Sample details: fa96e7ef567e26c7f4aeb1e4b2028657 --

Hashes
MD5: fa96e7ef567e26c7f4aeb1e4b2028657
SHA1: 0496ed44ea13d844a7bd4c3fcbf8b76db6a886fc
SHA256: c421e9bd014bb76b698c3389e96942a546e9bc098b9fdca87ed6aae2b7766672
SSDEEP: 6144:3BcH3pEGO3yMlhWKKaw5NVJvN3MthLNJRmckuNdFTc196UNlAOiwn845dQAPRZUG:Rc52Ma2F3MzLNJRNkq81hNl3TTQAP1Z
Details
File Type: PE32
Yara Hits
YRP/Microsoft_Visual_Cpp_v50v60_MFC | YRP/Borland_Delphi_30_additional | YRP/Borland_Delphi_30_ | YRP/Borland_Delphi_v40_v50 | YRP/Borland_Delphi_v30 | YRP/Borland_Delphi_DLL | YRP/IsPE32 | YRP/IsWindowsGUI | YRP/IsPacked | YRP/HasOverlay | YRP/HasDebugData | YRP/HasRichSignature | YRP/maldoc_find_kernel32_base_method_1 | YRP/maldoc_getEIP_method_1 | YRP/domain | YRP/IP | YRP/url | YRP/contentis_base64 | YRP/Antivirus | YRP/BITS_CLSID | YRP/DebuggerException__SetConsoleCtrl | YRP/anti_dbg | YRP/network_http | YRP/network_tcp_socket | YRP/network_dns | YRP/escalate_priv | YRP/win_mutex | YRP/win_registry | YRP/win_token | YRP/win_files_operation | YRP/Advapi_Hash_API | YRP/CRC32b_poly_Constant | YRP/Str_Win32_Winsock2_Library | YRP/Str_Win32_Wininet_Library | YRP/Str_Win32_Internet_API | YRP/Str_Win32_Http_API |
Source
http://fbcom.review/f/17.exe
http://fbcom.review/f/17.exe
Strings
          	            !This program cannot be run in DOS mode.
t%cst-
t%ctt.
tRich,
`.rdata
@.data
.gfids
@.reloc
xDig2B
*9P@u3
xDig2Au*;
s/j Y+
t6j X+
SSShBMSR
ShBMSR
>_SM_t
<Ar5<zw1<Zv
c!\YS*
n-hm{z
J	J	{}
};zsqb
[0L5]3
\0I5-3
R\'7L3
{9tMqL
g%$'O=
TJGAXJ
q~nmuq
$gf3C"
Eq/noy
jc-s	g
(c!\Y_
i1v`L:
k&cQa!
Uq/noE
g]w/,"_d
:!+mRhS
:!'mReS
<(?x(Q>
FA0yIy7
LG1KAC
,l,&#5
0?=sKkY
-2.ae5o
J	DEAQ2
kw5pug}
,fu3rke
;`*<YS
!GUw> 
x NB:a
J*5pw\
V7sj7G
s1liwC
e#b[i"
J	DA[R
~=x}{h0[
 !-fa*
02Sg&<
*Ax&!,[
ARRKIY!{
t3roo{d"Y
Pm+jca
D:WrnO
"imjcas	
?~{{gx5
|;zwwc|)
Ls1b _
lmiyj#
y_vaMA
@E{x{v
Ni'fgiO5]
$ve#b[}E
@E7x{v
>6-lig
Qq/noe
pm+d# 
m}w5puK
LnhGt9
e#b[uq
c!\YSG\p
<~av^$
Rj'\'VK
j)dao"
g6n`rR(
Nv3XB~?
3	VaLN/c
\K}O~;1f
v5pucG
i'fgAA
e#b[e@
$;3jc}
FG]z}t
(s1li{*'
i'fg}@
%4Y$=L
)w5puk
K	DAK_
s1d+o#
69q/f%m-
W7{9tq{
d"e#b[M
5-g%`e[
=VQ:Y@v
A|yk:7
m+b1a)
};zO}<t l+
w5pu?E
m+jcq|
T%`W%Uy-
e#b[MD
\0M5](
};r!q9
g4(7zsyU
;cnRNo
+@XgEa
s1lSg&c
};zIn<u
g%`_[h
ZHdb>0,
};zsam
d4>&%b
<z?zsy
wLp>i$
By9x}{
8~3vw}
{.X[R3
J:-xUg
Zl=@{&
a$@!kc
A4.({)
aurvR5
rKfRNo
v)$#/d
KZVIB9?|
=x}{f~
5NV*[y
A|}yiz#v0
daKr7JA
J9)xS{
o%d4U2\
|5t$G	
WVk\};
UvrnO0{|
Q(kxT2
OS687t
gN)rnO	
F\0W&s
m[xA-K
aC`Y%c
SrnO2HV
zsyn2d
T%>ZP@
d48wGd
LG0KJ*)
4)!~*o-
KRS5C9
YLA#QWJ
fgeG^_]
C]H~jvW)
2`Cini[d
z9J- AQag
:M9F65
v0Q52v
I*sjOQ
tz?D2~
GF6N7p
E?xqYe
`|p5Z\
 !:;q:}J
*JK!D]$
s~hg,-
y@='#>
H"y? 2n
n1vC`Uj
~.J*][
S~9{TEu*Mn
i`6$:2jt
TP8h;S
,Eu|^i
7&5&(L
|uxC?{0VS`
. <%U;
>6EG,>
i(QOQ`H
X5*SoVFj
 %CE/fn#c
!0}zsR
>R;e1c
Q:>eLM
Yv-:'$
WSoS:]
mY|-GG
x3JZyd
5yqm n
9fc&/C
Ii<`Uo
`L	dj~
a2Bqn\
.WUtLv6
14K%pST
D(1j&x
G'4~)A
bcp2%G
B<*Gra
J`n[q<
,&\}Er
|"8	)K
POjX	d
X_E8#+'=
><twj'
{A{NdS
B$v>T(
$CRS]('
_j ,\S
ZJHQOJ
Z>;-+I
W3*{R	Z+vHH}c
B}X@[N
M6D3:%
CSd=:.
