MZ@ !L!This program cannot be run in DOS mode. $rGGGGGGGGGGGGGGGGGRichGPEd }R"  n"H`T<`@BD@8.text hNONPAGEDS  h.rdata@ 0@H.data0 P:@.pdata`<@HPAGE*p,> `INITj .rsrc@B.reloc2@BLD$LL$ SUVWH(H3HHB H=Gx5HZLL$hHHӋo1xHH;wuf,_f,_Htf/H(_^][H\$WH HH/HHt FLtr;1HHt FLtr$1HHt FLtr 1H{PHtR?uFLtrH0=]@H :@L0f;=@rE@HT@H @HJ0?H }?0f;?r?H?H V?H 0H\$0H _@USVWATAUAWHHl$PHH^>H3H EDMIHLHHE3LmDmDmD3EEF`GFDJDwNDoRHVF`tHVhHtDHF`HE3DHEtHHtMHIE3Et*HHtAEH[HE32MEtHHtMH/IE3HNHtyLIMtIfA9:tBDHF fD;v1A+LcIHHF HF+HH$Ht"HQHtDHHFHE3fDHHF HH Ht#HP(HtDH}HF H HE3fDHHF HHHt#HPHtDHEHF HHE3fDHHN Ht"HQHtDHHN HE3fDH\$PHt$XH A_A^A]A\_̃y|VLIAA<t:<t0<t < t(<t<u6AAHAHH8#AA HAHH(AAA HAHH0I@SH DHAu&HIHt FLtrF HHtH [:00000000-0x00000000:00000001-@USWAUH(LHj@HHMHt} HM0HtHMHt FLtrHM Ht FLtrjHHHHHt FLtr?HHXPHtV;uFLtrHAH hzf;krsHHHH ;uHH 6f;rHHHH w1H'H(A]_[]@UAUH8LHjPHHM8HtHMHt FLtrRHHtHM(Ht FLtr*H8A]]@UAUH8LHjPHHMPHtNMtuTFLtrHMCOH ,>f;/r7HMHDHUH 7H8A]]lV@(شvZD*ҳjR>*̱|Rnв^J( ̰r`R:"įhP20Ȯ}R&D4D75D8303-6C21-4bde-9C98-ECC6320F9291058DD951-7604-414d-A5D6-A56D35367A467DA1385C-F8F5-41cc-B9D0-02FCA090F1EC127D46AF-4AD3-489f-9165-F00BA64D5467lN2v€BB CpC-L2`ZP@RSDSd GXޜ6hfiletrace.pdb td4#ӡrPBp ` P 0R0 pp2P T4 R p `rp d T 42p 4p`Pwzݘ* t*d)4(&Da0"RP1 4-" p`PD ~&9@   Bp0P  4 2p, p p`0PDl r&P bP3 d4 p PD0)/_:P * dvp pPD412:&P  d 4 2p6660X d T 4 Rp$  p`P% 4 p`P`+ #t##d!#4 #Px%   p0P   4 2p20 < 4 2p  4 Rp d 4 R p P  4 2p20B t dT422-+] fp]!lK2QٍvMA֥m56zF\8}AF}JHe MTgzE|~hFnxFG@HHrHHDHDH9H@9HrF 'F'Z0F\03 G38HG|88PH9_:TF_::F:S;Fpp$EpsTEsupEu w|E w{E{{|G{|G|HGHG Gؒ@Hܒ\H%lH(N|HݘHEݘ HE ,H D *E0E0RF@SH0d$ @AFLtr3HHu \$ ]L3H%H%%E3H H i؉D$ HyHtFLtrH=H%mH0[H\$Hl$VWATAVAWH0L$3IA!A;rND3I!^.FH(H H!HHv FH;|A.]#OA)A@AL#Aԋ0LvL#AԋM΃L= I3H I{HcHHH;Fu HDH;F t/|L}#AԹI;tH 3y uHfD91t H(|LH#DAԹ'yHHcL;#LHFLE@HNHHI H0)H =uHVDEHHR FLtrAL#D;qAMAAtfAA\A:Au3AFLtrHHHcHFH@HkHF@]I Nttt03AFLtrHHHut tAAFLtr3AAҶHHHHF@yAFLtr3HHHly0A0AFLtrA3ɋoHHHAHNHAHHA HBHA(HBHA0HBHA8HB HA@HB(HVH DB0HR(IHLpAt}AA HAtAA13AFLtrHHHHF@HFH H@HHAHH}H3AFLtroHHHAHF@HFHHH HHBHAHBHAHB HAHB(HA HB0HA(HB8HA0HB@HH@HEȉ83HMH3苋H$HpA_A^A]A\_^]HHXHpHx D@UATAUAVAWHHhHELE3DeLeLeLe@ALe8A3HE HE(HUHI ExVHU HM%ExAHE(Et$Ht,fD9u v2fx:u+ȃAwA} AAu}AH ̳AL U0}HcH AD r uAAH AFLtru ]Eĺ AHHE8HuIEHF~D~HNs؉EtH '!H HL=L~L9xt)HpH5H AHEHD$ E3AH ؉EE33AHM LM@LE3IM؉EHM@HtܰHE$H0HEHMHHA(HEfDp A,HEfD@"HMH3苍HE ft'HMf;A"wDHU(HI('HM HEfH HMHA4HAHEfDpAHEfD@HMH43(LE 3IM؉Eu #} wTU E3HMHAHML9qt'E fAE3HUIM؉E ]HUHE3IMjHML9qteLuHLLMHVxGLEIHD$0IEHD$(HHD$ L vM3ҍJ L=HMHt|HM(Ht3Ht}H yH=bH;t H?I;u?HO7HHHHHAH9JuH9uHHBAH;)H AHHMHtZL$I[0Is8I{HIA_A^A]A\]H\$WH H {H دH ˯H ԽH Ht FLtrH smH=V2HH9{uTH9XuNH>HxHK FLtrHBHH;uH !