windows\CurrentVersion\ModuleUsage
EuPEPVVh
SU3V+W
uBVSUUU=w
UUUt$$=w
t$(9l$
UUUt$(
Pt$ (u<$
VPUUUt$,=w
Pt$ u<$
VPUUUt$,=w
UUt$$w
t$$9l$
UUt$(9l$
UUD$4UPt$4
UUt$,9l$
UUD$4UPt$4
UUt$,9l$
uBVSUUU=w
UUUt$$=w
t$(9l$
UUUt$(
Pt$ u%Vh|
t$,9l$
Pt$ #u%Vh}
t$,9l$
t$$9l$
S3UV+W
t$(Vhw
t$(Vhy
t$(Vhz
t$(Vh|
t$(Vh}
t$(Vh~
t$(Vhz
t$(Vh{
t$(Vhx
t$(Vh{
t$(Vhx
t$(_^]3[
SUVW(c
Pl$$l$ l$
UUD$DUPt$4
Pl$$l$ l$
UUD$DUPt$4
UUD$DUPh
nu/Ut$
jPjh0n
l$ u1D$$PUUD$,UPUD$4UPUUUt$<
jPjh0o
C:\WINDOWS\system32\cacls.exe
L!This program cannot be run in DOS mode.
`.data
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
wAwX`wwfwcwuw4`w
w9w$ww}
wwEw~w@w=w
wslw`jww
>wXw26whwJww`wywww
{wwzww,ww!w<wwnw
wDw<w&w=w<w<w%w3w
FILE_WRITE_ATTRIBUTES
FILE_READ_ATTRIBUTES
FILE_DELETE_CHILD
FILE_EXECUTE
FILE_WRITE_EA
FILE_READ_EA
FILE_APPEND_DATA
FILE_WRITE_DATA
FILE_READ_DATA
FILE_GENERIC_EXECUTE
FILE_GENERIC_WRITE
FILE_GENERIC_READ
GENERIC_ALL
GENERIC_EXECUTE
GENERIC_WRITE
GENERIC_READ
MAXIMUM_ALLOWED
ACCESS_SYSTEM_SECURITY
SPECIFIC_RIGHTS_ALL
STANDARD_RIGHTS_REQUIRED
SYNCHRONIZE
WRITE_OWNER
WRITE_DAC
READ_CONTROL
DELETE
STANDARD_RIGHTS_ALL
cacls.pdb
EPEPSEPSv
zEuUE=H
X2MQMQPEPv
MQMQSMQSPv
zEuTu=H
X4MQMQPEPv
UQV39F
EPR;u=9~
t,OEPF
9Er39s
UQQSV3
;r3_^[
EPu9Et%u
X9MQuPj
YY0_[E^
YYt%h<
f|F\u?V
Yv6Vf|F:Yu*fD
UQSVW=
X MQuPj
_^[U$VWEPEPEP7
PEPyuQj
SSWPFVPSj
f>/t59M
EPWPSu
YE3fx\t
PQQQQPM
Etz4;;7}sE
!EF;7|eE
VQPhT
YYt33PVQPhU
EPEP\]MM
3\4_^[
SVW3Vu
YYEPM{u+uh
uDShS
VS hO
PYY_][
P`EPEPu
M$;u^E
PM;|(h
WWWWjuWW
EPEPEPEPVu
MQMQVuPv
f8MZuH<
EPEPEP
YY3hP7
+SVWEePEEE
Y_^[Q%
??3@YAXPAX@Z
??2@YAPAXI@Z
wcscpy
wcscmp
wcslen
_wcsicmp
wcscat
fwprintf
fprintf
vswprintf
wcschr
_stricmp
wprintf
printf
setlocale
_c_exit
_XcptFilter
_cexit
__winitenv
__wgetmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
msvcrt.dll
_controlfp
_except_handler3
LookupAccountSidW
LookupAccountNameW
EqualSid
GetLengthSid
InitializeAcl
AddAce
GetSecurityDescriptorDacl
GetFileSecurityW
SetFileSecurityW
SetSecurityDescriptorDacl
InitializeSecurityDescriptor
ADVAPI32.dll
LocalFree
LocalAlloc
GetLastError
FindClose
FindNextFileW
FindFirstFileW
GetFullPathNameW
WriteConsoleW
WideCharToMultiByte
lstrlenW
GetConsoleMode
GetStdHandle
lstrcmpiW
FormatMessageW
GetVolumeInformationW
GetVolumePathNameW
FormatMessageA
GetModuleHandleA
KERNEL32.dll
SetThreadUILanguage
BagarBubba
C:\WINDOWS\system32\asr_pfu.exe
L!This program cannot be run in DOS mode.
g(Rich
`.data
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
w{ywWwjww
|%x|q|n|0|
|c|sV||.|||
|j>|I|n+|
|1|/|_|e|
|wK|/|/|
|F,|t|{
AsrAddSifEntryW
CorExitProcess
mscoree.dll
runtime error
TLOSS error
SING error
DOMAIN error
- unable to initialize heap
- not enough space for lowio initialization
- not enough space for stdio initialization
- pure virtual function call
- not enough space for _onexit/atexit table
- unable to open console device
- unexpected heap error
- unexpected multithread lock error
- not enough space for thread data
This application has requested the Runtime to terminate it in an unusual way.
Please contact the application's support team for more information.
- not enough space for environment
- not enough space for arguments
- floating point not loaded
Microsoft Visual C++ Runtime Library
Runtime Error!
Program:
<program name unknown>
GetProcessWindowStation
GetUserObjectInformationA
GetLastActivePopup
GetActiveWindow
MessageBoxA
user32.dll
`h````
ppxxxx
(null)
asr_pfu.pdb
tDEWEEVE
VVVEPVu
tZSVWu
U4SV3Wuu
VEPSuu
t'9uvhEPj
VEPuuu
uVu9ut
uVu9ut
uVu39u_^
EPuuuu
-uVuuuVu
t+uSuuSuu]Su
uSu9]t
uSu9]t
uSu_^39][
jz^mPh
YYu&!E
Wffffff
@@fu+E
AABBft9f;t2Vu
GYGfYt
UV3F958
3^YY[]
3BYY[]
SVEW3;
@u+@<v)P
/VqGf>=Yt
3Y[_^5
ft;uf t
Bf8\tf8"u*
UQQSVWh
3VWf=P
EPEPWS3B}E
&EPEPV
]]_u.;
t2SSjVj
t?M+E+QVjWj
@:u+V|
E_^[uG
YEtWPjuj
;rSVWEP
3]3@]h 6
+SVWEePEEEEd
Y_^[QVC20XC00U
33333]^]
]_^[]UL$
YYuf_]h0
YYGG3f
YfdtSfitMfotGfxtAfXu
1ht lt
g~Bit!n
f+udOuC3Y%
YtdV(PW@!
GGf?^u
f]t`FFf9s
jx^f;tZfXtT
S=YYj0[
GIt%t)
Gt/KuD$
GKu[^D$
AABBfuE
W3;u4DP
WI <}}
MLD3#um
#Mj _^{
;]r;]u&
]#\D\D
_^[USVWUj
P(RP$R
t5|$(t
;t$(v(4v
UQPXY]Y[
EtVMf9MZ
;|Q+;E
uV9t*j
E_WEPE
UDSVWj
@@Ju;t
EPSQVQWS5t
;tG9]uB8\
EPSQVjWS5t
BF;U|GG;u
EPSSSjWS5t
u5SSWh
E SSSSu
]M3G9]u
uhYE;t}SSuuu
e33Mu;u
VY;thE
W|Y9]t
3@]3]UWVu
DDDDDDDDDDDDDD
t78t2=T
PMvYtDu
t!VGYu
W>+~'WPv
Y'V}Yt
USVW33395
~33F9=
u2EPVh
M3F]39}u
SVYYE;tuWWSuu
P.YEtnu
fNPSuu
u5EP3GWh
VjYEn}
YM`jDh
39}t WWu
tjEEb9}u
WWWWVSWu
;tG3Vj
YYE;t43WWVPVSWu
u]Ht"x
tsSYt@
AdjustTokenPrivileges
LookupPrivilegeValueW
OpenProcessToken
RegSetValueExW
RegOpenKeyExW
ADVAPI32.dll
CloseHandle
GetLastError
SetLastError
GetCurrentProcess
HeapFree
ExpandEnvironmentStringsW
HeapAlloc
GetProcessHeap
SetFilePointer
CreateFileW
WriteFile
BackupWrite
BackupRead
FreeLibrary
GetProcAddress
LoadLibraryW
CopyFileW
MoveFileExW
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetVersionExA
ExitProcess
GetModuleHandleA
GetStdHandle
GetModuleFileNameA
GetModuleFileNameW
FreeEnvironmentStringsA
MultiByteToWideChar
GetEnvironmentStrings
FreeEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineA
GetCommandLineW
SetHandleCount
GetFileType
GetStartupInfoA
HeapDestroy
HeapCreate
VirtualFree
LoadLibraryA
VirtualAlloc
HeapReAlloc
RtlUnwind
InterlockedExchange
VirtualQuery
WideCharToMultiByte
VirtualProtect
GetSystemInfo
LCMapStringA
LCMapStringW
SetStdHandle
GetStringTypeA
GetStringTypeW
GetLocaleInfoA
GetCPInfo
FlushFileBuffers
ReadFile
KERNEL32.dll
wsprintfW
USER32.dll
BagarBubba
C:\WINDOWS\system32\tcmsetup.exe
L!This program cannot be run in DOS mode.
#;p;p;pp:p;p
p6pp:p
p:pRich;p
`.data
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
USER32.dll
TAPI32.dll
qwew`w
wcyw~wvw[wCwwcw
qw9w,w
Xw26whww`wyw
w>wJwwzw
tcmsetup.pdb
@@BB3f
ft$f=
EPSSSSSSh
EP]]]]]]E
;uaWWWWEPPWu
EPS3Sh
EPEPEPSh
EPPEPj
EE9Er39E
_^[uhx
EPEPEPj
u/EPEPEPVh
9uSW=t
EPPEPVPuE
EPEPEPVPuE
PuEE;E
EPEPEPVh
9uu"EPh?
EPEPVh?
[SEPSVh0
u,Sh,0
3-EPVh
3G#5@0
f"UVWj _j
fuf"u/
frtffRt`fqt8fQt2fxt
f8MZuH<
EEP5D0
EPEPEP
>"u:Fu
<"u>"u
< v]EP
> vFuj
XPVSSP.u9]u
+SVWEePEEE
Y_^[Q%|
_c_exit
_XcptFilter
_cexit
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
msvcrt.dll
_controlfp
_except_handler3
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
RegSetValueExW
RegCreateKeyExW
FreeSid
CheckTokenMembership
AllocateAndInitializeSid
RegDeleteKeyW
RegEnumKeyExW
ADVAPI32.dll
GlobalFree
GlobalAlloc
lstrcmpiW
CloseHandle
lstrlenW
ReleaseMutex
WaitForSingleObject
CreateMutexW
GetCommandLineW
GetModuleHandleW
GetModuleHandleA
GetStartupInfoA
KERNEL32.dll
MessageBoxW
LoadStringW
wsprintfW
USER32.dll
NETAPI32.dll
lineRemoveProvider
lineAddProviderW
TAPI32.dll
tXTMbS
dk{:g*g
tXTyrCg
bR0Wy(uN5u
dk{:gS_MR
N/f[7b
ely(u[7b
bR0Wy(uN
(ul/f:
gRhVv:ghV
gRhVSs
N(udk}TN@b
N>f:ymo`FhV
gR[7b[
gRhVeQs
gRhVeQs
y(u[7beQs
[7beQs
g{vU_0R|~{
(u1Y%
c[v|~{
^7b/f&TX[(WTcknx,
hg{vU_v
^7b[hQT
c[v|~{
QeQlQh1Y%
hg{vU_v
^7b[hQv^
gR/f&TX[(W(
(Wc6Rb
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
BagarBubba
C:\WINDOWS\system32\proxycfg.exe
L!This program cannot be run in DOS mode.
u(Rich
.idata
@.rsrc
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
WININET.dll
WINHTTP.dll
winhttp.dll
RSDSa8[eH
proxycfg.pdb
VVMQVWPh
VVEPVWVh
E3EPVEPVu
SVVVVjuV
;YEt-VVuPjuVPVMQHPuu
3<SV5,A
WW3^[_]
US33Vu
MQPu0v
EEP2t-Wu
EHYYtIHHt
t4VW6u
^j$EEu0
EPEPjKj
Y_^j(h
f8MZuH<
EPEPEP
uuuU0u9}u
+SVWEePEEEEd
Y_^[Q%hA
|F||/|
|8|T||d|K|
OL\L|SLLL#LLL8
L~LLgL
??3@YAXPAX@Z
??2@YAPAXI@Z
wcslen
tolower
_c_exit
_XcptFilter
_cexit
__initenv
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_except_handler3
msvcrt.dll
_controlfp
FreeLibrary
FormatMessageW
LoadLibraryExA
WriteFile
WideCharToMultiByte
GetConsoleOutputCP
WriteConsoleW
GetConsoleMode
GetFileType
GetStdHandle
MultiByteToWideChar
lstrlenA
GetLastError
LocalFree
GlobalFree
GetModuleHandleA
KERNEL32.dll
InternetQueryOptionA
WININET.dll
WinHttpSetDefaultProxyConfiguration
WinHttpGetDefaultProxyConfiguration
WINHTTP.dll
HrCg@b
w.^ROo`
wS_MR
gRhVTS
NS_MR(u7bv
t{|W/f
PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD
BagarBubba
C:\WINDOWS\system32\fastopen.exe
!L!Packed file is corrupt
BagarBubba
C:\WINDOWS\system32\regedt32.exe
L!This program cannot be run in DOS mode.
`.rsrc
KERNEL32.dll
SHELL32.dll
regedit.exe
regedt32.pdb
<"u>"u
ExitProcess
GetModuleHandleA
GetStartupInfoA
GetCommandLineA
KERNEL32.dll
ShellExecuteA
SHELL32.dll
ffffffffffffff`
ffffffffffffff`
fffffff`
ffffffffff`
fffffffff`
ffffffffff`
fffffffff`
fffff`
ffffff`
fffff`
ffffffff`
fffffff`
ffffffff`
fffffff`
ffffffffff`
fffffffff`
ffffffffff`
fffffffff`
fffffffffff`
ffffffffffffff`
BagarBubba
C:\WINDOWS\system32\mountvol.exe
L!This program cannot be run in DOS mode.
`.data
msvcrt.dll
ADVAPI32.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
w=w@ww
wwwbjwwgw
wwR`wwgwEww
>wXw26whwJww`wyw
{ww<w=w
mountvol.pdb
+MQPV5
YYEP3VVu
P@f93u
GGfuf97uS
UQQEPj
3?WEPu
u-3WVPW
Pz&P4VPW
>/Eu>F
u1<dt%<Dt!<lt
WPEYYEfE\t
f:ujf\u`3f9uUVPPf
t,WVPWh
3WVPWP3_[^j(h8
f8MZuH<
EPEPEP
uuuW0u9}u
+SVWEePEEE
Y_^[Q%p
wcslen
wcscat
swprintf
_c_exit
_XcptFilter
_cexit
__initenv
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
msvcrt.dll
_controlfp
_except_handler3
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
ADVAPI32.dll
LocalFree
WriteFile
LocalAlloc
WriteConsoleW
FormatMessageW
GetLastError
GetVolumePathNamesForVolumeNameW
SetLastError
QueryDosDeviceW
FindVolumeClose
FindNextVolumeW
FindFirstVolumeW
DefineDosDeviceW
SetVolumeMountPointW
GetVolumeNameForVolumeMountPointW
DeleteVolumeMountPointW
GetConsoleMode
GetStdHandle
SetErrorMode
GetModuleHandleA
KERNEL32.dll
CharToOemW
USER32.dll
BagarBubba
C:\WINDOWS\system32\finger.exe
L!This program cannot be run in DOS mode.
z:0>[c>[c>[cxc?[c>[c
[cxc5[cxc?[cxc0[cxc?[cRich>[c
`.data
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
WS2_32.dll
USER32.dll
MSWSOCK.dll
w`jwEw}
VqAq2q3q"<q>q]>qm
{wXw26whwJww`wyw
w@:ww%wow
wwzwww
finger
finger.pdb
}L!EP_ElPELP3h
CV}L]T
Wbj Y3}ElH
@uV+Pu|W
SEsPW;t}
3Gt'8-u
u3_^j(h
f8MZuH<
EEP5d
EPEPEP
uuu60u9}u
+SVWEePEEE
Y_^[Q%d
^U3PPM
USVW=H
putchar
isspace
isprint
fflush
strrchr
_c_exit
_XcptFilter
_cexit
__initenv
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
msvcrt.dll
_controlfp
_except_handler3
GetLastError
GetModuleHandleA
KERNEL32.dll
getaddrinfo
WS2_32.dll
_write
LocalFree
FormatMessageA
CharToOemBuffA
USER32.dll
s_perror
MSWSOCK.dll
@(#) Copyright (c) 1980 The Regents of the University of California.
All rights reserved.
BagarBubba
C:\WINDOWS\system32\rsm.exe
L!This program cannot be run in DOS mode.
}^%}^^^
}^h}^%}^
^Rich^
`.data
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
NTMSAPI.dll
USER32.dll
wE=wyww$w
2cr6cr5cr&cr+cr"cr
(cr2cr1cr
$cr</cr#cr 8crY'cr%cr
hw26wXwJw>ww`wywwwzw
{w<w+ww=www<w%w&wwwFwkw3w
rsm.pdb
Error in Conversion from Unicode to OEM character set
Error in Conversion from Unicode to OEM character set
W3UUUUjt$,
t0UUSPjt$,Wj
Y_^][Y
U<VWEPEPEPEPEPEPEPq
EP}EPEPEPh
EfEfEfEfEE
EEEEEEEEEE
^VEPWj
zEuHWD
<3t'EEE
;Er#uC
E9Eu&uC
^VMQPu
zu?uRB
viEE`Pus
;EruA
_WMQPu
_WMQPu
zuJu9?
vfEEtPus
_WMQPu
zuJuW=
vfEEtPus
jX9_^[
jXO_^[
fft_fFtYfgt
fftXfFtRfgt
$9Uud9Uu_
YYE@;E
^t)WVEP,P
jVy9}tE,PEPs
u3tBPEPs
ElEdE\ETE(E,EXE@EHEDELE<E`EPE0E$E4E X9Exuj
fftafFt[fgt
fftgfFtafgt
fftafFt[fgt
fftafFt[fgt
fftafFt[fgt
!Edu}|
MhPu|6=
6Eh9EhYr
E8E8E|
u49}\t-Wj
9}Xt-Wj
u 9}LtT9}$t-Vj
9}Pt0j
j_v39}\u
3t^PuhEudulj
UUUUUu
fft_fFtYfgt
fftXfFtRfgt
$9Uub9Uu]
YYE@;E
E}R3Sj
39ut-Vj
9ut*Vj
jVi9uu
u3tIuEj
EEEEEEX9E
YYEPDP
FP7Dh2
FP7DhF3
D4PYEE
uq9Eu8h3
j'E430u
?tHtNt
_P;Yv
QVVVVh
X9ExUHUPU$U0UTULUlUXUhU\UDU,UdU`uj
#t?tII
fft_fFtYfgt
fftefFt_fgt
fft_fFtYfgt
PEPo}j
PEP}4j
E(@;ExE(
9UPu{9UXu
9ULub9UTu]j
39}Pt3Wj
Ed9}Tt4Wj
jj$u`E4Puds
9}`ue9}Du
j!_^[p
UUUUUUUUu
Dts?tII
fftefFt_fgt
d9Uu_=
39}tfWj
EP,P};
EEPWu,uPs
?tkHtfMt
ht\mu2uB
YY|t3C
~WaEPj
fftbfFt\fgt
E9ut0Vj
fftefFt_fgt
E}V3Zj
j7)guY9Et0Pj
EEEEEE
_0;Yv&E
fdtafDt[fgt
_t/EPWEP)P;
jW;9ut2Vj
MuQPEPs
YYPEPs
jSPEPs
YYPEPs
VU2hLX
VUtohX
VU0QhX
[]_^j(h
f8MZuH<
EPEPEP
+SVWEePEEE
Y_^[Q%l
??3@YAXPAX@Z
malloc
printf
swscanf
_wcsicmp
??2@YAPAXI@Z
wcscpy
iswdigit
wcslen
swprintf
_wcsupr
wcscat
_c_exit
_XcptFilter
_cexit
__winitenv
__wgetmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
msvcrt.dll
_controlfp
_except_handler3
GetModuleHandleW
WideCharToMultiByte
GetLastError
DeviceIoControl
CreateFileW
GetModuleHandleA
KERNEL32.dll
OpenNtmsSessionW
GetNtmsObjectInformationW
EnumerateNtmsObject
DeallocateNtmsMedia
CloseNtmsSession
MountNtmsMedia
DismountNtmsMedia
EjectNtmsMedia
AccessNtmsLibraryDoor
SetNtmsObjectInformationW
CreateNtmsMediaPoolW
DeleteNtmsMediaPool
SetNtmsDeviceChangeDetection
InventoryNtmsLibrary
AllocateNtmsMedia
NTMSAPI.dll
LoadStringW
USER32.dll
BagarBubba
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\LogTransport2.exe
L!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
WPQEP0
EVP]EPuE
EPuYSj
3SGWMJ#
3P}M]EPu
YPVEP3!
uEPF9X
u8]t3}>
PD$H3PL$(\$,@D$hVP$
.D$8Pt$X
D$(Pt$d
VYPVD$LP
VYPVD$hP~
t$ D$,P9X
|$D8\$
YL$`QL$,Q
jSt$(+
D$(P(,
YL$`Q$
SVL$0y
SVL$hn
YL$`Q$
83SFV$
t`D$(P|$HG+
YL$`Q$
YYPt$
PEP4YY3
8[Dux3GWPEP
HPWEPus
EPYSWMJ
EPuEYSj
jGWEPu
YMQMQE
3SFVMc
Ujh9ZC
S3SD$P$
FPL$Pt$$
t$ L$P
8^-u($(
D$(D$4D$4L$(9
PD$(Pt$D@*
QD$ThC
YPWt$@
j@Pt$ $l
3-t$Dn
L$ Y3\$
L$4t$0D$
L$Pt$LD$<
UV3jPu
3XE]]u]ME]]
WMMEPME
UQSVW}
WDHDPDOD
NDHDMFD
NDHDMFD
_^UQSu
EURPQNDEPEPEPFLP
;uREFI
x} s8Wj
#bFTtXtS~D
:~ FH9
3;t(F N0
EURURURURPQNDS
xb3A;~(
uV9MrB}
EQPQEP
uUQQVF WNH39
u6EPvT
thEPvT
u;EPvT
UVFT3;t59M
^3^UVWu
;wC+j8_;N
UVqWNhNh
UVqWN`=N`
wY3A+M
VQEP*u
Yt_^[]
SV3W9^Tt
FL_^T^D^[U}
~ ~$F0F4D
EURPQNDS
HtHHtl2j
MV`MFI
H@Vp<2P
V1W+j8_#I
+j8^G;v!$I
+SV@W}
S28YEu-Q
j8Y;sy
t,M;Mt
E8E;Euu
YEk8k8
Yu%!EEPM
;jSW|j/j
YL0 D0$|
!}!}EPe
L0@MuL08
L08WSu
L0 L0$M
L0@MuL08
L0 D0$e
L0@MuL08
L183SWP
L0 L0$M
L0@MuL08
E+MQPu/
PuQuuJu
8_-u,M
E8]t^M
8X-t8_-u
S28YEt
VE3P}E
EufF,}}E
H H$H(H,ePk
H K H$K$H(K(H,K,@0C0]
YY_UQQE
];tDVw
^G;v!I$
C C$C(K,C0
F(F N$V(U
Y_^[]h
h@eP@EePE
+W~%V+48
uJEPMElC
ED0P+AWQ
U$QMMh
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Eula.exe
L!This program cannot be run in DOS mode.