Spdom&
9lZe]}I
G~/kNZ
&~DSTh
q wka5\
WLp`0~
ljb?cV
,%!:'x7
)@Qn!1
F@tQKS
lW0{=a
4o[I]8
yBX%=^
)>ayAS
LUkx7s
<8H.|c
Ug_;^h
Yy*_)3
>l2@mG
2&	d7):
3"m=44
?,)+N9
&*WrKgX
P:uz*q
F^	Tz"
cY4Zzu6
\N6Wqe(
|uEl:.
7]tX*>V
eOqaY;
3}Y/uk.
a\}/tE
a+GAT',
Ut'G/D8
$`q.,e
Xk~a&v
[w`69^
[@"p1s-
w_3Ov Vp
4y"L$H.
,fE\um
!#Yji;
!PC}7X
YhBDVtuD
nUA~^>
QQSVWd
URPQQh
;t$,v-
UQPXY]Y[
Tt1jhZ;
Tt1jhZ;
^$+^8+
t	j-Xf
t0jXXf
~$+~8+
t	j-Xf
t0jXXf
~$+~8+
F2jgYf;
SVWjA_jZ+
uBjAYjZ+
u0jAXf;
u0jAXf;
D8(HXt:f
D8(Ht5F
Nj)[f9
u-jAXf;
tr;},sm
W8^0u:
W8^0u:
rr	jrZ
rr	jrZ
u-jAXj
Tt.jh^;
SVjA[jZ^+
jAZjZ^
PPPPPPPP
j"^f91j\^u8
j"^f9q
t/j=[f;
>=umF8
PPPPPWS
PP9E u:PPVWP
Wj0XPV
QQSWj0j@
taj*Xf
VWj\^j:
WWWPWS
SSVWh 
f9:t!V
PPPPPPPP
v	N+D$
v	N+D$
identifier removed
illegal byte sequence
inappropriate io control operation
interrupted
invalid argument
invalid seek
io error
is a directory
message size
network down
network reset
network unreachable
no buffer space
no child process
no link
no lock available
no message available
no message
no protocol option
no space on device
no stream resources
no such device or address
no such device
no such file or directory
no such process
not a directory
not a socket
not a stream
not connected
not enough memory
not supported
operation canceled
operation in progress
operation not permitted
operation not supported
operation would block
owner dead
permission denied
protocol error
protocol not supported
read only file system
resource deadlock would occur
resource unavailable try again
result out of range
state not recoverable
stream timeout
text file busy
timed out
too many files open in system
too many files open
too many links
too many symbolic link levels
value too large
wrong protocol type
address family not supported
address in use
address not available
already connected
argument list too long
argument out of domain
bad address
bad file descriptor
bad message
broken pipe
connection aborted
connection already in progress
connection refused
connection reset
cross device link
destination address required
device or resource busy
directory not empty
executable format error
file exists
file too large
filename too long
function not supported
host unreachable
FlsAlloc
FlsFree
FlsGetValue
FlsSetValue
InitializeCriticalSectionEx
InitOnceExecuteOnce
CreateEventExW
CreateSemaphoreW
CreateSemaphoreExW
CreateThreadpoolTimer
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
CreateThreadpoolWait
SetThreadpoolWait
CloseThreadpoolWait
FlushProcessWriteBuffers
FreeLibraryWhenCallbackReturns
GetCurrentProcessorNumber
CreateSymbolicLinkW
GetCurrentPackageId
GetTickCount64
GetFileInformationByHandleEx
SetFileInformationByHandle
GetSystemTimePreciseAsFileTime
InitializeConditionVariable