$H\$03H _ù)3H\$WH HQHd$0HH LD$0cxHD$0HHtH HH H;tHGH9Ct0HH;uH HL$0HtɬH\$8H _HK4H HCH9YuH9uHHAFLtrH=륹)H\$WH0HAHH;$uJHA H;u=ϬHHt/HL1AHH|$ y H3H\$@H0_H\$Ht$UWAVHH0E33HHU8IILu8Lu0AHEHE(HM8HUBfD9uH LE0HëxiHEAVAf+fwHEZHE0f+HE0 H ݬH جHE0HM0HtHMHt3H]H\$PHt$XH0A^_]IRP_MN_ENABLE_EVENTS: logger = %I64X, No matching guid TargetIndex = %d, Refcount now %d FileTrace!DisableSession: lh %I64X, target session %d, SESSION NOT FOUND! active session flags 0x%x FileTrace!DetachFromDrives: Start, kept drives 0x%x NOTHING!!! Detaching from 0x%x Keeping attachment to 0x%x FileTrace!DetachFromDrives: END FileTrace!AttachToRequestedDrives: Start Checking Volume: All drives mask Network drive mask Local drive mask Bad device object ->FAIL Drive letter '%c' Bit mask 0x%x Bad volume name ->PASS ->FAIL FileTrace!AttachToRequestedDrives: End @UH H} }H bHtFLtrH%JH ]@UH HFLtrHHH ]@USWAUHHLHHHMHt|HM(Ht 3}H}8HH smHVH;tHHEH;uAHK$HHHHHAH9JuH9uHHBFLtrH&)H FLtrHHMHtBHHA]_[]HHXHpHxATAVAWH`L@ H6 HHHL$HѡHE3D=D=icL5HYHZHKQL=RD=SE3AWH M_fD|$0FLtr\$(HD$ E3E33H RfD|$0\$(HD$ E3E33H H*D|$DH 683Ax L%AI|A߉\$DesXH4@I|$H*̱|Rnв^J( ̰r`R:"įhP20ȮExInitializeNPagedLookasideListRtlInitUnicodeStringxMmGetSystemRoutineAddressKeInitializeEventExDeleteNPagedLookasideListExAllocatePoolWithTag+IoWMIRegistrationControlExFreePoolWithTagExReleaseFastMutexxExAcquireFastMutex&WmiQueryTraceInformation'RtlQueryRegistryValuesIoVolumeDeviceToDosName- _vsnwprintfNObfDereferenceObjectqRtlUpcaseUnicodeCharUDbgPrintEx0IoWMIWriteEventPsReferenceImpersonationTokenPsReferencePrimaryTokenExpInterlockedPushEntrySList"RtlAppendUnicodeToStringPsGetProcessCreateTimeQuadPartExpInterlockedPopEntrySList!RtlAppendUnicodeStringToStringExQueryDepthSListRtlLengthSecurityDescriptorSeQueryInformationTokenPsGetProcessSessionIdRtlAbsoluteToSelfRelativeSDPsDereferenceImpersonationTokenIoGetTopLevelIrp|MmIsAddressValidZwQueryInformationFilePsGetProcessWin32WindowStationPsDereferencePrimaryTokenIoRegisterPlugPlayNotification~IoGetDeviceObjectPointerIoUnregisterPlugPlayNotificationExInterlockedInsertHeadListKeInitializeSpinLockntoskrnl.exeFltUnregisterFilterFltRegisterFilterFltStartFilteringFltObjectDereferenceFltAllocateGenericWorkItemFltQueueGenericWorkItemQFltEnumerateVolumes]FltFreeGenericWorkItemgFltGetDiskDeviceObjectFltGetVolumePropertiesFltAttachVolumeEFltDetachVolumezFltGetRequestorProcessFltGetVolumeContext{FltGetRequestorProcessIdFltQuerySecurityObjectFltQueryVolumeInformationFltIsDirectoryFltQueryInformationFileFltReleaseContextjFltGetFileNameInformationFltReleaseFileNameInformationFltGetVolumeGuidName FltAllocateContextFltObjectReferenceFltGetVolumeNameFltSetVolumeContextFLTMGR.SYS __C_specific_handler(@Xpr   \MUI4VS_VERSION_INFO@%@%?StringFileInfo040904B0LCompanyNameMicrosoft CorporationZFileDescriptionFile Trace Filter Driverr)FileVersion6.3.9600.16384 (winblue_rtm.130821-1623)<InternalNamefiletrace.sys.LegalCopyright Microsoft Corporation. All rights reserved.DOriginalFilenamefiletrace.sysj%ProductNameMicrosoft Windows Operating SystemBProductVersion6.3.9600.16384DVarFileInfo$Translation ETW File Trace Filter FileTrace,'g;c @íbє*Etb{{ MUIMUIen-US@УأXpP hإPpȦЦ(0HPhpȧЧ(0HhpȨШ(0HPhpȩЩ(0HPpȪЪ(0