403Webshell
Server IP : 209.209.40.120  /  Your IP : 216.73.217.112
Web Server : Microsoft-IIS/10.0
System : Windows NT NEWWWW 10.0 build 17763 (Windows Server 2019) i586
User : NEWWWW$ ( 0)
PHP Version : 8.3.30
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  C:/Windows/SysWOW64/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : C:/Windows/SysWOW64//vrfcore.dll
MZ����@���	�!�L�!This program cannot be run in DOS mode.

$�]K�|K�|K�|_�}H�|K�}�|_�M�|_�xM�|_�|J�|_�uZ�|_�J�|_�~J�|RichK�|PEL$��!�N`+�


@�@A@��@�(��p((0�)T���8.text7�� `.data�� �@�.idata��
�@@.rsrc����@@.reloc�0b@B��������p�\  �  @\Registry\Machine\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\� ���`)8�4Du0+P+`+�01P105�;P<�<=P>�>?0@�A�BpC�CD�DF0F`F�F�F�F�Hg�h�hi�m opu�z�p���P������А�p�0�ИР�P�УФP������`�@�����`��� �P�0�p�\\//ntdll.dllLdrGetProcedureAddressForCallerRtlAllocateHeapRtlReAllocateHeapRtlFreeHeapLdrGetProcedureAddressLdrGetProcedureAddressExCreateProcessWCreateProcessACreateProcessInternalWCreateProcessInternalAGetProcAddressVerifierGetPropertyValueByNamekernel32.dllverifier.dllPropagateAutoClr{E5DCDFAA-3B35-46A8-B370-9D3575A68E53}Coreonecore\base\avrf\avrf30\vrfcore\vrfcore.cpp_DllMainAVRF: Verifier Provider failed to initialized itself for DLL_PROCESS_VERIFIER.
Process will be terminated.AVRF: NtQueryVirtualMemory failed, error code: %u
AVRF: Verifier!AvrfpProvider : %p
AVRF: ERROR - Couldn't found Verifier!AvrfpProvider
%sStop-%08X-ErrorReportStop-%08X-SeverityStop-%08X-FlavorAVRF: Duplicate hooking tables for dll [%ws] found. Will chain the hooks.
AVRF: Duplicate [%ws!%s] (@ %p)[ %p %p ] <= (@ %p)[ %p %p ]
VerifierIsAddressInAnyPageHeapAVRF: Couldn't read %s @ %p
AVRF: Read just %Ix out of %Ix bytes of %s @ %p
StopProcessingstop codeAVRF: failed to allocated a verifier TLS slot.
Expected Thread IDThread IDExpected TEB addressTEB addressCorrupted TLS structureAVRF: verifier log file %ws kept open for too long (status %X)
AVRF: failed to open verifier log file %ws (status %X)
AVRF: Wait for pending write I/O operation failed with %X 
AVRF: failed to write into verifier log file %ws (status %X)
{ApplicationVerifierGlobalSettings}ProtectedProcessLogPathVERIFIER_LOG_PATHUSERPROFILETEMPAVRF: Failed to determine the parent directory for the logs (status %X)
\AppVerifierLogsAVRF: Failed to translate file name %S (status %X)
AVRF: Failed to create logging directory %ws (status %X)
AVRF: Created logging directory %ws 
%ws\%ws.%u.datAVRF: Failed to convert to an NT path the verifier log path.
AVRF: failed to create verifier log file %ws (status %X)