WakeConditionVariable
WakeAllConditionVariable
SleepConditionVariableCS
InitializeSRWLock
AcquireSRWLockExclusive
TryAcquireSRWLockExclusive
ReleaseSRWLockExclusive
SleepConditionVariableSRW
CreateThreadpoolWork
SubmitThreadpoolWork
CloseThreadpoolWork
CompareStringEx
GetLocaleInfoEx
LCMapStringEx
0123456789abcdefghijklmnopqrstuvwxyz
0123456789abcdefghijklmnopqrstuvwxyz
bad array new length
NKagj(h
bad exception
__based(
__cdecl
__pascal
__stdcall
__thiscall
__fastcall
__vectorcall
__clrcall
__eabi
__ptr64
__restrict
__unaligned
restrict(
 delete
operator
`vftable'
`vbtable'
`vcall'
`typeof'
`local static guard'
`string'
`vbase destructor'
`vector deleting destructor'
`default constructor closure'
`scalar deleting destructor'
`vector constructor iterator'
`vector destructor iterator'
`vector vbase constructor iterator'
`virtual displacement map'
`eh vector constructor iterator'
`eh vector destructor iterator'
`eh vector vbase constructor iterator'
`copy constructor closure'
`udt returning'
`local vftable'
`local vftable constructor closure'
 new[]
 delete[]
`omni callsig'
`placement delete closure'
`placement delete[] closure'
`managed vector constructor iterator'
`managed vector destructor iterator'
`eh vector copy constructor iterator'
`eh vector vbase copy constructor iterator'
`dynamic initializer for '
`dynamic atexit destructor for '
`vector copy constructor iterator'
`vector vbase copy constructor iterator'
`managed vector copy constructor iterator'
`local static thread guard'
operator "" 
 Type Descriptor'
 Base Class Descriptor at (
 Base Class Array'
 Class Hierarchy Descriptor'
 Complete Object Locator'
`h````
xpxxxx
`h`hhh
xwpwpp
(null)
[aOni*{
~ $s%r
@b;zO]
v2!L.2
 !"#$%&'()*+,-./0123456789:;<=>?@abcdefghijklmnopqrstuvwxyz[\]^_`abcdefghijklmnopqrstuvwxyz{|}~
 !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`ABCDEFGHIJKLMNOPQRSTUVWXYZ{|}~
CorExitProcess
UTF-16LEUNICODE
Sunday
Monday
Tuesday
Wednesday
Thursday
Friday
Saturday
January
February
August
September
October
November
December
MM/dd/yy
dddd, MMMM dd, yyyy
HH:mm:ss
NAN(SNAN)
nan(snan)
NAN(IND)
nan(ind)
AreFileApisANSI
LocaleNameToLCID
RoInitialize
RoUninitialize
_hypot
_nextafter
1#QNAN
1#SNAN
]vQ<)8
|)P!?Ua0
Eb2]A=
u?^p?o4
y1~?|"
?|I7Z#
>,'1D=
?g)([|X>=
:h"?bC
@H#?43
Ax#?uN}*
r7Yr7=
F0$?3=1
H`$?h|
&?~YK|
sU0&?W
<8bunz8
?#%X.y
F||<##
<@En[vP
?5Wg4p
"B <1=
?Microsoft Enhanced RSA and AES Cryptographic Provider
 (Prototype)
0123456789ABCDEF
{yFZBP
SCSIDISK
GetSystemFirmwareTable
NtOpenSection
map/set<T> too long
ApplyEmUpdate
        bucket sorting ...
        depth %6d has 
%6d unresolved strings
        reconstructing block ...
        main sort initialise ...