`.rdata
@.data
@.reloc
Y]U]% @
u0}Y3!Mf
f8{t'+VWSu
YEE};E|E_^[Vj
Y_^[]UM
M_^3[S
3_fH$fH&@(^V
u^Ux!A
39=H!A
;u!hd@
3fEfEh
3WUV395P!A
u#95P!A
3}}9=H!A
EPlt"}u
39=H!A
u/3f9}
3}}9=H!A
EPt$}u
39=H!A
3uW@;t
M3}9=H!A
39=H!A
x=?w5j
3@_^[]
3SVW2@
3_fC$fC&^[j
1Vq(9>u
F F$N(E)u
3@]3]U]%d@
VSYYu;VSu
;tI.r//v"7t
_^t];M
3}}9=H!A
EPt?}u4u0u,u(u$u u
39=H!A
u95H!A
395H!A
u+9ut&9uu
3uVJ9uu
+W+PQRu
SQ0x"E
YUQQSW39}
zu@3VVuu
}9=H!A
39=H!A
ExJtTH(
MV33f;A,s3
PSQPE}
@,F;|u
}f;}lu
48S1Yf
SQP3^_[U$ !A
EE VW}
[M_3^u
URURPQ
URSPQ$x
@0C;|oE
URSPQ x[Ee
URuPQ8x4E
]MQP]@]tiw
Se@N&QN$QF
PSKExJF
WP5X"A
F F$N(EUu
E+R+QPE++PVw
jPuuPh
jPuUQPh
jPuuPj
jPuMQPj
M_^33[l
EE VW}
[M_3^i
SPfPfi
WP3Sf3
WPjT0SPRi
M_^33[h
SA@N&QN$QF
PS'ExJF
PSF(EMt
UVW339~
VP([_^]
FYYt;!A
N(WPh@
N(WPh@
N(WPh@
N(WPh@
N(WPh@
M_3^3@[^
N(WPh@
N(WPh@
N(WPh@
N(WPh@
N(WPh@
M_3^3@[<]
F }~<~T~`~d~h~l~p~t~x~|
PV@YYE
[3CSWYYVu
3QQQQd
VPR,65@
M_3^3@[Y
/3CSWYYVu
3QQQQd
VPR,65@
M_3^3@[tW
jXWjZWE
jXWjZWE
u3_^]WUE
3H| 1H|3]
3H|@1H|3]
PE+EPuus
3_M^3[Q
3Hl 1Hl3]
tIE+EPE+EP6
3M_3^;P
WPE+EPuuv,
M_33^O
3Hh 1Hh3]
APU(Vu
Vj@|QP
PQDFtt
SVW39~puaEPv
E+EPE+EPS
E;tIPEPS
QQSWWWjj
WWSuuWWu
83M_^3[#I
EtfEfE
MEMPg^M_3[G
QQWRRRjj
;u#F N
f>{EPVu
3E;|lu
SuuVVPQ
WQWjPR,MM;t
I43tE
F43CtBe
Nw[tU+t9,t*-t
F`;t3}
tY9~dt`
WQWjPR,M
PWWW3n9
A`33Mt
PQd3^]
h@HZ3]
h?H83]
1H|H3]
QPdhAN3^]
1H|H3]
~dWh,@
PQ EJ9]
UQQS3VW9U
u:Cpti
RVPQ0E
Ey'svt
pRPu Q
j7WWWWW6
U Rh<@
9x<u2ME
ME_^[
3VMfEE
URRRRURP
PGYYt
VP,^]$
tvf9K@
C0;tkS(US
UURPQE0
cu(C0N
URPQNu
C4EC(EC
7fC@uM
fC@@3V
PEPEPx
3f;u'Vw
Au3_^[]
3f;u'Vw
u3_^[]
8EPlE;
S3VW;t
~<9u"E
~@9u"E
u3fEfEj
UVW39=
UVW39=X A
F P( A
9FuPQPh
9FuPQPh
W}}L;|PEVURh@
uK3u$Eu
;t);|#M
;} u u
a]u Eu
PQ(;|&M
;t>VjB
]]}SSh@
W;}3EE
MW]~Yu
;t>VjB
YY;}%uE
u8]]}WSh@
uE;} EE
U4SVWh"A
j0_D!A
3;ugX"A
}LE;uoX"A
tFuVJ|YYu
E^[UVWVF
ESVWPEd
3SfWP+
$]z($tSWP$P
3SfVPQ
EPPEP{
EPPh(@
P3SfVP
P(Pt1@V
Y_^[M3T
8V}tYYEj
EPuWA3
};tFSjB
RPWEPQh@
];tU9}t
WWuulE;
WWWWuS
EuVJsE
fEYYf;E
USV3W9]
3f;ukE
3f;u<l
USV3W9]
3f;ukE
3f;u<l
3;t(PWV
ptEP"A
;r_^]D$
tC,uW39~$~ x9;~$}4F
G;~$|N F
EE8csmt
Wt%Vh@
+SVW !A
EPeuEEEEd
+SVW !A
1E3PeuEEEEd
Y__^[]Q%@
SVW( !A
3PuEEd
SVW( !A
3PeuEEd
SVW( !A
3PEuEEd
Y__^[]Q
3EEEE;E
EEPEPu
YH]hT@
wOf;t
8csmu*x
;r_^%t@
B(;r3_^[]
SVW !A
1E3PEd
Y_^[]%h@
E3E3;u
^_[%L@
j+eNwCw8wT$
3xJ3n@
VMkuT$
MkM8iMTyvM`nvMdcvMhXvMlMvMpBvMt7vMx,vM|!vM
J3J34@
;uM3uM
+uM#uM
>M>hT$
9M)gMsMaMsT$
MfMsMbYM`aMsT$
J3VJ3LX@
@e^8eT"A
Unicows.dll
Kernel32.dll
CreateActCtxW
ActivateActCtx
DeactivateActCtx
FindActCtxSectionStringW
QueryActCtxW
GetModuleHandleExW
IsolationAware function called after IsolationAwareCleanup
Comdlg32.dll
GetSaveFileNameW
F59N\IPKl@
=sR@Qm6t
Eula.pdb
GetModuleHandleA
GetModuleHandleW
GetProcAddress
GetFileAttributesW
GetVersion
RaiseException
EnterCriticalSection
LeaveCriticalSection
GetLastError
InitializeCriticalSectionAndSpinCount
DeleteCriticalSection
GlobalAlloc
FindResourceW
FindClose
FindFirstFileW
lstrcatW
lstrlenW
lstrcpyW
FlushInstructionCache
GetCurrentProcess
LoadLibraryW
SetLastError
GetModuleFileNameW
OutputDebugStringA
GetCurrentThreadId
LoadLibraryA
GetPrivateProfileStringW
MultiByteToWideChar
lstrlenA
CopyFileW
LockResource
LoadResource
lstrcmpW
MulDiv
GlobalUnlock
GlobalLock
GlobalFree
GlobalHandle
GetPrivateProfileIntW
lstrcpynW
GetFullPathNameW
KERNEL32.dll
SetWindowLongW
GetWindowLongW
RegisterClassExW
GetClassInfoExW
DialogBoxIndirectParamW
DefWindowProcW
SetWindowTextW
MoveWindow
SetWindowPos
GetClientRect
RedrawWindow
IsWindowEnabled
EnableWindow
GetDlgItemTextW
SendDlgItemMessageW
SetDlgItemTextW
GetWindow
GetDlgItem
SetWindowContextHelpId
SendMessageW
MapDialogRect
GetSystemMetrics
EndDialog
CreateWindowExW
GetWindowTextW
GetSysColor
ClientToScreen
ScreenToClient
ReleaseDC
InvalidateRect
InvalidateRgn
SetCapture
IsChild
GetParent
GetClassNameW
CharNextW
ReleaseCapture
FillRect
DestroyWindow
CallWindowProcW
EndPaint
BeginPaint
GetDesktopWindow
SetFocus
GetFocus
IsWindow
DestroyAcceleratorTable
LoadCursorW
CreateAcceleratorTableW
GetWindowTextLengthW
RegisterWindowMessageW
GetActiveWindow
USER32.dll
GetDeviceCaps
DeleteDC
DeleteObject
SelectObject
CreateCompatibleBitmap
CreateCompatibleDC
BitBlt
CreateSolidBrush
GetObjectW
GetStockObject
GDI32.dll
RegCloseKey
RegSetValueExW
RegCreateKeyExW
ADVAPI32.dll
CoCreateInstance
CoAddRefServerProcess
CoReleaseServerProcess
StringFromGUID2
OleLockRunning
CoGetClassObject
CLSIDFromProgID
CLSIDFromString
CoTaskMemAlloc
CreateStreamOnHGlobal
OleInitialize
OleUninitialize
ole32.dll
OLEAUT32.dll
??3@YAXPAX@Z
??_V@YAXPAX@Z
_CxxThrowException
memcpy_s
memset
wcsncpy_s
wcslen
wcscspn
wcscpy_s
__CxxFrameHandler3
_recalloc
memcmp
??_U@YAPAXI@Z
calloc
??2@YAPAXI@Z
swprintf_s
malloc
_wtoi64
MSVCR100.dll
?terminate@@YAXXZ
_except_handler4_common
_unlock
__dllonexit
_onexit
_amsg_exit
__wgetmainargs
_cexit
_XcptFilter
_wcmdln
_initterm
_initterm_e
_configthreadlocale
__setusermatherr
_commode
_fmode
__set_app_type
?_type_info_dtor_internal_method@type_info@@QAEXXZ
_crt_debugger_hook
_invoke_watson
_controlfp_s
InterlockedCompareExchange
InterlockedPushEntrySList
HeapFree
GetProcessHeap
HeapAlloc
IsProcessorFeaturePresent
VirtualFree
VirtualAlloc
InterlockedPopEntrySList
EncodePointer
DecodePointer
InterlockedExchange
HeapSetInformation
GetStartupInfoW
TerminateProcess
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsDebuggerPresent
QueryPerformanceCounter
GetTickCount
GetCurrentProcessId
GetSystemTimeAsFileTime
UnregisterClassA
.?AVCAtlException@ATL@@
.?AVCEulaModule@@
.?AV?$CAtlExeModuleT@VCEulaModule@@@ATL@@
.?AV?$CAtlModuleT@VCEulaModule@@@ATL@@
.?AVCAtlModule@ATL@@
.?AU_ATL_MODULE70@ATL@@
.?AV?$CDlgEula@$0MK@@@
.?AV?$CAxDialogImpl@V?$CDlgEula@$0MK@@@VCWindow@ATL@@@ATL@@
.?AV?$CDialogImplBaseT@VCWindow@ATL@@@ATL@@
.?AV?$CWindowImplRoot@VCWindow@ATL@@@ATL@@
.?AVCWindow@ATL@@
.?AVCMessageMap@ATL@@
.?AV?$IDispEventImpl@$0MJ@V?$CDlgEula@$0MK@@@$1?GUID_NULL@@3U_GUID@@B$1?2@3U3@B$0A@$0A@VCComTypeInfoHolder@ATL@@@ATL@@
.?AV?$IDispEventSimpleImpl@$0MJ@V?$CDlgEula@$0MK@@@$1?GUID_NULL@@3U_GUID@@B@ATL@@
.?AV?$_IDispEventLocator@$0MJ@$1?GUID_NULL@@3U_GUID@@B@ATL@@
.?AV_IDispEvent@ATL@@
.?AV?$CDlgEula@$0MJ@@@
.?AV?$CAxDialogImpl@V?$CDlgEula@$0MJ@@@VCWindow@ATL@@@ATL@@
.?AV?$IDispEventImpl@$0MJ@V?$CDlgEula@$0MJ@@@$1?GUID_NULL@@3U_GUID@@B$1?2@3U3@B$0A@$0A@VCComTypeInfoHolder@ATL@@@ATL@@
.?AV?$IDispEventSimpleImpl@$0MJ@V?$CDlgEula@$0MJ@@@$1?GUID_NULL@@3U_GUID@@B@ATL@@
.?AV?$CDlgDecl@$0MP@$0MK@@@
.?AV?$CAxDialogImpl@V?$CDlgDecl@$0MP@$0MK@@@VCWindow@ATL@@@ATL@@
.?AV?$CDlgDecl@$0MO@$0MK@@@
.?AV?$CAxDialogImpl@V?$CDlgDecl@$0MO@$0MK@@@VCWindow@ATL@@@ATL@@
.?AV?$CDlgDecl@$0MP@$0MJ@@@
.?AV?$CAxDialogImpl@V?$CDlgDecl@$0MP@$0MJ@@@VCWindow@ATL@@@ATL@@
.?AV?$CDlgDecl@$0MO@$0MJ@@@
.?AV?$CAxDialogImpl@V?$CDlgDecl@$0MO@$0MJ@@@VCWindow@ATL@@@ATL@@
.?AV?$CComContainedObject@VCAxHostWindow@ATL@@@ATL@@
.?AVCAxHostWindow@ATL@@
.?AV?$CComCoClass@VCAxHostWindow@ATL@@$1?GUID_NULL@@3U_GUID@@B@ATL@@
.?AV?$CComObjectRootEx@VCComSingleThreadModel@ATL@@@ATL@@
.?AVCComObjectRootBase@ATL@@
.?AV?$CWindowImpl@VCAxHostWindow@ATL@@VCWindow@2@V?$CWinTraits@$0FGAAAAAA@$0A@@2@@ATL@@
.?AV?$CWindowImplBaseT@VCWindow@ATL@@V?$CWinTraits@$0FGAAAAAA@$0A@@2@@ATL@@
.?AUIAxWinHostWindowLic@@
.?AUIAxWinHostWindow@@
.?AUIUnknown@@
.?AUIOleClientSite@@
.?AUIOleInPlaceSiteWindowless@@
.?AUIOleInPlaceSiteEx@@
.?AUIOleInPlaceSite@@
.?AUIOleWindow@@
.?AUIOleControlSite@@
.?AUIOleContainer@@
.?AUIParseDisplayName@@
.?AV?$IObjectWithSiteImpl@VCAxHostWindow@ATL@@@ATL@@
.?AUIObjectWithSite@@
.?AUIServiceProvider@@
.?AUIAdviseSink@@
.?AUIDocHostUIHandler@@
.?AV?$IDispatchImpl@UIAxWinAmbientDispatchEx@@$1?_GUID_b2d0778b_ac99_4c58_a5c8_e7724e5316b5@@3U__s_GUID@@B$1?m_libid@CAtlModule@ATL@@2U_GUID@@A$0PPPP@$0PPPP@VCComTypeInfoHolder@ATL@@@ATL@@
.?AUIAxWinAmbientDispatchEx@@
.?AUIAxWinAmbientDispatch@@
.?AUIDispatch@@
.?AV?$CComObject@V?$CComEnum@UIEnumUnknown@@$1?_GUID_00000100_0000_0000_c000_000000000046@@3U__s_GUID@@BPAUIUnknown@@V?$_CopyInterface@UIUnknown@@@ATL@@VCComSingleThreadModel@6@@ATL@@@ATL@@
.?AV?$CComEnum@UIEnumUnknown@@$1?_GUID_00000100_0000_0000_c000_000000000046@@3U__s_GUID@@BPAUIUnknown@@V?$_CopyInterface@UIUnknown@@@ATL@@VCComSingleThreadModel@6@@ATL@@
.?AV?$CComEnumImpl@UIEnumUnknown@@$1?_GUID_00000100_0000_0000_c000_000000000046@@3U__s_GUID@@BPAUIUnknown@@V?$_CopyInterface@UIUnknown@@@ATL@@@ATL@@
.?AUIEnumUnknown@@
.?AV?$CComObject@VCAxFrameWindow@ATL@@@ATL@@
.?AVCAxFrameWindow@ATL@@
.?AV?$CWindowImpl@VCAxFrameWindow@ATL@@VCWindow@2@V?$CWinTraits@$0FGAAAAAA@$0A@@2@@ATL@@
.?AUIOleInPlaceFrame@@
.?AUIOleInPlaceUIWindow@@
.?AV?$CComObject@VCAxUIWindow@ATL@@@ATL@@
.?AVCAxUIWindow@ATL@@
.?AV?$CWindowImpl@VCAxUIWindow@ATL@@VCWindow@2@V?$CWinTraits@$0FGAAAAAA@$0A@@2@@ATL@@
.?AV?$CComPolyObject@VCAxHostWindow@ATL@@@ATL@@
.?AVtype_info@@
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo></assembly>PA
PAPADDINGXXPADDINGPADDINGXXPAD
0>0n0{000000000000,1111X3$4-4N4d444444444444
5!5(5/565=5D5K5R5Y5`5g55555555555555555555555555555
6"606N6m6t6666
7N7777
8$8-82878L8W8`8e8j8|8888888888888
9"9'999K9n9s9x999):S:\:::::::::
;';7;J;e;;;;;;;
<0<J<R<f<<<<<
=Z===D>X>g>>}??????
0h000011111
2E2w222222
4o4x4444 5Z5c5m5s5y5~5555_6666
77[7}7777777
8&8A8U8d888
9>999m:::
<.<7<R<c<<<<<C==
>C>z>>>>
1;1q111&2222444"55555
6:6o6u666C7n77
8K8U8\8o8v8888<9U9a99999:p:::::
;W;{;;;S<Y<<<<<<2=h=====>>>?F???
F0U0r000001111,292i2222233P3W33
44'5>5Z5n5t5555555506G6c6w6}66666666777
8*8>8`8t888888G9W9f9l999999
:':8:S:b::;
< <;<Z<`<
<<<<<<
=(=I=_=v====1>>>D>L>g>>>>>>>
?%?A?T?u?????
+02090@0G0N0U0\0c0j0q000000
1G1M1h1q11111+24D5q5555
6+6s66666
77;7X7|777777(969Q9]9z9
;!;.;c;r;;;<
=1===Q=X=e========
>7>A>H>>>
?h?w???????
:0k0000
131L111
2822222
4)424N4V4h4x44444N555555
6w6h8888_9
:/:C:Y::g;;&<<<
?'?e??
0,011/2q2223334M444I5z5579
:,:::.;B;;;;<<<<<<R====
0"00000
1E1111
222c2x2222%3~3333)4K4f4m4s44444495\555
6.66W777
9T9Y9w9C:l::::(;0;9;;;;;;
<<<<<+={===@>_>>>
060F0V0d0m00000
1-1:1J111
2Q2z222222
3 3I3V3q3~333
464W444444444444
5F5b5i5}555555
6=6C66666666
7787I7[7x7777777
8*8<8R888
9<9o999X:^:c:~::::::p;;;;;;
<;<J<V<i<t<<<<<<M=^={==">d>>>>>
?N????????
$080?0X0]0c0000}12|3333333333
4$474F4M4Y4q44444$5<5Y5h55
6/6P6^6d6k66,727F77777
8!8>8|888
9D9J9Q99
:):/:B:W:b:x:::::::::::
;!;5;;;H;\;e;;;;;;;;;;;;
<%<*<m<w<}<<<<<<<<<
="=-=9=?=H=N=S=X=]=d=j=|===============
>%>->9>B>G>M>W>`>k>w>|>>>>>>>>>>>
?!?*?2?7?X?]?|?
0/0M0a0g000
1/1<1H1P1X1d11111111
202S2v222
3>3q33O4u444435V5q55555
686}66
7=7G7Q7W7[7i7n7|7777777777777
4383<3@3D3L3T3\3l3p333335555555L6P6T6X6\6`6d6h6l6p6t6x6|6666666777
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|88888`9d9h9l9p9t9x9|99999999999999999999999999999999
: :$:(:,:0:4:8:<:@:D:H:L:P:T:X:\:`:d:h:l:p:t:x:|:::::::::::::::::::::::::::::::::
; ;$;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;;;;;;;;;;;;;;;;;;;;L=P=T=X=\=`=d=h=l=p=======================
>\>`>d>h>l>p>t>x>|>>>>>>>>>>>>>>>>>
?(?4?@?L?X?d?p?|???
11111111
2\2`222222222222
3 3(3@3P3T3X3\3d3|333333333333
4 4$4(4,40444<4T4X4p4444444444444444
505@5D5L5d5h55555555555555
6 6$6(6,646L6\6`6d6l6666666666
7(7,7074787<7@7D7H7L7P7X7p7t7777777777777777
8,8<8@8D8H8P8h8x8|88888888888888
9,909@9D9H9L9P9T9X9`9x9|99999999999999999
:4:D:H:L:P:T:X:l:p::::::::::::::::::
; ;(;,;0;4;8;<;@;D;H;L;P;T;X;\;`;d;h;l;p;t;x;|;;;;;;;;;;;;;;;;;;;;;;
< <$<(<,<0<4<8<<<@<D<H<L<P<T<X<\<`<d<h<l<p<t<x<|<<<<<<<<<<<<<<<<<<
=$=(=,=4=L=P=h=x=|=============
>$><>L>P>T>X>`>x>|>>>>>>>>>>
? ?8?H?L?P?X?p?t?????????????
0 0$0(000H0X0\0`0d0l000000000000
1,1<1@1D1L1d1h111111111111
2,202H2L2d2t2x2|222222222222
3,3<3@3D3L3d3h333333333333
4 4$4,4D4H4`4d4|4444444444444444
5,5054585@5X5h5l5p5x5555555555
6 60646D6H6X6\6l6p666666666666666666
7(787<7@7D7H7L7P7X7p7777777777777
8$8(8,8084888<8@8D8H8L8P8T8X8`8x8|888888888888888888
9,9<9@9D9H9L9P9X9p999999999999999
:$:(:@:P:T:d:h:x:|:::::::::::::::::::
; ;(;@;P;T;X;\;`;d;x;|;;;;;;;;;;;;;
<,<0<8<P<<<
=8=X=x======
>0>@>T>d>t>>>>>>>
?(?0?H?T?t??????????
0$0D0P0t000000000000000
101<1d1111111
2$2,242<2H2p2222222
3 3D3P3X3x3333333
4 444<4T4\4h444444444
5 5,5L5T5`555555
040P00000
1\1111
222(3H3h3304444 5l555
6L6P6h6l666687|77
8\88888
9 9@9\9|9999
:8:T:x:@;h;;;p<(===
>@>>>>t???
L>v"A,
~|NYKw
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
121221000000Z
201230235959Z0^1
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
%y"W*o
%CE{t"
MD$k_E;DC
&Mq1Qa
xE/W?=
Qlie)`
h]jxdE`F~T
_n\t}?L.02
http://ocsp.thawte.com0
8060420.http://crl.thawte.com/ThawteTimestampingCA.crl0
TimeStamp-2048-10
DnmX|0i#s
y@b%n7j!
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
121018000000Z
201229235959Z0b1
Symantec Corporation1402
+Symantec Time Stamping Services Signer - G40
[LvCK"+Ch@O8
2[^Z(P
Gf=Gpr_
L-wDh
[2V3cI:3
http://ts-ocsp.ws.symantec.com07
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
50301/-+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
TimeStamp-2048-20
_n\t}?L.0
Lb07x'
2m,&c3Idm
7Cxx(
]=Qy3+.{
[0W,I?
>"hcSit
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
140304000000Z
240303235959Z01
Symantec Corporation10
Symantec Trust Network1B0@
9Symantec Class 3 Extended Validation Code Signing CA - G20
S|?~+G
| ^(\|
^[pxFR{I)
{n3aKE%D#6(y
(0&0$"
http://s.symcb.com/pca3-g5.crl0
http://s.symcd.com0_
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0)
SymantecPKI-1-6290
u8*ZZL
(Nt|<qV
:_>dIAtA!
o8X~]`
<"j5c6
7D1{f'0
Symantec Corporation10
Symantec Trust Network1B0@
9Symantec Class 3 Extended Validation Code Signing CA - G20
150604000000Z
170507235959Z01
Delaware1
Private Organization1
27481291
California1
San Jose1$0"
Adobe Systems, Incorporated1
Acrobat 111$0"
Adobe Systems, Incorporated0
L,p.6F
$KMEj%A%P0`w
S&\AMju
QFK/g5h+
t|hV@0l7+oS1
US-Delaware-27481290
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0+
http://sw.symcb.com/sw.crl0
http://sw.symcd.com0'
http://sw1.symcb.com/sw.crt0
{k/Yi
)S9 2;|v
%D?Cy^~
,.|h;{>KN
Symantec Corporation10
Symantec Trust Network1B0@
9Symantec Class 3 Extended Validation Code Signing CA - G2
7D1{f'0
&D@"0V
1H0FDB
uhi^<GV'^#D
PXN$Tco
n]tWbPV
Symantec Corporation100.
'Symantec Time Stamping Services CA - G2
151217220749Z0#
O<|j9DK8v
hxuZo&
[>\`m'<VT
BagarBubba
C:\Program Files\Internet Explorer\ieinstal.exe
L!This program cannot be run in DOS mode.
%m%m%m]%m]%m]%m%l$m]%m]%m]%m]%mRich%m
`.data
.pdata
@.rsrc
@.reloc
ADVAPI32.dll
ntdll.DLL
KERNEL32.dll
USER32.dll
msvcrt.dll
PSAPI.DLL
ole32.dll
OLEAUT32.dll
RPCRT4.dll
urlmon.dll
WINTRUST.dll
iertutil.dll
C:\Program Files\Common Files\Microsoft Shared\ink\TabTip.exe
L!This program cannot be run in DOS mode.
`.data
.pdata
@.rsrc
@.reloc
USER32.dll
msvcrt.dll
NTDLL.DLL
API-MS-Win-Core-ProcessThreads-L1-1-0.dll
API-MS-Win-Security-Base-L1-1-0.dll
KERNEL32.dll
VERSION.dll
ole32.dll
OLEAUT32.dll
OLEACC.dll
SHLWAPI.dll
IMM32.dll
slc.dll
SHELL32.dll
COMCTL32.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
API-MS-WIN-Service-Management-L1-1-0.dll
Delete
NoRemove
ForceRemove
Invalid parameter passed to C runtime function.
FNx-XgA~2RphS
FAB{Kl
F8o!@a
rM>#FL(
&)q(&IOpIT
B1F\YW,9~+A
M>#FL(
KGC5d3%J
RunMessagePump
KGC5d3%JvL
vDQ?|OS
N<WVD-
[S_-yBF8
?G.zMju
2*~CZ&BVu-U
B1F\YW,90
9FWFR5
_OItJn4v/k@a
v{FetG,;FE5swrAte
RWVD"y
[SVse{$O`P'
==}GT&jQ.
CreateXmlReader
yrp@=iK
WinSqmIsOptedIn
TabTip.pdb
H%^HL$
SH0HD$ HH
3HK0Ht
H0[H\$
HH\$0H _@SH AL
HCpHH [H\$
HH\$0H _DD$
LL$ SUVWH
HHHL$ H
;rHL$0
_^][H\$
WH HQpH
H\$0H _H\$
HH\$0H _@SH d$0
HHH [@SH d$0
EAHHH [@SH0d$@
EAHD$
DHH0[H\$
HH\$0H _HHX
Hx ATH0Hy
HAP Ht
HP(3tJH
HP LHtVH
t%;rHG
H\$@Hl$HH|$XHt$PH0A\ B
HH\$0H _2
HH\$0H _HL$
VATAUH@HD$0H\$pHHzL
HD$8Ht
Ht$`H\$hHu
Ln L;n(r
2H\$pH@A]A\^HL$
VATAUH@HD$0H\$pHHzL
HD$8Ht
Ht$`H\$hHu
Ln L;n(r
2H\$pH@A]A\^@SH HHI
H [H\$
WH HH}
Hq H;w
H+tTHC
HK Hl$8Ht$@H\$0H _
A H(DL;A r
H(@SUVWATAUAVAWH(Ly
LL|$xL;v
LL+ILd$pH
L;t-H&
$HL+L+H
HP Ld$pL|$xM;u
Ld$pH$
H(A_A^A]A\_^][
LWH0HD$ I[
Is AHHH
BLFLBPFPHXHNX!
HW`HN`!
HWhHNh!
HH\$HHl$PHt$XH0_H\$
H\$0Hl$8Ht$@H _H(H
HH\$0H _H\$
UVWH Hy
LD$@HT$X
H\$HH _^]6
UVWH Hy
LD$@HT$X
KH\$HH _^]q5
VWATH@Hy
HtLL$`LD$ HT$x
HT$(HEA
HMILHT
fH\$hHl$pH@A\_^HSUVWATAUAVHpHHI
LD$dHD$PLt$HH$
HD$@Lt$8H$
HD$0HD$`E33Lt$(D$
HD$ Dt$`D$
D$`A;t
LD$dHD$PHl$HH$
HD$@Ld$8H$
HD$0HD$`LIH|$(HD$
A;u<I1
HpA^A]A\_^][@SWHHHHI
LD$hHT$`f|$`
LD$hHT$x
LD$hHT$
LL$hLD$(HT$p
LL$hLD$0HT$p
HH_[H\$
UVWATAUH0Hd$x
xLD$xH
pH\$xHu
3H\$xd$p
E3HD$pAQ
E3H@2HD$
)t$ptNH
0HHt=HD$pDL
E3HD$pEa
E3HAHD$
t$ptLH
HHt;HD$pDLAHHD$
I@H\$`H0A]A\_^]HHX
Hp WH03HHH;tqH9
E3E3HD$
WD\$HHKIC
H;t'DL$HHL$PS
HL$ LH
2H\$@Ht$XH0_@SH H%
H#H [H\$
Hl$ VWATAUAVHPH
H3HD$HE3HL$@ME(
sHD$0I;
HHD$8I;tbH;s]HT$0A
I;tFfD9+t@HD$@
HI;tRH
A:tu3HD$0L
Ll$0HD$
HL$0A;|3I;t9H
P HL$0I;t
IHL$0I;t
AHL$HH3H
L\$PI[0IkHIA^A]A\_^HHX
Hx ATAUAVHp
u,HT$PH
L5"H$`
Lt$`H\$hWH$
HL$`E3jH$
HL$`E3H-BH$
Hl$xH$
HL$xHE3
HL$xDE3HH$
HL$xE3HDH$
HL$xE3D\HT$xHL$`E3HL$hH\$@\$8H\$0E3E3t$(D$
E3E333
HL$(33LH
;|wH.H;tfLM
H\$XL;u
|$HT$XHM
HE(EAHD$
HL$XH;t
D:uE;|AH5e
L$pE3E3AQ
Hl$xH;t#H$
H;t#H$
1HHD$x
HL$`Lt$`RH$`
I[ Ik(Is0I{8IA^A]A\
u0SH H
E3E3AQ
uH [H\$
XLD$8H
DL$0HL$8E3AX
HD$0HD$
HL$8HHu
DL$0HD$0L
HL$8HL$@H
EHL$@9H=:
E3E3AQ
H%@WH0H=
HT$ Ht\H
HL$ 19
H0_@SUVWATHpHD$`HH
Dd$0Dd$(Dd$ L
Ld$HLd$PLD$HH
A:u`A;|[H$
A;|+H$
HL$HI;t
IHL$@D8%
DBPHA:t(
DBPHL$
HL$PI;t=H
HL$PI;t
A;|AHL$@I;t<H
HL$@L$
HL$@L$
HL$@M;t
HL$@L$
HL$@D8%k
tJI;tEL$
Ld$XLD$XH
7A;t)HL$XI;tH
HL$@I;t+3
P(HL$@I;t
IHL$@H
HL$@I;t
HL$PI;t
HL$HI;t
3HpA\_^][H\$
Ht$8HH\$0H _H\$
HH#H;u
t\DC"H
H!\$8HD$0
DKQDCSH3D$(
qE3E33AQ
lLD$@H
IH#I;u
Hl$hH\$`HP_Hu
3@SH I
3H [HHX
Hx ATAUAVH H
HtwHtaA
DHcx:H-h
LL$hEIPPH\$@Hl$HHt$PH|$XH A^A]A\HcH
L$pHD$8H$
DHD$0H$
HHD$(HD$xHD$ ARXH\$PH@_H\$
H\$0HG
HHt$8H _H(H
H3HPH:9J
H\$0H _@SH HH
A A @SH A Y u
AP`H [LD$
WATAUH0HD$(H\$PHt$XM3L;u
Dd$hH|$ X
HH;t)x
3DB(HH
@~8~HH~PH
3Ll$`Dd$hHt$ H;
HNPH;t
AH\$PHt$XH0A]A\_H(Hu
HH\$0H _H\$
uKHtFH
H\$0H _MLH
VWATAUAVH MMH
uAHL$h
CHx0Ld$hI
H\$XH A^A]A\_^LD$
SVWATAUH0HD$(IL3L;u
Dd$xH|$
HH;trx Hx(Hx0Hx@HxHHxPHxXHx`xhHxpxxx|@
3Ht$pLl$hDd$xH\$ H;t*C K H
HAP`AH0A]A\_^[LD$
VWATAUAVH@HD$(H\$pMLL3L;u
HHD$0H;
H{8H{@H{PH{XH{`H{hH{p{xH
QHC(Ls0H
H\$ H;t#H
H\$pH@A^A]A\_^@SH A Y
H [@SH A Y u
H [MLH
H [@SH 3L;u
H [HI H
HH\$0H _HL$
WH0HD$ H\$HHH
HH\$HH0_[H\$
WH HHQ
H\$0Ht$8H _HtFH\$
WH HH3H
HH;rH\$0Ht$8H _HL$
SVWH0HD$ H3H;u
t$XH\$`
H;t_X HX(HX0HX@HXHHXPHXXHX`XhHXpXxX|
3H|$Pt$XHD$`H;t
H0_^[H
WH0HHu
AHY@3H9;u%L
H\$@Ht$HH0_
H(L3ILA
MHIAS@DAH(H(H
D$ H8H\$
s&H7Ht
H\$0Ht$8H _HL$
VWATH@HD$ H\$hL3H;u
3Ld$`Ht$xH;u
2H\$hH@A\_^HtYH\$
WH HHI
Ht HYL
H\$0H _H!