AVRF:bogus string length, overflow

AVRF:Failed to save message into stop list
LogToFileonecore\base\avrf\avrf30\vrfcore\breaks.cppVfCoreRegisterBreaks%ws-%wsGlobalFlagVerifierFlagsVerifierDlls 0x%XAVRF: VfCoreFindMostRecentThunk => searching provider (%p) 
AVRF: VfCoreFindMostRecentThunk => searching thunks for %ws 
AVRF: VfCoreFindMostRecentThunk => searching for %p in thunk %s [ %p %p ]
AVRF: VfCoreFindMostRecentThunk => %p (hook chain length %u)
AVRF: VfCoreFindMostRecentThunk => %p (hook chain length %u) is not hooked by any verifier provider
AVRF: failed to make R/W old verifier stop function @ %p (%X) 
AVRF: failed to revert protection of old verifier stop function @ %p (%X) 
VerifierRedirectStopFunctionsVerifierStopMessageRtlApplicationVerifierStopPageHeapSizeRangeStartPageHeapSizeRangeEndPageHeapDllRangeStartPageHeapDllRangeEndPageHeapTargetDllsPageHeapFaultProbabilityPageHeapFaultTimeOutPageHeapRandomProbabilityDelayFreeSizeMB{4D056CEB-D8E3-4b85-B148-B543D56D9BDE}HeapsBasics{7CF16601-5646-4ecf-ACAF-D8B5872A0291}RPCForceDllUnloadUnloadPeriodMsSecuritySettingsEventRemoveCheckAggresiveMTATesting{91067D4F-67E6-4768-BEA4-2565236FDCBE}COMLocksHandlesStacksTLSMemoryExceptionsDirtyStacksDangerousAPIsRaceDeadLockLowResThreadpoolInputOutputLeakSRWLock0x%xPageHeapFlagsonecore\base\avrf\avrf30\vrfcore\base.cppVfRegisterBaseLayersVfUnregisterBaseLayersAVRF: VerifierIsLayerEnabled failed for %ws
TlsAllocTlsFreeTlsGetValueTlsSetValueSHSMP.DLLsmartcpu.dllTTDRecordCPU.dllTTTraceWriter.dllTTDWriter.dllvfbasics.dllAVRF: %ws: null entry point.
AVRF: %ws @ %p: entry point @ %p .
AVRF: low memory: will not verify entry point for %ws .
AVRF: hooked dll entry point for dll %ws 
AVRF: Failed to roll back all the hookings 
AVRF: Failed to snap provider's IAT 
AVRF: dll entry @ %p (%ws, %x) 
AVRF: Failed to resnap provider %ws .
AVRF: Could not find the section that owns the Delay Import Directory.
delayloaded dll %s for %ws.
AVRF: low memory: Failed to allocate dll info node for %ws .
AVRF: cretae delay load dll node %ws .
AVRF: Provider (%p - %p) 
AVRF: Unable to unprotect IAT to modify thunks (status %08X).
AVRF: Rollback (%ws: %p) with (%p). 
AVRF: internal error: New thunk for %s is null. 
AVRF: Snapped (%ws: %s) with (%ws: %p). 
AVRF: fault injecting call made from %p 
AVRF:FINJ: invalid fault injection class %X 
$�$l)l$�
p�)�$�$+ �P�p�RSDS���%"�~��J�\9vrfcore.pdbGCTL4.rdata$brc4\.gfids��.rdata`).rdata$sxdatal)�.rdata$zzzdbg0+`�.text$mn���.xdata$x@��.edata��.data$brc�� .data��(�.bss�8.idata$58�.00cfg@�.idata$2T�.idata$3h�8.idata$4��4.idata$6�P.rsrc$01P��v.rsrc$02 ���%"�~��J�\9<���6a���$���U��=�t�M3�B�.]�����������������̋�U��}ujjj��u�U�M�]���U���SV3���W3�F+��]+���+���+���+��9}u;��5��F���� �t������<�0�����3��Ad�0�T��5��Q����L����y��5��F���������K��y��5��F���������=��3�������E�Ph��3�WW����x-�E�PWh���u�����x3�������3�������3�d�0�(
f9��u
�\��E�\��k��y��5��F������9����1��y��5��F������E���E�PS����y��5��F������P��E�P�p �p�p0�ch\�S�Yk��y��5��F������`�d�b}��y��5��F������l�B�K&��y��5��F������x� �\s��y`��5��F�������� �t������0��=L����wh�Wj]����h�j�� ���_^[��9=��t���&��9=��t��&��9=�u�d�0�5��T��H��P���
;�t
9Yt���;�u���J��y.��5��F��������� �t��0������;��y��5��F��������ǻt9=��tt�ER�(��y2����
��A���� ������������0�Wh0+W����yH��5��F���� ������Q����s/��y��5��F������"�!����
T����W�7��t#��5��F���� �����0��9=�t�p{�=��Y���G����������u`h���5T��8��t��5��F������U����Y��t��5��F������`�e���h����9=����������������.�h���������5��F������t������������������̋�U��}|3��"�E;Xt;\t�M�{L��u�E]�����������̋�U��V�5����W�}W�u�u�u�8��֋�xj�7�u�u������_^]�������������̋�U��V�5����W�u�}W�u�u�u�8��֋�xj�7�u�u�4������_^]���U���8���3ʼnE�S���VWjY���}��5����jj�Mȋ�Q%�jPj��E���������}�t�}�@t�u��u��Dd�0�(
�f9��u�����,u$�F;�s;��rj�0�E�P������t1��;��s���htjj]�������M�_^3�[��y�Ã=D��5��tVhPjj]����3���Whjj]�������d�Ë�U��u��uQ��]���U��E3Ʌ�t=���v�W���x�M��Q�uQ�M������t�E3�f���]Ë�U��E3Ʌ�t=���v�W���x�M��Q�uQ�M�(���
��t�E���]�U��Q�e��E�P�Y�U��t��x�M��
��"����U��Q3��E���t�E���P�m�ЋE���W��M��t
��x����!������U��QV��`��΀8t@��u��U�����%���W���t
��t+�2��"^����U��VW3����t
f99t����u�M����%���W���t��t+�1��9_^]�����;��%W�ø���;��%W�Ë�U��SVW�u�r����u3�VW�8�����x;�wu
�>��>�z�_^��[]���U��SVW�u�r����u3�VW�$�����x;�wu
��z�3�f�w_^��[]���U���V��r������M���%��1^]����������������h�h�����E��,���3ۉ������ �����;���9\��*����P�����ˉ�0�����9t�Í<�;Eu��Fk�L9u뉍0�����uSSSSShh���r�����j
X���Q��4��������At�Yj@X9pt��4���9P�t��4���h��P���]�h`Sh �Y���jY��������E����}�=��E���E���E��3�f�x��0���9F8���E$P�v8Q��x�������������y.�5�h�Sj]������z�tDž ����#Dž���X��(���P��x�����(����t����(��������(���X� �}�=H�t��,����@$u
�7'�������Å�t�� �����=�����4�������=����$��(�vH��P�,������0����F�@�F�<hH�(��}�=P�T�E�X�\�E�`�d�E�h�l��4���tPj@X������=L��w	j=X����������QhHPj�@����D��w�`��d��D� � �l�Ft�x�����Dž�����|�������4���`u
�F �"d������������hx�v0�u�v(�u�v �u�vW�v�p �6�5�hh`��,�����@�����������$���P�Q���������É����;�$��������;�$���s$��_���;���������I��`��=hu��`�Ph�Sj]����;�$���s��;�����_�����끈_��=hu!h`�h�Sj]�����	��0����}����,�����4�����@��d�
0�yu,�=pu#�=P�u��t
��,����H̋�,�������������������F�������������F�E��]��}��]��F�E��]��E�E��]��F �E��]��E�Eĉ]ȋF(�Ẻ]ЋE�Eԉ]؋F0�E܉]�Dž<���!���@�����H�����D���DžL���DžP���AVrf��T�����������X�����<���P�`���� t��t�H̅�t�`��=H�t�"�E������W�����tD�u�5tSj]�����\�h!�j�� ���yP�5�Sj]����̋� ����43ۉh��X��SSSSPhh�������j	�1���3��M�d�
Y_^[���r������̋�U���QQ�d$VW�}��tn�u��tg�E��u
���uj�U��uh��L$3�Q���}.�)�~Lt3�V��t,�~t&h��L$Qj�v���)/�ȅ�u�D$����j	X_^��]���������������̋�U���QQ�d$VW�}��to�u��th�E��u
�Y��uj�V��uh��L$3�QB����-�)�~Lt3�V��t,�~t&h��L$Qj�v���.�ȅ�u�D$����j	X_^��]��������������̋�U��}t]�%L�]����������̋�U��Q�}Vt*�u��t#��t�v��u3��V�u����>u���j	X^Y]���U���S��3ۉE�V��W���������V�E�P�x��������M��
����uj��v�E�P�<��E�P�u��E�WjP�u��d���y3�=4���K����S�G��u9t0�>t(j�:��u9��u9��u9�߃�u9��v�GP�v�Tz���j[W����j	X_^[��������������������̋�U��QQ�e�V�uW��tI�}��tBh��U����/�ׅ�t=X�u
�M��F�������}���t	�u��L����j	X_^�����������̋�U���Q�}Vt*�u��t#��t�v��t�>tV�u���Lu�3��j	X^��]������������̋�U���$���3ʼnE�SV�u3�W�}f��������������9���6��������h�SP�t������������������������jY����������������u	����F�6������h�SP���������������u	����F�6������hSP������������O�����u	����F3��j	X�M�_^3�[�@l�����������̋�U��� ���3ʼnE�SV�u3�W�}f���������k���c9�[�~�j[tn�6������h�h�P�L�F���������������������t�������������������
Dž���������`�����~�tj�6������h�h�P���F���������������������t�������������������
Dž������������uw�~�tj�6������hh�P�h�F���������������������t�������������������
Dž���������|��u3��j	X�M�_^3�[�j�������������������̋�U��Q�EV��t8�u��t1�}u	�@d�3��%�M�QP�u�����u
�u�����3�@��3���j	X^����U���SV��3��E�W����t|��tx�G��tq��;�t
9wta9wt\��uj[P�E�P;�u"�<��E�P�u��D���y-=4�t&j'�!�<��w�E�wSVP�u��\���yj"^���j	X_^[�������̋�U���QQVW�}3��D$��td�u��t]9FtX�>t
9FtK9FtFh��T$����*�օ�t=X�u�L$�C�������|$��t
�t$�L����j	X_^��]��������̋�U��M3��Uf��m��yj*X�3�]������������̃=�t4�=`t3�@ád�d��xt�@t�;�u�3�@�`�3�Ë�V3��=@��u�7L���u����@���^��������̡@�Ë�U��QS�‹�VW�E��p�;srA�0�6�,�YY��u �~��M�1P�T�YY��t�����u��;sr	�E��Ë��3�_^[���������̋�U���V�u�v�>�VS�^W�]����P�6�,�YY��t�����u���=X�t�6h(jj]�����{��?���M��W��������!E�3ۋE�E������P�6�,�YY�����E��@�oP�7�T�Y���E�YuZ�}��Hu�}�O��K�=X�t;�Ӆ����׋υ�u��p�pP�r�qS�7�6htjj]���E���,�؃��E����u��E����E�����Z����E�t
��t�@�C���?�����]�����]�>�����_[^�����r��������̋�U��u�u�u�u�����x3��jX]������������d�0�@ht�o��t�x t3�@�3�����������N��t
�@t3�@�3�����������̋�U��Et&3�@�E�pt�l�Et�h�d��@4W3�]������������̡l����������̋�U��}tj	X��M���3�]���U��QVW�E���Pj�uWQ�H���y�}tDW�uh�jj]�����,�}�t&�}tW�uj�u�h�jj]�����A�_��^����U����ES�]VW���M�3ҁ8��U��u^h(�׍E�+H�Q��P�K��������}���+=H��E�h8Q�M�ǀP��������x^�E��W�E�Ph8�RR����x@Q���u���4���x+�
��+
H��U�99Bv�����9Bs�_��^[����U��QQSjj�E�3�PjQC�0���x$�}�ujj�E�Pjj��0���x3�9]��Ë�[������������������̋�U��Q�M�e�V�u������u����6�U�E��MW�}PW�����x�M���u
�?���A�U���t�
_^��jY�)ÉI�	�jY�)�9Ju�A9u�;‰B���jY�)�9HtjY�)��J�P�Ë�U��3���t�����v�W���xh����uQ���	��t3�f�]���U�������%���W���th����uQ�]���U��3���t�����v�W���x�}���v�W���u�uQ�c�	��t3�f�]���U��VW3����t
f99t����u�M����%���W���t��t+�1��9_^]�����;��%W�Ë�U���t)�EV�u+�W��t�<f��tf�9��N��u�_^��u����ҁ��3�f���z�]�d�0Qj�p�l�Ë�U��ud�0j�p���]�jh����l3ɉM܉M�M�M��E�PQj�t��E�d�0�@�@�p0�u��E�������ƋM�d�
Y_^[�Ëu�}�t�u�j����jhи�ql���3ɈM�
��E܉M��tJ��tF�M��d�0�x���E�PQj�t���M�;�t;Xu(�@0��e��E�������E܋M�d�
Y_^[�Ë�ˊM��t�u�j����jh���k3ɈM��E�
��M�M�d�0�x���E�PQj�t���]�7;�t(�v0h��,�YY��u5�F����F ����e��E�������E܋M�d�
Y_^[���6믊]��t�u�j���Ë�U��QV��W����s����G�M�E�SP�������x3�E����u���փ�����������x�E�+�ω0�E�3�[_^����U��� ���3ʼnE��ESVW�E��E3ۉE��E��Pj�E�]�P���]�B�E�V�U�]��p���x1S�E�P�u�V�����x�u�t������;�t�@��|���M�_^3�[��^���E�����������t/�E�0jW��j����tSV�S������3�f�_�E�83�몸�룋�VjY������u^�3ҋ�h�B�g�����^Ë�U����L�D$SVWPh�j<Z���������?���D$HSP�\$4�<�j�D$LP�D$XP�|������D$T�ωD$D���D$Phxj=Z�t��������xP�D$D�D$LP�<�j�D$LP�D$XP�|������D$T�ωD$<���D$Ph|j>Z�������V�|P�D$<�D$LP�<�j�D$LP�D$XP�|�����D$T�ωD$4���D$Ph�jAZ���������P�D$4�D$LP�<�j�D$LP�D$XP�|������\$T�D$Ph�j?Z�ω\$,���_������x��P�D$,�D$LP�<�j�D$LP�D$XP�|����>�\$T�D$Ph�j<Z�ω\$$�����������P�D$$�D$LP�<�j�D$LP�D$XP�|������\$T�D$Ph�j@Z�ω\$�����������P�D$�D$LP�<�j�D$LP�D$XP�|���xb�\$T�D$Ph�jBZ�ωt�P�����x4�=��D$HWP�<�j�D$LP�D$XP�|�����W���S����\$�t$����S�����\$�t$ ����S����\$$�t$(���S����\$,�t$0����t$4����t$8����t$<����t$@�z����t$D�q���S�k�����D$T3�����_^[��]ÍA�<	v�A�<w�A�ÍA�<w�A��2�Ë�U������3ʼnE�SV��څ��Q���I�Qf���f��u�+����&�.f�>{�$j-Xf9F�f9F�
f9F&�f9F0��f�~J}��W3�������f�N�K���f�N���@���f�N��
ЈU��/���f�N���$���f�N��
ЈU�����f�N
������f�N����
ЈU���f������j_���
ЈU�f�N����f�������f�N����
ЈU����f���������
ЈU�f�N���f������f�N����
ЈU��{���f����q������
ЈU�f�N�^���f����T���f�N����
ЈU��@���f����6������
ЈU�f�N�#���f�������j_���
ЈU�f�N����f���������
ЈU�f�N���f����������
ЈU�f�N����f���������
ЈU�f�N���f������f�L>��
ЈU����f�>��������u�
ЈU�3�����_����M�^3�[�^X�Ë�SVd�50��d�W��3����x�Wj�v@����ȃ��uhDWj]�������L�����C$�����
D�9PtjY�)�������P��DŽ�������_^[Ã=D��u3��d�
�D����Ã=D��td��D�����j<Y�����tCd�V���J$�` �H�H�P��9rtjY�)�q��J�
���^����V�k�����tm���ted�
9Nu�F;A$t.ht�q$h��vh�Qh��vh�hQ�h��F�9Bu�H9u��J3�����V��^�jY�)�yu�1�����A���U��E����A]�9	��Ë9Hu
�9Bu��J�jY�)��U��!f�Ef�A�Q]���U��QVWQ�E���P���r��x�E�+�Q�u��Q�G�_^����U��VW3����t
f99t����u�M����%���W���t��t+�1��9_^]�����;��%W�Ë�U��V3���t�����v�W���x�u�������E� ��^]���U���t+�EVW����+���t�<f��tf�9��N��u�_^��u����ҁ��3�f���z�]���U��SVW�u�r����u3�VW�$�����x
;�wt	����z�3�f�w�M��t�1_^��[]���U��A;�r�����;��M�%��]���U�������t3��#���xQQ����x�����]Ë�U����<�=�SVW�ډL$�m�=��`�=���S�L$$�3��D$ �ig����D$0�D$4�D$<@�D$8�D$@�D$D�3�PPPjPh�P�D$4P�D$PPh�D$8P�����C�;�u�D$ Pj���G��r��C���y8;�uP�5h��V�5hjj]��������3��D$(WPS�t$ �D$(�|$(PWWW�t$0�|$@�|$L�|$P�����u+WW�t$�Ȑ��x�t$�VhHWj]����̅�yV�5h�Wj]������t$�L��d�����_^[��]Ë�U��� ���3ʼnE�3��E�Vrf �E�E�E�d��E��@ �E�E�P�(�jZ�M������M�3��R�Ë�U��� ���3ʼnE�VW���P��������jP�^�G�����������G �����������������G$P���Dž��P���Dž����������|����M�_3�^�Q�Ë�U��� 3��f��S��V���b��yF�E�Pjh��
���u2�E��E�P�u��E��]��E����u���u3�����^[��d�0�@�@�@0Ë�U���DSVW��3�h@�ډ]�f��E�P�<��E���P�E�}�3�P�M�Qf�]�����yzhd�E�P�<��E�}�P�E�3�P�M�Qf�]�����yJh|�E�P�<��e��E�P�E�f�]�P3ۉ}�S�����yVh�Sj]��������3ۋU���h��Z���W�Đ����SS�E�PW�����uVWh�Sj]�������SSh!@ jjj�E��E��EȍE�SP�E��]�Ph��E��E�@P�]Љ]����u�d�
0��S�q�����yVh�h,Sj]�����3���h�hhSj]�����u��L�3�_^[�Ë�U��d�0��$�@SVW�@�X0����3���WSh�h�hh����������VVhh��������VVVjVh�V�E��E�P�E܉u�Pj�E��E�@P�E��u�u�����5�uhG���3��e�����yV�5h�jj]�������!�u��L���h�Vj]������_^[����U��QSWj ��Z����؅����c�
tV��td�E�P����u���yh,�'�֋��L�C��thx�֋��}���y+hT���Y�{�
�t�F��+ȃ� �
��5j�{��Y����9HtjY�)��K�X����^_[�Ë�SV�5���W�]3��VG3ɋ��;uI������r�=�u=�=�u4�=�u+�=�u"�~t�vhx�,�YY��t�63�;�u���_^[ø�3ɣ�����h��
��
��
��
���������U��QQ�E�����u^VW��V�P����09xuF�9Au?����
��y�E��E�h�P�E�Pj������;�u�V�X�V���_^��jY�)��U��QQV�1��uF��vF�e��E�jhPj�E��E�Pj������xR�E���������E��p�
��E���9QtjY�)��P�A�M����E���
����A��^��U��QSV��B��E�W�N3��^�;�v
���E����N�^�U��;�w���V��_^[�ÍB��)AË�U��� 3ɍE�APQh��M������u*jY�E��M�E�E�P�u��E��M��w���u����3�9E����Ë�U���<SV��3�W���E���}�M��u��k���c�X���X9�F�CH9s��E�93v��E�S�E�P�s��V�����t��M��S�EċE��E�CQP���g������C�M�S$���EȋE���M��E�C QP���7������C �M�S,���E̋E���M��E�C(QP�������t�C(�M�S4���EЋE���M��E�C0QP��������<�C0�M�SD���EԋE���M��E�C@QP��������C@�s8�M�S<���E؋E���ωE�E�PV�w���y�E��P���=����E��M�E��u�+��Ήu����E����U�x�0���u��@��P��H�K�H�H ��E�P�E�U�P��M�s�����-�U��E��M�P�E�P�s�k����
�U��E��M�P�E�P�s �K������U��E��M�P�E�P�s(�+������U��E��M�P�E�P�s0�������U��E��M�P�E�P�s8��������U��E��M�P�E�P�s@�����xq�=��}�t����
��xW����}�E��L�M�u�;�9���3�@����@���� ������������4�0���}�W������u��u��u��m��u��e��u��]��u��U��u��M��u��E����]�HD�pH3��SRRRRRhh�����3���@����@��!4�0��� ������M������_^[��SV3�W����t^��tZ9_tU����uG�w�;�v���v���v ���v(���v0���v8���v@���vL9u��_3��SSSSShh����������_^[�3��1�J��U��E���]��A9tjY�)�
�B��Q�U��V�u��t�����wV���W���y��t�&^]���U��VW3����t
f99t����u�M����%���W���t��t+�1��9_^]�;��%W��U��V3���t;Uv�W���x�u�������E� ��^]���U��3�V��t*�uSW�}+�t�f��t
f���O@��u�_[��u��H���3�f�1����M^��t���z�]���U��SVW�u�r����u3�VW�$�����x
;�wt	����z�3�f�w�M��t�1_^��[]��A�����������̋�U���4���3ʼnE�W�}���u2��t;S�E�P�E�Pj
j�@��؅�t V3���t�L���G2��tF;�r���|��^[�M���3�_�D�Ë�U���QSV�ً�W�������VL����yj��N�VP�����yj�3�9~t�֋��'�����yj����������h��P���� �؅�x#���N<��9tjY�)��A��
�h��X���yj��Et�����'����F`�D$PVW�]����u"V�t$�_��V�t$����t$�|��3�@��ljFd�F$t9=@�t	�vW��3��3�WWWWWhh�������j	X_^[��]������������������̋�U��U�Mj���]����������̋�U��u�U�M�h���]���������̋�U���Q�MSVW�����}����3�9wt�������yj
��O`���t�&��S�P��
����	�A�;�t+�	;�u�VVVVVhh�������j^S�X����9��<�9yu�G98u��A��jY�)3�VVVVVhh���Z����j	X_^[��]���h��������3��h����3�Ë�U��QS3�VW9Qu3��O���9P�t�yH9xw�qD�X;މu��ps�=�u��RW�u�SVhh������������_^[�Ë�U���,SVWh��E�U�3��M�P��<��E��E��E܍E�P�u�E��}�P�E�@�}�}�Ԑ��yjX�u�u��u��E�P�ܐ��yj�S�E�E܋E��E؍E�P�u�u�Ԑ=4�u"3�C9]�u&�E�}�PWWW�E�P�u�u����y��tj!�j _V�L���_^[����U���<���3ʼnE��ESVW�u����3��E�߉����������UP�����tjX�����������hWP��L���������������h�hP�����������P�����P�<������Dž���������������������P�uDž���@�������������Ԑ=4�u/�}u-������PWWW�����P�u������3�C��y�{V�L��NjM�_^3�[��?����U���SVW�����������G3ۅ�t4�wL�M��E�P�E��]��n�E��M�u�j/��G��w��ue3��|�F��t(�wL�M��E�P�E��]��(�E��M�t@�F�s�F��t(�wL�M��E�P�E�]���E�M�t�F�D��9u���6j+��-j,�j	X_^[����������������̋�U��S�]V3���uj	X�ZWh����P��
����t!�U��t
;;s�Aĉ��	G���u��3�Fh��X��}u�;��_���#��^[]���U���S���U�3ۉE��]�V��W�������s���������E�Ph�Wj�u��̐�����3���j\f�LG�GP���E�YY����3�f��Gj\P���E�YY��toh��P������tH�M����M��C�p�E�Q��YY��u��M����u���u�M�3�u������u3�Fh��X��]�W�����_�#��^[�������̋�U���t���3ʼnE��E3�S�]������������������������������VW����uj	X����u�_����������uj��h��P��5���F�S�p�������,�YY��t�6���u��3�Gh��X���uj땋������5��S�@L�������,�������YY��t�5��V������tj%�V���Dž����������PjV�'�����h�������3�P�������<�������Ph������Pj������P�������d�j^��y!=4�t�������L�V�����������P9����t8�������j������������P�����P�ؐ��Dž����������Dž����
������������������hP�<��������PW������Pj������P�������d���y=4�tj^���������9����u苅���
��ˉ�������	�����������h$P�<�������PW������Pj������P�������d��ȅ�y��4�t
j넃�����񋝸������Wf���f;�����u�+�3��j Z���f����������f�����f������f;���j	Xf;���W������S������ul�{3��f;�tj Zf;�tj	Yf;�uR�����3ۍQf���f;�u�+���MP�����PjS������������PS�\�����j���j Z�����f���V���f������������������y`�������E������t#S��`�����^���j�@���f�������Ћ�f��t-j [j	��^f;�t��f;�u�������f��u䋝����j^f��t`j [j	��^��f;�t��f;�t����Ћ�f��uዝ����j^f��t*3��f��AP�����������]���f������	3�f�����h@�������Z����.���S���������?�������f���h���h@�Ӎ�����������������P������������h@������������S���ҋ�������uDž����������h�������P�<���u
V������3�PV�HjY������3��}�hD�E�jP�:����M܃��Q3�f���f;�u�+���MP�E�PjW������PS�\�������h������P�<�V������PVW������PS�\��������������P�������������%����u
������������������L��ƋM�_^3�[�	7��������������������̋�U����T���3ĉ�$P�E3ɉD$ �L$�$S�]�\$VW����uj	X����u����؉\$ ��uj��h��P��5���t$,�^�s�\$�,�YY��t#�6���u܋�h��X�����j��D$����uh��X�3��g�5���t$0�,�YY��tm�5�3��D$���tM�D$�^�sL�pL�,�YY��u!�D$PS�t$(�a���|$�D$t;�tG��D$�6���u���s�|$3�C�D����|$�\$�7����D$�xL�D$Pj�t$(�|$(�h������h��D$(P�<��D$0Ph�D$HPj�D$4P�t$ �d���y��4�������`j^9t$Dt(�|$D�L3��D$�D$jP�D$TP�ؐ����D$L��h$�D$(P�<��D$0Ph�D$HPj�D$4P�t$ �d���y_=4�u_3�f�D$L3�G3�h�D$(�\$P�<��D$0Ph�D$HPj�D$4P�t$ �d�����=4������|$Dtj�Zj X�D$4����O3�f���f;�u�3��\$L+�f��$Lf�D$L�f���b���j	��Xj �D$<Zf;�tCf;�t>W�t$ S������u(�d$�ˍ{��ЉT$<f9D$t#f9D$4tf9D$8tj Z�����f��tvj	X�3�f����ǍA3�f;D$<u����$L+�PRQ�?�L$X���Q3�f���f;�u�+���MP�D$PPjS�D$4P�t$ �\���y�3��3�j Xf�|$L�y����|$Lf9D$Lu��f9t��D$�\$P�L$P��+�����+�� ��L$�Dž�t�<O��;�vj Yf9u��;�w��3�f�f9u3�G�����5�P�,�����Y�YG���9t$Dtj��D$L�D$�L$,�z�ظ���t�L$3�j���	����h�D$(��!\$P�<�V�D$PV3�P�D$4P�t$ �\���yj�4�\$ �D$P�t$S�����u@�t$�А�t$�������yj$^�"��t�|$�t�|$u	3�PS�,3���t$�L��Ƌ�$\_^[3��1��]�����̋�U����\���3ĉ�$XSVW�}3��t$��u��������ujX��D$PjW�D�����t3����\$9ut!S�А����=4���j)��D$ Ph��W�����u(�t$ �А�t$ �������y��4�tj$�uh�D$P�<��\$�D$PS�D���y=4�u'h$�D$P�<��D$PS�D���y=4�tj(�h��D$P�<��D$$Ph�D$0Pj�D$(PS�d���y
=4�����|$,t,�|$,tj��j�D$�t$P�D$<P�ؐ3���G��D$4j_%�����D$�D$h�P�<�9t$u�D$PS�D��q��uj�D$Pj�TjY�t$3���$HhD󫍄$LjP�+�����$T���Qf���f;�u�+���MP��$HPjV�D$(PS�\���yj^S�L��Ƌ�$d_^[3��U/��]���U���V��W��u�
��7�=���)P�E�P���E�Pj�E�PW����x�E��F�����u�_^��U����S3�!T$V��T$�
��W;�r����;�s9�u�D$ �=�����P�=�t�whPjj]���T$$���G�H3��L$$�D$9���ك=�t����3h�jj]�����|$ �K�L$t*h��3�,�YY�L$��u�����L$��3��D$9tG�ك=�t(k��s�s�3Vh�jj]���L$,���D$9st/@k��D$ك;u��D$�L$$@�D$����;t�D$�5����T$Bk��T$�t��T$�?���������t!�=�tRVhjj]��������=�tRVh`jj]����3�_^[��]�1�L�Ë�U��E���]���U����}V��v�F�F�:�u�e��E�P�<��E�P�E�Pjj���M���t�U�E�P�FP�H����^���9u�yt�q�������������̋�U���M�с����0�A�=�wj�u(�u �u�uQhX��B��rD��sj�u(�u �u�uQh(����sj�u(�u �u�uQh�������w��to��tj��Ptbd�0�xu	�=��tM����u��Ph��u,d��u(�u$�u �u�u�u�u�u�p Q�5�jj]����@̋�]�(��U���SVW�E��E�Pj�E���P�E�u�P+�j���������yWVh�jj]�������7�E���P�^�E��u�P�E�Pj�����yPVhjj]����3�_^[�Ë�U���,W3��E�h�P�}��}�}�}��}�<��E�P�E�PWW����xm9}�thVhT�E�P���E�PW�E�P�u����u�th���8����-ht�E�P���E�PW�E�P�u����M��t����^d�0�(
f9��td�0��f9��uUh��E�P�<��E�P�E�PWW����x&9}�t!h��E�P���E�PW�E�P�u����M��t�H���_��U��3���t;Uv�W�]���U��SVW�u�r����u3�VW�$�����x
;�wt	����z�3�f�w�M��t�1_^��[]���U������3ʼnE�SVWh�3ۍ�x���SP���r5����x���Vh$j@P贯����x���Džd���$�Љ�h������Jf���f;�u�+�Dž`�����ύU��`�����l����ž���M�_^3�[��(�Ë�U��� SV�ڋ�W���x3�U��E��}�茾�������U��E�����s���������u�U��E�� �Ή}��O���������u1�U��E� �Ή}��+��������U��E�, ��������uu��u�U��E�T �Ή}�����uU��u-�U��E�| �Ή}��ҽ����u5�U��E� ��载����u �}t�U��E�$�Ή}�蟽����u3�_^[����U�������3ĉ�$��d$�d$SVW���D$ �|$�څ��������D$�D$(j�D$0�T$(X�D$0�D$$�7������b�D$��Mh$�D$DP�<��D$<PjP�D$PPj�D$PPW�d���y
=4�u!t$ �9�|$Lt*�|$Ltj-��d$�D$jP�D$\P�ؐ����D$T�D$�=l�����?���w�s�,�YY��t���|$u���W�B��wx�����$����;u*�D$���s�D$�D$P�s�c2��3��M�;tj�]�|$ tP�B#D$�ɋ�|$$jY��T$$�L$�D$(����|$��L$�������?u
�L$���ض������j�j	X��$�_^[3���%��]Ë���7���U������3ʼnE�SV���W3��u��]��>�}��}�u�F��E��E��E�j�E���|���X�E���|����4�����x�������h$��l���P�<���t���PjP�E�Pj��l���PS�d���y=4�uj[�.�}�t%�}�tj-X�Qj�E��}�P�E�P�ؐ������]��=l����3�9��w�v�,�YY��t���}�u܋�x����M�_^3�[�$�ËW�B���A��J��$�:��>u�G��E��}��Bu%��#���>u�G��E��}��Btރ����>jYu����|������|����M��E��ݹ����tM�a����>jYu����|����M�3��qf���f;�u�+��ɉM�9}�t��t��뢁����u��}�3�9tl�E���t
%���������h
��u���Q�ΉE�����������Ӌ�����������E��E�j�E���|���X�E��Ή�|�����M����
����������9�j���VW����t!3�f97t�4���W�,�YY��tF��r�3�_^�����
T��X�j�����t83�A��
��A���� �4$��������`$��0��3��hX��5T������t83�A��
��A���� �4$�������x$��0��3�Ë�VW��j	^��th�"Q�,�YY��u3��(�_��^�����������̋�U����$S�]V�5D�W��D$��tS�u��u�u�8���=%�u\�M�T$�d$�|�����uB�t$��t:�v��t3jY�|$�j_��u�v�,�YY��t!�W�D$PV���;�u۸%�_^[��]��F;D$wP�v�u�Q-�F���3��։�#��͋�U����$�d$SV��3�W��ujX��9����D$Ph��V�v�����tVh�$jj]������9\$��h��P��=���G�t�(t�w�V�[���u3�C�?���u�h��X���tg�D$Ph��V�[�����uS�L$�D$�T$�D$�D$��D$�D$ �D$$�����L$�T$�D$����t$褰��3�_^[��]Ë�SVW������<�����t7jSVjW�0���x j\�v��YY��u�F��������V����_^[�������̋�U��=�V�5��tW�ESW����u���],��S�u(�u$�u P�u�u�u�u�u�8��֋�t��M�����u
W�s���_��[�(�u,��u(�u$�u �u�u�u�u�u�u�8���^]�(������̋�U��=�V�5��t]�E SW����u���u4�]0��S�u,�u(�u$P�u�u�u�u�u�u�8��֋�t������u
W�s���_��[�.�u4��u0�u,�u(�u$�u �u�u�u�u�u�u�8���^]�0����������̋�U��=�V�5��tW�ESW����u���],��S�u(�u$�u P�u�u�u�u�u�8��֋�t������u
W�s���_��[�(�u,��u(�u$�u �u�u�u�u�u�u�8���^]�(������̋�U��=�V�5��t]�E SW����u���u4�]0��S�u,�u(�u$P�u�u�u�u�u�u�8��֋�t��W�����u
W�s���_��[�.�u4��u0�u,�u(�u$�u �u�u�u�u�u�u�8���^]�0��U���Vh��E�3�P�u��<��E�P�E�PVV������9u���h�$�E�P��hTV�E�P�u�����x|h�$�E�P��hLV�E�P�u�����xVh�$�E�P��hPV�E�P�u�����x0h�$�E�P��hHV�E�P�u�����x
3�@�D�3�^�Ã=DVu������u��^Ë5T��8���^Ã=DV��u�����u^�V�5L��8���^������������������̋�U��=Du	�����tV�u�5P��8���^]����������������̋�U��=Du	�b�����tV�u�5H��u�8���^]�������������̋�U���VW�}Wh�$�,�YY��u/d�0�@�8����u3�VVVVVhh���ڣ�����SWh%�,��]YY��u�C�XWh%�,�YY��u�C�XWh@%�,�YY��u�C�\Whd%�,�YY��u�C�\Wh�%�,�Y3�Y��u�t�5�9su'�t��DWh�%Vj]�����-�t�t�s�sWh�%Vj]����hx�P��
d�*�A�	�E��M�9p$u�Hj�C,�M�PQ����tl�M�du�j<Y�����E�����j<VP��%���M��C�A(�C�A$�E�Y,;T�t�C0��I4��l�I8��q0�p9tjY�)�u��5`����E��0�p륉�A��t��
pt&Wh&��t�tWh�%Vj]����hx�X�95X�t95�t
3ҋ�B�q��[_^��������������̋�U��VW�xW�P��M�l��t-�9puZ�N91uS��H�N���t9Hu@�Q9
u9��PW�X���tV����=X�_^t�=�t�MjZ����]�jY�)�lVW�l���9N$w
�F,�@ F$;�w	;�u�3�_^Ë���������jh��#3ۈ]�xV�P��M������}�V�X���u2���u��un9tuQ��t�2�t�l��yhH&Sj]��������yhx&Sj]�����G0t��H��u	w0��u�O0�Ŀ���؉]܅�t�C �e��E��t�tV�G,�p(�w(h�&jj]�����=�u�G��t�p�:����uV�u�w(��8��ֈE�3�F9uu
�O0�ȉO4�}u
�O0���G8�=�u^�O��tW�f	�E؅�y�G,�p0h�&jj]�����xW�P���=�t����EԋM;H$u�5�W�X��e��'3�Ëe�}u�E�H0�}u�E�H0 �e��]��E�������E�M�d�
Y_^[���]܅�t�K �3�Ë�U����SVW��3���u
�
���C�L$Qj
jP�D$ ����tX9|$tR9xtI�p�F���L$u+�����<t�s0Wh8'jj]�������7����x	�� �~u�������th�&jj]����3�_^[��]Ë�U���SVWQ�E�P��j�E�P�E�P���؉]����8�5l�l���6�C,j��,P�E�P����t;�u�=d�d�a�xW�P��C�8u�
h�d91���0�H��hW�X���Nj?�xuj��P�E�P������;�u�j<Y�Ҳ���؅�u$���t�u�hX'Pj]�������kj<jS�} �E���C�x�E��C W�P��
h�C91tjY�)�0�H�W�h�X����t�u�h�'jj]�����E�_^[�øl�p�l�������dhx�h�d�����x3�Ë�V3�����u
hx������^�����̋�U��SV3�9u���]����Whx�P��M�������u���ijY莱���Ѕ�u���T�G,�@��G,�H H�J�G,�B�C�B�G�z�Z�W���
�99tjY�)�8�H����J����hx�X���_��
�^[]���3�VW����H;1r;qr�;�u����_��^�SVW�xW�P��5�����F�p�0h�'jj]���6��;�u�W�X�_^[�SWhx3��P������u���3V�5l�!�N$;Kt!�N�����u�N,������x
�6��lu�^hx�X���_[Ë�U���SV��W�����������]�����E�Pjj�v����u}�v���ȅ�u�{��u�Q�����щE�tJ�I3��E��M��t:�M�;Jr
�BB;�r�E���(@�E�;E�r���FB�J�M���u�J��u
�'3���M�����
�_^[����U���(�e����e��E�u�
��ÍM�Q�U�����������V�u���u3��SW�}��E�Pj�E�u�P�E�}�Pj����؉]؅�y,�����FSh�'jj]�����.��������������؉]������E��H������[����C�e��[�@�E�8���ȋ@3҉E܉U�9tu�ȋ;AuX�A��tQ���t#�q�E��q�@�p0h(jj]�����������E���tJ��E�H�j��t8�U��M�Bk��U�ȃ9u��M�E�@�E����8�g�������@�������������]؍E�P�u�E�P�E�Pj���_��[^�Ë�SVW�ً�j^��tB��t>hx�P��
l�l���	9X$t9x$t;�u��3�F�3�hx�X�_��^[Ë�U���(�e��ƒe��E��M�SVW���c���[�E�P�U��������L�u���u3��>�}�E�Pj�E�u�P�E�}�Pj����؉]؅�y%����tSh�'���YY�������}���3�9���E��Ӊ]�9�����ȋG�E��]�9to�؋ȋ;CuK�C��t���3hD(jj]������t�s�E�7�3�p0hx(jj]�����M��E�@k��E�ك;u��M�3ۋU�B���U���9�q����}�����}��C����]؍E�P�u�E�P�E�Pj����
����
�_^[�Ë�SW��3ۅ�u�
��MVhx�P��5l�#�N$;t$�e�����u�W�N,�.����؅�x
�6��lu�hx�X���^_[Ë�U��QSVhx3�P��5���;�t@W�>�ƉE�;�t"�V�O$�R�����؅�x�?��;�u�E��@�6;T�t;�u�_hx�X�^��[�á��SVW�x�d�S3��P��5�� �F;T�t�N$�x��]�������x
�6���u�S�X���_^[Ë�U������M�M��U�V��tlSW�B3ɉM��x�}�9tB�U��NjX�e��;t�M���9Pu�pAk�Ã8u�}�M�A���M���ǃ8uƋU�R�u��U�u��M�_[��+����#�^������������̋�U��V�u�5����u�8���^]���������������̋�U��V�u�5����u�8��֋���m�����t	��������^]���U��QQh������y	�%�3��SVW3�9=�uW�E�P���E���t��3��=�sV3ۉ=�sWC�=�th�"�����VWh�s��VWh���VWh�!�hWh�#���ƀWjh�t�5�����HWjh�z�{Wjh�~�nWjh��a�5��3�WVh�|�MWVh��AWVh�v�5��HWVh�x�&h@Vh�3����5�t��33�_^[�Ë�V���t+3����z��t94��~u
9��tw;�w@=�r�3�^���3�@^�V���t+3������t94��vu
9��|w;�w@=�r�3�^Í��x�3�@^�3�V@���t@����h�j���3V�L��jVj j�@�^�������̋�U��V3�95�3ujX�VW�}��uj	X�H���S�]Ã�@vjX�2h��P�������@w
��
���j^h��X���[_^]����������������̋�U��QQ�=�3SVW���u;5����3�9��"��9�ttB�E�P�(���t����Sj
RP�c�}�+=�s�M�
�s;�|{;�vu��t�M���q�����t`��������tUh�t��3ҹ@B��;��"s0���9��st�uh�(Sj]������`���3�@�
���!3�_^[����������̋�U��d�0V�@ht\�=�3tS�u;5��rVh�(jj]�����j	�2SW�}�@B;�v����S�P�S�<��"�X�_3�[�jX^]�������̋�U��=�u�E��t��3��]�������̋�U��W3�9=�3ujX�ASV�u��'	;�v��S�P�h�s�(���u�5�t�j_S�X�^��[_]�����̋�U��Qd�0S�@h���=�3���];�����}��VWh�3����P��Ƌ��z�E�H��u��M��u��#9��~u�M9��t�Mu�;�uދ}���u+���s#�E�~�$�����~���t���zh��X���_^�3�[�����������̋�U��d�0V�@ht}�=�3tt�u;5��siSWh�3��P��]���E3�;�܀u,;��vu$;��|u3���܀���v���|��܂������u�h��X���_[�3�^]�������̋�U��Qd�0S�@h���=�3���];�����}��VWh�3����P��Ƌ���E�H��u��M��u��#9��vu�M9��|�Mu�;�uދ}���u+���s#�E�~�$��x���v���|���h��X���_^�3�[�����������̋�U��d�0V�@ht}�=�3tt�u;5��siSWh�3��P��]���E3�;��xu,;��~u$;��!u3����x���~���!���z������u�h��X���_[�3�^]�������̋�U��d�0V�@h���=�3t~�u;5��ssW��W�P�3ɺ��;��vu���v���|������x��;�rً�;��~u���~���t���z�����;�r�W�X�3�@_�3�^]���������̋�U��d�0V�@htY�=�3tP�U;��sE�u��t>S3�W���<Nf��t����Af�<E�#��r��3��_f�U�#f9N[���3�^]�����������̋�U��V�u�5����u�u�8��֋�t�ud�
3�B�q$�u�uV�0��^]��������̋�U��V�u�5����u�u�u�8��֋�t�u�u�uV�ujZ����^]������������̋�U��SV�u�5����u�u�8��֊؄�t�ud�
�q$�uj�ujZ�^��[]�� �����u�D�%����3�Ë�V��F�iȠ����h�����u^Ã`�0^���%�Ë�U��QV�5���t�~t
�FP���V�9���^�Ë�U���W�=�f�U�����S�_�G�E�V��tP�P�3�@��G@3�7��3҉M���t#i����(�f9t�w��P�8��֋M�3�f�E�i�Rf�D>(�E�D>8�E�D><�E�D>@�E�D>D3�f�D>*�GH�Pj j�@���f��u3�@f�D>*�E�D>H�f�D>*^��[t	�u�X�_��;
��u�����U��}u��3�@]���U��}u���u��3�@]���U��QW�=��}���r� �������@S�$�V�3�S���K�;�t�{��3��	;�(�u�}�����������^[_��U��E�]���U��E�]���U��E�]���U��E�]���U��u�Th	�j��k]�U��QQ����
���������5���=��f���f�
��f���f���f�%��f�-�������E����E����E��������������	�������jXk�ǀ��jXk��
���L�jX���
���L�h�gh	�j��~��U��j�]�U��h��6�E����E��������������	�������jXk��M����h���]�U��Qh����E����E��������������	�����}v
�}u�e�}v�EH�E�E@���jXk��M�����e���E�@�E��E�;Es�E��M��U��������h�����Ë�U��=��t�=��N�@�uh���Y����У��]Ë�U���0jX����E��}�r)�E� ��E��E�E�EЋE�e����E��f�d�E�$��E��E�E�E��E� ��E��E�E�E��E�(��E܋�E؋E�;E�u��빋E�e���A�ȋE���e�ȉM��E�3E�M��E�8t�E�8N�@�u	�E�O�@����������̀�@s�� s����Ë�3Ҁ����3�3��%��%��%��%��%��%��%��%��% �����������̋�U��V�uW�}����t
�N�38�a����F�N�38_^]�N��������������̋�U���SVW�}�E��E��G�_3��SP�E�����u��E���w�@fu`�E�E�E�E�G����to���M��F�F�<����H�E��t��� ��M���xH��M������uɄ�t.� �E�����th��S��������3S�u�������E�_^[��]ËM��E9pth��S�֋���ES�u��x����M���ӋI��%$��%(��%,��%0��%4��%8��%<��%@��%D��%H��%L��%P��%T��%X��%\��%`��%d��%h��%l��%p��%t��%x��%|��%���%���%���%���%���%���%���%���%���%���%���%���%���%���%���%���%���%Đ�%Ȑ�%̐�%А�%Ԑ�%ؐ�%ܐ�%��%��%��%��%��%��%���%���%��%��%��%��%��%��%��%��% ���������������SVW�T$�D$�L$URPQQhP�d�5���3ĉD$d�%�D$0�X�L$,3�p���t;�T$4���t;�v.�4v�\���H�{u�h�C�2��C�D�d���_^[ËL$�A�t3�D$�H3���U�h�p�p�p�>�����]�D$�T$��Ë�U�t$�����L$�)�q�q�q(������]�UVWS��3�3�3�3�3���[_^]Ð���j�3�3�3�3�3���IU��SVWjjh	�Q�~_^[]Ë�U�l$RQ�t$�����]�����������d�Ë�U��E�]Ë�U��E�]Ë�U��E�@]Ë�U��8�=0�td�
�E���;Ar;Avj
Y�)]�U��8�=0�t;d��U�J;Hr;Hvj
Y�)�=<�tV�5<���j�r�8���^]�U��8�=0�tI�MVd�5W�}W�8��UY;Fr;Fvj
Y�)�=<�t�5<���j�w�8���_^]Ë
8�3���0�����U��SVWUjjhh��u�]_^[��]ËL$�A�t2�D$�H�3�����U�h�P(R�P$R���]�D$�T$���SVW�D$UPj�hp�d�5���3�P�D$d��D$(�X�p���t:�|$,�t;t$,v-�4v���L$�H�|�uh�D��I�D��_뷋L$d�
��_^[�3�d�
�yp�u�Q�R9Qu��SQ����SQ����L$�K�C�kUQPXY]Y[����%(���̋D$�L$ȋL$u	�D$���S��؋D$�d$؋D$���[�h �d�5�D$�l$�l$+�SVW���1E�3�P�e�u��E��E������E��E�d�ËM�d�
Y__^[��]Q����h �d�5�D$�l$�l$+�SVW���1E�3ʼnE�P�e�u��E��E������E��E�d�ËM�3��������%,��%$��%0����������������`;�����������2K������������K�����������kL�����������4���$�*�--h��к�0�H�C�D�<�FP<@���pu�z`�� ogpCD�F0F`F�AF�;�F?�>=P>�mP��h�hИ���ФP�0@�BУ05����Аi6�h�����»߻��)�R�g����Ҽ�L���:�^�w�����ʽ���5�R�m�����žݾ���7�\�z�����ÿٿ����	