        qsort [0x%x, 0x%x]   done %d   this %d
        %d pointers, %d sorted, %d scanned
      %d work, %d block, ratio %5.2f
    too repetitive; using fallback sorting algorithm
BSDIFF40
 {0x%08x, 0x%08x}
    combined CRCs: stored = 0x%08x, computed = 0x%08x
      %d in block, %d after MTF & 1-2 coding, %d+2 syms in use
      initial group %d, [%d .. %d], has %d syms (%4.1f%%)
      pass %d: size is %d, grp uses are 
      bytes: mapping %d, 
selectors %d, 
code lengths %d, 
codes %d
    block %d: crc = 0x%08x, combined CRC = 0x%08x, size = %d
    final combined CRC = 0x%08x
    [%d: huff+mtf 
rt+rld
EvaluateFileCondition
EvaluateRegistryCondition
EvaluateLanguageCondition
EvaluateEditionCondition
EvaluateVersionCondition
EvaluateOsCondition
EvaluateGuidCondition
EvaluateTimeCondition
EvaluateTimeSpanCondition
EvaluateResVersionCondition
EvaluateOperationCondition
EvaluateRemoteCondition
EvaluateIniCondition
EvaluateGeoCondition
EvaluateExitCodeCondition
LoadConfig
MakeFileLocal
GetSourceType
CopyFileOrBufferToResource
CopyResourceToFileOrBuffer
PrepareRemotePatchDescriptor
PrepareRemoteUpdateDescriptor
ConsoleHandlerRoutine
CONOUT$
CONIN$
MakeUniqueName
MakeTemporaryFileName
CryptCATAdminAddCatalog
CryptCATAdminAcquireContext
CryptCATAdminReleaseContext
CryptCATAdminReleaseCatalogContext
QueryFullProcessImageNameW
country":"
PrepareSchedulerInterface
FreeSchedulerInterface
StartJob_1
StartJob_2
RegisterJob_1
RegisterJob_2
PrepareOnceTriggerAfter_1
PrepareOnceTriggerAfter_2
UnregisterJob_1
UnregisterJob_2
CheckJob_1
CheckJob_2
DeleteAlreadyExecutedRestartJobs_1
DeleteAlreadyExecutedRestartJobs_2
RegisterRestartJob_1
RegisterRestartJob_2
invalid string position
string too long
ApplyPatches
RegDeleteKeyExW
GetUpdatesInfo
GetUpdatesInfoFromXmlRoot
GetBestUpdateInfoFromXmlRoot
ReadXmlNodeUpdateInfo
ApplyXmlUpdate
ApplyXmlUpdateFromXmlRoot
ApplyXmlFileUpdate
ApplyXmlCabUpdate
ApplyXmlRegistryUpdate
ApplyXmlVersionUpdate
ApplyXmlExecuteUpdate
ApplyXmlIniConfUpdate
CopyFilesToDestDir
HandleFiles
HandleRegistry
HandleVersions
HandleExecutes
HandleProductActions
HandleNotifications
list<T> too long
ApplyUpdates
ApplyCabUpdate
ApplyUpdate
ReloadVersions
PerformRemoteHttpOp
CheckInternetConnection
WaitForInternetConnection
PerformRemoteOp
IsWow64Process
Wow64EnableWow64FsRedirection
Wow64DisableWow64FsRedirection
Wow64RevertWow64FsRedirection
GetSystemWow64DirectoryW
Unknown exception
bad allocation
No error
File was not found
Error reading from file/stream
Could not allocate memory
Internal error occurred
Could not determine tag type
Error parsing document declaration/processing instruction
Error parsing comment
Error parsing CDATA section
Error parsing document type declaration
Error parsing PCDATA section
Error parsing start element tag
Error parsing element attribute
Error parsing end element tag
Start-end tags mismatch
Unable to append nodes: root is not an element or document
No document element found
Unknown error
@@@@@@@@@@
D:\BUILD\work\00\502d40550ce810a1\BUILDS\Release\x86\CCUpdate.pdb
.text$di
.text$mn
.text$x
.text$yd
.idata$5
.00cfg
.CRT$XCA
.CRT$XCAA
.CRT$XCC
.CRT$XCL
.CRT$XCU
.CRT$XCZ
.CRT$XIA
.CRT$XIAA
.CRT$XIAC
.CRT$XIC
.CRT$XIZ
.CRT$XLA
.CRT$XLZ
.CRT$XPA
.CRT$XPX
.CRT$XPXA
.CRT$XPZ
.CRT$XTA
.CRT$XTZ
.rdata
.rdata$T
.rdata$r
.rdata$sxdata
.rdata$zzzdbg
.rtc$IAA
.rtc$IZZ
.rtc$TAA
.rtc$TZZ
.xdata$x
.idata$2
.idata$3
.idata$4
.idata$6
.data$r
.gfids$x
.gfids$y
.tls$ZZZ
.rsrc$01
.rsrc$02
GetVersionExA
lstrcatA
GetLastError
SetLastError
GetFileSizeEx
CreateFileMappingW
MapViewOfFile
UnmapViewOfFile
CloseHandle
HeapFree
HeapAlloc
GetProcessHeap
GetProcAddress
CreateDirectoryW
LocalFree
FindResourceW
LoadResource
InitializeCriticalSectionAndSpinCount
EnterCriticalSection
LeaveCriticalSection
DeleteCriticalSection
HeapDestroy
HeapSize