VWATAUAVH@HD$0HH
HD$8Ht,D Hp
4HD$ L
H|$xH$
E3LD$xH$
HAR`x?Lt$xHd$x
3H@A^A]A\_^HWH
HD$`HX
H!T$@D
f;uJfD;uD
HT$@H$
HD$@HD$ D
HL$HHL$0Ht
HL$HHd$8
H\$8HL$0Hu
HtmHd$P
HL$PHD$XH;@
HL$PHt
HL$0H\$8
@2@uBH3HL$0Ht
HL$0Ht
HL$0Hd$0
.HL$8Ht
HL$0Ht
HL$HHt
Ik Is(I_H(H
E3E3H%
HL$83H;t);t
u HD$(DA(LI
A$A(HA
}ftTf;u>f t8f
3H\$0Ht$8H _H!
yH(H\$
H\$0Hl$8Ht$@H _@SH y
NH(H\$
WATAUH 3IIHLH;
I9A98u4A9x
H\$@Hl$HHt$PH A]A\_H(H
H(L$0H
H [H%v@WH0HD$ H\$HHH
HK8gHc`
hHH\$HH0_H
H3HD$HHH
H;tEDF
xf9t$ t,Ht$ H=
Ht$ H=
uHL$HH3
H\$`Ht$pHP_@SH HH
H [H%+uH\$
WH 3H@H;u
tHl$8Ht$@H\$0H _H\$
_tHt/H
H;t#H{
H\$0H _H\$
3;tyU\HL$
H\$ H;tPHf9+t
_^]HWH`HD$ HX
HT$xHP8xCHL$(2
HT$xHt
HL$(H5
HL$(U3
tL\$`I[
Is I_Ht
!tHT$8H
tD$8H(HVWATH
7rD\$(D\$HD$,D$LH\$HHH+
HL$ H;
HT$8PH9l$8
HT$(HP8;
-rDHMC
HT$(H;t8I
I+uH;t
l$<HL$ H
HT$<P(D
\$<D\$XDd$Pl$@HL$ H
D\$@D\$hDd$`\$xDd$pLHT$(H.
l$0l$4HL$ H
LD$4HT$0PXD\$0D$
HT$HP8D9l$HA
HL$ H;t
I[0Ik8IA\_^HHX
Hx ATAUAVH E3MHHEfD92u
IHHI;w
fA;t<HH+HHI;w+
H\$@Hl$HHt$PH|$XH A^A]A\LD$
SVWATAUAVAWH0HD$(MLL3L;u
HH;t"x
3DB(HH
HHt$ !3L$
L|$xLt$pD$
Ht$ H;teLv@HN
AH0A_A^A]A\_^[H(Hu
H(3H(Hu
u2Ht-A
H\$0H _LD$
VWATAUAVH0HD$(H\$`ML3L;u
Dd$xHt$ @
HH;t4p
3DB(HH
3Ll$pLt$hDd$xH|$ H;tMG
HAPPAH\$`H0A^A]A\_^LD$
SVWATAUAVAWH@HD$(MLL3L;u
HHD$0H;t?x
3DB(HN(
HHt$ 3L$
Ht$ H;tJHN(D;|
AH@A_A^A]A\_^[LD$
SVATAUAVH0HD$(MLMu
t$xHd$
HHt1H;
Ld$pLl$ht$xH\$ HtyC
HAPhH0A^A]A\^[LD$
SVWATAUAVAWH@HD$(MLL3L;u
HHD$0H;t@X
H|$ H;toHO0O;|
H_`HOpH;t
H@A_A^A]A\_^[@SH
APPH [MLH
@SH 3L;u
APhH [MLH
xJ@SH 3L;u
HH\$0H _HL$
WH0HD$ H\$HHH
HH\$HH0_H(H
pdH(H\$
HH\$0H _HL$
WH0HD$ H\$HHt$PHH
HH\$HHt$PH0_
WH0HD$ H\$HH
HH\$HH0_HL$
SH0HD$ H
aH0[HHX
Hx ATH HH`EH3
zaH9{Pu=H9sPt!H;t
HKPH;t
HsPHKPLCXH
aHl$8Ht$@D
H\$0H|$HH A\@SH0HN
H0[LVWATH@HD$0I[
IILHt~MtyMttH$
HI@HtEIc
HL$hHt
H\$ LLIP
HL$hHt
H\$`Hl$pH@A\_^HL@
SVWATAUAVAWH`MDH`
E2Dd$@HFHHD$PHtu
HD$0H$
HD$(H$
HD$ ML$
Dd$@HNX
H`A_A^A]A\_^[@WATAUAVAWH0HD$ H\$hHl$pHt$xIIDHH
HD$`Ht
HD$`Ht
u@Ht;H$
E:t'Et
H3H\$hHl$pHt$xH0A_A^A]A\_H\$
Ht$ WATAUH HHHu
HLL$HHfE
HfAfE+AR
ILL$HHfE
HfAfE+P
HHH\$@Hl$PHt$XH A]A\_@UVWHPHD$@H\$pIHHH
HT$xHT$ H
XZHd$8
P(HL$0H
HT$8P0HL$0Ht
HL$xHD$8H
HL$xHt
H\$pHP_^]HHX
Hx ATH HH
H\$0Hl$8Ht$@H|$HH A\H%X
VWATAUAVH0HD$(H\$`ML3L;u
t$xH|$
HH;tMHL
3Ld$pLl$ht$xH\$ H;tU
H\$`H0A^A]A\_^LD$
SVWATAUAVAWH@HD$(MLL3L;u
HHD$0H;tbx
H\$ H;tJH
H@A_A^A]A\_^[
H [MLH
j@SH 3L;u
HH\$0H _HL$
WH0HD$ H\$HHH
HH\$HH0_gH\$
HH\$0H _H
HxHxWH
HxHxWH
WH0HD$ H\$PHt$XH3q
@w@HwHHwPHwXHO`H
H\$HH3HK
HH\$PHt$XH0_HL$
VWATH0HD$ H\$`Hl$hHH
~o3HxR;}NI
;|,E3E3AQ
iPE3E3AQ
Hl$XHM
OHOXHt
OH\$`Hl$hH0A\_^H\$
WH HH`
HAS`HK`
mOHKPHt
HK`H\$0H _H%<OHHX
Hx ATH HH`H
HKPHul
NHKHHt
H\$0Hl$8Ht$@H|$HH A\H
P(L[H3Mu
NH9sXt!Ht
WH HH`3
xMHKXHt
OMHKHHt
H\$0Ht$8H _H\$
WH HH`3
MH{PHt
LHKXHt
LHKHHt
H\$0Hl$8Ht$@H _@WH@HD$0H\$PHl$XHt$`A
HD$hHt
3H\$PHl$XHt$`H@_@WH@HD$0H\$PHl$XHt$`A
HD$hHt
3H\$PHl$XHt$`H@_@WH0HD$ H\$@Ht$HHH8
HD$PHt
3H\$@Ht$HH0_@UVWH0HD$ H\$PLHHu
HHt HL$XH
HPXH\$`H
HL$XHt
)HL$XHt
HL$XHt
H\$PH0_^]HVWATAUAVH@HD$0HX
ufH9yHt`HX
sHH!|$xIMHH
GHHL$xHt
Ht$ LMIP
HL$xHt
L\$@I[0Ik@IA^A]A\_^H\$
Ht$ WH HiH3HH;u
1HL$0HM8
GH\$8Hl$@Ht$HH _HHX
Hx ATAUAVH HH
EL9wPt
HwPLwHLwPHO`
AI~iLck
E:t"I;
L4HI;|H
1IL3HDs
H\$@Hl$HHt$PH|$XH A^A]A\E3E3
WH Hy`HH
EH\$0H _@SUVWATHPHD$@DH3H
SEH]XH\$HHt
P(xJL$
rHt\xiH
HPA\_^][H\$
WH 3HH;t;H`
H\$0Hl$8Ht$@H _HL$
WH0HD$ H\$HHt$PHH
FBHHt"H
H\$HHt$PH0_H%AHHX
Hx ATH Hi
IAH\$0Hl$8Ht$@H|$HH A\
HH\$0H _
HH [H\$
HH\$0H _HL$
WH0HD$ H\$PHH
H|$HH'
HH\$PH0_H\$
HH\$0H _HL$
UVWH0HD$ H\$`HH
Ht$XHN
H\$`H0_^]H\$
H\$0H _H%/>HHX
f\$(D$0
?HT$pH
?fD$*38$
ED$,@t
H\$`Ht$hHP_HHX
Hx ATHpHHH
<E3D$
Dd$,Ld$8A;vn
l$0HL$HHT$ A(
fD$*fDd$(D$,
L\$(I HT$ HO
HT$HHO
uL\$pI[
Is I{(IA\@SH H
HIP HK
H [HHX
Hx ATH Hi
;|O333
;H\$0Hl$8Ht$@H|$HH A\HHX
YHcD$ H+H
H\$@Hl$HHt$PH0_HL$
WH0HD$ H\$HHH
Hy Hy(Hy0Hy8@y@@yAHH
H{pH{xH
HH\$HH0_
H [H\$
8HK8Ht
HH\$0H _@SH LM
H [@WH0HD$ H\$@Ht$PH
HD$HHt
HHtVE3E3AQ
3HH\$@Ht$PH0_@VWAUH@HD$8H\$hLH
HC0HS(LK HD$(HT$ LD$0HT$xAR
HS8P A
x)fL$`f
fL$`3E
x)fL$`f
fL$`3E
HL$pHt
e3C@H\$hH@A]_^
@SVWATH8=;q
HI#H;u
H\$pHtdHD$xLL$`LD$hHT$pH(HD$
Ht&HK
u.L%bo
HI#H;u
3H8A\_^[H\$
p1H\$0H _H\$
WH 3HHH;u
/HO LD$8HH\$8
2L\$8L_ HO
Z2;v);|%H
_@H\$0Ht$@H _HHX
Hx ATAUAVH E3IIHHI;
Ld$`M;
Ll$hM;
L2M0M1M4$Mu
gD8s@u
L9s t9A;|4HK I;u
AL9s(t9A;|4HK(I;u
AL9s0t@A;|;HK0I;u
H\$@Hl$HHt$PH|$XH A^A]A\Hu
WATAUAVAWH HHIMD38_8u
Ht$pH;
d.8_9t
HOhH;u
t*HOpH;t
(HOxH;t
H\$PHl$XHt$`H A_A^A]A\_H\$
UVWATAUAVAWH HHMIE3I;u
<-ED8{9t
H-^>L9
I;tYL|$`L|$pH
LLD$pHHA
HD$pHL$`H;@
HL$`I;t
AA:uGH
I;tYL|$`L|$pH
LLD$pHHA
HD$pHL$`H;@
HL$`I;t
t,HSpP`A;|2H
HSxP`A;|
*H\$hH A_A^A]A\_^]H\$
HH#H;u
u.H=Og
HH#H;u
3H\$0H _@WH`HD$PHHd$x
LQ0LY(HI H
HWxHD$HHT$@HD$xHD$8LT$0L\$(HL$ LO
t|Hd$p
HD$pHD$ L
3.x=HL$pHt
HT$xP8HL$px$HtH
HL$pHt
V*3H`_HHX
Hx ATHPyA
HM(HU HE0LE
H|$HH\$@Ht$8HD$0HL$(HT$ AE3H0
EAH\$`Hl$hHt$pH|$xHPA\HHX
WATAUAVAWH
E3IIM;
M;u}M;uxH$
(A;veH$
(A;uRL$
(A;v<AW
?ADL$(JzMHD$
E2ED|$dD|$`L|$pL|$hHt
LD$dHT$pH
LD$`HT$hH
D!+D8$
LL$hDD$dHT$p$
H\$PHl$HLd$@HD$8H$
HD$0H$
HD$(D$`D$
M!,$D!+Et
I[0Ik@IsHIA_A^A]A\_HHX
x?LD$@
x%D$H;D$@
H\$0Ht$8AH _H\$
UVWATAUH0
3tXH|$0H
%HD$ Ht
LD$ E3AHH
A]A\_^]@SH HH
Hx ATAUAVH E3IcLHI;
w$LcA4,A;}
#HI;tH
F$A;vQL
#H;3H\$@Hl$HHt$PH|$XH A^A]A\HL$
VWATH0HD$ H\$XHl$`HH
Ht9L3H
H\$XHl$`H0A\_^
UVWH HH8H
H;t)Ht
XHu9Ht
3HCHK8
H\$H3H _^]HtHd$@
LLD$PH
HD$PHL$@H;@
WATAUAVAWH HHI`H
P8E3HO8A:
A:tzLo
~9HGhE3E3A3HC
!L;HD{
tH\$PHl$XHt$`H A_A^A]A\_H\$
WH H33
HH;|HK
."H\$0Hl$8Ht$@3H _E3E3
HWATAUH`HD$ HX
Hp DHH8
Dd$8HN8
H\$(HtFH3H
HQLHAS
L\$`I[(Ik0Is8IA]A\_H\$
UVWATAUAVAWH E3HHI;
HCPHKPHD$hH
P(E3I;t
HxHL$hH
H\$`H A_A^A]A\_^]
HH [H\$
WH Hy
Ht$8HK
H\$0HH _H\$
HHuH!_
H\$0H _
H(HA H
]H(H\$
WH HHt
H\$0H _HL$
WH@HD$0H\$XHt$`H3q 3DF(I
@wPHwXHw`HwhHwpHOx@
u\E3E3V
E3E333
t$PHD$PHD$(t$ LL
HH\$XHt$`H@_@SH =O
H [H\$
HL$@Hp
H\$HHt$PH0_HHX
WATAUH@ALH
IHP D$ HKx
HL$`Hx
H\$hHt$pH@A]A\_LWH@HD$0I[
HH3HtlI![
HL$XHt
HP(HL$Xx
HL$XHt
H\$PHt$`H@_H\$
WH0HHyhH
E3E333
HL$@Hh
H\$HHt$PH0_H\$
WH HyP
)H9QPt!Ht
H_P3H\$0H _H\$
WH HyX
BH9QXt!Ht
H{XHKXHt
3H\$0H _HHX
HL$PH`
H\$XHt$`H@_HHX
ATH@DH
HL$PH`
H\$XHt$`H|$hH@A\HHX
ATAUAVH@EEDH
t6EEAH
HL$`H`
H\$hHt$pH|$xH@A^A]A\HHX
WATAUH@EDH
HL$`H`
H\$hHt$pH@A]A\_H\$
H\$0Hl$8Ht$@H _LWH@HD$0I[
H3H9Y`
HteI![
x!HL$PHt
HL$PHt
HNhHt.H
H\$XHt$`H@_LWH@HD$0I[
H3H9Y`
HteI![
x!HL$PHt
HL$PHt
HNhHt.H
H\$XHt$`H@_LWH@HD$0I[
Is HH3H9y`
HteI!{
x!HL$PHt
HL$PHt
HNhHt1H
H\$XHl$`Ht$hH@_LI[
Is WH0H
ICE3HT$ AAH
H;tHOXH;t
LD$@HP
H\$HHl$PHt$X3H0_H(Hu
VWATAUAVH0HD$(H\$`ML3L;u
t$xH|$
HH;tGHfL
3Ld$pLl$ht$xH\$ H;t^C
HK(E;|
HAP(H\$`H0A^A]A\_^LD$
SVWATAUAVAWH@HD$(MLL3L;u
HHD$0H;tVX
H|$ H;tXHO@;|
H@A_A^A]A\_^[
A @SH
AP(H [MLH
@SH 3L;u
H [HI H
HH\$0H _@SH HH
H [HL$
WH0HD$ H\$HHt$PHH
HH\$HHt$PH0_H
WH0HD$ H\$HHa(
3DB(H0
HH\$HH0_@SVWH@HD$0HHHu
LLD$xH
LLD$pH
LLD$hH
H|$ H9
H|$xH9
H|$pH9
H|$hH9
L[L\$(H
HT$(HK@
HL$hHt
HL$pHt
HL$xHt
HL$ Ht
3H@_^[HHX
Hx ATH L
It$@39~
)uUB;tK+
BHcLcHcH
H\$0Hl$8Ht$@H|$H3H A\
HVWATAUAVHPHD$@HX
HD$0H$
HD$(H$
HD$ MMAHAR
L\$PI[8Ik@IA^A]A\_^H(Mu
@WH0HD$ H\$HHt$PHH@
3H\$@H
H\$@HO@
H\$HHt$PH0_@WH0HD$ H\$HHl$PHt$XHH@
3H\$@H
H\$@HO@
H\$HHl$PHt$XH0_@WATAUH0HD$ H\$XHl$`Ht$hAEDHH@
h3H\$PH
H\$PHO@
DEAHP(H
H\$XHl$`Ht$hH0A]A\_@VWATH0HD$ H\$XHl$`ADHH@
3H\$PH
H\$PHO@
DAHP0H
H\$XHl$`H0A\_^H(Hu
VWATAUAVH0HD$(H\$`ML3L;u
t$xH|$
HH;tRH
3Ld$pLl$ht$xH\$ H;tIC(
HK0y;|
HAP H\$`H0A^A]A\_^LD$
SVWATAUAVAWH@HD$(MLL3L;u
HHD$0H;tax
HC8L{@H
H\$ H;tDHKHx;|
H@A_A^A]A\_^[@SH H
A(@SH
AP H [MLH
H [@SH 3L;u
H [HI(H
HH\$0H _@SH HH
eHK0y(
QH [HL$
WH0HD$ H\$HHt$PHH
HH\$HHt$PH0_H
H H 7H
WH HHu
H\$0H _HL$
VWATH0HD$ H\$XHl$`AILHH!
H|$pH9{
H|$xH9{ t!Ht
H{ s($
C,33Icl$
H~kxQA;|$
HH;|,E3E3AQ
GE3E3AQ
HC0HH\$XHl$`H0A\_^HWATAUAVAWHPHD$@HX
Hp HE33Lcq
AHI;}GE3E3AQ
_E3E3AQ
IE3E3AQ
3HN0Ht
KL\$PI[8Ik@IsHIA_A^A]A\_HL$
WH0HD$ H\$PHt$XH3H1H
zHs0Hs8H{@H|$HH7HO
HspHsxH
HH\$PHt$XH0_@VWATH0HD$ H\$`Hl$hH
1Hk@Hl$XHM
H\$`Hl$hH0A\_^H\$
WH0HH=)
H\$HHt$PH0_H\$
WH0Hd$
HT$ Ht
H9{0t!Ht
tMHd$
HL$ 3(
tHT$ Ht
*H\$@H0_H\$
H\$HH0_H\$
H\$HH0_H\$
H\$HHt$PH0_HL$
SVWH0HH
HC8H;t(Ht
H{8H|$`
HD$hHK
3E33HQ
H0_^[HL$
SVWH0HH
HS0HT$`Ht
HT$hHHK
H0_^[H\$
H\$HHt$PH0_HL@
UVWATAUAVAWHpHD$`HX
DHE3D8%$
ELd$HLd$@IH\$XH
H^8I;t
H\$XHN
PLn@AAE
A;~@II;|";}
E3E3AQ
EuAHd$P
HT$P3uH|$PHt%H
LL$@LD$HH$
HP0LHAS
HHD$PHtAA
HT$8D$0HD$@HD$(HD$HHD$ D$
~?3Hx";}
E3E3AQ
HL$@Ht
HL$HHt
HpA_A^A]A\_^]@SH@HD$0H
HD$PHt
E3E3AQ
E3E333
HCxE3E333
HD$PHD$(d$
DHH@[@SH H
H [@WH0HD$ H\$HHl$PHt$XH
HHD$@Ht
H\$HHl$PHt$XH0_@VWATH0HD$ H\$XHl$`DH
HHD$PHt
H\$XHl$`H0A\_^@VWATAUAVH0HD$ H\$hHl$pEEDH
+Hn@9]
HHD$`Ht
H\$hHl$pH0A^A]A\_^@WATAUH0HD$ H\$XHl$`Ht$hEDH
pHn@9]
HHD$PHt
H\$XHl$`Ht$hH0A]A\_LI[
I{ AUH@H
ICHAxICH
ICE3HT$ AAH
$E3E3A
3HL Ht
|H\$PHl$XHt$`H|$h3H@A]HHH
WH0HD$ HX
Hp H33Hci
E3E3AQ
OHK Ht
HH\$HHl$PHt$XH0_HHX
Hx ATH HH
H\$0Hl$8Ht$@H|$HH A\H\$
H\$0Ht$8H _3@SH HH
H [H\$
HAQ,E33HD$
XhHD$pHD$xLH$
<LD$hH
4H|$h3HL$`Ht/HD$`DI
HD$(E3HD$
HL$`Hu
HD$pL$
HD$PH$
E3HD$HHd$@
SHL$p=
L3H|$h
HL$`Ht
HL$`Ht
WH0HHIp
HShHKpHSpHt!HK`L
H\$@Ht$HH0_
SH@HD$0HH=
xsHd$`
tMHD$`HD$ L
HL$`HtH
P8HL$`Ht
kHL$`Ht
H@[@SH0HY(3H9
P8H0[H\$
WH@HHy8
u8HW`HOhOHWhHt"LOHOXD$(
HGHHt"LOHOPd$(
HO@D$(
L$ E3L
H\$PH@_@SH@HY H;
uH\$ L
HL$XHt
H@[@SH HHI@Ht
t>HK8Ht
P@HK 3
t+HKhHt
K`E3E3AQ
3H [@SH@HYH{(
HWH(H;
uH\$ L
HL$XHt
H@[H\$
HH9A(u
DPPH\$0H _@SH 3HH9A(u
PHH [HHX
ATAUAVHpMMD`
\$@H9_0u3H9_(u
D$@HO(HL$PHt
HO0HL$XHt;L
HD$(H$
HD$ MMAAR
D$@\$D
L\$pI[ Is(I{0IA^A]A\LD$
LL$ SUVWH(3HH;t
;|,HzLL$hH
f,~H(_^][H\$
DD;|*IDL;t
DLD;|RIK
CDI+t6HI+H+N
H;uH;u
Hx ATH H
HcI9\Pt
HIlPHc
Hl$8Ht$@H|$HH\$0H A\@SUVWATAUAWH@Hy
t~HoHHtu39]
~.E3HM
HW(E3I
HG HO(
HG H;X
H,Hl$8u:d$(
T$ LD$8E+T$$HA
2H@A_A]A\_^][E3E3A
[@WH0HD$ H\$HHl$PHt$XHHHI0
3;usHO@H;tjLG8HT$@*
HHO0H;
HG0H9]
H;O0t?
HO0H;u
H\$HHl$PHt$XH0_HHH
VWATH@HD$0HX
LcpLcxD
pA;t7L$
+A;t7L$
A;t<L$
A;t<L$
L[ E3AP
HH\$hHl$pH@A\_^HHH
WATAUH0HD$ HX
Hp HHy0
3)39A8v Hy(HH9
HHt<HO
HtHHtqHu
Ht&HN
Ht9Hf
33~dLHxF;
H4Ht"H
E3E3AQ
H\$XHl$`Ht$hH0A]A\_H%H\$
H\$0H _HVWATAUAVH
HD$xHX
L3H|$P3H\$H3Ht$`3Hl$hE3HT$X
L!d$@LL$pDG
HT$@H{
HL$`TH|$PH\$HHt$`
H|$PH\$HI
L!d$0D!d$(D$
LL$@E33H
MuME3A
Hl$ht`
HD$pHt*HL$@HL$0Hl$(Ht$ LLIHnL
MHT$HH
I[8Ik@IA^A]A\_^H\$
Hl$ VWATH
LHT$@Hx
LD3Hsx
LL$0LD$HH
L$ HL$P
;|wLL$4LD$8HT$PHH\$8
LL$8T$4LL;t3H
w*HMH;t
I[0Ik8IA\_^HHX
WATAUH0HHhHH
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
l$(H|$
33H\$PHl$X@Ht$`H0A]A\_@WH@HD$0H\$PHl$`Ht$hH
HHD$XHtUH`
HD$XHD$(Hd$
HL$XHt
H\$PHl$`Ht$hH@_HUVWATAUH@HD$8HX
HHE23HX @2H`
HP0u]D9/uSHO
HT$0PpD$
Et/L$(H
HD$ LD$0A
!D23McE~;u7
KHE f;
AH\$pH@A]A\_^]HHX
WH HHL@
;D|*HH
;|~8\$@u"HH0
;|VLD$@H
;|>8\$@u"HH<
H\$0Ht$8H _H\$
VWATH0HLW
LD$`3H(
3HH|$h(
HT$ Ht
xFLD$`H
x,LD$hHI
H|$hHl$ Ht
HtVIL$(LD$hHT$
33Ht9HO8Hg
Ht&HM
3H\$PHl$XH0A\_^
HVWATAUAVHPHD$0HX
3Hx3HXH
HT$ H(
HT$(H'(
IvpHt$8F
N$Ld$@Mt/Hu
N$Ld$@Mt+Hu
x3H|$ H
h3H\$(H
=H|$ P3
-EHL$(
3L\$PI[0Ik8IA^A]A\_^HUVWATAUAVAWH@HD$(HX
LLE3Dp
HT$ I4%
H\$ A;
H;w9I;v
L97u1HcG
N,Ll$8Mt/Hu
5IH\$ H
H@A_A^A]A\_^]HUVWATAUAVAWHPHD$HHX
LH3HXHX HXHXL@
HT$@H|
;})HL$0
?DHL$0
qH\$0H
;},HL$0
ADL$(Ht$0Ht$ L
HH;tpHX
HX H|$@H\$@HH
Ld$8HHM I;t
Le Du(H]
H|$8I/H
HPA_A^A]A\_^]HUVWATAUAVAWH@HD$8HX
E3I;t)L8Lx
Lx Lx(Lx0Lx8Lx@LxH
L|$0D$
HT$0Hh
H\$0A;
L$(H\$ AL
A:tPHE
fL|$0H
UL~8HN8H$
:H^8IFpHF@3
L~(HN(H$
H@A_A^A]A\_^]H\$
Ht<39y
Ht$8H\$0H _H\$
VWATH d$@
HH~+3H
H\$HHl$PHH A\_^
Ht.39y
Ht$8H\$0H _HHX
VWATAUAVH0MDHM
+|$(LD$
Hct$ B
/D$pt$tHu
Dxc;|$p|VH
*x2;|$
4HcD$pIH+H
H\$`Hl$hH0A^A]A\_^@SH
D$PH3H
K0HK8HK@HC
HH [LIK
WHPHD$8I[
IHHICICMK MC
LHuHH9
,DL$xDD$0HH
LHD$xH
IH\$hHt$pHP_H
WH0HD$ HX
Hp AHH
@tYHHH;v
H\$@|$HH
H\$PHt$XH0_H\$
WH A0H9
Ht139Y
HO8Hg@
FHHuH!_8O0H\$0Hl$8Ht$@H _H\$
H\$0Ht$8H _HHX
Hx ATH H
tPHt$P3H!>A
3H\$0Hl$8Ht$@H|$HH A\H\$
WH 3HHH;v
HH;rH\$0Ht$8H _
SVWH0HD$ HHd$`
H\$P|$XHt$`Hu
H0_^[HL$
WATAUH0HD$(H\$XHt$`AELHHy@
3IIHH r,H
yH{@3H
&H|$ HG
HHH\$XHt$`H0A]A\_H\$
WH HHu
`&HA@HB
u#HO8Hg@
FHHuH!_8H\$0H _HL$
H8HD$ L3HD$HI;s
HHD$HH8HHX
Hx ATH0
;u?IL$
AD$(9E(uxIL$
u<IL$
aHM I|$
PLE 3D
3H\$@Hl$HH|$X@Ht$PH0A\H\$
HT$ DwDC
:tR9_(u
:tA9_(HO
?;u%8_
Is I_HWH
HD$ HX
fD$(d$0
HT$`HL$(H
LD$@HT$`Ph
D$HG,HL$@
'x9HT$`HL$(H
HT$`PP
_HWATAUAVAWH
HD$(HX
Mt-EHT$0I
DH=HHL$ v
Ht-EHT$0H
DHHL$ #
Mt-EHT$0I
DHHL$
%DHHsH
I[8Ik@IsHIA_A^A]A\_HHX
Hx ATAUAVH HE3H
H3HfHH+LH
HDh+PH+@C|%
H4hIcJ
-Hl$HHt$PxH
H\$@HcH|$XfD4HH A^A]A\
Hx ATH H
HHKDcH
H\$0Hl$8H>Ht$@H|$HH A\@SH DH
})E~$H
LH SUVWATAUH(Lh
LHchHII
HH(A]A\_^][
H%AHHX
WH0H`
LD$@HT$XH
PpDL$@EtZLD$XL$(
J~HD$
LD$@HT$XH
DD$@Et
HT$XH@
AP8H\$HHt$P@H0_H\$
UVWH0Hd$h
LD$PHT$hH
Ppx.DL$PEt$LD$hL$(
J~Hl$
tH\$XH0_^]H\$
Ht$ WH0HH3
uRHtRHO
H!\$P!\$@H
LD$@HT$PPpx,DL$@Et"LD$PL$(
J~Ht$
tHt$XH\$HH0_@SH029
LD$@HT$PPpx0DL$@Et&LD$PL$(
J~H\$
2H0[H\$
UVWH 3
LD$@HT$P
DD$@Et
HT$PH.m
tH\$HH _^]HHH
WATAUH0HD$ HX
Hp HHH
3E3Lcj
M~fxL;^
IM;|,E3E3AQ
mE3E3AQ
WHH\$XHl$`Ht$hH0A]A\_HHH
WH0HD$ HX
H~:Hx;s
E3E3AQ
H\$HHl$PHt$XH0_@WH0HD$ H\$HHl$PHt$XH33Hci
tDHd$@
LHT$@HAS
HL$@Ht
HH;}.E3E3AQ
E3E3AQ
H\$HHl$PHt$XH0_H(Ht
H(H(LHt
IP H(H\$
HH\$0H _H(LHt
IP(H(H(LHt
IP0H(@SH HHH
WATAUAVAWH E3LI
I;uII;
;|A;}eA;u
A;|:w2H
;|A;|x;}tB;tj+Hc
BHcLcH
AE;veIA;
o3H\$PHl$XHt$`H A_A^A]A\_E3E3
HATAUAVH@HD$0HX
Hx MEHLH
Hu3Ht3H
HL$ HHL$ H
@HT$ H
E3E3AQ
HL$ sH\$ E
PHL$ H
'HL$ H\$ )
H\$ A8,$u]{
AS;HL$
IHL$ rHL$
HL$ JH
HL$ 9H
jHL$ (H\$ SH
3H\$`Hl$hHt$pH|$xH@A^A]A\HHX
Hx ATH D
2;w|Ld$PA;
;wHD;wC3
/H\$XLHH
|H+A<$3
H\$0Hl$8Ht$@H|$HH A\HHX
UVWATAUAVAWH@DP(3LA;s
QE3HHD$0I;u
w:HD$0EEHD$(H$
HD$ GH|$0D$
L+EL+I
A;t3H$
H@A_A^A]A\_^]fD
@SUVWATAUAVAWHx
LcLHL$XLD$`3HL$p3A
LL$hDl$PA
HD$pH$@
H\$@H;
+HL$@L\$<H$P
LL$8L\$(H$@
E3HD$
u8'|$8
bHDpHH
Dd$<D;
EEkZAD|$4E;sA3
LHD$HH;u
\$8HH$@
ILl$@D;
HD$XL$
HH+LdpI
;t&Il|H;~
;ul$0D;
D;w6DL$8DD$<HD$HHD$(HD$4AHD$ pD|$4Lt$H
=H;t-IL+H+I
F3fHLAH
fHHD+A
w7DL$8DD$<HD$HHD$(HD$4AAHD$ 6D|$4Lt$H
AAIcA+I
:H;t*H+H+H
l$0EfA
H<H3fH=
l$0Lt$H/
IcI|D.