 !"#$%&'()*+,vrfcore.dllAVrfAPILookupCallbackVerifierGetInfoForExceptionVerifierAreStaticDllsInitializedVerifierChainDuplicateHooksVerifierCloseLayerPropertiesVerifierConfigureStopOptionsVerifierCreateLayerPropertiesVerifierDisableFaultInjectionExclusionRangeVerifierDisableFaultInjectionTargetRangeVerifierDisableLayerVerifierDisableVerifierVerifierEnableFaultInjectionExclusionRangeVerifierEnableFaultInjectionTargetRangeVerifierEnableLayerVerifierGetAppCallerAddressVerifierGetLoggingDirectoryVerifierGetRecursionTlsSlotVerifierHandleVerifierStopExceptionVerifierIsDllEntryActiveVerifierIsInsideVerifierStopVerifierIsLayerEnabledVerifierLdrGetProcedureAddressVerifierOpenLayerPropertiesVerifierQueryGlobalPropertiesVerifierQueryLayerBreakVerifierQueryLayerBreaksVerifierQueryLayerPropertiesVerifierQueryLayerPropertyVerifierQueryRegisteredLayersVerifierRegisterFaultInjectProviderVerifierRegisterLayerVerifierRegisterLayerExVerifierRegisterProviderVerifierResetFaultInjectionAddressRangesVerifierSetAPIClassNameVerifierSetFaultInjectionProbabilityVerifierSetFaultInjectionSeedVerifierSetLayerBreakVerifierSetLayerPropertyVerifierShouldFaultInjectVerifierStopMessageExVerifierSuspendFaultInjectionVerifierTlsGetValueVerifierTlsSetValueVerifierUnregisterLayer�������@��p�,��p�P+���`����1P1���P@�QFH�RGX�SHP�TI�U8��H�XP�p����\�h�������������T 0!�!����!��!�!���!��"�"�8��!��!###�!��",# 4# D#\#@t#�#�#�#�#@�#��# �#� 
�����!����"�$�8"����\"���"�� , 
 dt����e@��L�f0�X�g���h���(�v���i8���j(���k���ld���m �,�o���p<�h�q�@�r@� �s,�L�t4�x�u�����w���y���x��4��!| 	�  �����@�������?��������?��������?�����?	
�?�? �?$%&'()*�?./01234�?89:;<=>	�?BCDEFGH
�?LMNOPQR�?VWXYZ[\�?��������?��������?��������?��������?��������?�?
�?	�? !"#$%&
�?*+,-./0�?456789:�?>?@ABCD
�?HIJKLMN�?RSTUVWX�?\]^_`ab�?fghijkl�?pqrstuv�?z{|}~��?��������?��������?(#)#*#+#,#-#.#�?2#3#4#5#6#7#8#�?<#=#>#?#@#A#B#�?F#G#H#I#J#K#L#�?P#Q#R#S#T#U#V#�?Z#[#\#]#^#_#`#�?d#e#f#g#h#i#j#�?n#o#p#q#r#s#t#�?x#y#z#{#|#}#~#	�?�#�#�#�#�#�#�#
�?�#�#�#�#�#�#�#�?�#�#�#�#�#�#�#�?�#�#�#�#�#�#�#
�?�#�#�#�#�#�#�#�?�#�#�#�#�#�#�#�?�#�#�#�#�#�#�#�?�#�#�#�#�#�#�#�?�#�#�#�#�#�#�#�?�#�#�#�#�#�#�#�?�#�#�#�#�#�#�#�?�#�#�#�#�#�#�#�?�#�#�#�#�#�#$�?$$$$$	$
$�?$$$$$$$�?$$$$$$$�?"$#$$$%$&$'$($�?,$-$.$/$0$1$2$�?6$7$8$9$:$;$<$!�?@$A$B$C$D$E$F$"�?J$K$L$M$N$O$P$#�?T$U$V$W$X$Y$Z$$�?^$_$`$a$b$c$d$%�?h$i$j$k$l$m$n$&�?r$s$t$u$v$w$x$'�?|$}$~$$�$�$�$(�?�$�$�$�$�$�$�$)�?�$�$�$�$�$�$�$*�?�$�$�$�$�$�$�$+�?�$�$�$�$�$�$�$,�?�$�$�$�$�$�$�$-�?�$�$�$�$�$�$�$.�?�$�$�$�$�$�$�$� '''''''���`�N�@���D �����Ȓ���
�&�@�L�b�p���������ʓ����(�2�L�X�r�������Ɣؔ���4�B�X�r�������̕ڕ��*�D�d�x�������ʖ����
��.�B�L�Z�d�v�������З��$�0�L�n���������ʘ0�h��������Ȓ���
�&�@�L�b�p���������ʓ����(�2�L�X�r�������Ɣؔ���4�B�X�r�������̕ڕ��*�D�d�x�������ʖ����
��.�B�L�Z�d�v�������З��$�0�L�n���������ʘ�LdrGetProcedureAddress#DbgPrintExNtQueryVirtualMemory�RtlDllShutdownInProgress�LdrLoadDllqLdrEnumerateLoadedModulessLdrFindEntryForAddress�_wcsnicmpyNtTerminateProcess�_vsnwprintfNtQuerySystemTime�_wcsicmp�NtQueryInformationProcess�LdrUnloadDll�_vsnprintfYRtlInitUnicodeString�RtlCaptureStackBackTraceMNtDeleteValueKeyNtReadVirtualMemoryNtClose�RtlEnterCriticalSection�_stricmp�RtlLeaveCriticalSectionjNtSetValueKey5RtlRaiseExceptionNtQueryValueKey�RtlApplicationVerifierStop�RtlAllocateHeapvLdrFindResource_U�LdrLockLoaderLock�RtlAcquirePebLock�RtlUnicodeStringToAnsiString�RtlFreeHeap�LdrUnlockLoaderLock�RtlFindClearBitsAndSetIRtlReleasePebLockfLdrAccessResourcejRtlDeleteCriticalSectionlNtFreeVirtualMemory�NtWriteFile�RtlFreeUnicodeString�RtlDosPathNameToNtPathName_U2RtlCopyUnicodeString�NtAllocateVirtualMemory
RtlQueryEnvironmentVariable_UENtDelayExecutionaRtlInitializeCriticalSectionNtCreateFile"DbgPrint�RtlDoesFileExists_U�NtWaitForSingleObject�NtQueryKeyJNtDeleteKey�NtOpenKeyZ	wcstoulZRtlInitUnicodeStringExLRtlInitAnsiStringV	wcsstr NtCreateKeyT	wcsrchrzLdrGetDllHandle�NtProtectVirtualMemoryRtlCompareMemory,NtResumeThreadRtlCompareUnicodeString�RtlAnsiStringToUnicodeStringDRtlImageDirectoryEntryToDataERtlImageNtHeader7RtlRandom�NtQueryPerformanceCounteroLdrDisableThreadCalloutsForDll�RtlCaptureContext�RtlUnhandledExceptionFilterntdll.dll�RtlUnwind	memcpy	memmove	memset ��:�0�H�`�x�
������9��?��@�A �B8�CP�Dh�E��F��~�������������(��@��X��p�������������3��4�5�60�7H�8`�9x�:��;��<��=��>��?�@ �A8�BP�Ch�D��E��F��G��H��I��J�K(�L@�MX�rp���	�	�	�	�	�	�			 	0	@	P	`	p	�	�	�	�	�	�	�	�					 		0		@		P		`		p		�		�		�		�		�		�		�		�		
	