HeapReAlloc
GetSystemDirectoryW
GetVolumePathNameW
GetVolumeNameForVolumeMountPointW
CreateFileW
DeviceIoControl
GetVersion
GetModuleHandleW
MultiByteToWideChar
WideCharToMultiByte
CreateMutexW
SizeofResource
LockResource
FindResourceExW
SetErrorMode
LoadLibraryW
FreeLibrary
DuplicateHandle
GetCurrentProcess
SetEvent
InterlockedIncrement
InterlockedDecrement
CreateEventW
GetTempPathW
WaitForSingleObject
MoveFileExW
DeleteFileW
ReadFile
WriteFile
SetFilePointer
GetSystemTime
SystemTimeToFileTime
GetPrivateProfileStringW
GetVersionExW
GetModuleFileNameW
GetFileAttributesExW
GetPrivateProfileSectionW
GetCurrentDirectoryW
GetFileAttributesW
CopyFileW
OutputDebugStringW
SetConsoleCtrlHandler
FreeConsole
AttachConsole
AllocConsole
GetTickCount
FindFirstFileW
SetFileAttributesW
FindNextFileW
RemoveDirectoryW
FindClose
ExpandEnvironmentStringsW
LocalAlloc
GetFileSize
GetLongPathNameW
GetCurrentThread
CreateProcessW
GetExitCodeProcess
OpenProcess
TerminateProcess
TerminateThread
GetLocalTime
FileTimeToSystemTime
WritePrivateProfileStringW
RaiseException
DecodePointer
GetFullPathNameW
MoveFileW
GlobalFree
CreateWaitableTimerW
SetWaitableTimer
KERNEL32.dll
CryptAcquireContextA
CryptCreateHash
CryptDestroyHash
CryptReleaseContext
CryptHashData
CryptGetHashParam
RegOpenKeyExW
RegQueryValueExW
RegSetValueExW
RegCloseKey
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
AllocateAndInitializeSid
OpenProcessToken
FreeSid
DuplicateToken
GetLengthSid
InitializeAcl
AddAccessAllowedAce
SetSecurityDescriptorGroup
SetSecurityDescriptorOwner
IsValidSecurityDescriptor
AccessCheck
GetTokenInformation
EqualSid
RegDeleteValueW
OpenThreadToken
ImpersonateSelf
LookupPrivilegeValueW
AdjustTokenPrivileges
CreateProcessAsUserW
OpenSCManagerW
OpenServiceW
QueryServiceStatus
QueryServiceStatusEx
ControlService
StartServiceW
CloseServiceHandle
RegCreateKeyExW
RegDeleteKeyW
ImpersonateLoggedOnUser
RevertToSelf
ADVAPI32.dll
CoInitializeEx
CoInitializeSecurity
CoUninitialize
CoCreateInstance
CoTaskMemFree
ole32.dll
OLEAUT32.dll
InternetOpenW
InternetSetOptionW
InternetCanonicalizeUrlW
InternetCrackUrlW
InternetConnectW
FtpOpenFileW
GopherOpenFileW
HttpOpenRequestW
HttpAddRequestHeadersW
InternetCloseHandle
HttpSendRequestExW
HttpSendRequestW
InternetWriteFile
HttpEndRequestW
HttpQueryInfoW
InternetReadFile
WININET.dll
WinHttpOpen
WinHttpSetOption
WinHttpCrackUrl
WinHttpConnect
WinHttpOpenRequest
WinHttpGetProxyForUrl
WinHttpSetCredentials
WinHttpAddRequestHeaders
WinHttpSendRequest
WinHttpWriteData
WinHttpReceiveResponse
WinHttpQueryHeaders
WinHttpReadData
WinHttpCloseHandle
WinHttpGetIEProxyConfigForCurrentUser
WINHTTP.dll
UuidFromStringW
UuidIsNil
UuidCreate
UuidToStringW
RpcStringFreeW
RPCRT4.dll
Cabinet.dll
DnsQuery_W
DnsFree
DNSAPI.dll
WS2_32.dll
EnumProcesses
GetModuleFileNameExW
PSAPI.DLL
CreateEnvironmentBlock
DestroyEnvironmentBlock
USERENV.dll
GetFileVersionInfoSizeW
GetFileVersionInfoW
VerQueryValueW
VERSION.dll
WTSEnumerateSessionsW
WTSQueryUserToken
WTSFreeMemory
WTSAPI32.dll
IsDebuggerPresent
GetStringTypeW
EncodePointer
TlsAlloc
TlsGetValue
TlsSetValue
TlsFree
GetSystemTimeAsFileTime
LCMapStringW
GetCPInfo
UnhandledExceptionFilter
SetUnhandledExceptionFilter
IsProcessorFeaturePresent
GetStartupInfoW
QueryPerformanceCounter
GetCurrentProcessId
GetCurrentThreadId
InitializeSListHead
RtlUnwind
LoadLibraryExW
GetCommandLineA
GetCommandLineW
GetConsoleMode
ReadConsoleInputA
SetConsoleMode
GetFileType
ReadConsoleW
SetFilePointerEx
GetConsoleCP
CreateThread
ExitThread
FreeLibraryAndExitThread
GetModuleHandleExW
ExitProcess
GetStdHandle
GetACP
SetStdHandle
SetEndOfFile
WriteConsoleW
FlushFileBuffers
FindFirstFileExW
IsValidCodePage
GetOEMCP
GetEnvironmentStringsW
FreeEnvironmentStringsW
Copyright (c) by P.J. Plauger, licensed by Dinkumware, Ltd. ALL RIGHTS RESERVED.