HI+HD+A
DL$8DD$<HD$HHD$(HD$4AAHD$ mD|$4
H<H3fHHD+M$LM;
D;w1DL$8DD$<HD$HHD$(HD$4AHD$ D|$4
=H;t-IL+H+I
l$0EfA
Lt$HAAA+Mc
>H;t.LL+L+I
HAD$Dd$0LfA
Lt$Hl$0H|$@L$8H$@
L$8H$@
;t*HD$hI
{HL$`H
HL$HH;t
A_A^A]A\_^][HHX
VWATAUAVHP3MAHXX
bz3LL$8;
L$1DH$
I(@D$0;t0LL$0M
LL$1HT$8DLl$ |;
HL$8D$1T$@A
@8t$Kt
@8t$Ju
#@8t$Lu
z3A3IM
-yI4$HL$8H;t
L\$PI[0Ik@IA^A]A\_^H\$
pD+@@~
3;f,p|-H
%Hl$8Ht$@xH
HHH\$0H _
WATAUH A0H9
H_@H;W(s
u#HO8Hg@
yHHuH!_8M
HO8Hg@
xHHuH!_8O0H\$@Hl$HHt$PH A]A\_HHX
Hx ATH A0H9
L$(fHG@IIL$
u#HO8Hg@
wHHuH!_8MuH
HO8Hg@
vwHHuH!_8O0H\$0Hl$8H|$HHt$@H A\
SVWH0HD$ HHd$`
H\$P|$XHt$`Hu
H;H0_^[f
AWH E3AHA
@?L9Ly
Lq Ly(Dy0Ly8Ly@A
@IHKHL9Ly
Lq Ly(Dy0A4
Ly8Ly@A
Lt$8HH\$0H A_L
DMt.3A5
SH0HD$ H
H\$@Hd$H
HT$HH^
HT$HH:
HT$HHb
HT$HH>
HT$HHf
HT$HHB
HT$HHj
HT$HHF
HT$HH"
HT$HHn
HT$HHJ
HT$HH&
HT$HHr
HT$HHN
HT$HH*
HH0[H\$
WATAUH E3HHI;
HH+HA;trH
L+PhL+@I+
HcL;H,
DH7Hl$HHt$PHH\$@H A]A\_H\$
H\$0Ht$8H
ATH0HD$ HX
Hx AALH
3IIHH r@H
QlLHt)H
H\$@HC
HH\$HHt$PH|$XH0A\H\$
HL$@L33
HD$@LL$ DG
HT$(OXHD$8H\$(fl$2f|$0|$
l;|tHL$8H;tjf9|$0tc
Hf<ALD$8
_^]H\$
Ht$ WH03
E3HHD$HE3HHD$ \$H
iD\$HHKIC
HH;tEDL$HHD$PS
LHHD$ \$P
D$H9D$Pw
Ht$XHH\$@H0_H\$
Ht$ WH03
E3HHD$HE3HHD$ \$H
>hD\$HHKIC
HH;tEDL$HHD$PS
LHHD$ \$P
D$H9D$Pw
Ht$XHH\$@H0_HHX
Hx ATH 3IHE3IHfAD$
HI;t]LHHfD
A;|/AT$
Hl$8Ht$@H|$HHH\$0H A\HHX
Hx ATH 3IHE3IHfAD$
HI;tZLHHfD
A;|,AT$
Hl$8Ht$@H|$HHH\$0H A\H\$
aHHtyDC
aHHtTE33H
`HH\$0Hl$8Ht$@H _@SH 39
H;ugH9
bHH;t/3H
H [H\$
4aH\$PHH@_
H%fH\$
HHtHH\$0H _
WH HHHu
t\9Hu39y@~(3Hx`;{@}[HC8H
;{@|HK8Ht
3H\$0Hl$8Ht$@H _E3E3
]`@SH HH(
`HKPHt
H [H\$
3HDB(I
HL$ L3HC
HL$ t$
Is I_HI
L3H%_H(Ht
_H(H(Hu
p_H(HI
L3H%\_H\$
H$HH\$0H _HI
H@SH H
HH [H\$
3HII;r:M
3H\$0H _@SH AA
L;w)Aw#HI
3H [H8
L-(bH=
\$$I;s
H|$0;t
HL$(T$ f9 wsf9
HL$(D$|
Mc IA]H(MZ
]3H(H(
VWATH@IALH
I+H\$`H
H\$hH@A\_^HLH D@
SVWATH8MIcH`
H+H\$`HAD$
H8A\_^[H\$
H"HH\$0H _%[%X[%4[%p[@SH HH
HD$8Hu
HD$@LD$@HT$8H
HHT$8H
HH [H(kH
WATAUH0MEHH3
\$$D$
H\$`Ht$hH0A]A\_%`ZH8LHt23HBII;s$
E3E333
[%Z%Z%Z@SH E
HcL#IcJ
L3IH [H(MA8HI
8csmu,x
u&@ =
fY3H(H(H
7V3H(%YHMZ
3HcH<H
LcA<E3LL
AH(E;r3HH(LL
BI^t"M+IIHt
3H(%~X%jXH
3H;tBHt<MZ
u*9Q<|%y<
SHt(HHt
H [H\$
WTH\$0
RHL$8DI3
TL\$8L3H
L#H3-+
H\$@H _HL$
L\$XE3HT$`HL$X
HD$PH|$P
tAHD$8
HD$HHD$0HD$@HD$(H
HD$ LL$PLD$XHT$`3
%U%U%rU%VU@SH0
HT$@HE3
KVHt9Hd$8
HT$@HL$HHL$0HL$PLHL$(HL$`LHL$ 3
[H8HD$`HD$ EH8%|T%U%U%U%P%P%
Q%pS%tS%`S%tQ%Q%LQ%O%U%pS%T%@THHX
Hx ATH IY8HMHLC
IHIhD[
LMHHlDH\$0Hl$8Ht$@H|$HAH A\%Rff
@UH HH
H ]@UH HHM8HM(HE(H
HM0HE08csmt
xRH ]@UH H}
LMxDEpHUhHM`8H ]@UH H
yH ]@SUH(H39] u
LMpDE$HUXHMPH(][@UH HH
H ]HT$
H ]@UH HHMh^H ]@UH HH
H ]@UH HH
H ]@UH HHM(
H ]@UH HHM@iH ]@UH@HHM`HMHE3HUHHR
H@]@UH0HHM8HM0E3HU0HR
H0]@UH HHM@GH ]@UH HH
&H ]@UH HHMP
H ]@UH HHMP
H ]@UH HHMXH
VH ]@UH HHM@H
4H ]@UH HHMHH ]@UH HH
cH ]@UH HH
CH ]@UH HH
#H ]@UH HHMx
H ]@UH HHMxH ]@UH HHM0H ]@UH HH
H ]@UH HHM HX
H ]@UH HHM H`rH ]@UH HHM HhRH ]@UH HHM Hp2H ]@UH HHM@H(
H ]@UH HHM@H0H ]HT$
H ]@UH HHM@H
iH ]@UH HHMPH
qiH ]HT$
SUWH HH]HHt
\KHu33xH _][HT$
H ]@UH HHM@
H ]@UH HHM`H ]@UH HHM@hH ]@UH HHM@H
H ]@UH HHM@H
qH ]@UH HHM@H QH ]@UH HHMPH
H ]@UH HHMPH0
H ]@UH HHMPH8H ]@UH HHMXH
_H ]@UH HH
H ]@UH HH
H ]@UH HHMPhgH ]@UH HHMPH
LH ]@UH HHMPH
,H ]@UH HHMPH
H ]@UH HHM8
H ]HT$
H0]@UH HHMx^H ]HT$
H ]@UH HHM(H ]HT$
H ]@UH HHM0KH ]@UH HHM0H
kH ]HT$
H ]HT$
H ]@UH HHMPH
$FH ]HT$
UH HHM@H
33H ]@UH HHM \H ]HT$
UH HHUPHB@HM HA
HJ@33XH ]@UH HHM0
H ]@UH HH
H ]@UH HH
cH ]@UH HHM@EH ]@UH HH
"H ]@UH HHM8
H ]@UH HHM0H ]@UH HHM
H ]@UH HHc
HM8^H ]@UH HHM tH ]@UH HHM(TH ]@UH HHc
HM@H ]@UH HHU8H
HM@H ]@UH HH
H ]@UH HHMPH
H ]@UH HHMPH
H ]@UH HHMPH
hH ]@UH HHMPH HH ]@UH HHMPH(
H ]@UH HHMPHpPH ]@UH HHMPH
H ]@UH HHM`H
H ]@UH HHM`H
H ]@UH HHM`H
H ]@UH HHM`H cH ]@UH HHM`H(/H ]@UH HHM`HpkH ]@UH HHM`H
H ]@UH HHM`NH ]@UH HHMP0H ]@UH HHM@
H ]@UH HHMHH ]@UH HHM@H ]@UH HHMXH ]@UH HHMPH ]@UH HHM@H
H ]@UH HHM@H06H ]@UH HHM@H8
H ]@UH HHMHH
H ]@UH HHM@H@H ]@UH HHM@H
CH ]@UH HHM H ]@UH HHMxuH ]@UH HHMpUH ]@UH HHMh5H ]@UH HHM0HM(E3HU(HR
H ]@UH HHMXH ]@UH HHM(
'H ]@UH HHMPH
&H ]@UH HHMPH8
H ]@UH HHM@H
H ]@UH HHM@H
H ]@UH HHM@H |H ]@UH HHM@H(|H ]@UH HHM@H0|H ]@UH HHM@H8H ]@UH HHM@HH+H ]@UH HHM@Hp+|H ]@UH HHM@Hx
|H ]@UH HHM@H
{H ]@UH HHM@H
H ]@UH HHM@H
H ]@UH HHM@H
H ]@UH HHM@H ]@UH HHMHH
&H ]@UH HHMhH ]@UH
]@UH HHM :H ]@UH HHM(zH ]@UH HHMxzH ]@UH HHM(,H ]@UH HHM@H
$H ]@UH HHM@H
H ]HT$
H ]@UH HHM@HXcH ]@UH HHM@H`CH ]@UH HHM@Hh#H ]@UH HHM@Hp
H ]@UH HHMh
H ]@UH HHM8H ]HT$
H0]@UH HHMh*H ]@UH HHM8nH ]HT$
H0]HT$
UH0H3HMxA
33H0]@UH HHMXH ]@UH HHMXH
rH ]@UH HHMXVH ]@UH HHM@H(H ]@UH HHM@H`H ]@UH HHM@H
H ]@UH HHM@H
H ]@UH HHM@H
H ]@UH HHM@H
H ]@UH HHMPH +H ]@UH HHMPHXOH ]@UH HHMPH`/H ]@UH HHMPHh
H ]@UH HHMPHpH ]@UH HHMPHx_H ]@UH HHMPH
H ]@UH HHMx>vH ]@UH HHMpnH ]@UH HHMpPH ]@UH HHMPH
H ]@UH HHMPHX
H ]@UH HHMPH`~H ]@UH HHMPH
[H ]@UH HHMPH
;H ]@UH HHMPH
H ]@UH HHMPH
kH ]@UH HHMPH
KH ]@UH HHMXH
H ]@UH HHM@H
H ]@UH HHM@HXH ]@UH HHM@H`\H ]@UH HHM@H
9H ]@UH HHM@H
H ]@UH HHMHH
H ]@UH@HHMXHMHE3HUHHR
H@]@UH HHM@H
H ]@UH HHM@H
H ]@UH HHM@H ]@UH HHM@H
H ]@UH HHM@H
H ]@UH HHM0H ]@UH HHM0H
VH ]HT$
H ]HT$
H ]HT$
H ]@UH HHMhIH ]@UH HHMH
H ]@UH HHM0
H ]@UH HHM8aH ]@UH HHMHCH ]@UH HHMP#H ]@UH HHM@
H ]@UH HH
H ]@UH HH
H ]@UH HHM@
H ]@UH HHMP4qH ]@UH HHMH
qH ]@UH HHM`pH ]@UH HHMhpH ]@UH HHMp H ]@UH HHM0
H ]@UH HHM0H
:H ]HT$
H ]HT$
H ]@UH HHM0|H ]@UH HHM0H
@+H ]HT$
H ]HT$
H ]@UH HHMHH ]@UH HHM0H ]@UH HHM0H
PH ]HT$
H ]HT$
H ]@UH HHM`RH ]@UH HHM`2H ]@UH HHM(HM E3HU HR
H ]@UH HHM@H
H ]@UH HHM0H ]@UH HHM0H
H ]HT$
H ]HT$
H ]@UH HHM@H
7H ]@UH HHM@H
(H ]@UH HHM@H
H ]@UH HHM@H
H ]@UH HL
H ]@SH 3H
DB(&%h
H(\H(H
H(4H(H
H(H(3H
DB(%_]
H(VH(H
H(0H(3H
l@SH H
H%>)@SH0HD$ H
H0[H(H
H(H(=Z
CharUpperW
GetMessageW
TranslateMessage
DispatchMessageW
PostThreadMessageW
SetTimer
KillTimer
CharNextW
GetUserObjectInformationW
OpenInputDesktop
CloseDesktop
SetProcessDPIAware
GetSystemMetrics
SetThreadDesktop
SetWinEventHook
UnhookWinEvent
GetClassNameW
SendInput
GetWindowThreadProcessId
GetForegroundWindow
GetKeyboardLayout
MapVirtualKeyExW
MapVirtualKeyW
WaitForInputIdle
GetDlgCtrlID
GetAncestor
GetWindow
USER32.dll
malloc
memcpy_s
_wcsicmp
wcsstr
memmove_s
_beginthreadex
_wcsnicmp
wcstol
calloc
_purecall
towupper
wcsrchr
iswspace
_vsnwprintf
_vscwprintf
vswprintf_s
wcsncmp
_callnewh
memset
__C_specific_handler
__wgetmainargs
_XcptFilter
_cexit
_wcmdln
_initterm
_amsg_exit
__setusermatherr
_commode
_fmode
__set_app_type
?terminate@@YAXXZ
??1type_info@@UEAA@XZ
msvcrt.dll
_unlock
__dllonexit
_onexit
realloc
_errno
EtwEventRegister
EtwEventWrite
EtwEventUnregister
WinSqmAddToStream
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
ntdll.dll
GetCurrentProcess
OpenProcessToken
GetCurrentThread
OpenThreadToken
GetCurrentThreadId
SetProcessShutdownParameters
CreateThread
CreateProcessAsUserW
GetCurrentProcessId
GetExitCodeProcess
GetStartupInfoW
TerminateProcess
API-MS-Win-Core-ProcessThreads-L1-1-0.dll
GetSidLengthRequired
InitializeSid
GetSidSubAuthority
CopySid
GetLengthSid
IsValidSid
EqualSid
InitializeAcl
AddAce
GetAclInformation
GetSecurityDescriptorOwner
SetSecurityDescriptorOwner
GetSecurityDescriptorGroup
SetSecurityDescriptorGroup
GetSecurityDescriptorDacl
SetSecurityDescriptorDacl
GetSecurityDescriptorSacl
GetSecurityDescriptorControl
MakeAbsoluteSD
InitializeSecurityDescriptor
GetTokenInformation
DuplicateTokenEx
API-MS-Win-Security-Base-L1-1-0.dll
InitializeCriticalSection
DeleteCriticalSection
EnterCriticalSection
LeaveCriticalSection
CloseHandle
GetLastError
CreateEventW
SetEvent
WaitForSingleObject
FreeLibrary
lstrlenW
GetProcAddress
RaiseException
RegisterWaitForSingleObject
UnregisterWait
GetModuleHandleExW
LoadLibraryExW
HeapSetInformation
GetModuleFileNameW
GetModuleHandleW
GetCommandLineW
CreateTimerQueueTimer
GetTickCount
QueueUserWorkItem
CompareStringW
WaitForMultipleObjects
OpenEventW
CreateFileW
GetFileTime
OpenProcess
K32EnumProcessModules
K32GetModuleFileNameExW
K32GetModuleBaseNameW
CompareFileTime
LoadLibraryW
GetVersionExA
HeapDestroy
HeapAlloc
HeapFree
HeapReAlloc
HeapSize
GetProcessHeap
SetUnhandledExceptionFilter
QueryPerformanceCounter
GetSystemTimeAsFileTime
UnhandledExceptionFilter
OutputDebugStringA
KERNEL32.dll
GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
VERSION.dll
CoInitializeEx
CoUninitialize
CoCreateInstance
CoInitializeSecurity
CoResumeClassObjects
CoInitialize
CoRegisterClassObject
CoRevokeClassObject
CoDisconnectObject
CoTaskMemFree
ole32.dll
OLEAUT32.dll
AccessibleObjectFromWindow
OLEACC.dll
PathFileExistsW
SHCreateStreamOnFileEx
SHLWAPI.dll
ImmDisableTextFrameService
IMM32.dll
SLGetWindowsInformationDWORD
slc.dll
SHGetFolderPathW
SHELL32.dll
COMCTL32.dll
UnregisterClassA
GetThreadDesktop
wcschr
NtQuerySystemInformation
RtlReportException
RegQueryValueExW
RegOpenKeyExW
RegCloseKey
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
OpenSCManagerW
OpenServiceW
StartServiceW
CloseServiceHandle
API-MS-WIN-Service-Management-L1-1-0.dll
CreateMutexW
DeleteTimerQueueTimer
CoEnableCallCancellation
CoDisableCallCancellation
CoCancelCall
__CxxFrameHandler3
memcpy
_CxxThrowException
memcmp
.?AVCAtlException@ATL@@
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
</windowsSettings>
</application>
<assemblyIdentity
version="5.1.0.0"
processorArchitecture="amd64"
name="Microsoft.TabletPC.TabletTIP"
type="win32"
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel level="asInvoker" uiAccess="false"/>
</requestedPrivileges>
</security>
</trustInfo>
<description>Tablet Input Panel.</description>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="amd64"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
</assembly>
444444444444444444444444444444444,+*''%%''(*+
yqkkiikly}4
yqkkkqv{}4
zhhhhhhhhhhhhhhhhhhhhhhWTSFD98778ADFPTUWz4
hbbbbbbbbbbbbbbbb`_^^_`bbbbbbbbbbbbbh4
h=Gnrh4
h1nH-h4
ho\OBc
}hhhhhhhhhhhhhhhhhhhhhhh$t
"hhhhhhhhh}4
%%%%%%%%%%%%%%%!
hkpfUU[ko%
hxiQQQQQQQQ<;/(%'+/:`s%
htYyLcy
htYOOG0IJ*HLOOOOOOQk%
hxY12"
hxYTE|
hk]]]]]]]]]^.
hhhhhhhhhhhhhhV=@
#-------------
-
,555555-
+55555-
!11111
''''')
IDATx^}
{{\H)&m0333333s
sH+vgg]y
*Zd_~f
s/[5o2f;K.0QD
*Y$M&.%Jx(
HbRj7k
}87xZjE={!C
SOD|g?Aq
?7|SwW
S>?Rz(Yd
%m?iIRUk_Y
x[0?*mL_~
%[oBj;`$h
JWM|+lqiey
4cl6`|##yZ(Om
MRh*TR5
h?-Y^e9
#h4ez6|
sQu(S"&[
}};O\e
,LypF%;2
JjDrR,
H.oSfH
>5J8qr`
:s?3`+4Zq
zTZ}Q8
<uE4|e*Q&V
F]AFL]R&@5
8S1M7V{
q(G;_#e)
yTb5*T&e-X
7(?eS
~cuzC-89~+
YRx,q sMaI}oM
sd=Zv-h
t!z0m&.T
yOO2gt
&Eto^=6
O?D'O
t4iBqO
;6}W(mFJ3/
Rp?}L"?E
O5w}Hy,
SeTx/SV3PB(Gr
H9/mb/hldiWO
RJE1q'NNfYsS*/E
'xObp^5K
%NORdI)k6g k
)Yl}i3P4iRQ
m{"7$d?k
=t7<~!)C
eOw'Jr
N~g1&2n|o
pB{k>y
8iGL;ke}^7
jI>X3SJ
_wX[Nm
87{>J+D)
~7$f<o)V^#
r(O9Q?-
ALlJCd
O#hqoY
C=4cVj9:|
|w;<7l>}Tmw*^.
\G4wBEO1
5O#NjY-
>M8m,?
@{K}#0xuz
4zbG^4`a:p*
;i;o]J
*gWK44qk
#OUN.Tl
8e.XRX
OeW9}S}/[tM
451"1x2m<;)Az[z/YJ
/V,e,PAI9
,YR)3GG|g
{7U^2G;sozM(K"
H)Jsx_r
w<_b&N
)]tT?]V}
cg;by_(7"
x"=xV\IUT
SNN#?S}Tl
:G~Ne?%
:x.\Lw
}W&M)E
/yJW(a7*
A9sf[{
stg)]~ls?1
,Vx0Z8?G
3^SoQj^%oAf
e)I|w>:AO
8vky'_;
<?zH{R=)}
)JNvM>(F
M%L_VMj7"
$E*G~a
c|+ZxJ
-M|5;i%8
TNSFis
~2Qdge(E}c8~
9An=`.m
wFwFQ
~~#>q^c.>
Mi2goM^_Y
e+Vr'Q
5dT!S^
Tm7*]%(Yw|1KVS
2"eqv]
P}lC6+
I:}6x>{EV+WQ
06S1GNO
Qhg~xSK
^{T*[6*\
LM#&RN^l<Sz^=
=v/}#$xr
2`x>&of
q&,\%68ts6>sV=Js+7
?>)Pl.8
Ju:RZ2
;=wCll~
0iD)RR_
#6t1KwCg(M*-Amq
im$jo8
s>@"7/
ReIjE7
uDkid@A
:s11XP'6
;&IA)g3#@xu:
,'?LT2u
?WT2?_
MZ)bo0O
>-:Qa^
+'Q^K=
o.OaiOz
b<{|lyM
|vS~7Sg*?(6
F)M;Pj
(k1O}y?c,TLyJ)hq
ysQLF`
}`CF17f7Z
N;lb-;
lq qqZt
"57}V1
5f*o1w
Zq rC?7/c1S
}qXs0>5
>2B%KSz3v4[cMm
@A;Mv&?&V{
7_}0p{s6
g~od 4^
k1geA
Bl_e-ek
E5@a~;jj^j
wI+X8`T|
2rgG9d"~k
cw`bo?
%MNy?Lx
$mX\((c^#(
ac/iQTWF*V
>:B_W*Q
>b,}2e?1L`7
M3y-?V8qILm'Bu
@xMSA1WVIR$
-[f/*wI
(^q]{k
ck?xrBir
\155!t^
wvKoa67y
[v,%<|l?eK@Lq.
OT/^'O
4o]uSc
%?zL~6=x
eqn5:N_t%x%
@G\#L`(st
h~Awu@I
r}=m7o
J3S,VU'
_EJ5k
=|f:qZ
>,a<~)
=zRPQV#L
7XkOxw
Ody>ig"R:
)Y,g@=
.A P+6w/_
=~b)Vv
u[h"^m>
FcoO~
'rPP[J'y_=LVbM/Iyg
G=*QlQNiW
8)@MMw
A@P~_$A@
|BGb/B
p@d3u}5
/L}A?
YdFbTb
-X4jLRy
.EiyQSfetT
jV`o8+
G^h}`(WX
{jpiTH1
UX5kF5U3
vHGo[*PHI5%y
H"GA*W
0aBL_(=
s*jG P
H5:9~mjf
ro?Lq/uTC
4`*o0#
jGd"EP
.Zy`rS{8:
ZOW?_S
5_c(VM'
|s^_J)S!/?)'d
yX$G!G
TL9~zeA
+WfJ3d
_E_f<~%_W
DMZ)*Kw
F8Fw)\0
%_#L/M)9
b I @@[
+m}Y4*kXa
+s5/M|
>.+W0PO
TP!1iRo]
|{Z0U&{
eT3T`m
wa({k]
eg ]t"E
:n\*Y,Mcw=W
gK4[~*^
+fgh;x
5E?ag`G
+&UruA
RpCi?<
Qvq39KWd<(
wR~V&\3
L}mo^#G
1-h St
z=Z7Fz
0/G{9[
/r-!{1^
EF?fFTE;J=
%]}.CF*X7
8v$!&3?r
I7{HSakk
{CV?0?28IG&
a#W_?_"!
s~vl#
v|.i!/\!uA
\lX:v;E<<7X
}G~?0G
/9Vj@klvF)
I0IUfb
;WeV.d
<x~8vH>
;S*UDL
#;wn[tw
@Dac7M
<rx7/i*Fj,2_D2R_
(?G1:uDz
)AH-Ft_`
pzok?l0
axBt_m~o`b
}KT_S~??
"pI<F;vJ+
C$P~LS~
@DZS'S
>>R}#F
>)?GL!?
FJtiO1
K4w47>,?
A?,;tP
L<?y(O?<dW
be#ePd&LG>/
DG=`#
r`mt{;ScD
CrCT__
7>EAmyG
RlPTLkZ4s
ne(W\k<csOl~
9}?]N$TXQz#
~?[cGGn
]<w,R[
?a#O#g#0
Ba17mL57S&F
Q-:T<sma
|`?|[
~?yz_?
(_k~?;,
M>*?6#
;M;Pu~
HuJQ-rfl
\ojsuw
HxK2<u
./u^&{?Y
Xsx~2t6l6TZUM-
y]E?c+o
X~-s;/z_
#S#}~L%
~y#wE(^D~
R}}Hw0
w@@&hM.w
~$M,YR
ZUENSG
x7Q>Hs8VZ
{c?V!B;3
hl=D?WM
ywB[4b?~#
i|>d`/R
H.mFY}Cwc
p4s|4h
w<0Ag
?`&m^CF
x>3~!jG9
z(6@`@1t
k Eb{fO"
p/@_Q|oJ8a$/Bx
MmyzoPGy
!;XqsQ6
,^0)/T
BFeMI63.>
ES;"w7i
#@l}1jc^RQF
O9)$~c~ AH
+@O~ F|
\Gj]'uo6FM6
0{pHac
kS~P~L
)G(Vdy'
W,v=zd7'
>>vQ)#aSi
QlAl~D
f3?_<l
tlE>z
=%wGSG
/)]{xP`g`
Kjjx0"O
lSC.?wk<p}
G_ylNTb/
%s<GP=
yf`;or\wY
+8pKm3<=.x/
^-+AAl
wyh'u>G
vE+g6Zf/fjov
JF|/7[XC~
OWo/;\
WJG)x>,ai1|]
?FzdBOlhn
U(^l#vw+>iY
1eXu3e-
{)zGAFc_
yL3\w,z
B||YG-P
]hlfEX*;4_&MD
>W_EsN
X#\}&yE}`
4uM~sKy2my
]e1Q687
{`8WU2P(*G
u{,UXT
lX C.z6
)[d_ow
yLq]Og
RK[n'ovSO
~,>,xf
wu`G'W
n#RT&{}*!
OU=v]E
u]q>6Y
xtVM6YE?L
b/(?~l
+Vl*S(
G[G:Y2a?kCYWy-3
>8xtI#eTm>z
fsIN/gC
VOP|MyS .t~
yseW;sQ7
~ n'}-}bS
YGg;sR{zk2
eWY'K\mr
v[n>{M1d
3 ;ho_3=%/
uD:T`S
cGZ<@$
-d*GMp
pN6NT
SZk;{{Qsm-
LT,S-A7GuBe~
/EOo7O
:sr,KqnT^~GQ?UwQ7F%vw^AZUu
Xl,WE.7+
T!oC7b
uY7uhvC
}In! y$
U_>k=5;{=:IWeZQ
:C)I%Qe6P}iYeQP%gw
j-+WOYsE
yUo\[b
{p>|~xF877
{CvQnF
,^} *~7*SJ+.
``8{~F>>
p-:YgW
tL5x"T=u}_7N}}_}l?
e:ln7d
W[}u05!
/hPthJNF]_
2/\mF?Y
<9iQz@/
3>+LQwYu.~C,
?uejlF+f
i@N._zZu4n
H;6&e,>Z0W
~:,xU}3|x>W
[SFX}-rX
@TbxTz|ox6
PWpfUW&
-Y2gx)g=n
-V>dYfzb
j9uJ1=o*
sfY=,^S
}.zwZ3%I
y3U/_}'
G)3w[V[fD
3Q+}|L/`
ue|f\h]g}^0=
4E(Y7>\
o{u<4W]_n
:8k7\,
uu|^{P
oQwkI~]m
_Qu]|?V?u}e
eF&Q-?z+O
yM&>oxW|F~^4wXY
rCjQQg
|zm5xhmUo]G7
|2m5k>|
7_,a_*%lil_
{p7m]5
Ywgd\s
3e]?]o
_o yM~Nyq
tjV0Nu5Ifta [g
wsE/<\o 7o:
8)Od)CN92A&=N9
}9Nwm3M
guvxGMtxb
kG[/Sr
-Org.2
[du]6YSu0BI
kk9~^_+=
0dEK\x
&#-s6{
<joQs^Q
u4mU)@v
lWAn[Z`"]?F(
^LOYAuY?
@ldPD/
Os,G>/
fJ+5}Q
R=]]G/G
Nb0YEX
Ytlq~\:st>;.^BW.e`XR<w:Zzrg=
|y+jS;~sO5/}j
n_lGwHys\S
l;~3yo
@7P,_.S
4;o uI=[v
RTd#P-
uy $^W/nb@d
=O=3;&]))
V2 f"]:P
2eIUnS
\ZT m%%
b 3BX-
39l%,d+a1",[
S$oMYUu7
:![KffB'C~L
$q/~{h+(
,:Cxt~@]Q
Y_YgF\}G(G
2o^\Bw.gw
vCeP`z
e n^XN'S:N
AStd3
*@`aa5
g(}P$*
|\q%<c!+JXA
wu#tgU>5i
Cn4?{<2
3dJ![}2X
<RUy\$,)o2U=D;
?/e'uj(QOPwWkKYQ)
,zraI
}~,F~?"N=r
mnj,;hDkQiFTbjV! z*iv
UO'iX+xY
*L{3),
aLX(}K
p4>y/~A/
GXe]u%z_y
o!~^O'h
q4k(1m
#[0o<-Y4-
ZMt6:$p6.__Y>@;y
}K%I(K
zR)5_kL
@Z;S6|]'^UG?
mh64sR;3=
%2zv77t
!3]}*d{K
a<(-Q_S
7W,|u]
$yY~j6W-5
!}lx:u
=8e)z@f
%5q/|e' xeaG
x|U_Pup_
~BA4,aZD.e4x
D6^#xq
CLPrc)f(2X
;I!'O;
JQ5::P
6|>-v_a
V$DUV3'=X!
&}8AKe
9ez&lsi
^e@xrk
H2W|aM
DVye GG<@
s<6gtlX
<?gj[',letdL+
qbSt<[
,`Wa!"