	 
	0
	@
	P
	`
	p
	�
	�
	�
	�
	�
	�
	�
	�
			 	0	@0�x��b�Th�� ���dp�bP�>��r��� �Z���`�v������(�d���p�b����6(�����hp����<� ��#�`+�8-H.v�1�@�
�N�pa|	�j�
�u`����,И^0����>��H@�����
���@�b��t �Fh��@�r���p��B�h@� �P���4VS_VERSION_INFO��
�aJ
�aJ?6StringFileInfo040904B0LCompanyNameMicrosoft Corporation�:FileDescriptionApplication Verifier Provider - Core Verification and SDKl&FileVersion10.0.19041.685 (WinBuild.160101.0800)8InternalNamevrfcore.dll�.LegalCopyright� Microsoft Corporation. All rights reserved.@OriginalFilenamevrfcore.dllj%ProductNameMicrosoft� Windows� Operating SystemBProductVersion10.0.19041.685DVarFileInfo$Translation	�<AVRF: Terminate process after verifier stop failed with %X 
kThis verifier stop is not continuable. Process will be terminated 
when you use the `go' debugger command.
LThis verifier stop is continuable.
After debugging it use `go' to continue.
9AVRF: Formatting message failed in VerifierStopMessageEx
LAVRF: Noncontinuable verifier stop %p encountered. Terminating process ... 
�

=======================================
VERIFIER STOP %p: pid 0x%X: %S 

	%p : %S
	%p : %S
	%p : %S
	%p : %S

%S
=======================================
%S
=======================================

�

=======================================
VERIFIER STOP %p: pid 0x%X: %s 

	%p : %s
	%p : %s
	%p : %s
	%p : %s

%s
=======================================
%s
=======================================

AutoDisableStopLoggingWithLocksHeldExceptionOnStopMinimumMemoryOverheadlPropagate verifier settings from parent process to child process. Note that not all tests can be propagated.[After specified image starts to run, the verified image will clear the settings for itself.:Verifier will only complain once for the same issue found.wThe dll load/unload event will be logged. Verifier is doing I/O when the loaderlock is hold. It may bring the app hang.QFor each verifier reported stop, exception will be raised instead of debug break.QReduce memory overhead by disabling some of the features used just for debugging.FullDllsSize	SizeStartSizeEndRandRateBackwardUnalignTracesProtectNoSyncNoLockFaults	FaultRateTimeOutAddr	AddrStartAddrEndRandomUseLFHGuardPagesDelayFreeSizeInMBInPlaceShrinkAlloc4TRUE for full page heap. FALSE for normal page heap.iPage heap allocations for target dlls only. Name of the binaries with extension (.dll or something else).%Page heap allocations for size range.Beginning of the size range.Ending of the size range.uDecimal integer in range [0..100] representing probability to make page heap allocation vs. a normal heap allocation.Catch backwards overruns.No alignment for allocations.Collect stack tracescProtect heap internal structures. Can be used to detect random corruptions but execution is slower.LCheck for unsynchronized access. Do not use this flag for an MPheap process."Disable critical section verifier.Fault injection.Probability (1..10000) for heap calls failuresQTime during process initialization (in milliseconds) when faults are not allowed.'Page heap allocations for address rangeBeginning of the address rangeEnding of the address range'Page heap allocations with probability.Use LFH guard pages.=Maximum amount of memory to use for delayed free list (in MB)VAllows in-place shrinking re-alloc to succeed (valid only when LFH guard pages is on).ForceDllUnloadREnables aggressive Dll unload on certain events in COM framework and periodically.UnloadPeriodMs+Forceful Dll Unload Period in milliseconds.SecuritySettingsjChecks if security blanket settings (per-process, per-interface etc) are at or above recommended minimums.EventRemoveCheck5Checks for bad patterns in COM+ Event remove queries.AgressiveMTATesting>Enables aggressive MTA testing ensuring MTA are uninitialized.�Checks that applications and components use RPC correctly. Common mistakes and problems while using RPC are flagged. A debugger is required to see the test results.�Checks that applications and components use COM correctly. Common mistakes and problems while using COM are flagged. A debugger is required to see the test results.GChecks the heap errors. A debugger is required to see the test results.7VerifierRegisterLayer called with an invalid parameter.	Not used.	Not used.	Not used.	Not used.\This stop is issued if a verifier layers passes invalid parameters to VerifierRegisterLayer.9VerifierUnregisterLayer called with an invalid parameter.	Not used.	Not used.	Not used.	Not used.^This stop is issued if a verifier layers passes invalid parameters to VerifierUnregisterLayer.7VerifierStopMessageEx called with an invalid parameter.Layer descriptor address.	Not used.	Not used.	Not used.mThis stop is usually issued if a verifier layer calls VerifierStopMEssageEx with an invalid layer descriptor.;VerifierStopMessageEx called with a non-existent stop code.
Stop code.	Not used.	Not used.	Not used.�This stop is usually issued if a verifier layer calls VerifierStopMessageEx with a stop code that was not registered by any of the layers.3Another verification layer uses the same stop code.Min code in first range.Max code in first range.Min code in second range.Max code in second range.�This stop is issued if another verifier provider already has a stop code with the same value. All codes should be distinct in order to avoid confusion in error processing.GMore than 128 (current limit) verification layers have been registered.	Not used.	Not used.	Not used.	Not used.This stop is issued if more than 128 (current limit) verification layers have been registered with the verifier infrastructure.LThe registering layer used the SAMPLE name or the GUID from the sample code.	Not used.	Not used.	Not used.	Not used.�The layer code was copy pasted from the sample code and there was no new GUID generated (they must be unique) or the SAMPLE name was used for the verification layer.7The registering layer used an invalid layer descriptor.	Not used.	Not used.	Not used.	Not used.NA field from the layer descriptor has not been filled or has an invalid value.6VerifierIsLayerEnabled called with invalid parameters.	Not used.	Not used.	Not used.	Not used.oVerifierIsLayerEnabled is called for a layer that is not registered or the layer descriptor has invalid fields.7This error code is issued for old style stop functions.
Code used.First parameter.Second parameter.Third parameter.�Getting this stop means there is an error in converting old stop codes to new codes. All of them should have been converted and reported as belonging to appropriate verification layers (heaps, locks, etc.).7This error code is issued for old style stop functions.
Code used.First parameter.Second parameter.Third parameter.�Getting this stop means there is an error in converting old stop codes to new codes. All of them should have been converted and reported as belonging to appropriate verification layers (heaps, locks, etc.).'SmartHeap (shsmp.dll) is not supported.	Not used.	Not used.	Not used.	Not used.7Heap managers other then the NT heap are not supported.Unknown error.Not usedNot usedNot usedNot usedlThis message can happen if the error encountered cannot be classified in any other way.

Not used right now.Access violation exception.%Invalid address causing the exception)Code address executing the invalid accessException recordContext record�This is the most common application verifier stop. Typically it is caused by a

buffer overrun error. The heap verifier places a non-accessible page at the end

of a heap allocation and a buffer overrun will cause an exception by

touching this page. To debug this stop identify the access address that caused

the exception and then use the following debugger command:

    !heap -p -a ACCESS_ADDRESS

This command will give details about the nature of the error and what heap block is

overrun. It will also give the stack trace for the block allocation.



There are several other causes for this stop. For example accessing a heap block

after being freed. The same debugger command will be useful for this case too.CMultithreaded access in a heap created with HEAP_NO_SERIALIZE flag. Heap in which operation happens.9Thread ID for current owner of the heap critical section.5Thread ID of current thread trying to enter the heap.Not usedA heap created with HEAP_NO_SERIALIZE flag is not supposed to be accessed

simultaneously from two threads. If such a situation is detected you will

get this message. The typical way this situation creeps into a program is

by linking with a single-threaded version of the C-runtime. Visual C++

can for instance link statically such a library when proper flags are used.

Then people forget about this detail and use multiple threads. The bug is

very difficult to debug in real life because it will show up as mysterious

data corruptions.Extreme size request. Heap in which operation happens.Size requestedNot usedNot used�This message will be generated if in a HeapAlloc() or HeapReAlloc() operation

the size of the block is above any reasonable value. Typically this value is

0x80000000 on 32-bit platforms and significantly bigger on 64-bit platforms.%Heap handle with incorrect signature.0Heap handle used in the call to a heap interfaceNot usedNot usedNot used�The heap structures are tagged with a magic value. If the heap handle

used in the call to a heap interface does not have this pattern then

this stop will be generated. This bug can happen if somehow the internal

heap structure got corrupted (random corruption) or simply a bogus value

is used as a heap handle. To get a list of valid heap handle values

use the following debugger commands:

    !heap -p

Note that if you just switch a valid heap handle with another valid

one in a heap operation you will not get this stop (the handle looks

valid after all). However the heap verifier detects this situation

and reports it with SWITCHED_HEAP_HANDLE stop.+Corrupted heap pointer or using wrong heap.Heap handle used in the call.%Heap block involved in the operation.Size of the heap block.*Heap where block was originally allocated.
Typically this happens if a block gets allocated in one heap and freed in another.

Use !heap -p command to get a list of all valid heap handle values. The most common

example is a msvcrt allocation using malloc() paired with a kernel32 deallocation

using HeapFree().Heap block already freed.*Heap handle for the heap owning the block.Heap block being freed again.Size of the heap block.Not used�This situation happens if the block is freed twice. Freed blocks are marked in a

special way and are kept around for a while in a delayed free queue. If a buggy

program tries to free the block again this will be caught assuming the block was not

dequeued from delayed free queue and its memory reused for other allocations.



The depth of the delay free queue is in the order of thousands of blocks therefore

there are good chances that most double frees will be caught.Corrupted heap block.Heap handle used in the call.%Heap block involved in the operation.Size of the heap block.ReservedqThis is a generic error issued if the corruption in the heap block

cannot be placed in a more specific category. Attempt to destroy process heap."Heap handle used with HeapDestroy.Not usedNot usedNot usedlIt is an error to try to destroy the default process heap (the one

returned by GetProcessHeap() interface).AUnexpected exception raised while executing heap management code.Heap involved in the operation.Exception record.Context record.,Exception code (C0000005 - access violation)This stop is generated if while executing the heap manager code an

access violation is raised in illegitimate situations.

There are very few situations where this is ok, for example when

calling HeapValidate() or HeapSize(). The exception record information

(third parameter) can be used to find the exact context of the exception.

Use the following debugger commands for this:



    $ .exr STOP-PARAMETER-2

    $ .cxr STOP-PARAMETER-3



Usually this stop can happen if there is some random corruption in

the internal heap structures.7Exception raised while verifying the heap block header.*Heap handle for the heap owning the block.Heap block that is corrupted.7Size of the block or zero if size cannot be determined.	Not used.This situation happens if we really cannot determine any particular type of

corruption for the block. Most likely this stop will happen when the heap block

address passed to a heap free points to a non-accesible memory area (corrupted

pointer, uninitialized pointer, etc.).0Exception raised while verifying the heap block.Heap handle used in the call.%Heap block involved in the operation.Size of the heap block.	Reserved.�This situation happens if we really cannot determine any particular

type of corruption for the block. For instance you will get this if

during a heap free operation you pass an address that points to a

non-accessible memory area.



This can also happen for double free situations if we do not find the

block among full page heap blocks and we probe it as a light page heap block.'Heap block corrupted after being freed.*Heap handle for the heap owning the block.Heap block that is corrupted.7Size of the block or zero if size cannot be determined.	Not used.LThis situation happens if a block of memory is written to after being freed.-Corrupted infix pattern for freed heap block.*Heap handle for the heap owning the block.Heap block being freed.Size of the heap block.Corruption address.�Freed blocks are sometimes marked non-accessible and a program touching

them will access violate (different verifier stop). In other cases (light page heap)

the block is marked with a magic pattern and will be kept for a while.

Eventually in a FIFO fashion the blocks get really freed. At this moment the infix

pattern is checked and if it has been modified you will get this break.

Use !heap -p -a HEAP_BLOCK_ADDRESS to get the stack at the time the block was freed.(Corrupted suffix pattern for heap block.Heap handle used in the call.%Heap block involved in the operation.Size of the heap block.Corruption address.EMost typically this happens for buffer overrun errors. Sometimes the application

verifier places non-accessible pages at the end of the allocation and buffer

overruns will cause an access violation and sometimes the heap block is

followed by a magic pattern. If this pattern is changed when the block gets

freed you will get this break. These breaks can be quite difficult to debug

because you do not have the actual moment when corruption happened.

You just have access to the free moment (stop happened here) and the

allocation stack trace (!heap -p -a HEAP_BLOCK_ADDRESS)%Corrupted start stamp for heap block.Heap handle used in the call.%Heap block involved in the operation.Size of the heap block.Corrupted stamp value."This happens for buffer underruns.#Corrupted end stamp for heap block.Heap handle used in the call.%Heap block involved in the operation.Size of the heap block.Corrupted stamp value."This happens for buffer underruns.(Corrupted prefix pattern for heap block.Heap handle used in the call.%Heap block involved in the operation.Size of the heap block.Corruption address."This happens for buffer underruns.6First chance access violation for current stack trace.&Invalid address causing the exception.*Code address executing the invalid access.Exception record.Context record.�This is the most common application verifier stop. Typically it is caused by a

buffer overrun error. The heap verifier places a non-accessible page at the end

of a heap allocation and a buffer overrun will cause an exception by

touching this page. To debug this stop identify the access address that caused

the exception and then use the following debugger command:

    !heap -p -a ACCESS_ADDRESS

This command will give details about the nature of the error and what heap block is

overrun. It will also give the stack trace for the block allocation.



There are several other causes for this stop. For example accessing a heap block

after being freed. The same debugger command will be useful for this case too. Invalid process heap list count.Actual heap count.Page heap count.Not usedNot used�This message can happen if while calling GetProcessHeaps

the page heap manager detects some internal inconsistencies.

This can be caused by some random corruption in the process space..OLE32 library has been unloaded and re-loaded.	Not used.	Not used.	Not used.	Not used.&Ole32 has been unloaded and re-loaded.%COM API or Proxy called from DllMain.	Not used.	Not used.	Not used.	Not used.�This stop is generated when a COM Proxy or a dangerous COM API is called

with the loader lock held.  To debug this run a simple `kb' to get the stack

of the misbehaving DLL.  The DLL should remove its call to the COM API in question. Unhandled exception in COM call.!Exception pointers for exception.Object being called on.Pointer to IID being called on.Method number being called on.dThis stop is generated if, while processing a COM call, the object being invoked

raises an exception.  The exception record information (first parameter) can be

used to find the exact context of the exception. Use the following debugger

commands for this:



    $ dd parameter1 L2

    $ .exr first_dword

    $ .cxr second_dword



Sometimes we know the exact object we called into that raised the error.