                          
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
                          
abcdefghijklmnopqrstuvwxyz
ABCDEFGHIJKLMNOPQRSTUVWXYZ
.?AVlogic_error@std@@
.?AVlength_error@std@@
.?AVout_of_range@std@@
.?AVtype_info@@
.?AVbad_array_new_length@std@@
.?AVbad_exception@std@@
.?AVCAtlException@ATL@@
.?AVCWin32Heap@ATL@@
.?AUIAtlMemMgr@ATL@@
.?AVCAtlStringMgr@ATL@@
.?AUIAtlStringMgr@ATL@@
.?AUIUnknown@@
.?AVCNotifyInterface@@
.?AUIBackgroundCopyCallback2@@
.?AUIBackgroundCopyCallback@@
.?AVbad_alloc@std@@
.?AVexception@std@@
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
  <compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1">
    <application>
      <supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}" /> <!-- Windows Vista -->
      <supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}" /> <!-- Windows 7     -->
      <supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}" /> <!-- Windows 8     -->
      <supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}" /> <!-- Windows 8.1   -->
      <supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}" /> <!-- Windows 10    -->
    </application>
  </compatibility>
  <dependency>
    <dependentAssembly>
      <assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*" />
    </dependentAssembly>
  </dependency>
  <trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
    <security>
      <requestedPrivileges>
        <requestedExecutionLevel level="highestAvailable" uiAccess="false" />
      </requestedPrivileges>
    </security>
  </trustInfo>
</assembly>
	-J^rY
&S?"%(&
	81<y^5E
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0"><dependency><dependentAssembly><assemblyIdentity type="win32" name="Microsoft.Windows.Common-Controls" version="6.0.0.0" processorArchitecture="*" publicKeyToken="6595b64144ccf1df" language="*"></assemblyIdentity></dependentAssembly></dependency><trustInfo xmlns="urn:schemas-microsoft-com:asm.v3"><security><requestedPrivileges><requestedExecutionLevel level="highestAvailable" uiAccess="false"></requestedExecutionLevel></requestedPrivileges></security></trustInfo><compatibility xmlns="urn:schemas-microsoft-com:compatibility.v1"><application><supportedOS Id="{e2011457-1546-43c5-a5fe-008deee3d3f0}"></supportedOS><supportedOS Id="{35138b9a-5d96-4fbd-8e2d-a2440225f93a}"></supportedOS><supportedOS Id="{4a2f28e3-53b9-4441-ba9c-d69d4a4a6e38}"></supportedOS><supportedOS Id="{1f676c76-80e1-4239-95bb-83d0f6d0da78}"></supportedOS><supportedOS Id="{8e0f7a12-bfb3-4fe8-b9a5-48fd50a15a9a}"></supportedOS></application></compatibility></assembly>
0)0:0E0K0Q0W0]0c0l0
1*191g1
212`2}2
3(323b3x3
525;5C5
6#6)6/6B6
:V:d:}:,;2;D;S;
0)0>0y0
304O4]4}4
5/6t6~6
8D8I8O8V8
8*8Z8k8Z9t9~9
;#;);;;i;v;
<?<Q<^<r<}<
=F=X=^=y=
?'?=?a?w?
070E0O0]0g0u0
>%>3>H>]>r>
?$?7?A?T?^?q?{?
0)0<0F0Y0c0v0
202H2n2
7!717P7X7c7n7|7
8&8C8J8`8l8q8{8
899V9b9j9~9
: :+:6:U:r:
;/<9<?<d<
="=8=J=V=f=n=
0,0=0S0
4/5;5k5
<==J=x=
>&>4>B>P>^>l>z>
? ?&?,?6?A?G?M?W?`?p?v?|?
0"0(02080>0D0J0P0V0\0b0h0n0
6N6!9R9
2I3f3t4
4H;L<P<T<X<\<`<d<h<l<p<t<x<|<
656D6v6
1&1-141;1B1f1x1
3(323<3F3P3Z3d3k3u3|3
4#4)414
4"5;5F5Q5X5_5f5m5w5
;f<m<t<{<
7'8J8i8
7`8g9t9
:,;6;F;q;~;
<?<U<v<|<
=W=\=a=g=l=q=
2$2>2`2
3)3K3l3
505J5g5p5
6(666C6T6g6v6
:B;G;{;
;	<"<6<N<b<
<'=;=Y=u=
252=2E2S2[2
>6>X>x>
?;?A?l?
-0E0V0d0n0s0
1&1,1L1Z1_1
2;3I3O3[3`3k3x3
4:4?4N4T4\4h4
6%6;6\6
9R9i9p9z9
:':8:B:S:]:n:x:
; ;0;d;n;
0,161S1c1j1
2+2A2P2_2x2
2&313@3L3u3|3
4 5.5:5U5
6+6G6a6y6
7 7i7w7
2K3T3z3
3&404@4O4
5&5C5R5\5
6&6/6H6Q6u6
8)8R8f8|8
9>9P9j9
:&:I:S:v:
;.;;;W;l;
;/<<<J<V<a<
=)=;=B=o=
1(191@1
6N7_7v7
@0M0<2I2.4;4
556?6D6M6S6x6
7&878_8
93:j:p:z:
6K7\7m7
8&9C9l9
1+1t1y1
6-696?6N6_6q6z6
6N7\7g7
8!8'8+81858;8?8E8I8O8S8Y8]8c8g8m8q8y8
9-9d9{9
<$<K<b<
<'=D={=
>">(>i>v>
4L4b4|4
4;5P5F6
7&8/8=8H8O8m8
:2;A;-<A<
>+>H>e>
0"1K1t1
7,7L7h7
:(;=;r;
>+>K>k>
3!3l3w3
8J9T9d9p9{9
>)>^>g>u>
?/?D?y?