X}V,8C?c
jb`5d/*EtxBG(ith
e(l [`}nJQ
"n0`*]=
w2`@oiUy;sv[tn
H&xFp_m
?a@aoM
fn@q34]L
Jn#U9g|>lp
eE0krka*0@(
-- U0{2
m9#=O-v
1BJo]f8Syk7Gz
Y'_#Lut0fMuzf\r5*iYRa
,')0mB
mX|7m%
n7y&9Ftmh
7M'S95
^jqw1J
<2xjq7
<}NowP
af(,tnM
e[mZ>
0gLwoG9
^BX}zLZ
*3^iE5
e~2G_PFU
;fbpu/4
_(+TH
%>e5a(1-Q ae
+TdDo=
BG)<=M
;@V<kZ
w.HESE@*L6
M3uT~cs
5GfS)}
S}(9;||dZ!
h'|9S1
/@~lgUtFPkX
Ms4LxKS
Bj3ztme
>&5nG8
#@Cw5[Vk
}wGJ$ NplX
"h(*#(
%jY.@7
.gtmrk
`e&0Fr
^ae*RE0a,N
M06uIi
7CCx"9_.-
CEI^$)X
z2b":5H
=5g*[a-+0Lsa`y>B
FwR(eU
Lq[@%@qiJ
?c!!?6I$`TE
sPml#W
2^-:iE
DAW?+.~i
pJ-`Qa
=<doa.V
9YX.,1/j
H*CGShBes6-
!~ )DG
@cIFPJi
DL1L?)I6
*Y2(j,WQP
e[JU*]
PFMvTYK6av
?-:$;IM~
?vH-t/
=jo#|A{y5o:]
e: y8>xv
L~8D@
x= 4a9Io
|%^f,XLSg
GM'N1J<NNxi2
f/ZFs,+V
vm{sC(hwa
<B6 /t
Md~4HH
-4M+"Pa&.eE
|2hvZv+
kZki2M
Mgq?E;Vn3|T[Ick)Qf
qq\}xVZ
3}.2MF~
9x8u7:
$3SPW>v
5h8Yeb=d
>9xo%L
>-Jl=L
PvVtA|
4G'(cge
#w/V^=A
#{}03
|)m(W ,
@+:*K_ER:!pZ
6xv7`k
Qabch;d4
E0M<0k-
s1lL+;
|CPyM;t
LU*@0d*
YCif43WR+(L(
|;eIVL
{)}]Y7
'&7A>@Y*)gU/Rl qYL
<QnC\>UQGD
*cj*Oa
S2HLepT$SRTDI*X$
D}-'6-%M%mh_in'+
5yW@s~y
)Lj<yrPd
L4i+I$i6q
G=T}PN
M&01C'fK&E
`a/X)J1
*u7u[_\RA
_MQ.a`T
z \e>&VL&dbl
MhYH2Ump
=Boc3LG
}^B?W-#cNP
IENDB`
iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV
SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@SM@RL?PK>NH<KE:GB7D?4B=3A<2A=2B=3C?4FA6HC8LF:xsg\JK7
PK>cPQ3
RL?gST2
~zt}xmtoemh_hd[faYgcZje\ojaupf}xm~sx|~SM@iUV1SM@iUV1zy}SM@iUV1~SM@iUV1SM@iUV1}~~~~~~~}}~~~~~|ytqruy{}}~~~~~~~~~~SM@iUV1SM@iUV1kOa|m|SM@iUV1gFY`rtJYZ
SM@iUV1xXk""!&'SM@iUV1
`qsSM@iUV1
3<=SM@iUV1
mcdd```
!&(SM@iUV1
~i~cmo,,,
2;;SM@iUV1
bvoXY\
LXYSM@iUV1pJ^ussfdf
xSM@iUV1jzm|[dc111
SM@iUV1gih
SM@iUV1yyy
SM@iUV1IFA<<<
SM@iUV1
VVU_[Q_WGD;+/)
xvmSM@iUV1
||oT>5(/*SM@iUV1
pX=5&/+!
SM@iUV1
mbJ5/!SNDC=0iUV'3
v_V>:1
tl\iUV'
jMF4*%
uZ60#$
pZR<0)
VOAA8(,$
]VN570"(#
TM=Lqld4,%
vpdoQLD&!
tU-+&#
LE:'QI9
iUV1iUV0iUV0iUV0iUV0iUV0iUV0iUV0iUV0iUV0iUV0iUV1iUV0gST1eRS2_MN4[JK6[JK6]KL5aNO3eRS4dQR
d]Se]Se]Se]Se]Se]Se]Se]Se]Se]Se]Se]Se]Sd\RbZP]ULVPGRKCRKCUNFZSJ`MN-
`ZPcPQ3
~vytikf]c_WeaXnj`zuku
d^SgST1
|d^SiUV0
d^SiUV0
~~uklyxuUuyiz|}~~~~d^SiUV0
ucsym}ASU$-.d^SiUV0
#''d^SiUV0
o1;<!
d^SiUV0
xew!##
d^SiUV0
N[\&((
d^SiUV0
d^SiUV0
vtmRJ>60#
d^SiUV1
841d^SiUV(
l70(~{xd^S
i`kbU9<6)
obIX0(
iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV1iUV
oi^oi^oi^oi^oi^oi^oi^oi^oi^oi^oi^oi^oi^oi^
iUV1oi^iUV1~~nw~~~~~~~oi^iUV1cheYoooi^iUV1#))FWWoi^iUV1ddc
LLLoi^iUV1
.-,"""430oi^iUV1~221
RPLoi^iUV1
WWS,,,
MHEoi^
(08@HPX`
(08@HPX`hpx
(08@HPX`hpx
(08@HPX`hpx
(08@HPX`hpx
(08@HPX`hpx
08@HPX`hpx
(08@HPX`hpx
(08@HPX`hpx
(08@HPX`hpx (08@HPX`px
(08@HPx
HPX`hpx
(08@HPX`hpx
(08@HPX`hpx
(08@HPX`hpx
(@HPhpxPX`h
BagarBubba
C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32Info.exe
L!This program cannot be run in DOS mode.
%"Rich
`.rdata
@.data
@.reloc
S28YIu-Q
S28YIt
x9SVW}
w_^[]U
ufPPP3WS
M_^3[i
3@_^]j
+WV4F}
sUV3jf
W2G8F8b
PSYEYt
SPcYYt
QWfYYt=E
PSYYt8SMle
EP4PVEPouMMFD
t};t!Qx
SM3CVM]3jfEWEPME
u*ShpB@
FWSM]_MWSMQ
vE;tAj\5`@
YY;t-3fH
@^_]U,
PW[M_3^
u<EPEPEPVhB@
_^U]%$@@
U]% @@
39=p`@
;u!hC@
3fEfEh
3WUV395x`@
u#95x`@
3}}9=p`@
39=p`@
UQVWt\= @@
Wt%Vh1@
SVW(T`@
3PuEEd
SVW(T`@
3PeuEEd
SVW(T`@
3PEuEEd
Y__^[]Q
M3-%@@
+SVWT`@
EPeuEEEEd
+SVWT`@
1E3PeuEEEEd
Y__^[]Qh:/@
Yj\hH@
wOf;t
EE8csmt
8csmu*x
EEPEPu
;r_^%@@
B(;r3_^[]
Ujh(I@
SVWT`@
1E3PEd
Y_^[]%@@
E3E3;u
^_[%@@
J3CJ39G@
invalid string position
string too long
map/set<T> too long
Software\Adobe\Adobe Acrobat\11.0\Security
NtSetInformationProcess
SetProcessDEPPolicy
Unicows.dll
Kernel32.dll
CreateActCtxW
ActivateActCtx
DeactivateActCtx
FindActCtxSectionStringW
QueryActCtxW
GetModuleHandleExW
IsolationAware function called after IsolationAwareCleanup
AcroWinMain
AcroRd32Info.pdb
GetProcAddress
GetModuleFileNameW
FreeLibrary
GetProcessHeap
GetVersionExW
HeapSetInformation
GetCurrentProcess
GetModuleHandleW
GetModuleHandleA
GetFileAttributesW
GetVersion
LoadLibraryW
GetLastError
SetLastError
OutputDebugStringA
SetUnhandledExceptionFilter
KERNEL32.dll
RegCloseKey
RegQueryValueExW
RegOpenKeyExW
RegQueryValueExA
RegOpenKeyExA
ADVAPI32.dll
?_Xout_of_range@std@@YAXPBD@Z
?_Xlength_error@std@@YAXPBD@Z
MSVCP100.dll
memcpy
memmove
??0exception@std@@QAE@ABQBD@Z
?what@exception@std@@UBEPBDXZ
??1exception@std@@UAE@XZ
??3@YAXPAX@Z
wcslen
_vsnwprintf
??2@YAPAXI@Z
_CxxThrowException
??0exception@std@@QAE@ABV01@@Z
__CxxFrameHandler3
wcsncat_s
wcsncpy_s
wcsrchr
malloc
_get_heap_handle
memset
wcsstr
MSVCR100.dll
_except_handler4_common
_amsg_exit
__wgetmainargs
_cexit
_XcptFilter
_wcmdln
_initterm
_initterm_e
_configthreadlocale
__setusermatherr
_commode
_fmode
__set_app_type
?terminate@@YAXXZ
?_type_info_dtor_internal_method@type_info@@QAEXXZ
_crt_debugger_hook
_unlock
__dllonexit
_onexit
_invoke_watson
_controlfp_s
InterlockedExchange
InterlockedCompareExchange
GetStartupInfoW
EncodePointer
TerminateProcess
UnhandledExceptionFilter
IsDebuggerPresent
DecodePointer
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
.?AVbad_alloc@std@@
.?AVexception@std@@
.?AVtype_info@@
"O8M"0(]5_
YZV8yger
PA<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><assemblyIdentity version="1.0.0.0" processorArchitecture="X86" name="Adobe.Acrobat.AcrobatInfo" type="win32"></assemblyIdentity><description>Adobe Acrobat PDF Info 7.0</description><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="X86" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="asInvoker" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
<application>
<supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS>
</application>
</compatibility></assembly>PADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGX
60<0H0N0
1 161<111$2S222
3L3o3m4r4}444'55555A666d777
:;v=='>l>>>>>W?d?j?|??????????
0T00000
1%191I1S1g1o1}111111111
2"2-262;2@2R2]2f2k2p22222222222222
3!3D3I3N3333)424\4q444444444
5 5;5]5s5555
6A6F6N6W6k6v666666666 7.7B777777777738v88888
9Z9d9k9q9v9{99999999999
:#:-:2:7:Y:^:g:l:y::::::::
;@;H;Q;W;_;k;};;;;;;;;;;;;;;;
<'<<<<
=$=+=2=9=@=G=N=U=]=e=m=y===============
>I>O>X>_>j>p>>>>>>>
?>?C?b?
00=0Q0W00001,181@1H1T1}111111111111
272d22
X1d1h1111T3X3\3`34444$5(5h5l5|555555555555
6 6d6l6t6x66666666
7(7<7D7P7p7|777777
8$8D8L8T8\8d8888888
9 9<9@9
mon#$`
~|NYKw
Western Cape1
Durbanville1
Thawte1
Thawte Certification10
Thawte Timestamping CA0
121221000000Z
201230235959Z0^1
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
%y"W*o
%CE{t"
MD$k_E;DC
&Mq1Qa
xE/W?=
Qlie)`
h]jxdE`F~T
_n\t}?L.02
http://ocsp.thawte.com0
8060420.http://crl.thawte.com/ThawteTimestampingCA.crl0
TimeStamp-2048-10
DnmX|0i#s
y@b%n7j!
Symantec Corporation100.
'Symantec Time Stamping Services CA - G20
121018000000Z
201229235959Z0b1
Symantec Corporation1402
+Symantec Time Stamping Services Signer - G40
[LvCK"+Ch@O8
2[^Z(P
Gf=Gpr_
L-wDh
[2V3cI:3
http://ts-ocsp.ws.symantec.com07
+http://ts-aia.ws.symantec.com/tss-ca-g2.cer0<
50301/-+http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
TimeStamp-2048-20
_n\t}?L.0
Lb07x'
2m,&c3Idm
7Cxx(
]=Qy3+.{
[0W,I?
>"hcSit
VeriSign, Inc.10
VeriSign Trust Network1:08
1(c) 2006 VeriSign, Inc. - For authorized use only1E0C
<VeriSign Class 3 Public Primary Certification Authority - G50
140304000000Z
240303235959Z01
Symantec Corporation10
Symantec Trust Network1B0@
9Symantec Class 3 Extended Validation Code Signing CA - G20
S|?~+G
| ^(\|
^[pxFR{I)
{n3aKE%D#6(y
(0&0$"
http://s.symcb.com/pca3-g5.crl0
http://s.symcd.com0_
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0)
SymantecPKI-1-6290
u8*ZZL
(Nt|<qV
:_>dIAtA!
o8X~]`
<"j5c6
7D1{f'0
Symantec Corporation10
Symantec Trust Network1B0@
9Symantec Class 3 Extended Validation Code Signing CA - G20
150604000000Z
170507235959Z01
Delaware1
Private Organization1
27481291
California1
San Jose1$0"
Adobe Systems, Incorporated1
Acrobat 111$0"
Adobe Systems, Incorporated0
L,p.6F
$KMEj%A%P0`w
S&\AMju
QFK/g5h+
t|hV@0l7+oS1
US-Delaware-27481290
https://d.symcb.com/cps0%
https://d.symcb.com/rpa0+
http://sw.symcb.com/sw.crl0
http://sw.symcd.com0'
http://sw1.symcb.com/sw.crt0
{k/Yi
)S9 2;|v
%D?Cy^~
,.|h;{>KN
Symantec Corporation10
Symantec Trust Network1B0@
9Symantec Class 3 Extended Validation Code Signing CA - G2
7D1{f'0
1H0FDB
R14T;W~#7
U8J$]uA
KP(-Ct
L3!wu_sz](
Symantec Corporation100.
'Symantec Time Stamping Services CA - G2
151217220735Z0#
g{gP#iG
Fh,P?*Y
Q%D6H!DQqO
q%x91X;n
c~4[.%
BagarBubba
C:\WINDOWS\system32\cmd.exe
L!This program cannot be run in DOS mode.
YYY_Y^
[XmXRichY
`.data
msvcrt.dll
KERNEL32.dll
NTDLL.DLL
USER32.dll
MM#MuMgMM8
iMPoMMM
MNMJMz]MM/M"MM~MwMMqM|SMM
MJMMMj
MM7M1<M
Ma~MlMkMn
MMrM~M=McMtmM~MjMgM+M
MMhM/MaM\M~M
||f||t|P|)|
|=|U|h|,|
<|;|G|
|]|X||[|
|Y|Rj||<x|
|7|2#|
||l|x,|
|f|y||1
|w||(|<|
||,|8|
|Y||+|_|
x;JVW}
J3fG8Y@
+SVWEePEEEEd
JYPhJj
U$x;JVu
PIf=;J3fE
Ef}t2E;Juuu
fffEufd]
3@EE3f
PEPzu?e
PuA_[M^
PYt0F<f8
JYYSYfdC
UQQW39}
JYYf97
UVW39}
|$;Jvu
~`J_^]
N8f<Yf"
WhCJu
F8f<Xf
J5xJ%J
J$J0J]
V3ShFJ;YYuHS
JY@=FJ
UQQSVWj
h@FJYY
!$J0Juu@
UQQSVW
$J_^0J[
}x;JVE$JW3;
1j%[f;
M_^a3f
UVW=FJ
"u+=:J
t;Jf8:
J1t095DJu
h(Jh$Jj-h0%J
0J$J3LfEM
UQQSVWE3P]]{
t$SMEP]F
5t;JhFJ
5t;JhBJ
5t;JhFJ
5t;Jh,CJ
5t;JhFJ
^UQSV3WVu]
VVqEG4_^[
(Jj0h,%J
SS3_^[]
(Jh(Jj/h(Js
h(Jh(Jj.h(JN
JYYw<3UVu
|*3fXS
W3t)9}
fEf;JfEEPfE:
3VKJS;t
uKJFB;|f$uKJ
t4V3f7V
5J__^[
J3F!0R
SV3WC3
x;JEfE
fEf;JVfEE3PfE:
t)VVVVPh
h2J(x;JEE
$(3A,jdX04DfH
J|MQSSj
JxMQSSj
JE;tMMQuPj
GGEPuWj
E +JW;u
DJVSSj
JSuh+Ju
J(;JEM[
J1J_1J
JEPhH3JEP=
JVEPh;Jx}
Vh2Jh;J^9t
JYY3f;JPP.
f;JfEEPPfE:
3f;JPP
JSYYWSS
3f;JPSf
GCF3f9
Y@@M_^[
wft f="
3f<w"tf
x;JSVu
EWt j*V8
PPj'V3
Sh4:JD
FJ5(Y4VW
5t;JEfX
VW=:JG
t)t)6Pv
x;JSVW}
w4E3;tXF
Y3M_^[
PVYY3f;JPVF
j8h@J23
]Sg]EP}
EKJKJ5JPV};
WSE;tE
hhAJx;JE
JJh;JP
Ef;Jf;
S3;fEfE:
fEffEfVP
J3YYPPh
u"ff;Eu
DJ3[_M^`
GGrEFFg3mUh
FFfu3@[_M^
JSWPSRM
_^[3=dJ
U`x;JS]
VEHJWP]xJ
JYPVVj
Jh;JPJ
JPS3SJP9
JJt5;t1h
JhIJPXHJhlIJ5XHJlJhTIJ5XHJpJ
3@M_^[
SetConsoleInputExeNameW
IsDebuggerPresent
CopyFileExW
JVu+WEuE
EPEhLJ4
P3VhLJuu
PVhLJu}
dJEPPE
PVhLJu}
PVhlLJu}
ffJEPPE
PVhLLJu}
ffXJf;t
PVh$LJu}
ff\Jf;t
XJj Zf;
\JEPPE
JYY_^[
J2XHJu
JXHJhMJP
SetThreadUILanguage
M9}t>v
3@UQQVu
Jh;JPJ
;JY@GJ
JE3E3%
j(hxQJ3W
TJ9=xHJ
hpHJhlHJt
EP5|HJEPEPEP
JEhhHJh`HJ>
}=iJJ%
3YdJ3f;J
f>"u*Fj"FV
U SVW5
HJ|J_^[
x;JSVWE6
JYY<JhVJh IJhVJhHJ
0KJVJSPj$
j JJSj1
j JJSj2
j `JJSj3
j JJSj4
j IJSj5
j IJSj6
j `IJSj7
JYYM_^[A
YP\UQQE
SX8@<VWj(E
E9=(;JEt
JYP5(;J
W=(;J=J;
6T]>9;
$;J=(;J=Ju
(;JE J
W5Jm[3%J
3%SPW
G3CUQVu
WJ;t,@
f;Wt,=
W~A3GW
+FFSSu
FFfuf9
j>V$usj(V
uOj^VuCj|Vu7f9
SVW5t;J3hFJ3
Wj+5t;J
JYY_^[
HuKQS1=dJ
;WEDHJ
?3f;Jf;}
u/%H;J
;JtZf=:
tXAAC~
ij.WUF
x;JSVW}
j E-V>-F
JYYtgf
;tqWSx
h%*JG]
UQQSVu
tDSSVWju
3+U@SVWu
x;JSVEE
3PSVPu
f1rGf9wAEj%PuuE;E
x;JV3Vh@FJE"YY
95h;Ju
PPPPPPPu
x;JSVu
JYY3f;JPP
e3f;JPP2@@t
x;JSV5
3@M_^[
ftSf=
r,Vh0nJW
Wh+JPj
CCfuf;
JYYu S
uN3f;JPU
CC3f;JP
JYYu$PSW
39tS3f;JP
PYtGSYD0
JYYM_^3[
t7=P;J
J9u=9t
95P;Jt$I
J950;J
=L;J5P;J3j!s
UQSVW3j
Wh@FJ0;JZYY
DJ?J3F5P;J5L;J=`;J5<;J5H;J=D;J=@;J=8;J
:E5`;JhwJS
0;JE_^[
U0x;Jf
h;JVW}
EEP+JV
PEPVPzj
EPW3f9>
JYYuEPEPEPEPuV
u]3SuuuJ
<;Jt(}
u1Wu'<;J
3@=<;J
,thPYN
JYYE_^[
3f;JSVu
CC3f;JPW
JYY+f$p
JYYM_^[
SV3fW}
JYY_^[
PPou"PV
vEPEPEPEPuuuV
GYGU<x;JEE
395JWE
N8f9:tq9]
PJWv8j(
Jh;JPJ
J;uV=
J%j*v8
;Jx;Jfe
6f;t8V
JQ3@SP:J3
J_[^]
S@VfEWEPfE=
PZSW6*v
P_[^UVu
g]a33jZ
5 Jlh|
hJ3Y=4J
DJh`^JSh5#
4F)lt(
Sh`^JV
FFup=dJ
]tPPEPa
DJhJPW
4EJGNQ
JJPJJEJbJ#J#JlJJU
f9:t6/
Hv8F<t
PSvYYV
hHJYvDhJvH
h<Jh@J
h(Jh,%JhPJj
v<v8hJ
JlJJJJJ*JoJoJJ
JF88,Jtj
v8F88,t
JWgY9}
hDJWFLYYt
PWYYhBJ
F8,Pv<hlJxv@3
th(JHWWv<
JYMWDA
JYMWDA
?v<Qv8hJE
YY@<QSv<YY3y
3@B=dJ
Rh JPVh@FJNu
SPVh@FJ
X$J4FM0
Wft+f}
f;t"=dJ
QPYYF<f
hJ<|x;JEU
3Cx3|j
PJVJ0C
JY<EPJf'
JAHJ@HD
JA J@
JYYJH HpjLX
|PpPtP3GW
fdu1fHfMt
fmu!fHfCt
PVw_^[]
SSp<-y
Yu3_^[]
AAQhl*Jp<x=dJ
JYYf9;unW
DJVuVhJPYY= J3M_^[4s
x;JSVu
E3W=J3@;
JSv<;8
M_^[]q
USVW3Su
Wh;J(qu*Wh8J
f<XCFF;]
@@SP{f8:
j:hPJf
EPJIo;
JYY<GJ@
WPYYJ@
t+jL_p}#Jt
Pf2f t
JYYL3C
NtQueryInformationProcess
UPSVW3Fj
]twf;Etqf=*
UAHuEf
3B;~7E
f93EEu
E3SuuE
ECCf!4Ch4JS]
S}st;Jf
u;t-} }'M3@#EEt
t@3f9>t
hJ5t;J
F<;tSP
v<Nz;t
:J3^[]
x;JSVu
:JcSSV,ff9
J3Gf9\F
JYVAat
iM_^[~`
hJp< J]
3@^[M__
JYuSh;J_uS
NNcW3;
Vh]Jff
PP{8-u
PH_39^
;Jx;Jfe
QPd_39N@^D]
f;Mtyf;
3M_^[Y
\JE3@3
XJBSVW3
JcSSVc}
JJh;JP
JSZWSWZ
JJh;JP
JSZjpE
3M+fMV
JEPuuj S
JE39}E
3d;JT;J4;J\;JX;Ju
V395l;Ju
p;J;t^W}
JS]EPh
E[_fE^
SVW39M
=\;J_54;J^T;JX;J3[;
X;Jd;J
JT;JYYMP
3SV395d;JWuuuufufu}fufu}fufu}fufu}fufu}fufu}uu
EPSp9u
VVVVVuuWuL
J;YYd;J
ft(PhJ
JULx;Je
ESPYHWE
hJ9}}E
M3MQPMQPu
J@hPJP
JUQS39
:Ju@VWE
JiL[Ks
;JVW3;
;J=$;J=(;J_^
W3PVH}
3w _^[]
39}u&j
u;PMf8\t
SM_^[E
3M_^lE
JYYEWWWWWj
JYYu:E
;Er3u|utul;u
u(Eu$F
x;JS3VWffE3ffu
ffffffff=Jh
DJYYW$B
M_^[@
JRh3JQV
NXN`WNd
[M_^=>
SVWj,A&
JYYPPSVWR
UQ3S@9E
VWErC5
hL`JS
YYt3hJS
YYt%hlJS
hJp< J]
H7PPV^O
hPhat+VP
:JPPf
PHu@3G;
Fx;JSVW}
33SFWER
JSSSYP
WQPPS5J
}OM_^[]4
SVWtHu
J395T;J~
d;J4G;=T;JY|5d;JY5d;J;
3^3iuhdJj
Ju.EPj
fEfJf9
3@j EP?
+hJ9}Sh4#
3Y3@gUQQE
UQSV38
G<]tcj/P0;tU3fF
V|0;u9]t$SSj
J3_^[
[t:f>f'
fhtcfHt]fmtW
j EPPPSrP
dJW]tcj/P\.;tU3fG
W0.;u9]t$SSj
J3_^[
x;JSVu
u35J5JPPSp=P
JujSSPPSvpP
VPJPPS5J-pP
5JPhJv
3AFFf9
f;Jf9E
}U3f;JVu
hJu=<;J
g=<;J\UE
UjhxJhJd
t8x;JESVWeE
DHLPTX\lf
J3GSP@f
JYYSV'5
P=Ph]J=P
=PYY=9
J;t_PVj
nJJUQSVu
JYu69E
;Ju3;]
@@}PPWd;
th4J}PYY
hJ}PYY
shJ}PYY
hJ}PYY
hJ}PYY
hJ}PYY
hJ}PYY
hJ}PYY
fEYEPfE:
JYY3_#j<hJ$x;JEE
Q3Sp<"&u8
dJt!V(;v
Vl J;u
JMu !
ZJSVWj
JFFF3f
f>0u!Jt
8+FFN0
PP O5
Jj\P;YY
PYYPVV
JYY_^]
x;JVW}
PPj7P2
W3f9>EE
WWv<&SPuuV
3=3^9E
f\t)f:
x;JSVu
JfD_f=:
JYYChL`JP
x;JS3WxffE3ffM
ffffffffJxPQ
EEPEPj
;Jx;Jfe
39O@_D]
q3M_^[
u)j?v8
t#SP`YY3@3h9
Q+`YY3@<
F8SPV;
U\x;JSVu
W33Cj E}=
2SuV+Eu;
;JEM_^[S
R3@kUS]
Vs<>6W
Wt;Jf
t;Jf8(uv
v8~f=@
W3Wv<,
F<@@PhJWYY_3^]
UQS39]
% J.UW}
WYY^_]
t;JtPW
_^^SVW5t;J3hFJ3
j)5t;J_
5t;Jh<J
5t;JhDJ
;5t;JhLJ
t;Jf8%
FD3fFDPh;J
I5t;JF8PPhXJ]
5t;JF8PP
h,JF<;
JYYj)p
t;Jf8)
5t;JWW'/
^SVW5t;J3hFJ3
j*5t;J}
5t;Jh`J
USVW3S
5t;JhBJ
dJt65t;JhAJ
5t;JhAJ
W3j0E=
JYYPYD
JYYPYD
"3M_^[p
x;JVEE
PVPVVVP
E E$SE(Vu
^ ^$^(^,
JYO0DA
JWtpSY39E
WYY3_^[]
UlW39=J}
u(u$u u
ffVWE3M
ff5JffffffffPQ
WEP3Wj
;Jx;Jfe
x;JSVu
3M_^[f
a<;Ja}
_3@z^7
X3hJWDhJMD
u 5`;JhwJ]Pj
WVS3D$
;JQPFF3f
3f;JPVu%J
u!VJ0p
JShJ@Yy=
t"gjnghl#
BYYggJH
WPHL;YY
;J0tS+
FFf>FFCC
F<3f98
F<Gf<x
A3Y@Y J
FFeSEPj
v@gv<_u
JfSht#
?YY33@wWe
J>YY3@
SSSSVhPJS5J
t$SSSShPJS5J
SPJ+SFSFSVP9t
JP3FVh#
J+M+kd
lcP5Jj
3@c3@cf='
E+PVS]
JE+f$C
u)CCS]Ef8"u
f0EHH;
f8 t3PPj
J3PPPW
J9uu8]
;JE4e]
@@BBf^u
YYu&Sj
3qcPh#
9YY3@\c
;J3C{FL;u
JWWWPE;
u3FVh#
oWPuu;t;E}uTf8\t
JYYWWv<PuuVum
;JWht#
0KJ)J,
0KJ)Jq,h
JSYY,h)JSYY,h)JSYY,h)JSYY,h)JSYY,h)JSYY,h)JSYY,h)JSYY,h
-h)JSYY
IJ| JJrj
YPllPq
C50KJP
JPhSc}
=J }3j@5J
SPKJPWPVhJj 5J
J 3g5JhJ2YuP5J
uIj_t#5JW
Jh]JW5J5JWYYW
JY3QPo
h@KJP`KJPQP
JYY!39
f!Ez=<J
RQh`KJPhHJEj P
SPJF<f9
u"Sh7#
<YYSSj
hJ0YSv<Po
u"Sh8#
d<YYSSj
SOhJf0Yjw<
JhTJ@hJP
hhJp<3f9
0Y3Y@mBmPCo
.mBAAf9;t;
\PWSht#
Sh0nJWut
DJVSSj
JYYu?~
E5J JE
K,@Ru+j
Q[-YYZdj
V+YY3A9GGf
W9\9Vh
_83@Y83R8h
*Y3Y@{j
*Y3Y@{h*#
$PhJ&YY5=
HEf8.u
g53<3F-i5hwJ?Pj
953@295J
hxAJp;t6SQh
LHJu=9u=SPVWj
Pt PPYD
J@hPJP
PVYYf>:uj
PVYYf>:u)j
PVYYf>:u"j
*95JYYusVh#
tT95JuLVh#
*95JYYu7Vh#
*95JYYu"Vh#
x*95JYYu
Vhl*JW4
JE3f;JYYPS1MLK;t
JYYVSW6
V3VSHHt
Xst2Ht#
HHuwD;f
JYYt.f&
u 9tPj
WetGPPh
t1Jf;t'JQt
tT`PPuW
WVS`P%4Ff
FWFVS`P4F
FFVSPSH
YY>PYY5<f=
YYjh@FJ
x$J4$Jf
{C+PQ5$J
`#YY;]EPEj
;EEf<EJ
fk50Jh|HJ
JYYF<t
JYYF8~<f$X
EPVEPj
PW;WtG>6h
Y3P}EPV
hHJ>F8~<
eJSh)'
VLSFS@Sh)'
YY3+Pj
YY3C3,N
;Jv i}H
J ;JWp
;J@ ;J|Wj
;Jp$ ;JF ~$5 ;J5
JCPVu4|=
HF$|SWj
CC;r;t?j
EP+VWj
CC;]r;t9VL|
EP+VWj
Jt;9uu6u
xh`^JP
zf?" t
GG;}r;t;j
+MQWPj
Jtr9}umEE
GG};}r;t>V
;WN_^]
MHJ%3@
5t;J5DJh0RJ
t;Jf<AC
]]PF<]=dJ
hSJ5t;J
uhSJ5t;J
YhSJ5t;J
=hSJ5t;J
!hSJ5t;J
AGgt;Jf
JYYj*D;
Y3Y@P\S
f:j\^j
f;twf;t
t]Kf;t
f;uf;u9f
3EPPPEP
Jt!Ut
;JfDfEf
PPUPDW}
ftXf=
JYYXX"Su
&  j:W
J$=<;J
3jna=<;J
5P;JPSRt
395P;Jt,=<;J
eP;J3;t
=<;JPPSs
PhyJPs
JPPPYP
J3PPPYP
tX9uJ9t
!3GPWh'
3VWPWw
u<958;Ju
u<=<;J
3950;Jt<u-PPl
PeC |3~]
PurIHf
u&=@;J
@EFHJy
VgPDSh*#
zY3Y@}D
mVWh]#
j EPjEPj
JEPSVj
B;UrPSVj
JT J;E
EPEPRp
J;r+E
JE<U3E}
@ Hu3B
Y202*u
395JuAVu
YYt-};t
YY95Jt
ffEff;Jfh
JPEPuP
vREh`tJP
JYYRuj
EPhJYY/SEhJEYTN
3Y@|3CEPP
JYYt;v
YYWW>Ht
rf;JfEfF
qf;JfEfF
JP9YYCPP
JP)YYP
31Sh*#
JYYh(#
UWP+YY
YYGGdj
Y+tS+t4
2Bd :du
];3f;JPW)u[f?.