In these cases, the second parameter will point to the interface pointer

we tried to call on.  The third and fourth parameters will indicate which

interface and method we think we called on, as well.?Unbalanced CoInitialize/CoUninitialize calls on current thread.4Current number of CoInitialize calls on this thread.5Previous number of CoInitialize calls on this thread.�Stack traces of CoInitialize calls on this thread. If non-zero, do !list -t ntdll!_LIST_ENTRY.Flink -x "dps poi(" -a " -4) l 0n32" param (use -8 for x64).�Stack traces of CoUninitialize calls on this thread. If non-zero, do !list -t ntdll!_LIST_ENTRY.Flink -x "dps poi(" -a " -4) l 0n32" param (use -8 for x64).This stop is generated when COM detects that there has been an unbalanced call to

CoInitialize on this thread.  Causes for this include exiting a thread with

outstanding CoInitialize calls on it, calling CoInitialize without calling CoUninitialize,

or calling CoUninitialize without calling CoInitialize.  The stacks of the most recent

CoInitialize and CoUninitialize calls may be present in the third and fourth parameters.

If they exist (non-zero), they may help to locate the culprit. The following example shows how to manually dump these stacks:



Assume the parameter value is addr. Use the following debugger commands:



For 32-bit: !list -t ntdll!_LIST_ENTRY.Flink -x "dps poi(" -a " -4) l 0n32" addr

For 64-bit: !list -t ntdll!_LIST_ENTRY.Flink -x "dps poi(" -a " -8) l 0n32" addrAUnbalanced OleInitialize/OleUninitialize calls on current thread.5Current number of OleInitialize calls on this thread.6Previous number of OleInitialize calls on this thread.�Stack traces of OleInitialize calls on this thread. If non-zero, do !list -t ntdll!_LIST_ENTRY.Flink -x "dps poi(" -a " -4) l 0n32" param (use -8 for x64).�Stack traces of OleUninitialize calls on this thread. If non-zero, do !list -t ntdll!_LIST_ENTRY.Flink -x "dps poi(" -a " -4) l 0n32" param (use -8 for x64).%This stop is generated when COM detects that there has been an unbalanced call to

OleInitialize on this thread.  Causes for this include exiting a thread with

outstanding OleInitialize calls on it, calling OleInitialize without calling OleUninitialize,

or calling OleUninitialize without calling OleInitialize.  The stacks of the most recent

OleInitialize and OleUninitialize calls may be present in the third and fourth parameters.

If they exist (non-zero), they may help to locate the culprit. The following example shows how to manually dump these stacks:



Assume the parameter value is addr. Use the following debugger commands:



For 32-bit: !list -t ntdll!_LIST_ENTRY.Flink -x "dps poi(" -a " -4) l 0n32" addr

For 64-bit: !list -t ntdll!_LIST_ENTRY.Flink -x "dps poi(" -a " -8) l 0n32" addrMUnbalanced CoEnterServiceDomain/CoLeaveServiceDomain calls on current thread.Current COM object context.�Stack traces of CoEnterServiceDomain calls on this thread. If non-zero, do !list -t ntdll!_LIST_ENTRY.Flink -x "dps poi(" -a " -4) l 0n32" param (use -8 for x64).�Stack traces of CoLeaveServiceDomain calls on this thread. If non-zero, do !list -t ntdll!_LIST_ENTRY.Flink -x "dps poi(" -a " -4) l 0n32" param (use -8 for x64).Not usedXThis stop is generated when COM detects that there has been an unbalanced call to

CoEnterServiceDomain on this thread.  Causes for this include exiting a thread

with outstanding CoEnterServiceDomain calls on it, calling CoEnterServiceDomain

without calling CoLeaveServiceDomain, or calling CoLeaveServiceDomain without

calling CoEnterServiceDomain.  The stacks of the most recent CoEnterServiceDomain

and CoLeaveServiceDomain calls may be present in the second and third parameters.

If they exist (non-zero), they may help to locate the culprit. The following example shows how to manually dump these stacks:



Assume the parameter value is addr. Use the following debugger commands:



For 32-bit: !list -t ntdll!_LIST_ENTRY.Flink -x "dps poi(" -a " -4) l 0n32" addr

For 64-bit: !list -t ntdll!_LIST_ENTRY.Flink -x "dps poi(" -a " -8) l 0n32" addr.Calling CoInitializeSecurity with a NULL DACL.;Security Descriptor that was used for CoInitializeSecurity.	Not used.	Not used.	Not used./This stop is generated when COM detects that DCOM security is being initialized

with a security descriptor containing a NULL DACL.  A NULL DACL for COM means

that anybody can call any of your objects.  While not functionally different

from supplying no security descriptor at all, the rationale behind this stop

is that if you went through all the trouble to create a security descriptor

with a NULL DACL, you must think you're getting something you're not.



To debug this, look at the call stack.  The security descriptor can come

from one of the following places:



1. The calling code could pass it in directly.  If the security descriptor is

being supplied directly by the function calling CoInitializeSecurity,

then that code needs to be corrected.



2. CoInitializeSecurity could be reading the values out of the AppID key

specified in the call to CoInitializeSecurity.  In this case, the specific

application configuration needs to be fixed.



3. CoInitializeSecurity could be reading the values out of the AppID key

associated with the current EXE.  Again, the specific application

configuration needs to be fixed.



4. CoInitializeSecurity could be using the global default access permissions.

This indicates a machine-wide misconfiguration.  The administrator should

fix the machine-wide settings.OSYSTEM Process initialized DCOM security with impersonation allowed by default.Process token.Default impersonation level.	Not used.	Not used.This stop is generated when COM detects that a process running as SYSTEM is

initializing DCOM security with an impersonation level of RPC_C_IMP_LEVEL_IMPERSONATE

or better.  This means that, by default, any COM call made grants the callee the right to impersonate SYSTEM.



To debug this, look at the call stack.  Either the caller is passing the

unsafe impersonation level directly to CoInitializeSecurity, or the impersonation

level is being read out of the registry, from the AppID key associated with

the current process./A COM+ Proxy was called from the wrong context.,Pointer to IID of interface being called on.Method number being called.	Not used.,Pointer to the COM+ proxy that was smuggled.�This stop is generated when COM detects that a user has tried to call a

COM+ proxy from the wrong object context.  In general, COM+ proxies have

affinity to the context that they were unmarshalled in, and must only be

called from those contexts.



To debug, look at the call stack.  The caller of the proxy (the code

before ole32.dll) needs to check to make sure that they correctly

unmarshalled that interface pointer into the current context..A COM Proxy was called from the wrong context.,Pointer to IID of interface being called on.Method number being called.)The apartment that the proxy is valid in.The current apartment.�This stop is generated when COM detects that a user has tried to call a COM

proxy from the wrong apartment or context.  In general, COM objects have

affinity to the apartment and context that they were unmarshalled in,

and must only be called from those places.



To debug, look at the call stack, and parameters three and four.

Parameter three indicates the apartment that the proxy is valid in,

and parameter four indicates the apartment that the current call stack is in.

The apartment values are interpreted as follows:



- If the number is 0, then the apartment is the MTA.

- If the number is 0xFFFFFFFF, then the apartment is the NA.

- Otherwise, the number is the thread ID of an STA.



If the numbers match, this indicates that the proxy was smuggled to a

different COM+ object context.  In this case, treat this stop as a COM_SMUGGLED_WRAPPER stop.



The most common cause of this error is putting an interface pointer into

a global variable and using it from more than one thread.=A class factory has returned success, but with a NULL object.Pointer to the class factory.#Pointer to the CLSID being created.#Pointer to the IID being requested.The HRESULT returned.�This stop is generated when COM detects that a class factory has returned a

success HRESULT from IClassFactory::CreateInstance(), but has returned

NULL in the ppv argument.  This is always a bug in the implementation

of the class factory.



To debug, examine the implementation of the class factory.

Information about which class and interface were being requested is

available from the second and third parameters.  The first parameter is

the pointer that ole called on, so you can dump that to examine the state

of the class factory in question.  Finally, the HRESULT might be something

strange when it was supposed to be an error-the fourth parameter will

tell you what was actually returned from the class factory.IA call to DllGetClassObject has returned success, but with a NULL object.2Name of the DLL whose DllGetClassObject we called.#Pointer to the CLSID being created.#Pointer to the IID being requested.The HRESULT returned.]This stop is generated when COM detects that a call to DllGetClassObject

has returned a success HRESULT, but a NULL class factory.  This is always

a bug in the implementation of the DllGetClassObject function.



To debug, examine the implementation of the DllGetClassObject function in

the DLL named by parameter 1.  Information about which class and interface

were being requested is available from the second and third parameters.

Finally, the HRESULT might be something strange when it was supposed to

be an error-the fourth parameter will tell you what was actually returned

from the function./Freeing memory containing marshaled COM object.1Pointer to the COM object in the block of memory.5Pointer to the start of the memory block being freed.Size of the memory block.	Not used.�This stop is generated when COM detects that a block of memory is being

freed that contains a COM object.  This is generally the result of freeing a

COM object that still has outstanding marshaled references to it (i.e., COM is

still holding a stub alive for the object).  It indicates a reference

counting bug for the object in question.



To debug, use 'ln poi PARAM1' to identify the VTBL of the COM

object being freed.  Examine the implementation and clients of the

COM object for obvious reference counting problems.  Unfortunately,

debugging reference counting problems is difficult, as it generally

requires putting a breakpoint on the AddRef() and Release() implementations

for this kind of object and reproducing the problem.0Unloading a DLL containing marshaled COM object.1Pointer to the COM object in the block of memory. The name of the DLL being freed.The base address of the DLL.	Not used.VThis stop is generated when COM detects that a DLL is being unloaded which

contains a COM object.  As this stop is only issued when unmapping a

DLL from memory, the COM object in question is almost always a global

object or a singleton.  Therefore, this stop indicates a bug in the

DLLs DllCanUnloadNow implementation.



To debug, use 'ln poi PARAM1' to identify the VTBL of the COM

object being freed, and 'du PARAM2' to identify the DLL.

Examine the implementation of the DLL's DllCanUnloadNow function,

and make sure that the DLL always returns S_FALSE when there are

still active objects in the DLL.  The other possible cause of this

is a DLL handle reference counting bug.  If the current stack does

not indicate that ole32 is unloading the DLL, then check to make

sure that the code unloading the DLL actually has a valid module handle.AFreeing memory containing implementation of marshaled COM object.The object VTBL.-The address of the start of the memory block.The size of the memory block.	Not used.�This stop is generated when COM detects that a block of memory is being freed

which contains a VTBL (i.e., the implementation) for a COM object.

This is extremely rare-in general, it only happens when code is

generated dynamically into memory, or code is mapped into memory

with a mechanism other than LoadLibrary().  As such, this stop usually

indicates a problem in a runtime (i.e., in a VM) that is implementing the COM object.



To debug, dump the memory block and see if it has useful information in it.

If this is hit, and you know the code in question is using the CLR or JVM,

then probably the page heap information on the block will give the best

information for debugging this.DUnloading a DLL containing implementation of a marshaled COM object.The object VTBL. The name of the DLL being freed.The base address of the DLL.	Not used.This stop is generated when COM detects that a DLL is being unloaded which

contains a VTBL (i.e., the implementation) for a COM object.  This is

generally the result of unloading a DLL that implements one or more

COM objects that still have outstanding marshaled references to them (i.e.,

COM is still holding a stub alive for objects implemented in this DLL).

As this stop is only issued when unmapping a DLL from memory, this stop

indicates a bug in the DLLs DllCanUnloadNow implementation.



To debug, use 'ln PARAM1' to identify the VTBL of the COM object

being freed, and 'du PARAM2' to identify the DLL.  Examine the

implementation of the DLL's DllCanUnloadNow function, and make sure

that the DLL always returns S_FALSE when there are still active objects in the DLL.CA lock is being held across a COM call (examine the current stack).	Not used.	Not used.	Not used.	Not used.cThis stop is generated when COM detects that a critical section is being held

across a remote (i.e., at least cross-thread) COM call.  This is not a bug,

per se, it's usually just a bad design.  First of all, callbacks to the

object on a different thread have a good chance of deadlocking.  Second of

all, there is no way of knowing how long the remote call is going to block,

so holding the lock across the call is generally very bad from a scalability

and performance point of view.



To debug, look at the stack, and use the !locks debugger extention to figure

out which locks this thread is holding.:Low security blanket (explicit CoInitializeSecurity call).Authentication service.Authentication level.	Not used.	Not used.WThis stop is generated when COM detects that a client process configures security

settings (by calling CoInitializeSecurity explicitly) too low:

the authentication service is RPC_C_AUTHN_WINNT (10) or authentication level is less

than RPC_C_AUTHN_LEVEL_PKT_INTEGRITY (5).



To debug, look for CoInitializeSecurity caller in the call stack.(Low authentication level (from registry)Authentication service.Authentication level.Registry path.	Not used.This stop is generated when COM detects that a client process does not configure security

settings explicitly. CoInitializeSecurity is called implicitly, authentication level is

read from registry and turns out to be too low: less than RPC_C_AUTHN_LEVEL_PKT_INTEGRITY (5). Low security blanket on a proxy.Authentication service.Authentication level.	Not used.	Not used.�This stop is generated when COM detects that a client process configures security

settings on a remote proxy (by calling IClientSecurity::SetBlanket or CoSetProxyBlanket)

too low: the authentication service is RPC_C_AUTHN_WINNT (10) or authentication level

is less than RPC_C_AUTHN_LEVEL_PKT_INTEGRITY (5).



To debug, look for IClientSecurity::SetBlanket or CoSetProxyBlanket caller in the call stack.1Low security blanket (incoming call on a server).Authentication service.Authentication level.	Not used.	Not used.�A server process is accepting a remote call with security settings that are too low:

the authentication service is RPC_C_AUTHN_WINNT (10) or authentication level is less

than RPC_C_AUTHN_LEVEL_PKT_INTEGRITY (5).&Application should call OleInitialize.OLE API called.	Not used.	Not used.	Not used.�This stop is generated when an application calls one of the OLE clipboard or drag and drop APIs,

without first calling OleInitialize.,Invalid query syntax in IEventSystem::RemoveprogID parameterqueryCriteria parameterApproximate error location	Not used.�This stop is generated when COM+ Event System detects that the IEventSystem::Remove

method has been used incorrectly by an application.  Incorrect usage can in some cases

remove unintended objects, including objects owned by other applications.



The query contains a syntax error.  PARAM3 contains the approximate location of the error,

expressed as an offset into the queryCriteria string.3"ALL" used as queryCriteria to IEventSystem::RemoveprogID parameterqueryCriteria parameter	Not used.	Not used.�This stop is generated when COM+ Event System detects that the IEventSystem::Remove

method has been used incorrectly by an application.  Incorrect usage can in some cases

remove unintended objects, including objects owned by other applications.



The query has the value "ALL".  This value is inappropriate because it selects all

subscriptions or event classes registered on the machine, not just those created by this

application.UqueryCriteria in IEventSystem::Remove contains no "identifying" subscriber propertiesprogID parameterqueryCriteria parameter	Not used.	Not used.NThis stop is generated when COM+ Event System detects that the IEventSystem::Remove

method has been used incorrectly by an application.  Incorrect usage can in some cases

remove unintended objects, including objects owned by other applications.