3%303C3V3t3
3H4W4h4z4
5	616k6
7K7U7^7e7
8!8A8S8#9f9
0Z1g1L3Y354d4i4
;%<3<P<
4S5Y5^5e5m5s5~5
596C6S6
7#74797H7
;(;/;:;[;a;w;
;9<]<g<w<
2$2E2x2
3*3A3X3d3
5&5/5B5c5r5
6?6T6Y6b6
:5:Y:s:
;@;J;Z;h;r;
;V<l<u<
<*=/=:=]=
>H>P>u>
1#1.1u1
:+;B;Y;p;
535J5z5
>#>)>/>5><>@>D>H>L>P>T>X>\>`>d>h>l>p>t>x>|>
0J1a1x1
:/;a;s;
</<N<f<
=!=1=?=M=
>/>k>q>x>
? ?&?+?1?7?=?B?H?N?T?Y?_?e?k?p?v?|?
0#0(0.040:0?0E0K0Q0V0\0b0h0m0s0y0
1 1%1+11171<1B1H1N1S1Y1_1e1j1p1v1|1
2A2M2`2s2
2L3_3r3~3
5"5-545T5Z5`5f5l5r5y5
6(6[6a6g6m6s6y6
:.:3:@:
;*<-=;=V=a=
=A>P>W>
	0!0'0o0
1:1U1a1p1y1
2'2-252:2`2e2
5$5(5,505
<,=D=J=R=
;)<A<F<
=!=%=)=-=1=5=9=
0.0B0^0h0r0
1+1K1Y1`1f1
1&2B2Q2]2k2
3?3K3P3U3|3
4 4,4U4a4x5
6?8H8P8>9
:3:F:`:u:
;"<?<J<
6v<3=P>b>
2:3>3B3F3J3N3R3V3
3Z4^4b4f4j4n4r4v4
2024282<2@2D2H2L2P2T2X2\2
5%545B5N5Z5h5x5
6&6<6P6Y6
7!898i8
>P>\>t>
8K8U8p8
;-<J<l<
=8=b=0>y>
<S=X=_=
1d2m2y3
2[2`2e2
:%:\:c:
="?*?a?h?
#=d=h=l=p=t=x=|=
D6`6d6h6l6p6t6x6|6
=:>G>W>d>N?
0*0^1t1
252L2S2_2r2w2
4*404D4
5V5a5g7
9.9I9Y9^9h9m9x9
<4=F=|=
>">->3>>>D>R>
?+?F?Q?}?
0,0Q0X0a0
2!2=2{2
>X>T?h?
191E1P1
2)222?2I2k2|2
=4>;>K>Z>a>y>
1,2>2D2
2-3]3x3
6$6;6@6E6U6Z6_6o6t6y6
7	707I7X7d7r7
868A8F8K8f8p8
9;9F9K9P9k9u9
9':K:g:
;.;D;O;\;q;|;
<)<J<Q<g<}<
?-?5?^?e?|?
0%0O0b0l0
3c4k4=5Q5
<"=8=v=
9Q<X<_<f<1=8=B=M=k=v=
>V>c>p>}>
1 1[1q1
293E3]3e3
718`8-9A9Y9a9
:(;0;=;><o<
k0l1|1
3>3W3c3r3}3
819P9s9
>!>&>3>7>=>A>Z>e>
2/2A2S2e2w2
6D6h6s6
8H8m8y8
8?9K9W9c9v9
i0q0y0
111=1I1i1
:"<|>_?
3=3G3O3U3]3t3o4
:.:Q:l:
<	=J=p=
8n9Y:|:
;,;G;p;
1	2$2?2
9%:@:y:
;);D;_;z;
;1<z<D>
0P132N213L3g3
4,4G4b4}4
4#5F5z5
7&8Q8l8
0(0\0w0
1>1H1R1\1f1p1
4 4$4(4,4044484<4H4L4P4T4X4\4`4t4x4|4
44585<5@5D5H5L5P5T5X5\5`5d5h5l5
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>
5$5,545<5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7$7,747<7D7L7T7\7d7l7t7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
< <(<0<8<@<H<P<X<`<h<p<x<
= =(=0=8=@=H=P=X=`=h=p=x=
> >(>0>8>@>H>P>X>`>h>p>x>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
6<6@6D6H6
7 7$7(7,7074787<7@7D7H7L7P7T7X7\7`7d7h7l7p7t7x7|7
8 8$8(8,8084888<8@8D8H8L8P8T8X8\8`8d8h8l8p8t8x8|8
9 9$9(949<9@9D9H9L9
= =$=(=,=0=4=8=<=@=D=H=L=P=T=X=\=`=d=h=l=p=t=x=|=
> >$>(>,>0>4>8><>@>D>H>L>P>
4$4,444<4D4L4T4\4d4l4t4|4
6p7t7x7|7
8$8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=t=|=
>$>,>4><>D>L>T>\>d>l>t>|>
? ?(?0?8?@?H?P?X?`?h?p?x?