JhL`JS
;PSYY
6YY3@zUPPYYPw
u(Thl*JP
T6F`PvXPo
Tv\6Pro
THt?Ht"
~T6@vTu
YY9_f;JfEfG
Jr|PPq5
{OShw#
{YYiOf|OP
SDC,P6KIJ
JtPPPPPj
hhJ)PGhl
S,S6GI
K,SQPg`
CG]C;]]r[39
3@FS5Jj
JJcPPj
@fEabb@b
}PPWe;
bPWhb#
ahJ}PYY
PYYh88J
J}PWhu#
PYYtahHJu;u
J(tof9tfP=
s#h]J}P
J`3aSS
BB8Zu8
3P[f8.
JYYtPj0y
joqjoXeQP^<
jo3Fdht#
J@}3@3@^Aot
1HX;J1@
JY0u9}u
Null environment
JvDNt@Nt4Nt(Nt
USV5JW3;
@<;t'WP
@@f/uUf
f0rLf9sF
:8x,x(uF
3;t8f9
3Y@Y J
NDNl3_^[]
JPZhJ+Y3
ub3!5Jj
JY33f97t
@@fuf90u+D
CCFFf9
uCCFFf9
VYYV'FFhL`JVYYP
trPXFFPVhl
M_^[Iz
JS3+VWt
JYYtzVC
U x;JM
PEP"xuW}
ftfPEPwt-f
f3@M_^['w
x;JSVu
f`KJfE:
fEh@KJEP
J;YYt.f9
PhJYYEPEP
JEh48JP
EPPyf9
J;EPVPu
JPYY3@M_^[
JhTJ@hJP
}9}vL9=Ju?E9Er.u
4Cf>f&
YY3E\C
JhTJ@hJP
APerformUnaryOperation: '%c'
zt]%t>Ht0
T<tUHtGHt* t
APerformArithmeticOperation: '%c'
YYuWSpJS
JYYt<E
,EPEPE
3F_^[]
UHx;Je
JEEj P
JEPSot
JEMEf>_^[&m
F<W3;t
u*j;v<llt
Jhl*JP*j
h48Jv<
JPQn,9}
JRatPVhJ
pPh$FJ$nP
mpPh$FJ
x;JSVu
uj"V;YYt
FFf>"u
f;uj"V;YYt
v"Mf8 s
;t.fEh
YY3@M_^[0i
P2ftIf=t4ShPJ
JYYt1E
u0uu)u
S3;VWtvf9
E]]uEPm}9]u
HY3Y@_^[
VWjuS5J
E_tuVUe
j X;wC
IIt/It,IIt$
;w1tx+tqIt
+t@3t4
Jugf.uMPPPS
uo3k3@hj
Pyj W~ht
3;twf9>trV
JE;uG}WWWh
x;JSVW}
Jugf!uPPPj
f?.u$j{^Wj
M_^[g^
VWvj We;t
f0WhlJh
PPPVhl*J
ShlJEh
;ttf9>to
FFf9>uf
WWWPf>
;tIf9>tDV
JM_^[[
UQQSEPhJh
hhJp<O`f9u
f8=YEu_WV[5
WF[PWYY
3t W2[t
W([PWYY
UQQSEPhJh
hhJp<1_f9u
f8=YEu_W8Z5
W(ZPWYY
PWuX_3F9u
x;JSVW3Vh@FJE
VVp<]f93
XPYYW}Xt
WsXPWYY8
t!QPYY
;JQPgW
YEPmj ;XQq
ts3f;JPP]
QPYYPP
UDx;JVEj EPj"}
VmYEPj
VMYM% J
x;JEhJVu
WElJ3f9>Eu
JYWWWWPh
J;u+hJ
Ph`JPj
Ph`JPj
3@M_^R
Jp< J]
VW3VVp<:Wf97u!95JVt
JShBJpT3JSW
YY[_3^]
v TYY^3]
YYjh@FJ
WYf|G t
JYY_^[]
uaj!EPVj
JEY<_]Y4F0=J
Vr4W{4E
JYYE9F
C4;{4u
R/x_^[
Vp4W3;f}tSS]
EPSNf~
JWPS(Wv
Ht^HuR}
:uRv4j
|3_^[]
H9uv4}
|iUSVu
3CSv8WlF<86u
JWOWv<tWv@k~H
SvDW)WvH
3CShBJW
ShLJWFLt
SPWShBJ
JWF8S,PWsWv@
3C,|d-~X.tL/t@0t41t
9uFShPJu
JtHFD;u
v<_^3[]
h@FJZTYYt
UV3zt!U
UQSVW3u
Utx;JV5
j EPjEPj
3@M_^C
h|JY`EfEfEfEfEfEfEWfE3EPf}uEWPSf}f}fE
Jf}f}ujP
p<5IIt
P/YY3]
v<O5HH
Hubv<=X38P
fuVWf8
Vp4t=h
uhJ>^]
hJ/t;Jf
j hJOYYu
YYSv<Sv@~~H
j hJzOYYuvDh8JhvHOF8H,Qv<Ph JNv@
5~j6uRv8h8J
HuhSVh(J
SVh0%JvSVh
JjSVh(Ja7t
9u7SVhPJN6v8hJ
YYV6%6hJ
SVh,%J
SVWt#j
3_^[]4
x;JVW}
VPPnDu/VWP\Du
3M_^{<
SVW3Vj
t#EPEPF
3uU3Vj
J3_^[]
UQQ<;J
CCjnQ@j
S?_^[]
x;JSVu
0;Jt7j
PVB3G;
PVPW/9
0;Jt=Ou.PP
PhJfYYP^
trSP=0;J
!=3M_^[3
=3@<<jn9j
SR<WN<Njn9
<SwNlNj
J3PPh]Jh+#
PP7hJP
EPj)0{(=#
EPj*=#
P*YYM3/1
x;JVQQEE
Jt#;sf
UQx;JEE
u3_^[]
W8j.0V06
P @$Vq ;
tAHt3HHt$
j P+D5
j.Sk3+
33f}Pt
t0_t'3fG
VQPPPh
JWuQVPj
P#Ph`^JWXu%PPD
J3M_^)
JYPWVu
VM_^^)
t0Pf;w@F
r_^f[]
JYY3WWWWPh
WPxuY3Y@
ff9t PPj
V$_M^S'
x;JSVEE
Wh KJ$
WS-/N0N0
t(9,t ,,
4Fh KJV
,Wh KJV
Yt83;w2r
9(s(;$r
A3A;wr
JYY$YM_^[%
tVwF F
PW,Ph`^JWJ
W>M_^+%
t.u*F' t$J
@PWUF F
PWPh`^JWO[M_^
JYYPIt
Wffffff
E(Ex;J tHJ$j
QRPh J
ADVAPI32.dll
ZSHELL32.dll
MPR.dll
SaferRecordEventLogEntry
ImpersonateLoggedOnUser
SaferCloseLevel
SaferComputeTokenFromLevel
SaferIdentifyLevel
RevertToSelf
RegQueryValueW
RegEnumKeyW
RegDeleteKeyW
RegSetValueW
RegCloseKey
RegQueryValueExW
RegOpenKeyW
RegSetValueExW
RegCreateKeyExW
CreateProcessAsUserW
RegOpenKeyExW
FreeSid
LookupAccountSidW
GetSecurityDescriptorOwner
GetFileSecurityW
ShellExecuteExW
SHChangeNotify
WNetCancelConnection2W
WNetGetConnectionW
WNetAddConnection2W
msvcrt.dll
KERNEL32.dll
USER32.dll
__p__fmode
__p__commode
_adjust_fdiv
__setusermatherr
_initterm
__getmainargs
__initenv
_cexit
_XcptFilter
_c_exit
calloc
_wcslwr
_vsnwprintf
wcsstr
_open_osfhandle
_close
swscanf
_ultoa
_seh_longjmp_unwind
_setmode
wcsncmp
iswxdigit
fflush
__set_app_type
wcsrchr
malloc
wcstoul
_errno
iswalpha
printf
swprintf
fprintf
towlower
realloc
setlocale
_snwprintf
wcscat
_wcsupr
wcsncpy
_wpopen
_pclose
memmove
wcschr
iswspace
longjmp
wcscmp
_wcsnicmp
_wcsicmp
wcstol
iswdigit
_getch
_get_osfhandle
_controlfp
_setjmp3
_except_handler3
wcscpy
wcslen
wcsspn
towupper
FlushConsoleInputBuffer
LoadLibraryA
InterlockedExchange
FreeLibrary
LocalAlloc
GetVDMCurrentDirectories
CmdBatNotification
GetModuleHandleA
SetUnhandledExceptionFilter
UnhandledExceptionFilter
GetCurrentProcess
GetSystemTimeAsFileTime
GetCurrentProcessId
GetTickCount
QueryPerformanceCounter
GetThreadLocale
GetDiskFreeSpaceExW
CompareFileTime
RemoveDirectoryW
GetCurrentDirectoryW
SetCurrentDirectoryW
TerminateProcess
WaitForSingleObject
GetExitCodeProcess
CopyFileW
SetFileAttributesW
DeleteFileW
SetFileTime
CreateDirectoryW
FillConsoleOutputAttribute
SetConsoleTextAttribute
ScrollConsoleScreenBufferW
FormatMessageW
DuplicateHandle
FlushFileBuffers
HeapReAlloc
HeapSize
GetFileAttributesExW
LocalFree
GetDriveTypeW
InitializeCriticalSection
SetConsoleCtrlHandler
GetWindowsDirectoryW
GetConsoleTitleW
GetModuleFileNameW
GetVersion
EnterCriticalSection
LeaveCriticalSection
ExpandEnvironmentStringsW
SearchPathW
WriteFile
GetVolumeInformationW
SetLastError
MoveFileW
SetConsoleTitleW
MoveFileExW
GetBinaryTypeW
GetFileAttributesW
GetCurrentThreadId
CreateProcessW
LoadLibraryW
ReadProcessMemory
SetErrorMode
GetConsoleMode
SetConsoleMode
VirtualAlloc
VirtualFree
SetEnvironmentVariableW
GetEnvironmentVariableW
GetCommandLineW
GetEnvironmentStringsW
GetLocalTime
GetTimeFormatW
FileTimeToLocalFileTime
GetDateFormatW
GetLastError
CloseHandle
SetThreadLocale
GetProcAddress
GetModuleHandleW
SetFilePointer
lstrcmpW
lstrcmpiW
HeapAlloc
GetProcessHeap
HeapFree
MultiByteToWideChar
ReadFile
WriteConsoleW
FillConsoleOutputCharacterW
SetConsoleCursorPosition
ReadConsoleW
GetConsoleScreenBufferInfo
GetStdHandle
GetFileType
VirtualQuery
RaiseException
GetCPInfo
GetConsoleOutputCP
WideCharToMultiByte
GetFileSize
CreateFileW
FindClose
FindNextFileW
FindFirstFileW
GetFullPathNameW
GetUserDefaultLCID
GetLocaleInfoW
SetLocalTime
SystemTimeToFileTime
GetSystemTime
FileTimeToSystemTime
GetUserObjectInformationW
GetThreadDesktop
MessageBeep
GetProcessWindowStation
cmd.pdb
JJaJaJaJJJJJJ4WJ?MJNMJ
J'JOJ6JEJTJcJ
CMD Internal Error %s
wwwwwwwwwwwwwwww
wwwwwwww
T3333333333333333333333333333333333333333B7501'22222222222222222222222222222222222222'46A(
))))):::::::::::::::::::::::::::::::;+
8!RhyvegggggggggggggggggggggggffwL
=C]xz|}}}}}}}}}}}}}}}}}}}}}}{z~
$WjkkkkkkkkkkkkkkkkkkkkkkkklrtpmnsqocdO9
SPQ^[KIIIIIIIIIIIIIIIIIIIIIIIIJEDHJZDFGYa`_XV/
&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&&
22222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222.............................22
000000000000000000000000000
111111111111111111111111111
111111111111111111111111111
111111111111111111111111111
111111111111111111111111111
111111111111111111111111111
111111111111111111111111111
111111111111111111111111111
111/---/11-111-1-------1111
111-/1/-11111/-111111111111
111-111111111-/111111111111
111-111111-1/-1111111111111
111-/1/-1111-/1111111111111
111/---/1111-11111111111111
111111111111111111111111111
111111111111111111111111111
111111111111111111111111111
111111111111111111111111111
.2"***************************
.2!$$$$$$$$$$$$$$$$$$'#)(#)
&.2222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222222
*****************'''''''''''''''
)))))))))))))
)))))))))))))
)(&&())))(&))
)&((&)&))&())
)&))))))(&)))
)&((&)&)&()))
)(&&()))&))))
)))))))))))))
' $""""""""!#!%
*********************************11
pH\=oE/tG1uH1uI1uI1uI1uI1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1uJ1sJ1qI2U.NU+
!,tA*NW+
@@@PPP
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
``````
@@@000
@@@000
h[uiKzkL|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mN|mMzhDyf@{iG{lKzjIyf@ygD}jHnFn<o:pDd4I
}|||||||||||||||||||||||||~
k4qDRh@nslS
M4h@xMwwozsHS
t/FOKKKKKKKKKKKKKKKKKKKKKKKKNZ^VOR]ZTUq
szIg7Q'\/
H{D{D{D{D{D{D{D{D{D{D{D{D{D{D{D{D{D{D{D{D{D{D{D{D{Ct:r7v=zBy?r7s:x={;
;w2Z#Q!F
P#NNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNNO"H
"U&$R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##R##T&$N
O!M!M M M M M M M M M M M M M M M M M M M M M M M M M M M B#
c---------------------------------------------------------------------------------L!E$
HHHHHH
HHHHHH
;wwwwwwwwwwwwwwwwwwwwwwwwwwwJ
?yMSswj?
?iMMmh14
Zh9X.I(
P!O!O!O!O!O!O!O!O!O!O!O!O!O!O!O!O!O!O!O!O!O!O!O!O!i:
O3U5 Z8#Z8#Z8#Z8#Z8#Z8#Z8#Z8#Z8#Z8#Z8#X8$t>L'
HHHHHH
HHHHHH
HHHHHH
HHHHHH
uDpZ1v]3v]3v]3v]3v]3v]3v]3v]3v_9v_8v_9l^AP*L%
[O_\9H
i.k1j0j0j0j0j0j0j0o6n5p7k;I
BagarBubba
DVCLAL
PACKAGEINFO
DVCLAL
PACKAGEINFO
rePlace
Revoke
Continue
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Control ACLs Program
FileVersion
5.1.2600.0 (XPClient.010817-1148)
InternalName
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
CACLS.EXE
ProductName
Microsoft
Windows
Operating System
ProductVersion
5.1.2600.0
VarFileInfo
Translation
Displays or modifies access control lists (ACLs) of files
CACLS filename [/T] [/E] [/C] [/G user:perm] [/R user [...]]
[/P user:perm [...]] [/D user [...]]
filename Displays ACLs.
/T Changes ACLs of specified files in
the current directory and all subdirectories.
/E Edit ACL instead of replacing it.
/C Continue on access denied errors.
/G user:perm Grant specified user access rights.
Perm can be: R Read
W Write
C Change (write)
F Full control
/R user
Revoke specified user's access rights (only valid with /E).
/P user:perm Replace specified user's access rights.
Perm can be: N None
R Read
W Write
C Change (write)
F Full control
/D user Deny specified user access.
Wildcards can be used to specify more that one file in a command.
You can specify more than one user in a command.
Abbreviations:
CI - Container Inherit.
The ACE will be inherited by directories.
OI - Object Inherit.
The ACE will be inherited by files.
IO - Inherit Only.
The ACE does not apply to the current file/directory.
ACCESS_DENIED: %0
Are you sure (Y/N)?%0
processed dir: %0
processed file: %0
<User Name not found>%0
<Account Domain not found>%0
(OI)%0
(CI)%0
(NP)%0
(IO)%0
(DENY)%0
(special access:)
SHARING_VIOLATION%0
Invalid arguments.%0
The Cacls command can be run only on disk drives that use the NTFS file system.%0
/backup
/restore
/register
%systemroot%\repair\asr.err
SOFTWARE\Microsoft\Windows NT\CurrentVersion\Asr\Commands
ASR protected file utility
/context=%lu
%systemroot%\system32\smss.TMP
%systemroot%\system32\ntdll.TMP
%systemroot%\repair\smss.ASR
%systemroot%\repair\ntdll.ASR
%systemroot%\system32\smss.exe
%systemroot%\system32\ntdll.dll
[COMMANDS]
1,4990,1,"%SystemRoot%\system32\asr_pfu.exe","/restore"
Wsyssetup.dll
SeRestorePrivilege
SeBackupPrivilege
%ws %ws
(null)
((((( H
h(((( H
H
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Automated System Recovery Protected Files Utility
FileVersion
5.1.2600.5512 (xpsp.080413-2111)
InternalName
asr_pfu.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
asr_pfu.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
5.1.2600.5512
VarFileInfo
Translation
ProductType
ServerNT
LANMANNT
System\CurrentControlSet\Control\ProductOptions
Software\Microsoft\Windows\CurrentVersion\Telephony\Providers
Software\Microsoft\Windows\CurrentVersion\Telephony
ProviderID
NumProviders
NextProviderID
ProviderFilename
RemoteSP.TSP
Provider
Server
NumServers
ConnectionOrientedOnly
NoDSQuery
TapisrvProviderListMutex
;Must be an administrator to run this program - setup failedOThis machine is not running Windows NT Server.
It cannot be a Telephony Server
RegOpenKey failed
RegSetValueEx failed
OpenThreadToken failed
GetTokenInformation failedAllocateAndInitializeSid failed3User account does not have administrator privileges
OpenSCManager failed
&Telephony Server successfully disabled TAPI Server successfully set up.>This machine is not currently a client - cannot disable client!TAPI Client successfully disabled TAPI Client successfully set up.
Windows NT Server
RegOpenKey
RegSetValueEx
OpenThreadToken
GetTokenInformation
AllocateAndInitializeSid
OpenSCManager
TAPI
TAPI
TAPI
TAPI Administration Setup
ChangeServerConfig failed
Usage is:
SCLIENT SETUP
TCMSETUP [/R] [/Q] [/X] /C remoteservername [remoteservername2 ...]?
remoteservername is the machine name of the telephony server_
/R - disable automatic server discovery, only servers specified in this command will be usedA
/Q - will cause message boxes to not be displayed during setupV
/X - connection-oriented callbacks (default is connectionless), for lossy networks '
CLIENT DISABLE
TCMSETUP [/Q] /C /D
Telephony Client Setup Help8A failure occurred while disabling the Telephony Server.9A failure occurred while setting up the Telephony Server.
ChangeServerConfig
SCLIENT SETUP
TCMSETUP [/R] [/Q] [/X] /C remoteservername [remoteservername2 ...]
remoteservername
/X - connection-oriented callbacks (default is connectionless), for lossy networks '
CLIENT DISABLE
TCMSETUP [/Q] /C /D
-A failure occurred while disabling the client.A failure occurred while setting up the clientiA password is required for the administrator account (since "/N" as not specified), but none was supplied-The name of the 'mapper.dll' was not supplied1You are not logged in on an Administrator account`OpenPolicy system call failed - verify the specified administrator account is correct and existsiSetPrivilege on account failed - verify security of logged on account and specified administrator accountZWriting values to the registry failed - verify security of logged on account and try again_OpenService failed - verify that Telephony Service exists (in the Control Panel\Services applet
CreateMutex failed
mapper.dll
(OpenPolicy
SetPrivilege
(OpenService
CreateMutex
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Microsoft
Windows(TM) Telephony Administration Setup
FileVersion
5.1.2600.0 (xpclient.010817-1148)
InternalName
tcmsetup
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
TCMSETUP.EXE
ProductName
Microsoft
Windows
Operating System
ProductVersion
5.1.2600.0
VarFileInfo
Translation
VS_VERSION_INFO
StringFileInfo
080404B0
CompanyName
Microsoft Corporation
FileDescription
Microsoft(R) Windows(TM) Telephony Administration Setup
FileVersion
5.1.2600.0 (xpclient.010817-1148)
InternalName
tcmsetup
LegalCopyright
(C) Microsoft Corporation. All rights reserved.
OriginalFilename
TCMSETUP.EXE
ProductName
Microsoft(R) Windows(R) Operating System
ProductVersion
5.1.2600.0
VarFileInfo
Translation
SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Microsoft (R) WinHTTP Default Proxy Configuration Tool
Copyright (c) Microsoft Corporation. All rights reserved.
usage:
proxycfg -? : to view help information
proxycfg : to view current WinHTTP proxy settings
proxycfg [-d] [-p <server-name> [<bypass-list>]]
-d : set direct access
-p : set proxy server(s), and optional bypass list
proxycfg -u : import proxy settings from current user's
Microsoft Internet Explorer manual settings (in HKCU)
Migration failed with error. (%1!d!) %2
Updated proxy settings
Error writing proxy settings. (%1!d!) %2
Error reading proxy settings. (%1!d!) %2
Current WinHTTP proxy settings under:
HKEY_LOCAL_MACHINE\
%1\
WinHttpSettings :
Direct access (no proxy server).
Proxy Server(s) : %1
Error: Proxy access type is WINHTTP_ACCESS_TYPE_NAMED_PROXY, but no proxy server is specified.
Bypass List : %1
Bypass List : (none)
Error: Unknown proxy access type set.
Migration requires Microsoft Internet Explorer version 5.01
Microsoft (R) WinHTTP Default Proxy Configuration Tool
(C) Microsoft Corporation.
proxycfg -? :
proxycfg :
WinHTTP
proxycfg [-d] [-p <server-name> [<bypass-list>]]
-d :
-p :
proxycfg -u :
Microsoft Internet Explorer
HKCU
(%1!d!) %2
(%1!d!) %2
(%1!d!) %2
WinHTTP
HKEY_LOCAL_MACHINE\
%1\
WinHttpSettings :
: %1
WINHTTP_ACCESS_TYPE_NAMED_PROXY
: %1
: (
y Microsoft Internet Explorer 5.01
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Proxy Config Tool for Windows HTTP Services
FileVersion
5.1.2600.5512 (xpsp.080413-2105)
InternalName
proxycfg.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
proxycfg.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
5.1.2600.5512
VarFileInfo
Translation
VS_VERSION_INFO
StringFileInfo
080404B0
CompanyName
Microsoft Corporation
FileDescription
Proxy Config Tool for Windows HTTP Services
FileVersion
5.1.2600.5512 (xpsp.080413-2105)
InternalName
proxycfg.exe
LegalCopyright
? Microsoft Corporation. All rights reserved.
OriginalFilename
proxycfg.exe
ProductName
Microsoft? Windows? Operating System
ProductVersion
5.1.2600.5512
VarFileInfo
Translation
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Registry Editor Utility
FileVersion
5.1.2600.0 (xpclient.010817-1148)
InternalName
regedt32.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
regedt32.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
5.1.2600.0
VarFileInfo
Translation
SystemPartition
SYSTEM\Setup
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Mount Volume Utility
FileVersion
5.1.2600.0 (xpclient.010817-1148)
InternalName
mountvol
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
MOUNTVOL.EXE
ProductName
Microsoft
Windows
Operating System
ProductVersion
5.1.2600.0
VarFileInfo
Translation
Creates, deletes, or lists a volume mount point.
MOUNTVOL [drive:]path VolumeName
MOUNTVOL [drive:]path /D
MOUNTVOL [drive:]path /L
MOUNTVOL drive: /S
path Specifies the existing NTFS directory where the mount
point will reside.
VolumeName Specifies the volume name that is the target of the mount
point.
/D Removes the volume mount point from the specified directory.
/L Lists the mounted volume name for the specified directory.
/S Mount the EFI System Partition on the given drive.
Possible values for VolumeName along with current mount points are:
%1
%1
*** NO MOUNT POINTS ***
The EFI System Partition is mounted at %1
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
TCPIP Finger Command
FileVersion
5.1.2600.0 (xpclient.010817-1148)
InternalName
finger.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
finger.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
5.1.2600.0
VarFileInfo
Translation
%1:TLOOK returned %2!d!%0
%1:TLI Error %2!d!
poll failed%0
Timeout occurred
t_look returned %1!d!
The network is down
Not super user
GATE Table alloc error%0
GATE Table read error%0
Smart Gateway: %1%0
Network Address Gateway Address Redirect Life
%1!d! mins%0
%1!ld! mins%0
Unable to alloc conn block
Server port %1!d! in use!
Unable to allocate packet
%1 packet, foreign host %2, foreign port %3!d!:
Contents in hex bytes and characters:
Unable to open connection
Unable to fork daemon
Received bad packet. Length = %1!d!
Received bad opcode. Opcode = %1!d!
Error on server : %1
Received packet with unexpected block number. Block number = %1!d!
Received bad initial opcode. Opcode = %1!d!
Bad transfer mode '%1' specified
Unknown host: %1
Displays information about a user on a specified system running the
Finger service. Output varies based on the remote system.
FINGER [-l] [user]@host [...]
-l Displays information in long list format.
user Specifies the user you want information about. Omit the user
parameter to display information about all users on the
specifed host.
@host Specifies the server on the remote system whose users you
want information about.
tcp/finger: unknown service.
The network is down.
Finger: socket:%0.
Finger: bind:%0.
Finger: connect:%0.
Finger: read:%0.
Finger: send:%0.
Finger: WSAStartup:%0.
%8X%4X%4X%2X%2X%2X%2X%2X%2X%2X%2X
LIBRARY
CHANGER
STORAGESLOT
IEDOOR
IEPORT
PHYSICAL_MEDIA
MEDIA_POOL
PARTITION
LOGICAL_MEDIA
MEDIA_TYPE
DRIVE_TYPE
LIBREQUEST
RSM Command
Memory allocation failed
Memory allocation failed
Memory allocation failed
Memory allocation failed
Memory allocation failed
Memory allocation failed
Memory allocation failed
Memory allocation failed
Memory allocation failed
Memory allocation failed
Memory allocation failed
Memory allocation failed
errunavail
offline
normal
lowest
highest
infinite
deferred
guiddisplay
Memory allocation failed
Memory allocation failed
%08lX%04X%04X%02X%02X%02X%02X%02X%02X%02X%02X
%08lX%04X%04X%02X%02X%02X%02X%02X%02X%02X%02X
\\.\CdChanger
%08lX%04X%04X%02X%02X%02X%02X%02X%02X%02X%02X
existing
always
Bad library type?
default
infinite
errunavail
%08lX%04X%04X%02X%02X%02X%02X%02X%02X%02X%02X
Memory allocation failed
allocate
deallocate
dismount
ejectatapi
createpool
deletepool
refresh
inventory
VS_VERSION_INFO
StringFileInfo
040904b0
Comments
CompanyName
Microsoft Corp
FileDescription
Removable Storage Manager Command Line Interface
FileVersion
5, 0, 2074, 0
InternalName
RSM.EXE
LegalCopyright
Copyright
LegalTrademarks
OriginalFilename
RSM.EXE
PrivateBuild
ProductName
Microsoft(R) Windows (R) 2000 Operating System
ProductVersion
5.0.2074.0
SpecialBuild
VarFileInfo
Translation
The syntax of this command is:#The command completed successfully.
Unable to process command.
RSM HELP command
Commands available are:
RSM ALLOCATE
RSM DEALLOCATE
RSM DELETEMEDIA
RSM DISMOUNT
RSM MOUNT
RSM VIEW
The following conventions are used to indicate command syntax:
Capital letters represent words that must be typed as shown. Lower-
case letters represent names of items that may vary, such as filenames.
The [ and ] characters surround optional items that can be supplied
with the command.
The { and } characters surround lists of items. You must supply one
of the items with the command.
The | character separates items in a list. Only one of the items can
be supplied with the command.
For example, in the following syntax, you must type RSM COMMAND and
either SWITCH1 or SWITCH2. Supplying a name is optional.
RSM COMMAND [name] {SWITCH1 | SWITCH2}
When typed at the command prompt, service names of two words or
more must be enclosed in quotation marks.
For example, RSM MOUNT /N"MY MEDIA" mounts the media named "my media".
Additional arguments required.
Unable to view drive information.
No objects were found..
Unable to view information for all objects.
Unable to retrieve value.
RSM [ALLOCATE | DEALLOCATE | MOUNT | DISMOUNT | EJECT | EJECTATAPI |
CREATEPOOL | DELETEPOOL | VIEW | REFRESH | INVENTORY]
The command line is case insensitive, except when you refer to Media
Objects (including media, drives, changers, libraries, media types, slots)
by their friendly names.
The arguments for a command may be specified in any order.
All commands return an error code - success, a system defined error
code or one of the application defined error codes shown below:
536870913: Invalid Arguments
536870914: Duplicate Arguments
536870915: No Guid For Friendly Name
536870916: Insufficient Arguments
536870917: Invalid Guid
536870918: Ioctl Failed
There should be no spaces between a tag and the actual argument. For
example, for the timeout option in allocate, the timeout is specified
as /t50 and not /t 50.
See Start->Help (search for "Using the command line for Removable
Storage") for more details.
Creates a media pool.
RSM CREATEPOOL
/M<MediaPoolName>
[/T[G|F]<MediaPoolTypeID>]
/A[EXISTING|ALWAYS|NEW]
Name of the Media Pool to be created.
The /TG option should be used when the MediaPoolTypeID is supplied
as a GUID.
The /TF option should be used when the MediaPoolTypeID is supplied
as a friendly name.
/A actions:
One of the following must be specified.
EXISTING:
Open existing media pool.
ALWAYS:
Open existing media pool or create new one.
Create new media pool. Returns error if one already
exists.
Media pool can draw media from free pool.
Media pool can return media to free pool.
Ejects a specified piece of media from the port of the current library.
RSM EJECT
/P[G|F]<PhysicalMediaID> | [/S[G|F]<SlotID> /L[G|F]<LibraryID>] |
[/D[G|F]<DriveID> /L[G|F]<LibraryID>]
[/A[START | STOP | QUEUE]]
[/O<EjectOperation>]
The /[P|S|C|D]G option should be used when the PhysicalMediaID, SlotID,
LibraryID or DriveID is supplied as a GUID.
The /[P|S|C|D]F option should be used when the PhysicalMediaID, SlotID,
LibraryID or DriveID is supplied as a friendly name.
The location (through {SlotID and LibraryID} or {DriveID and LibraryID})
of the physical media can also be specified instead of providing the
physical media ID.
Eject media from an atapi changer.