When removing subscriptions, be sure the query selects by properties that can distinguish

this application's subscriptions from subscriptions created by other applications.  The

heuristic used by this stop requires at least one of the following properties to be

present in the query:

-SubscriptionID uniquely identifies a subscription.  This is preferred whenever possible.

-SubscriptionName and Description can identify an application's subscriptions, if the

 application assigns them unique values.

-SubscriberCLSID or SubscriberMoniker can identify persistent subscriptions belonging to a

 particular component.

-To avoid false positives, the heuristic also accepts OwnerSID or MachineName because some

 administrative tools or scripts might use them.  Most applications should not rely on

 these properties to select their subscriptions.GqueryCriteria in IEventSystem::Remove selected a COM+-configured objectprogID parameterqueryCriteria parameter	Not used.	Not used.�This stop is generated when COM+ Event System detects that the IEventSystem::Remove

method has been used incorrectly by an application.  Incorrect usage can in some cases

remove unintended objects, including objects owned by other applications.



The query selected a subscription or event class that was created through the COM+

Administration library.  These objects cannot be removed with IEventSystem::Remove.

Please check whether the query is correct.HE_ACCESSDENIED removing a transient subscription in IEventSystem::RemoveprogID parameterqueryCriteria parameter	Not used.	Not used.�This stop is generated when COM+ Event System detects that the IEventSystem::Remove

method has been used incorrectly by an application.  Incorrect usage can in some cases

remove unintended objects, including objects owned by other applications.



An E_ACCESSDENIED (0x80070005) error occurred while attempting to remove a transient

subscription.  It is unexpected for this error to occur when an application removes its

own transient subscriptions.  Please check whether the query is correct.



This error can also occur if a service is impersonating when creating a subscription, but

not impersonating when it attempts to remove it, or vice versa.>queryCriteria in IEventSystem::Remove selects multiple objectsprogID parameterqueryCriteria parameter	Not used.	Not used.This stop is generated when COM+ Event System detects that the IEventSystem::Remove

method has been used incorrectly by an application.  Incorrect usage can in some cases

remove unintended objects, including objects owned by other applications.



The progID parameter indicates that the caller is requesting a single object be removed,

but the queryCriteria parameter selects multiple objects.  This is a logical error in the

caller because the behavior of IEventSystem::Remove is nondeterministic.  Please check

whether removing multiple subscriptions or event classes was intended - in which case

progID should be PROGID_EventSubscriptionCollection or IDPROGID_EventClassCollection,

respectively - or whether the query is missing properties that uniquely identify the

object.YAn object marked as requiring full trust should not be marshaled to an untrusted process.,Pointer to IID of interface being marshaled.*Pointer to the COM object being marshaled.	Not used.	Not used.DThis stop is generated when COM detects that an object that has not been hardened

to be usable from a low trust application is being marshaled to an untrusted

application.  In general, this can be either (1) older objects that don't implement

the IInspectable::GetTrustLevel function to determine where the object is safe to

be used from or (2) objects that return FullTrust from the GetTrustLevel function.



To debug, look at the call stack.  The method that allows this marshaling should be

changed to only allow the marshaling of trusted interfaces to untrusted callers.;Unexpected QueryInterface on server side standard marshalerPointer to the IID queried&IMarshal pointer of standard marshaler!IUnknown pointer of server object	Not used.�This stop is generated when QueryInterface is called on a server-side standard marshaler,

as obtained by CoGetStandardMarshal, with an IID that this object does not support.



The server-side standard marshaler is designed for specific usage patterns to support

specializing the marshaling behavior of a server object. Typically the server object

calls CoGetStandardMarshal to get the IMarshal interface, calls the IMarshal methods

as necessary, and Releases it when finished, with no need to QueryInterface. Calling

QueryInterface with an IID that the standard marshaler does not support can indicate

a bug in the caller, relying on undocumented and unsupported behavior of this object.Premature Stub Rundown DetectedPointer to the IID of the call
Method Number Pointer to the IPID of the call.RundownType)This stop is generated when the COM runtime detects that a same machine call

failed because the stub manager for the object has been prematurely

rundown.



For Store Application and Connected Standby scenarios that involve application suspension,

this verifier stop points to a bug in the COM runtime's mitigations to

prevent premature stub rundowns.



The CallType could be one of the following:



1 - RundownInRemoteAddRefCall

2 - RundownInRemoteQueryInterfaceCall

3 - RundownInRemoteQueryInterface2Call

4 - RundownInNonIUnknownInterfaceCall�The async operation's completed delegate was set to null, which prevents the async operation from ever receiving a callback on completion.5The async operation object that was used incorrectly.Not usedNot usedNot used�The async operation's completed delegate was set to null, which prevents

the async operation from ever receiving a callback on completion because

the completed delegate property is write-once.xThe async operation's completed delegate was set more than once, which is not allowed since it is a write-once property.5The async operation object that was used incorrectly.LThe duplicate completed delegate that was being set on the operation object.Not usedNot usedyThe async operation's completed delegate was set more than once,

which is not allowed since it is a write-once property.�The async operation was released before its completed delegate was set, so it was never capable of notifying its client of completion during its lifetime.5The async operation object that was used incorrectly.Not usedNot usedNot used�The async operation was released before its completed delegate was set,

so it was never capable of notifying its client of completion during its

lifetime. The completed delegate property of the async operation should

be set soon after creating the async operation so that the async operation

can notify the client of completion. Failing to register a completed

delegate is a violation of the WinRT Async Pattern.�The async operation was released after it was notified of completion but before it called GetResults, so its completed delegate did not follow the contract.5The async operation object that was used incorrectly.HThe async operation's completed delegate that failed to call GetResults.Not usedNot used
The async operation was released after it was notified of completion but before

it called GetResults, so its completed delegate did not follow the contract.

The completed delegate should either call GetResults or otherwise ensure

that the client calls GetResults.vThe call failed because the AsyncBaseStateMachine was not in a terminal state (Error, Canceled, Completed, or Closed).5The async operation object that was used incorrectly.Not usedNot usedNot usedwThe call failed because the AsyncBaseStateMachine was not in

a terminal state (Error, Canceled, Completed, or Closed).JThe call failed because the AsyncBaseStateMachine was in the Closed state.5The async operation object that was used incorrectly.Not usedNot usedNot usedJThe call failed because the AsyncBaseStateMachine was in the Closed state.�Clients should not marshal their async operation objects out of the current process and servers should not marshal their completed delegates or progress delegates out of the current process.GThe async object that tried to be marshaled out of the current process.Not usedNot usedNot usedAClients should not marshal their async operation objects

out of the current process and servers should not marshal

their completed delegates or progress delegates out of

the current process because to work correctly in all cases

this usage relies on implementation details of cross-process

calls to WinRT Async APIs.�Calling Close after Cancel is unnecessary and prone to hangs since Cancel requires a response from the server and Close is a blocking operation that will wait until Cancel completes.5The async operation object that was used incorrectly.Not usedNot usedNot used�Calling Close after Cancel is unnecessary and prone to hangs

since Cancel requires a response from the server and Close is

a blocking operation that will wait until Cancel completes.MIllegal attempt to use a COM object after uninitializing COM for the process.HThe IUnknown of the COM object that was used after final CoUninitialize.Not usedNot usedNot used�Attempting to use objects provided by the COM runtime after uninitializing COM

for the process is illegal since the global COM data structures used internally

by those objects were cleaned up during COM uninitialization for the process.9Marshaling an agile object from a disconnectable context.[The IUnknown of the agile COM object that is being marshaled from a disconnectable context.+The v-tbl address pointed to by the object._The name of the DLL that contains the v-tbl(du to dump). Heuristically, this is the service DLLNot used�An agile object hosted by a service DLL is being marshaled from a disconnectable

context. CoDisconnectContext will not disconnect the stub (if any) for the object. 

Hence, the service DLL may be unloaded while the object is active, this is a bug.Stream usage leaking HGlobalNot usedNot usedNot usedNot used�Leaking HGlobal - Stream created with CreateStreamOnHGlobal(nullptr, false, ...)

is released without calling GetHGlobalFromStream to manage the HGlobal lifetime\Possible security threat: Client is calling a remote endpoint without mutual authentication.	Not used/	Not used/	Not used/	Not used/�This stop is generated if a component uses RPC in such a way as to create

security vulnerabilities.  The user code in the current thread is the culprit.

The stop does not cause a debug break and machine needs to be broken-into

prior to debugging. The stop message is followed by some debugging information.



To debug this stop use the following debugger commands:



    $ Ctrl-C or PrintScr - to break into the machine.



    $ !process pid 0 - to get the address ADDR of the faulting process;

    here pid is the faulting process id displayed in the verifier stop message.



    $ .process ADDR - to switch into the context of the faulting process.



    $ After the verifier stop message RPC will print the dump of the stack that

    has caused the stop.  The printout will be preceded by: `RPC: Offending Stack:'.

    In the context of the faulting process, do an `ln' on the displayed stack addresses

    to get the corresponding symbols.



    $ If the faulting stack is not displayed or in addition to it,

    RPC will print some information identifying the faulting user code or component.

    These messages begin with `RPC:' and contain interface UUID's and other

    useful information:



    ===========================================================

    VERIFIER STOP 00000500: pid 0x3A4: Possible security threat: An unsecure interface becomes remotely accessible



    00000000 : (null)

    00000000 : (null)

    00000000 : (null)

    00000000 : (null)

    ===========================================================



    RPC: Starting to listen on protsec: ncacn_ip_tcp endpoint: (null)