0 0(00080@0H0P0X0`0h0p0x0
1 1(10181@1H1P1X1`1h1p1x1
2 2(20282@2H2P2X2`2h2p2x2
3 3(30383@3H3P3X3`3h3p3x3
4 4(40484@4H4P4X4`4h4p4x4
5 5(50585@5H5P5X5`5h5p5x5
(=,=0=4=8=<=@=D=H=L=P=T=X=
: :$:(:@:D:T:X:\:d:|:
;,;0;@;D;L;d;t;x;
< <4<8<P<T<X<l<|<
= =(=,=4=L=P=h=l=
> >8><>T>X>l>|>
7(7L7T7\7d7l7t7|7
8$8,848@8d8l8t8|8
9$9,949<9H9l9t9|9
:,:4:<:D:L:T:`:
;8;@;H;P;d;t;
< <D<L<T<\<d<l<t<|<
=$=,=H=X=d=l=
>4><>H>P>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1<1D1L1T1\1d1l1t1|1
2(2X2`2
3 3@3L3l3x3
444@4`4l4t4
5 5D5L5T5\5d5l5t5|5
6$6,646<6D6L6T6\6d6l6t6|6
7,747<7D7P7p7|7
8 8,8L8X8x8
9$9,949<9D9L9T9\9d9l9t9|9
:0:8:@:L:l:x:
;8;@;H;T;t;|;
<$<,<4<<<D<L<T<\<d<l<t<
=$=,=8=X=`=h=p=x=
>$>,>8>X>h>
?(?4?T?`?
0$0,040<0D0L0T0\0d0l0x0
1<1D1L1T1\1d1l1t1|1
2$2,242<2D2L2T2\2d2l2t2|2
3$3,343@3d3l3t3|3
4$4,444<4D4L4T4\4d4l4t4|4
5$5,545@5H5|5
5,6<6H6P6
7 7<7L7X7`7
8,848<8D8L8T8\8d8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
: :D:L:T:\:d:l:t:|:
;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<P<t<|<
=$=0=8=l=|=
>,>8>@>X>`>p>x>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1(1L1T1\1d1l1t1|1
202<2\2h2
3(3L3T3\3d3l3t3|3
4$4,444<4D4L4X4x4
5(5L5T5\5d5l5t5|5
6(686D6L6
7H7X7d7l7
8(848<8p8
8 909<9D9x9
: :@:H:P:\:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<@<`<h<x<
=(=0=<=\=d=l=t=
> >(>0><>\>d>l>t>|>
?$?,?4?<?D?L?T?\?d?l?t?|?
0(080\0d0l0t0|0
0$141@1H1|1
1,2<2H2P2p2
3<3L3X3`3
4D4T4`4h4
50585@5H5P5X5d5
6(6H6P6X6`6h6p6
7$7,747<7H7l7t7|7
8 8(80888H8l8t8|8
9$9,949<9D9L9T9\9d9l9t9|9
:$:,:4:<:D:L:T:\:d:l:t:|:
;$;,;4;<;D;L;T;\;d;l;t;|;
<$<,<4<<<D<L<T<\<d<l<t<|<
=$=,=4=<=D=L=T=\=d=l=x=
>$>,>4><>D>L>T>\>h>
?$?,?4?<?D?L?T?\?d?l?t?|?
0$0,040<0D0L0T0\0d0l0t0|0
1,141<1D1L1T1\1d1l1t1|1
2<2D2L2T2\2d2l2t2|2
3 3D3L3T3\3d3l3t3|3
444<4D4L4T4\4d4l4t4|4
5 5,545T5\5x5
686H6T6\6|6
747<7D7`7p7|7
8(848<8p8
8 909<9D9x9
:$:,:8:@:t:
;0;8;D;L;
<8<H<T<t<
=D=T=`=
>$>,>4>@>d>l>t>|>
?$?,?4?<?D?L?T?\?h?
0$0,040<0D0L0T0\0d0l0t0|0
1$1,141<1D1L1T1`1
2$202P2X2`2h2p2x2
3(303<3\3d3x3
404L4P4p4
50585<5T5X5t5x5
6(6H6h6
7(7H7h7
8(8H8h8
909L9P9p9x9|9
:8:X:x:
;8;X;t;x;
<4<8<@<\<l<t<x<
2(383H3X3h3