RSM EJECTATAPI
/N<AtapiChangerNumber>
/N: This is the number found at the end of the string which is the
device name of this changer - for example, \\.\CdChanger0 will
have 0 as the changer number.
Refresh the library, physical media or all devices of a particular
media type.
RSM REFRESH
/L[G|F]<LibraryID> | /P[G|F]<PhysicalMediaID> | /TG<MediaTypeID>
The /[L|P|T]G option should be used when the LibraryID, PhysicalMediaID
or MediaTypeID is supplied as a GUID.
The /[L|P]F option should be used when the LibraryID or PhysicalMediaID
is supplied as a friendly name.
/O options: More than one may be specified by using the
switch repeatedly. Only one of the following can be used.
ERRUNAVAIL: The mount request will generate an error if either the
media or the drive is not available.
READ: Mount for read access.
WRITE: Mount for write access. If this option is selected
completed media will not be mounted.
DRIVE: To be specified if drive guid or name is provided.
OFFLINE: Error is returned if media is not on-line. If this option
is not used then operator request is queued.
/T Timeout: Specifies a timeout in milliseconds. Default is INFINITE
/R Priority: Default priority is NORMAL.
/O options:
More than one may be specified by using the
switch repeatedly. One of the following is used.
ERRUNAVAIL:
Prevents submission of an operator request for new
media if none can be allocated with the specified
constraints.
Allocates the partition of a media that cannot be
shared with another applications logical media. This
can be used to reserve the second side of two-sided
media. The second side can then be allocated by the
application using the NEXT option.
Allocate the next partition of a previously allocated
media using the NEW option.
/T Timeout:
Specifies a timeout in milliseconds. Default is
INFINITE
Bare option used with scripts. Displays only GUIDs.
Queues an inventory to the specified online library. If the library is busy,
RSM queues the command and returns success.
RSM INVENTORY
/L[G|F]<LibraryID> /A<Action>
The /LG option should be used when the LibraryID is supplied as a GUID.
The /LF option should be used when the LibraryID is supplied as a friendly
Note that the LibraryID is the unique identifier of an online library.
/A Actions:
Only one action is allowed. The available choices are:
A full on-media inventory is performed.
If the library has a bar code reader installed, then a
bar code inventory is performed. Otherwise a differential
inventory is performed.
DEFAULT:
Uses the Inventory method specified in the library object.
No inventory is performed.
Stops the current inventory in the specified library.
/A actions: Default is START. Only one of the following actions may be
specified.
START:
Start the EJECT operation. The media is ejected until timeout
(specified through the library object for all ejects in the
library) occurs OR this command is called with the STOP action.
Terminate the EJECT operation. The EJECT operation is specified
by using the GUID returned when this command is called with the
START action.
QUEUE:
Queue the media for ejection. This can be used to group media
for multi-slot IEports.
Used with the STOP action(or switch). Obtain the GUID when
eject is used with the START action(or switch).
Bare display of only the Eject Operation GUID (for use in
scripts).
Allocate a piece of available media.
RSM ALLOCATE
/M<MediaPoolName>
[/L[G|F]<LogicalMediaID> | /P[G|F]<PartitionID>]
/O[ERRUNAVAIL|NEW|NEXT]
[/T<timeout>]
[/LN<LogicalMediaName>]
[/LD<LogicalMediaDescription>]
[/PN<PartitionName>]
[/PD<PartitionDescription>]
/M<MediaPoolName>: media pool to allocate from.
The /[L|P]G option should be used when the LogicalMediaID, or
PartitionID is supplied as a GUID.
The /[L|P]F option should be used when the LogicalMediaID, or
PartitionID is supplied as a friendly name.
The /[L|P]N option should be used to specify the friendly name to be
assigned to the LogicalMedia Object or Partition Object of the
allocated media .
The /[L|P]D option should be used to specify the description to be
assigned to the LogicalMedia Object or Partition Object of the
allocated media.
Deallocate the partition associated with the specified logical media or
partition.
RSM DEALLOCATE
/L[G|F]<LogicalMediaID> | /P[G|F]<PartitionID>
The /[L|P]G option should be used when the LogicalMediaID, or
PartitionID is supplied as a GUID.
The /[L|P]F option should be used when the LogicalMediaID, or
PartitionID is supplied as a friendly name.
RSM DELETEMEDIA /N[physicalmedianame] /P[physicalmediaid]
/N physicalmedianame Specifies the physical media (using the name) to delete
/P physicalmediaid Specifies the physical media (using the id) to delete
Release a specified piece of media from a drive.
RSM DISMOUNT
/L[G|F]<LogicalMediaID> | /P[G|F]<PartitionID>
[/O[DEFERRED]]
The /[L|P]G option should be used when the LogicalMediaID,
or PartitionID is supplied as a GUID.
The /[L|P]F option should be used when the LogicalMediaID,
or PartitionID is supplied as a friendly name.
/O options: The following option may be used (not required).
DEFERRED: Marks media as dismountable but keeps media in the drive.
Default is to dismount immediately from the drive.
Mount a specified piece of media.
RSM MOUNT
/L[G|F]<LogicalMediaID> | /P[G|F]<PartitionID> |
[/S[G|F]<SlotID> /C[G|F]<ChangerID>]
[/D[G|F]<DriveID>]
/O[ERRUNAVAIL|DRIVE|READ|WRITE|OFFLINE]
[/R[NORMAL|HIGH|LOW|HIGHEST|LOWEST]]
[/T<timeout>]
The /[L|P|S|C|D]G option should be used when the LogicalMediaID,
PartitionID, SlotID, ChangerID or DriveID is supplied as a GUID.
The /[L|P|S|C|D]F option should be used when the LogicalMediaID,
PartitionID, SlotID, ChangerID or DriveID is supplied as a friendly
View all instances of a specific object type.
RSM VIEW
/T[DRIVE|LIBRARY|CHANGER|STORAGESLOT|IEDOOR|IEPORT|PHYSICAL_MEDIA|
MEDIA_POOL|PARTITION|LOGICAL_MEDIA|MEDIA_TYPE|DRIVE_TYPE|
LIBREQUEST]
[/CG<ContainerID>]
[/GUIDDISPLAY]
Specifies the object type to enumerate and view.
Specifies the GUID of a container object.
/GUIDDISPLAY:
Displays Guids along with friendly names.
Bare option used with scripts. Displays only GUIDs.dDeletes a media pool.
RSM DELETEPOOL
/M<MediaPoolName>
Name of the Media Pool to be deleted.
Unable to parse arguments.
Could not open media pool
Duplicate arguments given. Invalid timeout value specified.
Invalid option specified.(Invalid option for the allocate command.+Unable to open session with the RSM server.1Media Pool Name not given: non-optional argument.2Unable to convert Changer's friendly name to guid.
0Unable to allocate media - allocate call failed.#Get Object Information call failed.#Set Object Information call failed.#Mapping from partid to lmid failed.'No partid match was found for the lmid.>Convert string to guid failed - guid given is probably wrong.#Cannot convert partid name to guid.!Cannot convert lmid name to guid.
Enumerate Object api failed.2No match was found for the friendly name supplied.4Unable to deallocate media - deallocate call failed.
LMID not provided.%Invalid option for the mount command.!Cannot convert slot name to guid."Cannot convert drive name to guid.%Mapping from slotid to partid failed.
Mount command failed.=No pmid matches the given slotid. Is there media in the slot?
Partid not provided.#Invalid option to dismount command.
Dismount command failed.*Unable to convert media type name to guid.!Delete media pool command failed.-Unable to convert Pmid friendly name to guid.
Eject command failed.0Changer has no IE Ports. Door Access was queued.FChanger has no IE Ports. Door Access Failed. PMID name probably wrong.4Invalid Changer Number - Should contain only digits.DCreate Handle failed. Changer does not exist or ntmssvc is running. 0Unable to convert library friendly name to guid.
Refresh command failed.$Invalid option to inventory command.
Inventory command failed.
Mapping from the Slot Information you provided to a piece of Physical Media failed. Either the Slot (+Changer) Information provided was incorrect or the Slot is empty.
Mapping from the Drive Information you provided to a piece of Physical Media failed. Either the Drive (+Changer) Information provided was incorrect or the Drive is empty.5Media type of existing Media Pools cannot be changed.
Work item GUID:
New logical media GUID:
l???.???
@@Kernel32.dll
Legal\
AtlAxWin100
AtlAxWinLic100
Comctl32.dll
license.html
eula.ini
labels
@@Comdlg32.dll
License.html
HTML Files (*.HTML)
*.html
All Files (*.*)
DeclText2
DeclText1
DeclTitle
Decline
Accept
License Agreement
@#32770
@ATL:%p
AXWIN Frame Window
AXWIN UI Window
WM_ATLGETCONTROL
WM_ATLGETHOST
Software\Adobe\Acrobat Reader\11.0\AdobeViewer
RightToLeft
Delete
NoRemove
ForceRemove
@@@@@@@@
@@@@@@
@@@@@@@@
@@@@@@
Dialog
MS Shell Dlg
Decline
Accept
{8856F961-340A-11D0-A96B-00C04FD705A2}
Press the Accept button to agree to the License Agreement and continue.
Dialog
MS Shell Dlg
Decline
Accept
{8856F961-340A-11D0-A96B-00C04FD705A2}
Press the Accept button to agree to the License Agreement and continue.
Decline License Agreement
MS Shell Dlg
Are you sure you want to decline the End User License Agreement?
You must accept the End User License Agreement in order to use this product. To go back and accept the agreement, select the Back button. To decline, select Quit.
Decline License Agreement
MS Shell Dlg
Are you sure you want to decline the End User License Agreement?
You must accept the End User License Agreement in order to use this product. To go back and accept the agreement, select the Back button. To decline, select Quit.
VS_VERSION_INFO
StringFileInfo
040904e4
CompanyName
Adobe Systems Incorporated
FileDescription
Eula display
FileVersion
11.0.14.16
InternalName
Eula.exe
LegalCopyright
Copyright 2010-2012 Adobe Systems Incorporated. All rights reserved.
OriginalFilename
Eula.exe
ProductName
ProductVersion
11.0.14.16
VarFileInfo
Translation
<<<Obsolete>>
BAdobe Acrobat_Reader Win binarie
TabTip-EndSession
Tabtip-MainUI
loadhooks
Default
Winlogon
Screen-saver
Automation
Embedding
LaunchInkWatson
QuitInfo:
ManualLaunch
SeekDesktop
TabletPCInputPanel-EnableTIP
tipskins.dll
tipres.dll
Mscoree.dll
(null)
Shell_TrayWnd
Progman
LegacyFactoid
\Microsoft Shared\Ink\TabTip32.exe
/%s /Parent:%p
{DFFDE213-8CB4-46a9-90EB-3DA843AF66F9}-show
\VarFileInfo\Translation
\StringFileInfo\%04x%04x\ProductVersion
IS_DEFAULT
IS_PHRASELIST
IS_REGULAREXPRESSION
IS_XML
IS_ADDRESS_CITY
IS_ADDRESS_COUNTRYNAME
IS_ADDRESS_FULLPOSTALADDRESS
IS_ADDRESS_POSTALCODE
IS_ADDRESS_STREET
IS_ADDRESS_STATEORPROVINCE
IS_ADDRESS_COUNTRYSHORTNAME
IS_CURRENCY_AMOUNTANDSYMBOL
IS_CURRENCY_AMOUNT
IS_DATE_FULLDATE
IS_DATE_MONTH
IS_DATE_DAY
IS_DATE_YEAR
IS_DATE_MONTHNAME
IS_DATE_DAYNAME
IS_EMAIL_USERNAME
IS_EMAIL_SMTPEMAILADDRESS
IS_FILE_FULLFILEPATH
IS_FILE_FILENAME
IS_LOGINNAME
IS_DIGITS
IS_NUMBER
IS_ONECHAR
IS_PASSWORD
IS_PERSONALNAME_FULLNAME
IS_PERSONALNAME_PREFIX
IS_PERSONALNAME_GIVENNAME
IS_PERSONALNAME_MIDDLENAME
IS_PERSONALNAME_SURNAME
IS_PERSONALNAME_SUFFIX
IS_TELEPHONE_FULLTELEPHONENUMBER
IS_TELEPHONE_COUNTRYCODE
IS_TELEPHONE_AREACODE
IS_TELEPHONE_LOCALNUMBER
IS_TIME_FULLTIME
IS_TIME_HOUR
IS_TIME_MINORSEC
IS_URL
Version
Version_Number
Manifest
Screen
CustomDefinitionList
WLFactoidList
AssociationList
IScope
Factoid
CustomInputScope
Expression
WLFactoid
WordList
AccessibleName
WindowClassName
WindowID
ControlName
ControlLocality
AccessibleNameMandatory
InputScopeEnumList
InputScopeEnum
RegExpName
PhraseListName
WindowsForms
P[Null,
:PR[Null,
:PR[%s,
:NE[Null,
:NE[%s,
~Unknown~
xmllite.dll
telnet://
ftp://
https://
http://
WORDLIST
Software\Microsoft\Internet Explorer\TypedURLs
{DFFDE213-8CB4-46a9-90EB-3DA843AF66F9}-request
TabletInputService
Ntdll.dll
file:///
sgjty|p~v|n}~xqty}}
X_uv~`jjkx
toxuixuz||}~
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Tablet PC Input Panel Accessory
FileVersion
6.1.7600.16385 (win7_rtm.090713-1255)
InternalName
TabTip.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
TabTip.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
6.1.7600.16385
OleSelfRegister
VarFileInfo
Translation
gSoftware\Adobe\%s\%s\Privileged
Software\Policies\Adobe\%s\%s\FeatureLockDown
gbProtectedMode
AcroRd32.dll
sntdll.dll
ykernel32.dll
l???.???
@Kernel32.dll
Comctl32.dll
nbPDFShellProtectedMode
Acrobat Reader
/PDFShell
API_ADOBE_PUBLIC_KEY
T405_ADOBE_PUBLIC_KEY
VS_VERSION_INFO
StringFileInfo
040904E4
CompanyName
Adobe Systems Incorporated
FileDescription
Adobe Reader
FileVersion
11.0.14.16
LegalCopyright
Copyright 1984-2012 Adobe Systems Incorporated and its licensors. All rights reserved.
ProductName
Adobe Reader
ProductVersion
11.0.14.16
OriginalFilename
AcroRd32Info.exe
BuildInfo
VarFileInfo
Translation
LanguageInfo
EnglishName
English
LanguageId
FileVersion
11.0.14.16
Signature
<<<Obsolete>>
BAdobe Acrobat_Reader Win binarie
CMD.EXE
()|&=,;"
COPYCMD
\XCOPY.EXE
RANDOM
CMDCMDLINE
WKERNEL32.DLL
AutoRun
PathCompletionChar
CompletionChar
DefaultColor
DelayedExpansion
EnableExtensions
DisableUNCCheck
Software\Microsoft\Command Processor
Software\Policies\Microsoft\Windows\System
PMM/dd/yy
Unknown
0123456789
ENABLEEXTENSIONS
sNTDLL.DLL
tokens=
delims=
useback
usebackq
pushd
mkdir
rmdir
chdir
<noalias>
DIRCMD
????????.???
%d.%d.%04d
cmd.exe
SHARED
SEPARATE
REALTIME
NORMAL
BELOWNORMAL
ABOVENORMAL
DISABLEDELAYEDEXPANSION
ENABLEDELAYEDEXPANSION
DISABLEEXTENSIONS
dd/MM/yy
yy/MM/dd
HH:mm:ss t
Ungetting: '%s'
DisableCMD
GeToken: (%x) '%s'
%s\Shell\Open\Command
Software\Classes
System
Application
*** no open command defined ***
\Shell\Open\Command
REM /?
FOR /?
/D /c"
%x %c
Redir:
*** Unknown type: %x
Args: `%s'
Cmd: %s Type: %x
%s (%s) %s
=ExitCode
=ExitCodeAscii
CMDEXTVERSION
DEFINED
PROMPT
ENDLOCAL
ERRORLEVEL
RENAME
SETLOCAL
VERIFY
=,;+/[]
PATHEXT
PROMPT
COMSPEC
fdpnxsatz
(%s) %s
%s %s%s
%s %s
&()[]{}^=;!%'+,`~
%02d%s%02d%s
%2d%s%02d%s%02d%s%02d
%02d%s%02d%s%02d
%04X-%04X
.COM;.EXE;.BAT;.CMD;.VBS;.JS;.WS
<>+-*/%()|^&=,
\CMD.EXE
IDI_APPICON
@FKNORTVZZ]^
ronnnnnnnnnnnnnnnnnnnnnnnmmu
l{{{{{{{{{{{{{{{{{{
gggggggggggggggggg
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Windows Command Processor
FileVersion
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
InternalName
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
Cmd.Exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
5.1.2600.2180
VarFileInfo
Translation
An incorrect parameter was
entered for the command.
The syntax of the command is incorrect.
Press any key to continue . . . %0
%1, Delete (Y/N)? %0
The system cannot accept the path
or file name requested.
The system cannot accept the date entered.
No batch label specified to GOTO command.
'%1' is not recognized as an internal or external command,
operable program or batch file.
The system cannot accept the time entered.
(C) Copyright 1985-2001 Microsoft Corp.
%1 file(s) copied.
The current date is: %0
The current time is: %0
Directory of %1
The system is out of environment space.
The system cannot execute the specified program.
The input line is too long.
The contents of the target file
were lost.
Insert the diskette that contains the batch file
and press any key when ready. %0
Enter the new date: (mm-dd-yy) %0
Enter the new time: %0
The handle could not be duplicated
during redirection of handle %1.
ECHO is off.
ECHO is on.
VERIFY is off.
VERIFY is on.
The file cannot be copied onto itself.
%1 was unexpected at this time.
The Process Identification Number is %1.
A duplicate file name exists, or the file
cannot be found.
%1, Are you sure (Y/N)? %0
The following character string is too long:
Microsoft Windows XP [Version %1]%0
The handle could not be duplicated during
a pipe operation.
More? %0
The system cannot complete the process.
Volume Serial Number is %1
A subdirectory or file %1 already exists.
Error occurred while processing: %1.
Volume in drive %1 has no label.
Volume in drive %1 is %2
KEYS is on.
KEYS is off.
The system cannot accept the START command parameter %1.
The system cannot find the file %1.
The process tried to write to a nonexistent pipe.
"%1" is not a recognized device.
The batch file cannot be found.
%1 file(s) moved.
A program attempted to reference storage outside the
limits of a stack segment. The program was ended.
Command not implemented.
<DIR> %0
Out of memory.
Invalid switch - "%1".
Parameter format not correct - "%1".
(Error occurred in environment variable)
%1 File(s) %2 bytes
%1 Dir(s) %2 bytes free
Total Files Listed:
Terminate batch job (Y/N)? %0
The current directory is invalid.
Displays the name of or changes the current directory.
CHDIR [/D] [drive:][path]
CHDIR [..]
CD [/D] [drive:][path]
CD [..]
.. Specifies that you want to change to the parent directory.
Type CD drive: to display the current directory in the specified drive.
Type CD without parameters to display the current drive and directory.
Use the /D switch to change current drive in addition to changing current
directory for a drive.
Clears the screen.
Copies one or more files to another location.
COPY [/D] [/V] [/N] [/Y | /-Y] [/Z] [/A | /B ] source [/A | /B]
[+ source [/A | /B] [+ ...]] [destination [/A | /B]]
source Specifies the file or files to be copied.
/A Indicates an ASCII text file.
/B Indicates a binary file.
/D Allow the destination file to be created decrypted
destination Specifies the directory and/or filename for the new file(s).
/V Verifies that new files are written correctly.
/N Uses short filename, if available, when copying a file with a
non-8dot3 name.
/Y Suppresses prompting to confirm you want to overwrite an
existing destination file.
/-Y Causes prompting to confirm you want to overwrite an
existing destination file.
/Z Copies networked files in restartable mode.
The switch /Y may be preset in the COPYCMD environment variable.
This may be overridden with /-Y on the command line. Default is
to prompt on overwrites unless COPY command is being executed from
within a batch script.
To append files, specify a single file for destination, but multiple files
for source (using wildcards or file1+file2+file3 format).
Displays or sets the date.
DATE [/T | date]
Type DATE without parameters to display the current date setting and
a prompt for a new one. Press ENTER to keep the same date.
Deletes one or more files.
DEL [/P] [/F] [/S] [/Q] [/A[[:]attributes]] names
ERASE [/P] [/F] [/S] [/Q] [/A[[:]attributes]] names
names Specifies a list of one or more files or directories.
Wildcards may be used to delete multiple files. If a
directory is specified, all files within the directory
will be deleted.
/P Prompts for confirmation before deleting each file.
/F Force deleting of read-only files.
/S Delete specified files from all subdirectories.
/Q Quiet mode, do not ask if ok to delete on global wildcard
/A Selects files to delete based on attributes
attributes R Read-only files S System files
H Hidden files A Files ready for archiving
- Prefix meaning not
Displays a list of files and subdirectories in a directory.
DIR [drive:][path][filename] [/A[[:]attributes]] [/B] [/C] [/D] [/L] [/N]
[/O[[:]sortorder]] [/P] [/Q] [/S] [/T[[:]timefield]] [/W] [/X] [/4]
[drive:][path][filename]
Specifies drive, directory, and/or files to list.
/A Displays files with specified attributes.
attributes D Directories R Read-only files
H Hidden files A Files ready for archiving
S System files - Prefix meaning not
/B Uses bare format (no heading information or summary).
/C Display the thousand separator in file sizes. This is the
default. Use /-C to disable display of separator.
/D Same as wide but files are list sorted by column.
/L Uses lowercase.
/N New long list format where filenames are on the far right.
/O List by files in sorted order.
sortorder N By name (alphabetic) S By size (smallest first)
E By extension (alphabetic) D By date/time (oldest first)
G Group directories first - Prefix to reverse order
/P Pauses after each screenful of information.
/Q Display the owner of the file.
/S Displays files in specified directory and all subdirectories.
/T Controls which time field displayed or used for sorting
timefield C Creation
A Last Access
W Last Written
/W Uses wide list format.
/X This displays the short names generated for non-8dot3 file
names. The format is that of /N with the short name inserted
before the long name. If no short name is present, blanks are
displayed in its place.
/4 Displays four-digit years
Switches may be preset in the DIRCMD environment variable. Override
preset switches by prefixing any switch with - (hyphen)--for example, /-W.
Quits the CMD.EXE program (command interpreter) or the current batch
script.
EXIT [/B] [exitCode]
/B specifies to exit the current batch script instead of
CMD.EXE. If executed from outside a batch script, it
will quit CMD.EXE
exitCode specifies a numeric number. if /B is specified, sets
ERRORLEVEL that number. If quitting CMD.EXE, sets the process
exit code with that number.
Creates a directory.
MKDIR [drive:]path
MD [drive:]path
Displays or sets a search path for executable files.
PATH [[drive:]path[;...][;%%PATH%%]
PATH ;
Type PATH ; to clear all search-path settings and direct cmd.exe to search
only in the current directory.
Type PATH without parameters to display the current path.
Including %%PATH%% in the new path setting causes the old path to be
appended to the new setting.
Changes the cmd.exe command prompt.
PROMPT [text]
text Specifies a new command prompt.
Prompt can be made up of normal characters and the following special codes:
$A & (Ampersand)
$B | (pipe)
$C ( (Left parenthesis)
$D Current date
$E Escape code (ASCII code 27)
$F ) (Right parenthesis)
$G > (greater-than sign)
$H Backspace (erases previous character)
$L < (less-than sign)
$N Current drive
$P Current drive and path
$Q = (equal sign)
$S (space)
$T Current time
$V Windows XP version number
$_ Carriage return and linefeed
$$ $ (dollar sign)
Removes (deletes) a directory.
RMDIR [/S] [/Q] [drive:]path
RD [/S] [/Q] [drive:]path
/S Removes all directories and files in the specified directory
in addition to the directory itself. Used to remove a directory
tree.
/Q Quiet mode, do not ask if ok to remove a directory tree with /S
Renames a file or files.
RENAME [drive:][path]filename1 filename2.
REN [drive:][path]filename1 filename2.
Note that you cannot specify a new drive or path for your destination file.
Displays, sets, or removes cmd.exe environment variables.
SET [variable=[string]]
variable Specifies the environment-variable name.
string Specifies a series of characters to assign to the variable.
Type SET without parameters to display the current environment variables.
Displays or sets the system time.
TIME [/T | time]
Type TIME with no parameters to display the current time setting and a prompt
for a new one. Press ENTER to keep the same time.
Displays the contents of a text file or files.
TYPE [drive:][path]filename
Displays the Windows XP version.
Tells cmd.exe whether to verify that your files are written correctly to a
VERIFY [ON | OFF]
Type VERIFY without a parameter to display the current VERIFY setting.
Displays the disk volume label and serial number, if they exist.
VOL [drive:]
Calls one batch program from another.
CALL [drive:][path]filename [batch-parameters]
batch-parameters Specifies any command-line information required by the
batch program.
Records comments (remarks) in a batch file or CONFIG.SYS.
REM [comment]
Suspends processing of a batch program and displays the message
Press any key to continue . . . %0
Displays messages, or turns command-echoing on or off.
ECHO [ON | OFF]
ECHO [message]
Type ECHO without parameters to display the current echo setting.
Directs cmd.exe to a labeled line in a batch program.
GOTO label
label Specifies a text string used in the batch program as a label.
You type a label on a line by itself, beginning with a colon.
Changes the position of replaceable parameters in a batch file.
SHIFT [/n]
Performs conditional processing in batch programs.
IF [NOT] ERRORLEVEL number command
IF [NOT] string1==string2 command
IF [NOT] EXIST filename command
NOT Specifies that Windows XP should carry out
the command only if the condition is false.
ERRORLEVEL number Specifies a true condition if the last program run
returned an exit code equal to or greater than the number
specified.
string1==string2 Specifies a true condition if the specified text strings
match.
EXIST filename Specifies a true condition if the specified filename
exists.
command Specifies the command to carry out if the condition is
met. Command can be followed by ELSE command which
will execute the command after the ELSE keyword if the
specified condition is FALSE
The ELSE clause must occur on the same line as the command after the IF. For
example:
IF EXIST filename. (
del filename.
) ELSE (
echo filename. missing.
The following would NOT work because the del command needs to be terminated
by a newline:
IF EXIST filename. del filename. ELSE echo filename. missing
Nor would the following work, since the ELSE command must be on the same line
as the end of the IF command:
IF EXIST filename. del filename.
ELSE echo filename. missing
The following would work if you want it all on one line:
IF EXIST filename. (del filename.) ELSE echo filename. missing
Runs a specified command for each file in a set of files.
FOR %%variable IN (set) DO command [command-parameters]
%%variable Specifies a single letter replaceable parameter.
(set) Specifies a set of one or more files. Wildcards may be used.
command Specifies the command to carry out for each file.
command-parameters
Specifies parameters or switches for the specified command.
To use the FOR command in a batch program, specify %%%%variable instead
of %%variable. Variable names are case sensitive, so %%i is different
from %%I.
Starts a separate window to run a specified program or command.
START ["title"] [/Dpath] [/I] [/MIN] [/MAX] [/SEPARATE | /SHARED]
[/LOW | /NORMAL | /HIGH | /REALTIME | /ABOVENORMAL | /BELOWNORMAL]
[/WAIT] [/B] [command/program]
[parameters]
"title" Title to display in window title bar.
path Starting directory
B Start application without creating a new window. The
application has ^C handling ignored. Unless the application
enables ^C processing, ^Break is the only way to interrupt
the application
I The new environment will be the original environment passed
to the cmd.exe and not the current environment.
MIN Start window minimized
MAX Start window maximized
SEPARATE Start 16-bit Windows program in separate memory space
SHARED Start 16-bit Windows program in shared memory space
LOW Start application in the IDLE priority class
NORMAL Start application in the NORMAL priority class
HIGH Start application in the HIGH priority class
REALTIME Start application in the REALTIME priority class
ABOVENORMAL Start application in the ABOVENORMAL priority class
BELOWNORMAL Start application in the BELOWNORMAL priority class
WAIT Start application and wait for it to terminate
command/program
If it is an internal cmd command or a batch file then
the command processor is run with the /K switch to cmd.exe.
This means that the window will remain after the command
has been run.
If it is not an internal cmd command or batch file then
it is a program and will run as either a windowed application
or a console application.
parameters These are the parameters passed to the command/program
Sets or Clears Extended CTRL+C checking on DOS system
This is present for Compatibility with DOS systems. It has no effect
under Windows XP.
Starts a new instance of the Windows XP command interpreter
CMD [/A | /U] [/Q] [/D] [/E:ON | /E:OFF] [/F:ON | /F:OFF] [/V:ON | /V:OFF]
[[/S] [/C | /K] string]
/C Carries out the command specified by string and then terminates
/K Carries out the command specified by string but remains
/S Modifies the treatment of string after /C or /K (see below)
/Q Turns echo off
/D Disable execution of AutoRun commands from registry (see below)
/A Causes the output of internal commands to a pipe or file to be ANSI
/U Causes the output of internal commands to a pipe or file to be
Unicode
/T:fg Sets the foreground/background colors (see COLOR /? for more info)
/E:ON Enable command extensions (see below)
/E:OFF Disable command extensions (see below)
/F:ON Enable file and directory name completion characters (see below)
/F:OFF Disable file and directory name completion characters (see below)
/V:ON Enable delayed environment variable expansion using ! as the
delimiter. For example, /V:ON would allow !var! to expand the
variable var at execution time. The %var% syntax expands variables
at input time, which is quite a different thing when inside of a FOR
loop.
/V:OFF Disable delayed environment expansion.
Note that multiple commands separated by the command separator '&&'
are accepted for string if surrounded by quotes. Also, for compatibility
reasons, /X is the same as /E:ON, /Y is the same as /E:OFF and /R is the
same as /C. Any other switches are ignored.
If /C or /K is specified, then the remainder of the command line after
the switch is processed as a command line, where the following logic is
used to process quote (") characters:
1. If all of the following conditions are met, then quote characters
on the command line are preserved:
- no /S switch
- exactly two quote characters
- no special characters between the two quote characters,
where special is one of: &<>()@^|
- there are one or more whitespace characters between the
the two quote characters
- the string between the two quote characters is the name
of an executable file.
2. Otherwise, old behavior is to see if the first character is
a quote character and if so, strip the leading character and
remove the last quote character on the command line, preserving
any text after the last quote character.
If /D was NOT specified on the command line, then when CMD.EXE starts, it
looks for the following REG_SZ/REG_EXPAND_SZ registry variables, and if
either or both are present, they are executed first.