    RPC: Unsecure interface UUID: 621dff68-3c39-4c6c-aae3-e68e2c6503ad

    RPC: Unsecure interface UUID: 00000134-0000-0000-c000-000000000046

    RPC: Unsecure interface UUID: 18f70770-8e64-11cf-9af1-0020af6e72f4

    RPC: Unsecure interface UUID: 00000131-0000-0000-c000-000000000046



    In the above example, the owners of the interfaces that have not been secured are at fault.00000$0�1�1�1�1 �7;�;�;�;�;�;�;�;
<<<.<9<S<^<m<<�<�<�<�<�<�<�<�<�<="=6=B=M=m==�=�=�=�=�=�=�=�=�=>
>>>$>->=>L>[>j>x>~>�>�>�>�>�>�>�>�>�>??(?/?:?>?E?K?R?^?i?p?�?�?�?�?�?�?�?�?�?00
00!0,0F0Q0_0e0k0w0�0�0�0�011X1q1�1�1�1�1�122B2Y2c2�2�2�2�2�2�2�3�4�465^5�5�5�56	66!61666=6B6J6O6X6`6h6p6x6�6�6�6�6�67"7+7^7x7�7�7�7�7�7�7�7�7�7�7�7�7�7�7�78/888@8K8S8[8a8f8v8�8�8�8�8?9]9c9l9r9{9�9�9�9�9�9�9�9�9�:�:;";+;<;G;P;d;i;o;;�<�=�=�>�>?]?�?�?@�<0�0�0e1�2�2�2�2.3U3�3�3�3�3�3�34444K4�4�4�4�4545W5�5�5�6�6�6�6�67,767U7_7�7�7�7�7�7�7�788$8*8:8n8�8�:�:�:�:B;J;�;�;�;<"<(<6<><y<�<1=D=�=>>.>@>Y>c>z>�>�>�>�>�>�>�>??2?B?T?l?{?�?�?�?�?�?�?�?PL0&050I0Y0k00�0�0�0�0U1�144&4,484D4M4]4b4j4o4u4�4�4�4�4�4�4�4�4�4�45535P5k5s5{5�5�5�5H7�7�7�78?8q8�8�8�8�8�8�8�8�89'909?9D9M9V9`9~9�9�9K:~:�:�:�:;;2;=;G;b;m;w;�;�;�;�;�;�;�;�;B<X<b<g<p<}<�<�<�<�<�<�<�<�<�<6=B=Q=X=j=o=y=�=�=�=�=�=�=>>>'>:>F>N>S>k>q>�>�>�>�>�>�>�>�>�>�>�>??????$?)?.?4?I?T?[?`?w?�?�?�?�?�?�?`�	0)04090A0�0�0�2�3�344444$4�4�4�4�4�4�4�4�4�4N5�6	707�7�7�7�788 8�8�8Y9`9f9k9�9�9�9�9�9�9�9�9:	:%:K:`:�:�:�:�:;,;B;[;�;�;?<r<�<�=�=�=�=�=�=�=L>k>�>�>�>�>�>�>�>�>�>,?�?�?�?�?�?�?�?�?�?�?p�20G0o0�0�01
1311�1�132�2�3�3,4_4l4�4�4�4�45F55�5�5�5�5�566%6,626?6I6U6a6v6�6�6�67`7y7�7�7�7�7�7w89�9�9	::3:^:�:�:#;G;[;~;�;�;�;�;�;�;�;�;;<\<c<u<�<�<�<,=9=J=�=�=�=�=�=�=�=�=�=>
>#>+>D>Z>p>z>�>�>�>�>???0?n?�?�?�8070p0y00�0�0�0�01101;1E1b1x1�1�1�1�1�1�1�1�1�1&202@2N2X2j2�2�2343�3�3�34!4>4^4v4�4�4�425=5W5�5�5�5�5�5�6�6�6�6�6+787U7�7�7�7�7�7
9:9>9B9F9t9{9�9�9�9�9�9�9�9�9�9�9�9�9::::&:*:1:G:N:\:�:�:�:�:`;p;�;�;�;�;�;�;�;�;�;<:<w<�<�<�<�<=>=W=_=�=�=�=>>E>b>�>�>�>�>?:?O?^?n?�?�?�?�?�?�?�?�?�?�?�?�?�?��0000,0D0L0V0n0v0�0�0�0�0�0�01%1M1a1g1x1~1�1�1�1�1�1�1�1�1�1�1�1�12	22)222:2@2F2k2x2�2�2�2�2�2�23333'30383>3D3L3x33�3�3�3�3434B4I4]4v4~4�4�4�4�4�455'505T5�5�5�5�5�5�5�5�5�5u6�6�6�6�6�6�677.737L7Z7_7f7m7{7�7�7�7�7�7�7�788#8<8B8H8S8]8m8r8w8|8�8�8�8�8�8�8�8�8�8�8�8�8P9V9k9x9~9�9�9�9�9�9�9�9�9:
:::!:1:Z:b:h:�:�:�;�;�;�;�;a<z<�<�<='=-=3=8=Z=`=�=�=�=�=�=V>`>j>>�>�>???F?M?S?f?n?t?y?�?�?�?�?�?�?�?�?�?�?��00 040F0�0�0�011A1G1Q1_1l1t1y1�1�1�1�1�1�1�1�1�1�1�1�122$2-292E2T2d2r2x2�2�2�2�2�2�2�233-3C3Z3s3�3�3�3�3�3�3�3�3�344424;4K4j4p4�4�4�4�4�4�4�4�4�45"5)51575W5b5g5m5�5�5�5�5�5�5�5�56#60696S6_6�6�6�6�6�6�6�6�6�6�6777!7'7-737B7H7|7�7�7�7�7�7�788888%8W8c8l8t8�8�8�8�8�8�8�8�8�8�8999%9-93999?9N9V9\9b9h9v9�9�9�9�9:):k:|:�:�:;;Q;`;t;�;�;�;,<Y<d<�<n=t=z=�=�=�=�=�=�=�=�=�=�=�=�=�=�=�=�=�=�=>>#>3><>g>t>>�>�>�>�>�>�>�>�>�>�>�>�>�>�>)?8?`?g?y?�?�?�?�?���0�0�0�0�0�0�0�0�0A1�1242:2@2F2L2R2X2^2d2j2p2v2|2�2�2�2�2�2�2�2�2�2�2�2�2�2�2�2�2�2�2�2�2�2333333$3*30363<3B3H3N3T3Z3`3f3l3r3x3~3�3�3�3�3�3�3�3�3�3�3�4e5j5�5�5�5�5�5�5�566$616=6E6\6�6�6E7_7h7�7�7�7!8>8y88�8�8�8�89(90949�$0000 0,0@0H0`0d0h0�0�0�0�0�0�0�0�0�0�0�0�0�0�0�0�01(1@1X1�1�1�1�1�1�1�1�1�1�1�1�1�1�1�1�1<2L2\2`2h2l2p2�2�2�2�2,30383<3@3�3�3�3�3�3�3�3�3�3�3�3�3�3�34444 4@4L4X4d4p4|4�4�4�4�4�4�4�4 5,585D5P5\5h5t5�5�5�5�5�5�5�5�5�5�5�5666(646@6L6X6d6p6|6�6�6�6�6�6�6�6�6�6�677(747@7x7�`?h?x?�?�81((0�(	*�H��
��(0�(10
	`�He0��
+�7���0��0�Y
+�70�I��B��>���մ�$f��ڎ`��(1�$0� 
+�71��1�.Z�;_y����3�G���A�wj�%>����E����C
o�T��i�K�p*Rh�ـ�y�����(<�XB�����j׽�E�] �i�d%a$\B;P���t<� ��j��T�$w���(<?N4�[�/#��-D�I�k��kt^b����d��Dp�ik�d�rf���^�Hk,��&γ�U�� 2T\*�b}cR�[������^�r�G��0�="�oGd��r�$Rs�m+��wn�*�{��[�a��@��t�!��e�,��*���R|��O_���	{���q��
�=��LQ�ua���&Mp63}U�<�ȹP\ �ϋ3��z9�P�س^^D�{#�/z��'�d��µ�sl�?��W,���U<���~v �us>�c�ۗ�}����f�
�;S'��A7��ɞ5�G��d��-Ws��L�۶�u��
��uP��3�*�i]��@����˶P,ݧb��y\�����'ߎ2���?�7(�@m]��/
f��1i��I�ۢ�:�bi�T��,=z|��Q����	�rx�O��P%���W1*���븛�m��p8�V7�y���QX��?-�i1�� j�1����abP�u+��7!72sÕʆ�d�b�y0��oF ���.+H
�@��X���{\�[r��$��0�
�03w3H�M�]ҁ��#�Y����@Cts^u�kӽ�J�~�9�P�w�gEB��.%}UPG���4�iN;h����g �+Q��%D�w��`X"r���C3�bཪ���,�k�m�Wb���pc0���m�ɈV6���Qb��ߡ����AIw{�r@ɔ�GUP�|n/K�Br̗�ީV]�_��ʧ�T;�[�u}��=$�*�A�cL��p}9���@[���*���0���1t��)�^����A�"�X���Y ���m,��H�
Ik���Xc܌�Hbm�*�9m�>��?&�Ӧ�uηl.��S�pX�
��3W|�Sq�,�\Ӑ@PF��<G�j����
u�r�Zwߋղc*�Yqi�V�r׏�gc�<�!}�� �u�����u�z���[p��'=@�h�kO�m%�LT�TC��l�}�M�cd������r��y\ɛ�(�
�i�պ8�KN�m���� �00-��ItjW�{+�~+��	��@v���x`wP0*]u�ɮ�q�?�V�6�z����"�w?@�v�@�����%M�/����W��x�
�ʛ�p�H�P�i��F���ND?Q[
EQ�\�"� |Ç~D`NThu��V��C���ٺ���%.tT=T��b�J�HP�� ������������l�����p010
	`�He ��y�hL蓵�Ycg���:�@�FW�)�X����v0��0��3&����{�&0
	*�H��
0~10	UUS10U
Washington10URedmond10U
Microsoft Corporation1(0&UMicrosoft Code Signing PCA 20100
200304182929Z
210303182929Z0t10	UUS10U
Washington10URedmond10U
Microsoft Corporation10UMicrosoft Corporation0�"0
	*�H��
�0�
���4Ļ^њx=[4nɽ���������G0��x���&i�]9�~�XT���������lc4Q��E��״i���K���{i��HG	9����B:�M��n2�yg+}��)�9Z�U�uA��,�R�o=�$:�j
{,N��m����.��b$l��!��P3\�ȿS`d��YXaٴF����>����o��"qE��t-�.|Ѕ]���?�q�3����#�|1�-���jcS��iQm�SZ{�#���ǔ�)6�w+���}0�y0U%0
+�7=+0U]s���z�]�N�-/����0TUM0K�I0G1-0+U$Microsoft Ireland Operations Limited10U
230865+4584940U#0��_{�"X�rN��!t#2��0VUO0M0K�I�G�Ehttp://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl0Z+N0L0J+0�>http://www.microsoft.com/pki/certs/MicCodSigPCA_2010-07-06.crt0U�00
	*�H��
����q�,��r�ㄐ<�Eؤf����}
`%l��zeS��"��u�ca��`2y=�6��u}��4�$�.�QG����ʵ�=(C���#�1���Y��#�[i�3sP	�ﲦ76Iu����u�S!�K�h��(�`�!��o���m��;��1���W�i}`�6�iƥO���q���p�6�����WQ�[Xj�ؘhɍ_m�zT�c��n3N�똎�V�Ӑ�dX{gB���x��.���(]�-0�p0�X�
aRL0
	*�H��
0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1200U)Microsoft Root Certificate Authority 20100
100706204017Z
250706205017Z0~10	UUS10U
Washington10URedmond10U
Microsoft Corporation1(0&UMicrosoft Code Signing PCA 20100�"0
	*�H��
�0�
��dPyg���	L����Vh�D���XO��v|mE��9�����e��ҏ�D��e��,U��}�.+�A+��KnILk���‰q�͵K���̈�k�:��&?��4�W�]I��*.Յ�Y?���+�t�+�;F��FI�fT���UbWr�g�% 4�]���^�(��ղ���cӲ�Ȋ&
Y��5L��R[����HwօG�����j-\`ƴ*[�#_E�o7�3�j�M�jfcx��0ϕ���0��0	+�70U�_{�"X�rN��!t#2��0	+�7
SubCA0U�0U�0�0U#0��Vˏ�\bh�=��[�Κ�0VUO0M0K�I�G�Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z+N0L0J+0�>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0��U ��0��0��	+�7.0��0=+1http://www.microsoft.com/PKI/docs/CPS/default.htm0@+042 Legal_Policy_Statement. 0
	*�H��
�t�WO){��x�P�"�	�����4�*,����Ͽ���4�ہ����5o��y�w������Na��Z#�bQEg�?<��0��9@���!)奡i�"��t��GC�S��0i��% moa����r,i�v=Qۦ9H�7am�S˧�a¿⃫�k���}(Q��JQ��lȷJi���~�Ip����rGc��֢���D�c��i��F�z?��!�{�#-�A˿L�ﱜ�"KI�n�v[�Sy������=s5�<�T�RGj���Ҏڙg^2��7���u����ZW�¿�
���-���'ӵ^i���$gs�MO��V�z��RM�wO�����B	�
v�#Vx"&6�ʱ�n���G3b��ɑ3_q@��e�"�B!%�-`�7�A�*�a<�h`R��G���@��w>��SP8��f3'9x�6�N�_��=GS����a=*ג,�7Z>@B1��V��$]Q�jy�����{%qD�j����#��u�1��0��0��0~10	UUS10U
Washington10URedmond10U
Microsoft Corporation1(0&UMicrosoft Code Signing PCA 20103&����{�&0
	`�He��0	*�H��
	1
+�70
+�710
+�70/	*�H��
	1" ���(<�
pW��20E:���@؈ǚ{.;�r�nG0<
+�7
1.,teCA34yvdtDNsEFabCm4I17qbTQK2u43T5ncZmEnG/U=0Z
+�71L0J�$�"Microsoft Windows�"� http://www.microsoft.com/windows0
	*�H��
�,�F���=�Y�ނ�-�J2d�7c8���+��2�c,�gԏ�v[˼�B�;+W��X����(���6h�Ǯ8�,u�x
:��"Z���d�}f��:^�xp��B~v�O2@fns�d�-�G���UG}3���ʆ�H�l6�(�,d�]Rù�r姀�Ry7�_��zܛ���g�-cn�J�NL�([{�h���W���]+��B'��:*K���xk�g�P�:>(#��P_�M�`���t��c�r�b���0��
+�71��0��	*�H��
���0��10
	`�He0�X*�H��
	��G�C0�?
+�Y
010
	`�He �?�<��x�Dݡ�i�����FL��ҏpn�_���9�20201202130209.11Z0��ؤ��0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1-0+U$Microsoft Ireland Operations Limited1&0$UThales TSS ESN:3BD4-4B80-69C31%0#UMicrosoft Time-Stamp Service��M0��0��3;�#RZ�;0
	*�H��
0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100
201015172822Z
220112172822Z0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1-0+U$Microsoft Ireland Operations Limited1&0$UThales TSS ESN:3BD4-4B80-69C31%0#UMicrosoft Time-Stamp Service0�"0
	*�H��
�0�
��6֕���0R��U��O��]�а�TJ�᱘��@�!m���%�ۤz�<�(�����@��sr$/��yYYu��$6��1�L������9J���se�x�p�ie���~Bu�ګv���K�*��06�C��~��V����Z/�:!����������Aِ���d��bw�D̦�@,��>B�^#���1nj�2�+��$P��DݥF�J�VV�S�{�������NM
nh��p1%E;�_v�4���"d%5�!D1��0�0U�Ϗ���W��Vd	AE���我0U#0��c:\�1��C{|F�3hZ�mU0VUO0M0K�I�G�Ehttp://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl0Z+N0L0J+0�>http://www.microsoft.com/pki/certs/MicTimStaPCA_2010-07-01.crt0U�00U%0
+0
	*�H��
�A���5�U�1-L���5D1��o�c��mmM�]�0��"x6~�e��.=�U`o��[h��kfd�(����}�{o�Ѝ�ٍte���-�>u�#��mWo�����%���A�y+��$=j�<^����m1�����Dž�*�X���#V)�'9��sT�T��F���gJ��a�F,y�l�P��}UR�#L�F�u,������P!Ĺ�����[��)��x�K�ʟ�����PTU�=���"0�q0�Y�
a	�*0
	*�H��
0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1200U)Microsoft Root Certificate Authority 20100
100701213655Z
250701214655Z0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100�"0
	*�H��
�0�
��
�w�: ����i�ktTե
����|hK,_���a�v�>f+[�S'1A��	�|a0Y�0D�`��TC�M�8�Bݓ��s0W&��E
��G�Ϳ$`2X`F�XG�2�tag�_�T�ϓL��Ħ]�an(������a�F�'$gr!��Kd�Pb�]�w=�Wu���BM@Q��>g�f��D~��K�n�ʱ��z*
1��N���5�x���<�/D����d��� 	�x����D]^�O"M���0��0	+�70U�c:\�1��C{|F�3hZ�mU0	+�7
SubCA0U�0U�0�0U#0��Vˏ�\bh�=��[�Κ�0VUO0M0K�I�G�Ehttp://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl0Z+N0L0J+0�>http://www.microsoft.com/pki/certs/MicRooCerAut_2010-06-23.crt0��U ���0��0��	+�7.0��0=+1http://www.microsoft.com/PKI/docs/CPS/default.htm0@+042 Legal_Policy_Statement. 0
	*�H��
��Q
���?�q=���!o���1����Wm0���f�j���x�Ǩ�%��kTW+Q�D��S���`�v�@@A��\�\�^5�$VKt�Bȯ���7}Z?�yJ�R�8�/y�e٩�k����zoK0D$"<�����Y)����p�2J'�U�/���3�b_��W@��Ιf���jb��J�&�9�Jqc�{!mÜ��<�}�j�x�m���8ؔ�ƥ
������B�����"8 �%�d��~cY%z.9Wv�q����a�˚�G����ͧ��}���;q	�]t�"aڰPo�����1��:�eGx�H���r~akow��˧	�9����؂�r�����*T9�[��
U�z�s;�-��3.)��/T'!�ȬN�(���ۖ��B���AM�*��f0ӻt2K�c{���/�!�Y���D<�Pqס��U�i�W���0����M�
�]O�8/��X.�
�P5��	'ճ~5��6��_��t�I���0�@0���ؤ��0��10	UUS10U
Washington10URedmond10U
Microsoft Corporation1-0+U$Microsoft Ireland Operations Limited1&0$UThales TSS ESN:3BD4-4B80-69C31%0#UMicrosoft Time-Stamp Service�#
0+(3��)ԝF�{>Eu$�\}䠁�0���~0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20100
	*�H��
�q��0"20201202141624Z20201203141624Z0w0=
+�Y
1/0-0
�q��0
��0"0
�s806
+�Y
1(0&0
+�Y
�
0� �
0��0
	*�H��
��	��fB���rخ�=�2�J���r3��S
��ꍃ�ߕ��A�f�=k8�Y���d�f��IG�ѹw�.DP�$;�ynTkB�)��4�M�4�# hv��<�'c��|���t�No3K��.u1�
0�	0��0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20103;�#RZ�;0
	`�He��J0	*�H��
	1
*�H��
	0/	*�H��
	1" 8�"�'ݷK�Lpw�v��Z���+m|H�8��x:�0��*�H��
	/1��0��0��0�� 6�7y�&�mٟ�B�U�QkX��Q�;d��@0��0���~0|10	UUS10U
Washington10URedmond10U
Microsoft Corporation1&0$UMicrosoft Time-Stamp PCA 20103;�#RZ�;0" ��V�O�roV�%�Y�+8����m�k�l;�f��0
	*�H��
��$S���Yz,���5'�Ԗ]]-TUN�y�<I�m62D��.&����^�r�x8�:��AK�w�Kf��l���ԡ&�X_�}�`|? �Y(T��[�սFz�q�R
'��8/���xn�CA^�+��q���Y���0,��z�tɄh�����[c�Ĝ���3��"�!m�B���%>�U���a&�m�����U*jcE����Rg��mLgt�yRM�Tq�wB��I�Ïu$z�`骖œ

Youez - 2016 - github.com/yon3zu
LinuXploit