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\AutoRun
and/or
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\AutoRun
Command Extensions are enabled by default. You may also disable
extensions for a particular invocation by using the /E:OFF switch. You
can enable or disable extensions for all invocations of CMD.EXE on a
machine and/or user logon session by setting either or both of the
following REG_DWORD values in the registry using REGEDT32.EXE:
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\EnableExtensions
and/or
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\EnableExtensions
to either 0x1 or 0x0. The user specific setting takes precedence over
the machine setting. The command line switches take precedence over the
registry settings.
The command extensions involve changes and/or additions to the following
commands:
DEL or ERASE
COLOR
CD or CHDIR
MD or MKDIR
PROMPT
PUSHD
POPD
SET
SETLOCAL
ENDLOCAL
IF
FOR
CALL
SHIFT
GOTO
START (also includes changes to external command invocation)
ASSOC
FTYPE
To get specific details, type commandname /? to view the specifics.
Delayed environment variable expansion is NOT enabled by default. You
can enable or disable delayed environment variable expansion for a
particular invocation of CMD.EXE with the /V:ON or /V:OFF switch. You
can enable or disable completion for all invocations of CMD.EXE on a
machine and/or user logon session by setting either or both of the
following REG_DWORD values in the registry using REGEDT32.EXE:
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\DelayedExpansion
and/or
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\DelayedExpansion
to either 0x1 or 0x0. The user specific setting takes precedence over
the machine setting. The command line switches take precedence over the
registry settings.
If delayed environment variable expansion is enabled, then the exclamation
character can be used to substitute the value of an environment variable
at execution time.
File and Directory name completion is NOT enabled by default. You can
enable or disable file name completion for a particular invocation of
CMD.EXE with the /F:ON or /F:OFF switch. You can enable or disable
completion for all invocations of CMD.EXE on a machine and/or user logon
session by setting either or both of the following REG_DWORD values in
the registry using REGEDT32.EXE:
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\CompletionChar
HKEY_LOCAL_MACHINE\Software\Microsoft\Command Processor\PathCompletionChar
and/or
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\CompletionChar
HKEY_CURRENT_USER\Software\Microsoft\Command Processor\PathCompletionChar
with the hex value of a control character to use for a particular
function (e.g. 0x4 is Ctrl-D and 0x6 is Ctrl-F). The user specific
settings take precedence over the machine settings. The command line
switches take precedence over the registry settings.
If completion is enabled with the /F:ON switch, the two control
characters used are Ctrl-D for directory name completion and Ctrl-F for
file name completion. To disable a particular completion character in
the registry, use the value for space (0x20) as it is not a valid
control character.
Completion is invoked when you type either of the two control
characters. The completion function takes the path string to the left
of the cursor appends a wild card character to it if none is already
present and builds up a list of paths that match. It then displays the
first matching path. If no paths match, it just beeps and leaves the
display alone. Thereafter, repeated pressing of the same control
character will cycle through the list of matching paths. Pressing the
Shift key with the control character will move through the list
backwards. If you edit the line in any way and press the control
character again, the saved list of matching paths is discarded and a new
one generated. The same occurs if you switch between file and directory
name completion. The only difference between the two control characters
is the file completion character matches both file and directory names,
while the directory completion character only matches directory names.
If file completion is used on any of the built in directory commands
(CD, MD or RD) then directory completion is assumed.
The completion code deals correctly with file names that contain spaces
or other special characters by placing quotes around the matching path.
Also, if you back up, then invoke completion from within a line, the
text to the right of the cursor at the point completion was invoked is
discarded.
The special characters that require quotes are:
<space>
&()[]{}^=;!%'+,`~
Command Processor Extensions Enabled
Command Processor Extensions enabled by default. Use CMD /? for details.
Deleted file - %1
Displays or modifies file extension associations
ASSOC [.ext[=[fileType]]]
.ext Specifies the file extension to associate the file type with
fileType Specifies the file type to associate with the file extension
Type ASSOC without parameters to display the current file associations.
If ASSOC is invoked with just a file extension, it displays the current
file association for that file extension. Specify nothing for the file
type and the command will delete the association for the file extension.
File association not found for extension %1
Displays or modifies file types used in file extension associations
FTYPE [fileType[=[openCommandString]]]
fileType Specifies the file type to examine or change
openCommandString Specifies the open command to use when launching files
of this type.
Type FTYPE without parameters to display the current file types that
have open command strings defined. FTYPE is invoked with just a file
type, it displays the current open command string for that file type.
Specify nothing for the open command string and the FTYPE command will
delete the open command string for the file type. Within an open
command string %%0 or %%1 are substituted with the file name being
launched through the assocation. %%* gets all the parameters and %%2
gets the 1st parameter, %%3 the second, etc. %%~n gets all the remaining
parameters starting with the nth parameter, where n may be between 2 and 9,
inclusive. For example:
ASSOC .pl=PerlScript
FTYPE PerlScript=perl.exe %%1 %%*
would allow you to invoke a Perl script as follows:
script.pl 1 2 3
If you want to eliminate the need to type the extensions, then do the
following:
set PATHEXT=.pl;%%PATHEXT%%
and the script could be invoked as follows:
script 1 2 3
File type '%1' not found or no open command associated with it.
Invalid parameter to SETLOCAL command
The restartable option to the COPY command is not supported by
this version of the operating system.
The following usage of the path operator in batch-parameter
substitution is invalid: %1
For valid formats type CALL /? or FOR /?
Environment variable %1 not defined
Invalid attempt to call batch label outside of batch script.
The system cannot find the batch label specified - %1
The unicode output option to CMD.EXE is not supported by this
version of the operating system.
If Command Extensions are enabled DEL and ERASE change as follows:
The display semantics of the /S switch are reversed in that it shows
you only the files that are deleted, not the ones it could not find.
If Command Extensions are enabled CHDIR changes as follows:
The current directory string is converted to use the same case as
the on disk names. So CD C:\TEMP would actually set the current
directory to C:\Temp if that is the case on disk.
CHDIR command does not treat spaces as delimiters, so it is possible to
CD into a subdirectory name that contains a space without surrounding
the name with quotes. For example:
cd \winnt\profiles\username\programs\start menu
is the same as:
cd "\winnt\profiles\username\programs\start menu"
which is what you would have to type if extensions were disabled.
If Command Extensions are enabled MKDIR changes as follows:
MKDIR creates any intermediate directories in the path, if needed.
For example, assume \a does not exist then:
mkdir \a\b\c\d
is the same as:
mkdir \a
chdir \a
mkdir b
chdir b
mkdir c
chdir c
mkdir d
which is what you would have to type if extensions were disabled.
If Command Extensions are enabled the DATE command supports
the /T switch which tells the command to just output the
current date, without prompting for a new date.
If Command Extensions are enabled the TIME command supports
the /T switch which tells the command to just output the
current time, without prompting for a new time.
If Command Extensions are enabled the PROMPT command supports
the following additional formatting characters:
$+ zero or more plus sign (+) characters depending upon the
depth of the PUSHD directory stack, one character for each
level pushed.
$M Displays the remote name associated with the current drive
letter or the empty string if current drive is not a network
drive.
If Command Extensions are enabled the PUSHD command accepts
network paths in addition to the normal drive letter and path.
If a network path is specified, PUSHD will create a temporary
drive letter that points to that specified network resource and
then change the current drive and directory, using the newly
defined drive letter. Temporary drive letters are allocated from
Z: on down, using the first unused drive letter found.
If Command Extensions are enabled the POPD command will delete
any temporary drive letter created by PUSHD when you POPD that
drive off the pushed directory stack.
If Command Extensions are enabled SET changes as follows:
SET command invoked with just a variable name, no equal sign or value
will display the value of all variables whose prefix matches the name
given to the SET command. For example:
SET P
would display all variables that begin with the letter 'P'
SET command will set the ERRORLEVEL to 1 if the variable name is not
found in the current environment.
SET command will not allow an equal sign to be part of the name of
a variable.
Two new switches have been added to the SET command:
SET /A expression
SET /P variable=[promptString]
The /A switch specifies that the string to the right of the equal sign
is a numerical expression that is evaluated. The expression evaluator
is pretty simple and supports the following operations, in decreasing
order of precedence:
() - grouping
! ~ - - unary operators
* / %% - arithmetic operators
+ - - arithmetic operators
<< >> - logical shift
& - bitwise and
^ - bitwise exclusive or
| - bitwise or
= *= /= %%= += -= - assignment
&= ^= |= <<= >>=
, - expression separator
If you use any of the logical or modulus operators, you will need to
enclose the expression string in quotes. Any non-numeric strings in the
expression are treated as environment variable names whose values are
converted to numbers before using them. If an environment variable name
is specified but is not defined in the current environment, then a value
of zero is used. This allows you to do arithmetic with environment
variable values without having to type all those %% signs to get their
values. If SET /A is executed from the command line outside of a
command script, then it displays the final value of the expression. The
assignment operator requires an environment variable name to the left of
the assignment operator. Numeric values are decimal numbers, unless
prefixed by 0x for hexadecimal numbers, and 0 for octal numbers.
So 0x12 is the same as 18 is the same as 022. Please note that the octal
notation can be confusing: 08 and 09 are not valid numbers because 8 and
9 are not valid octal digits.
The /P switch allows you to set the value of a variable to a line of input
entered by the user. Displays the specified promptString before reading
the line of input. The promptString can be empty.
Environment variable substitution has been enhanced as follows:
%%PATH:str1=str2%%
would expand the PATH environment variable, substituting each occurrence
of "str1" in the expanded result with "str2". "str2" can be the empty
string to effectively delete all occurrences of "str1" from the expanded
output. "str1" can begin with an asterisk, in which case it will match
everything from the beginning of the expanded output to the first
occurrence of the remaining portion of str1.
May also specify substrings for an expansion.
%%PATH:~10,5%%
would expand the PATH environment variable, and then use only the 5
characters that begin at the 11th (offset 10) character of the expanded
result. If the length is not specified, then it defaults to the
remainder of the variable value. If either number (offset or length) is
negative, then the number used is the length of the environment variable
value added to the offset or length specified.
%%PATH:~-10%%
would extract the last 10 characters of the PATH variable.
%%PATH:~0,-2%%
would extract all but the last 2 characters of the PATH variable.
Finally, support for delayed environment variable expansion has been
added. This support is always disabled by default, but may be
enabled/disabled via the /V command line switch to CMD.EXE. See CMD /?
Delayed environment variable expansion is useful for getting around
the limitations of the current expansion which happens when a line
of text is read, not when it is executed. The following example
demonstrates the problem with immediate variable expansion:
set VAR=before
if "%%VAR%%" == "before" (
set VAR=after
if "%%VAR%%" == "after" @echo If you see this, it worked
would never display the message, since the %%VAR%% in BOTH IF statements
is substituted when the first IF statement is read, since it logically
includes the body of the IF, which is a compound statement. So the
IF inside the compound statement is really comparing "before" with
"after" which will never be equal. Similarly, the following example
will not work as expected:
set LIST=
for %%i in (*) do set LIST=%%LIST%% %%i
echo %%LIST%%
in that it will NOT build up a list of files in the current directory,
but instead will just set the LIST variable to the last file found.
Again, this is because the %%LIST%% is expanded just once when the
FOR statement is read, and at that time the LIST variable is empty.
So the actual FOR loop we are executing is:
for %%i in (*) do set LIST= %%i
which just keeps setting LIST to the last file found.
Delayed environment variable expansion allows you to use a different
character (the exclamation mark) to expand environment variables at
execution time. If delayed variable expansion is enabled, the above
examples could be written as follows to work as intended:
set VAR=before
if "%%VAR%%" == "before" (
set VAR=after
if "!VAR!" == "after" @echo If you see this, it worked
set LIST=
for %%i in (*) do set LIST=!LIST! %%i
echo %%LIST%%
If Command Extensions are enabled, then there are several dynamic
environment variables that can be expanded but which don't show up in
the list of variables displayed by SET. These variable values are
computed dynamically each time the value of the variable is expanded.
If the user explicitly defines a variable with one of these names, then
that definition will override the dynamic one described below:
%%CD%% - expands to the current directory string.
%%DATE%% - expands to current date using same format as DATE command.
%%TIME%% - expands to current time using same format as TIME command.
%%RANDOM%% - expands to a random decimal number between 0 and 32767.
%%ERRORLEVEL%% - expands to the current ERRORLEVEL value
%%CMDEXTVERSION%% - expands to the current Command Processor Extensions
version number.
%%CMDCMDLINE%% - expands to the original command line that invoked the
Command Processor.
If Command Extensions are enabled GOTO changes as follows:
GOTO command now accepts a target label of :EOF which transfers control
to the end of the current batch script file. This is an easy way to
exit a batch script file without defining a label. Type CALL /? for a
description of extensions to the CALL command that make this feature
useful.
If Command Extensions are enabled the SHIFT command supports
the /n switch which tells the command to start shifting at the
nth argument, where n may be between zero and eight. For example:
SHIFT /2
would shift %%3 to %%2, %%4 to %%3, etc. and leave %%0 and %%1 unaffected.
If Command Extensions are enabled CALL changes as follows:
CALL command now accepts labels as the target of the CALL. The syntax
CALL :label arguments
A new batch file context is created with the specified arguments and
control is passed to the statement after the label specified. You must
"exit" twice by reaching the end of the batch script file twice. The
first time you read the end, control will return to just after the CALL
statement. The second time will exit the batch script. Type GOTO /?
for a description of the GOTO :EOF extension that will allow you to
"return" from a batch script.
In addition, expansion of batch script argument references (%%0, %%1,
etc.) have been changed as follows:
%%* in a batch script refers to all the arguments (e.g. %%1 %%2 %%3
%%4 %%5 ...)
Substitution of batch parameters (%%n) has been enhanced. You can
now use the following optional syntax:
%%~1 - expands %%1 removing any surrounding quotes (")
%%~f1 - expands %%1 to a fully qualified path name
%%~d1 - expands %%1 to a drive letter only
%%~p1 - expands %%1 to a path only
%%~n1 - expands %%1 to a file name only
%%~x1 - expands %%1 to a file extension only
%%~s1 - expanded path contains short names only
%%~a1 - expands %%1 to file attributes
%%~t1 - expands %%1 to date/time of file
%%~z1 - expands %%1 to size of file
%%~$PATH:1 - searches the directories listed in the PATH
environment variable and expands %%1 to the fully
qualified name of the first one found. If the
environment variable name is not defined or the
file is not found by the search, then this
modifier expands to the empty string
The modifiers can be combined to get compound results:
%%~dp1 - expands %%1 to a drive letter and path only
%%~nx1 - expands %%1 to a file name and extension only
%%~dp$PATH:1 - searches the directories listed in the PATH
environment variable for %%1 and expands to the
drive letter and path of the first one found.
%%~ftza1 - expands %%1 to a DIR like output line
In the above examples %%1 and PATH can be replaced by other
valid values. The %%~ syntax is terminated by a valid argument
number. The %%~ modifiers may not be used with %%*
If Command Extensions are enabled SETLOCAL changes as follows:
SETLOCAL batch command now accepts optional arguments:
ENABLEEXTENSIONS / DISABLEEXTENSIONS
enable or disable command processor extensions. See
CMD /? for details.
ENABLEDELAYEDEXPANSION / DISABLEDELAYEDEXPANSION
enable or disable delayed environment variable
expansion. See SET /? for details.
These modifications last until the matching ENDLOCAL command,
regardless of their setting prior to the SETLOCAL command.
The SETLOCAL command will set the ERRORLEVEL value if given
an argument. It will be zero if one of the two valid arguments
is given and one otherwise. You can use this in batch scripts
to determine if the extensions are available, using the following
technique:
VERIFY OTHER 2>nul
SETLOCAL ENABLEEXTENSIONS
IF ERRORLEVEL 1 echo Unable to enable extensions
This works because on old versions of CMD.EXE, SETLOCAL does NOT
set the ERRORLEVEL value. The VERIFY command with a bad argument
initializes the ERRORLEVEL value to a non-zero value.
If Command Extensions are enabled ENDLOCAL changes as follows:
If the corresponding SETLOCAL enable or disabled command extensions
using the new ENABLEEXTENSIONS or DISABLEEXTENSIONS options, then
after the ENDLOCAL, the enabled/disabled state of command extensions
will be restored to what it was prior to the matching SETLOCAL
command execution.
If Command Extensions are enabled, external command invocation
through the command line or the START command changes as follows:
non-executable files may be invoked through their file association just
by typing the name of the file as a command. (e.g. WORD.DOC would
launch the application associated with the .DOC file extension).
See the ASSOC and FTYPE commands for how to create these
associations from within a command script.
When executing an application that is a 32-bit GUI application, CMD.EXE
does not wait for the application to terminate before returning to
the command prompt. This new behavior does NOT occur if executing
within a command script.
When executing a command line whose first token is the string "CMD "
without an extension or path qualifier, then "CMD" is replaced with
the value of the COMSPEC variable. This prevents picking up CMD.EXE
from the current directory.
When executing a command line whose first token does NOT contain an
extension, then CMD.EXE uses the value of the PATHEXT
environment variable to determine which extensions to look for
and in what order. The default value for the PATHEXT variable
is:
.COM;.EXE;.BAT;.CMD
Notice the syntax is the same as the PATH variable, with
semicolons separating the different elements.
When searching for an executable, if there is no match on any extension,
then looks to see if the name matches a directory name. If it does, the
START command launches the Explorer on that path. If done from the
command line, it is the equivalent to doing a CD /D to that path.
If Command Extensions are enabled, and running on the Windows XP
platform, then the BREAK command will enter a hard coded breakpoint
if being debugged by a debugger.
If Command Extensions are enabled, the following additional
forms of the FOR command are supported:
FOR /D %%variable IN (set) DO command [command-parameters]
If set contains wildcards, then specifies to match against directory
names instead of file names.
FOR /R [[drive:]path] %%variable IN (set) DO command [command-parameters]
Walks the directory tree rooted at [drive:]path, executing the FOR
statement in each directory of the tree. If no directory
specification is specified after /R then the current directory is
assumed. If set is just a single period (.) character then it
will just enumerate the directory tree.
FOR /L %%variable IN (start,step,end) DO command [command-parameters]
The set is a sequence of numbers from start to end, by step amount.
So (1,1,5) would generate the sequence 1 2 3 4 5 and (5,-1,1) would
generate the sequence (5 4 3 2 1)
FOR /F ["options"] %%variable IN (file-set) DO command [command-parameters]
FOR /F ["options"] %%variable IN ("string") DO command [command-parameters]
FOR /F ["options"] %%variable IN ('command') DO command [command-parameters]
or, if usebackq option present:
FOR /F ["options"] %%variable IN (file-set) DO command [command-parameters]
FOR /F ["options"] %%variable IN ('string') DO command [command-parameters]
FOR /F ["options"] %%variable IN (`command`) DO command [command-parameters]
filenameset is one or more file names. Each file is opened, read
and processed before going on to the next file in filenameset.
Processing consists of reading in the file, breaking it up into
individual lines of text and then parsing each line into zero or
more tokens. The body of the for loop is then called with the
variable value(s) set to the found token string(s). By default, /F
passes the first blank separated token from each line of each file.
Blank lines are skipped. You can override the default parsing
behavior by specifying the optional "options" parameter. This
is a quoted string which contains one or more keywords to specify
different parsing options. The keywords are:
eol=c - specifies an end of line comment character
(just one)
skip=n - specifies the number of lines to skip at the
beginning of the file.
delims=xxx - specifies a delimiter set. This replaces the
default delimiter set of space and tab.
tokens=x,y,m-n - specifies which tokens from each line are to
be passed to the for body for each iteration.
This will cause additional variable names to
be allocated. The m-n form is a range,
specifying the mth through the nth tokens. If
the last character in the tokens= string is an
asterisk, then an additional variable is
allocated and receives the remaining text on
the line after the last token parsed.
usebackq - specifies that the new semantics are in force,
where a back quoted string is executed as a
command and a single quoted string is a
literal string command and allows the use of
double quotes to quote file names in
filenameset.
Some examples might help:
FOR /F "eol=; tokens=2,3* delims=, " %%i in (myfile.txt) do @echo %%i %%j %%k
would parse each line in myfile.txt, ignoring lines that begin with
a semicolon, passing the 2nd and 3rd token from each line to the for
body, with tokens delimited by commas and/or spaces. Notice the for
body statements reference %%i to get the 2nd token, %%j to get the
3rd token, and %%k to get all remaining tokens after the 3rd. For
file names that contain spaces, you need to quote the filenames with
double quotes. In order to use double quotes in this manner, you also
need to use the usebackq option, otherwise the double quotes will be
interpreted as defining a literal string to parse.
%%i is explicitly declared in the for statement and the %%j and %%k
are implicitly declared via the tokens= option. You can specify up
to 26 tokens via the tokens= line, provided it does not cause an
attempt to declare a variable higher than the letter 'z' or 'Z'.
Remember, FOR variables are single-letter, case sensitive, global,
and you can't have more than 52 total active at any one time.
You can also use the FOR /F parsing logic on an immediate string, by
making the filenameset between the parenthesis a quoted string,
using single quote characters. It will be treated as a single line
of input from a file and parsed.
Finally, you can use the FOR /F command to parse the output of a
command. You do this by making the filenameset between the
parenthesis a back quoted string. It will be treated as a command
line, which is passed to a child CMD.EXE and the output is captured
into memory and parsed as if it was a file. So the following
example:
FOR /F "usebackq delims==" %%i IN (`set`) DO @echo %%i
would enumerate the environment variable names in the current
environment.
In addition, substitution of FOR variable references has been enhanced.
You can now use the following optional syntax:
%%~I - expands %%I removing any surrounding quotes (")
%%~fI - expands %%I to a fully qualified path name
%%~dI - expands %%I to a drive letter only
%%~pI - expands %%I to a path only
%%~nI - expands %%I to a file name only
%%~xI - expands %%I to a file extension only
%%~sI - expanded path contains short names only
%%~aI - expands %%I to file attributes of file
%%~tI - expands %%I to date/time of file
%%~zI - expands %%I to size of file
%%~$PATH:I - searches the directories listed in the PATH
environment variable and expands %%I to the
fully qualified name of the first one found.
If the environment variable name is not
defined or the file is not found by the
search, then this modifier expands to the
empty string
The modifiers can be combined to get compound results:
%%~dpI - expands %%I to a drive letter and path only
%%~nxI - expands %%I to a file name and extension only
%%~fsI - expands %%I to a full path name with short names only
%%~dp$PATH:I - searches the directories listed in the PATH
environment variable for %%I and expands to the
drive letter and path of the first one found.
%%~ftzaI - expands %%I to a DIR like output line
In the above examples %%I and PATH can be replaced by other valid
values. The %%~ syntax is terminated by a valid FOR variable name.
Picking upper case variable names like %%I makes it more readable and
avoids confusion with the modifiers, which are not case sensitive.
If Command Extensions are enabled IF changes as follows:
IF [/I] string1 compare-op string2 command
IF CMDEXTVERSION number command
IF DEFINED variable command
where compare-op may be one of:
EQU - equal
NEQ - not equal
LSS - less than
LEQ - less than or equal
GTR - greater than
GEQ - greater than or equal
and the /I switch, if specified, says to do case insensitive string
compares. The /I switch can also be used on the string1==string2 form
of IF. These comparisons are generic, in that if both string1 and
string2 are both comprised of all numeric digits, then the strings are
converted to numbers and a numeric comparison is performed.
The CMDEXTVERSION conditional works just like ERRORLEVEL, except it is
comparing against an internal version number associated with the Command
Extensions. The first version is 1. It will be incremented by one when
significant enhancements are added to the Command Extensions.
CMDEXTVERSION conditional is never true when Command Extensions are
disabled.
The DEFINED conditional works just like EXISTS except it takes an
environment variable name and returns true if the environment variable
is defined.
%%ERRORLEVEL%% will expand into a string representation of
the current value of ERRORLEVEL, provided that there is not already
an environment variable with the name ERRORLEVEL, in which case you
will get its value instead. After running a program, the following
illustrates ERRORLEVEL use:
goto answer%%ERRORLEVEL%%
:answer0
echo Program had return code 0
:answer1
echo Program had return code 1
You can also using the numerical comparisons above:
IF %%ERRORLEVEL%% LEQ 1 goto okay
%%CMDCMDLINE%% will expand into the original command line passed to
CMD.EXE prior to any processing by CMD.EXE, provided that there is not
already an environment variable with the name CMDCMDLINE, in which case
you will get its value instead.
%%CMDEXTVERSION%% will expand into a string representation of the
current value of CMDEXTVERSION, provided that there is not already
an environment variable with the name CMDEXTVERSION, in which case you
will get its value instead.
Enables or disables command line editing on DOS system
This is present for Compatibility with DOS systems. It has no effect
under Windows XP, as command line editing is always enabled.
CMD.EXE was started with the above path as the current directory.
UNC paths are not supported. Defaulting to Windows directory.
CMD does not support UNC paths as current directories.
UNC paths not supported for current directory. Using
PUSHD %1
to create temporary drive letter to support UNC current
directory. Use POPD or EXIT to delete temporary drive
letter.
Invalid parameter to SHIFT command
Unbalanced parenthesis.
Missing operand.
Missing operator.
Invalid number. Numeric constants are either decimal (17),
hexadecimal (0x11), or octal (021).
Invalid number. Numbers are limited to 32-bits of precision.
Divide by zero error.
The COMSPEC environment variable does not point to CMD.EXE.
Overwrite %1? (Yes/No/All): %0
<JUNCTION> %0
The directory name %1\%2 is too long.
The full path of %1 is too long.
The path %1\%2 is too long.
Unable to find library %1.
Cannot find function %1!S!:%2!S!.
Cannot find ordinal %1!S!:%2!d!.
File Not Found
Could Not Find %1
The FAT File System only support Last Write Times
Begins localization of environment changes in a batch file. Environment
changes made after SETLOCAL has been issued are local to the batch file.
ENDLOCAL must be issued to restore the previous settings. When the end
of a batch script is reached, an implied ENDLOCAL is executed for any
outstanding SETLOCAL commands issued by that batch script.
SETLOCAL
Ends localization of environment changes in a batch file.
Environment changes made after ENDLOCAL has been issued are
not local to the batch file; the previous settings are not
restored on termination of the batch file.
ENDLOCAL
Sets the window title for the command prompt window.
TITLE [string]
string Specifies the title for the command prompt window.
Allows programs to open data files in specified directories as if they were
in the current directory.
APPEND [[drive:]path[;...]] [/X[:ON | :OFF]] [/PATH:ON | /PATH:OFF] [/E]
APPEND ;
[drive:]path Specifies a drive and directory to append.
/X:ON Applies appended directories to file searches and
application execution.
/X:OFF Applies appended directories only to requests to open files.
/X:OFF is the default setting.
/PATH:ON Applies the appended directories to file requests that already
specify a path. /PATH:ON is the default setting.
/PATH:OFF Turns off the effect of /PATH:ON.
/E Stores a copy of the appended directory list in an environment
variable named APPEND. /E may be used only the first time
you use APPEND after starting up your system.
Type APPEND ; to clear the appended directory list.
Type APPEND without parameters to display the appended directory list.
Moves files and renames files and directories.
To move one or more files:
MOVE [/Y | /-Y] [drive:][path]filename1[,...] destination
To rename a directory:
MOVE [/Y | /-Y] [drive:][path]dirname1 dirname2
[drive:][path]filename1 Specifies the location and name of the file
or files you want to move.
destination Specifies the new location of the file. Destination
can consist of a drive letter and colon, a
directory name, or a combination. If you are moving
only one file, you can also include a filename if
you want to rename the file when you move it.
[drive:][path]dirname1 Specifies the directory you want to rename.
dirname2 Specifies the new name of the directory.
/Y Suppresses prompting to confirm you want to
overwrite an existing destination file.
/-Y Causes prompting to confirm you want to overwrite
an existing destination file.
The switch /Y may be present in the COPYCMD environment variable.
This may be overridden with /-Y on the command line. Default is
to prompt on overwrites unless MOVE command is being executed from
within a batch script.
Stores the current directory for use by the POPD command, then
changes to the specified directory.
PUSHD [path | ..]
path Specifies the directory to make the current directory.
Changes to the directory stored by the PUSHD command.
%1 - %0
Maximum setlocal recursion level reached.
Enter the new date: (yy-mm-dd) %0
Enter the new date: (dd-mm-yy) %0
ERROR Verify - %1
Cannot move multiple files to a single file.
The handle could not be opened
during redirection of handle %1.
%r%1%% copied %0
Sets the default console foreground and background colors.
COLOR [attr]
attr Specifies color attribute of console output
Color attributes are specified by TWO hex digits -- the first
corresponds to the background; the second the foreground. Each digit
can be any of the following values:
0 = Black 8 = Gray
1 = Blue 9 = Light Blue
2 = Green A = Light Green
3 = Aqua B = Light Aqua
4 = Red C = Light Red
5 = Purple D = Light Purple
6 = Yellow E = Light Yellow
7 = White F = Bright White
If no argument is given, this command restores the color to what it was
when CMD.EXE started. This value either comes from the current console
window, the /T command line switch or from the DefaultColor registry
value.
The COLOR command sets ERRORLEVEL to 1 if an attempt is made to execute
the COLOR command with a foreground and background color that are the
Example: "COLOR fc" produces light red on bright white
Maximum path length exceeded - %1
****** B A T C H R E C U R S I O N exceeds STACK limits ******
Recursion Count=%1!d!, Stack Usage=%2!d! percent
****** B A T C H PROCESSING IS A B O R T E D ******
There are too many directories already in the PUSHD stack.
The command prompt has been disabled by your administrator.

DNS

Name Response Post-Analysis Lookup
dns.msftncsi.com A 131.107.255.255 131.107.255.255
dns.msftncsi.com AAAA fd3e:4f5a:5b81::1 131.107.255.255

TCP

No TCP connections recorded.

UDP

Source Source Port Destination Destination Port
192.168.56.101 53179 224.0.0.252 5355
192.168.56.101 49642 224.0.0.252 5355
192.168.56.101 137 192.168.56.255 137
192.168.56.101 61714 114.114.114.114 53
192.168.56.101 56933 114.114.114.114 53
192.168.56.101 138 192.168.56.255 138

HTTP & HTTPS Requests

No HTTP requests performed.

ICMP traffic

No ICMP traffic performed.

IRC traffic

No IRC requests performed.

Suricata Alerts

No Suricata Alerts

Suricata TLS

No Suricata TLS

Snort Alerts

No Snort Alerts

Sorry! No dropped files.
Sorry! No dropped buffers.