Static | ZeroBOX

PE Compile Time

2009-07-14 08:36:34

PDB Path

dfrgui.pdb

PE Imphash

4673ad56625d375f2efee239af061364

Sections

Name Virtual Address Virtual Size Size of Raw Data Entropy
.text 0x00001000 0x0001dbaa 0x0001dc00 6.62003732328
.data 0x0001f000 0x00001c30 0x00001600 3.09541180832
.pdata 0x00021000 0x00000900 0x00000a00 4.76664363448
.rsrc 0x00022000 0x00073af0 0x00073c00 6.38518875343
.reloc 0x00096000 0x00000228 0x00000400 0.799159222283

Resources

Name Offset Size Language Sub-language File type
MUI 0x00095a00 0x000000f0 LANG_ENGLISH SUBLANG_ENGLISH_US data
PNG 0x00022fe0 0x00005635 LANG_ENGLISH SUBLANG_ENGLISH_US PNG image data, 24 x 432, 8-bit/color RGBA, non-interlaced
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_ICON 0x00095458 0x00000468 LANG_ENGLISH SUBLANG_ENGLISH_US GLS_BINARY_LSB_FIRST
RT_GROUP_ICON 0x000958c0 0x0000013a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000958c0 0x0000013a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000958c0 0x0000013a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_GROUP_ICON 0x000958c0 0x0000013a LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_VERSION 0x00028618 0x000003a8 LANG_ENGLISH SUBLANG_ENGLISH_US data
RT_MANIFEST 0x00022aa0 0x00000539 LANG_ENGLISH SUBLANG_ENGLISH_US XML 1.0 document, ASCII text, with CRLF line terminators

Imports

Library ADVAPI32.dll:
0x100001008 RegCreateKeyExW
0x100001010 CloseTrace
0x100001018 GetTraceLoggerHandle
0x100001020 GetTraceEnableLevel
0x100001028 GetTraceEnableFlags
0x100001030 RegisterTraceGuidsW
0x100001038 UnregisterTraceGuids
0x100001040 RegCloseKey
0x100001048 OpenProcessToken
0x100001050 TraceMessage
0x100001058 DuplicateToken
0x100001060 ControlTraceW
0x100001068 StartTraceW
0x100001070 EnableTrace
0x100001078 CheckTokenMembership
0x100001080 GetTokenInformation
0x100001088 RegOpenKeyExW
0x100001090 CreateWellKnownSid
0x100001098 RegQueryValueExW
Library KERNEL32.dll:
0x100001158 GetLocaleInfoW
0x100001160 FormatMessageW
0x100001168 FreeLibrary
0x100001170 GetProcAddress
0x100001178 LoadLibraryW
0x100001180 Sleep
0x100001188 GetLocalTime
0x100001190 GetCalendarInfoW
0x100001198 QueryPerformanceCounter
0x1000011a0 GetModuleHandleW
0x1000011b0 GetStartupInfoW
0x1000011b8 CreateThread
0x1000011c0 GetDriveTypeW
0x1000011c8 GetVolumeInformationW
0x1000011d0 InitializeSListHead
0x1000011d8 RtlCaptureStackBackTrace
0x1000011e8 InterlockedPopEntrySList
0x1000011f0 FileTimeToSystemTime
0x1000011f8 SystemTimeToFileTime
0x100001200 LeaveCriticalSection
0x100001208 EnterCriticalSection
0x100001210 CloseHandle
0x100001218 SetEvent
0x100001220 DeleteCriticalSection
0x100001238 GetTimeFormatW
0x100001240 GetDateFormatW
0x100001248 SetLastError
0x100001250 WaitForSingleObject
0x100001258 CreateEventW
0x100001260 GetCurrentProcess
0x100001268 SetErrorMode
0x100001270 GetCurrentThreadId
0x100001278 GetCurrentProcessId
0x100001280 GetSystemTimeAsFileTime
0x100001288 TerminateProcess
0x100001290 GetTickCount
0x100001298 UnhandledExceptionFilter
0x1000012a0 FindFirstFileW
0x1000012a8 FindNextFileW
0x1000012b0 GetProcessHeap
0x1000012b8 HeapSetInformation
0x1000012c8 GetCommandLineW
0x1000012d0 LocalFree
0x1000012d8 GetLastError
0x1000012e0 CreateDirectoryW
0x1000012e8 DeleteFileW
0x1000012f0 GetFileAttributesW
0x1000012f8 FindClose
0x100001300 CreateFileW
0x100001308 DeviceIoControl
0x100001310 MoveFileExW
0x100001318 LoadLibraryExW
0x100001320 GetVolumePathNameW
Library GDI32.dll:
0x1000010f0 DeleteDC
0x1000010f8 GdiFlush
0x100001100 SelectObject
0x100001108 SetLayout
0x100001110 CreateCompatibleDC
0x100001118 CreateDIBSection
0x100001120 SetTextColor
0x100001128 ExtTextOutW
0x100001130 CreateFontIndirectW
0x100001138 DeleteObject
0x100001140 GetDeviceCaps
0x100001148 SetBkColor
Library USER32.dll:
0x1000013c0 LoadStringW
0x1000013c8 IsDlgButtonChecked
0x1000013d0 GetDlgItemTextW
0x1000013d8 SetDlgItemTextW
0x1000013e0 CheckDlgButton
0x1000013e8 DrawFrameControl
0x1000013f0 OffsetRect
0x1000013f8 SetTimer
0x100001400 KillTimer
0x100001408 GetSysColorBrush
0x100001410 GetWindowLongPtrW
0x100001418 DestroyWindow
0x100001420 EnableWindow
0x100001428 EndDialog
0x100001430 SetWindowLongPtrW
0x100001438 EndPaint
0x100001440 GetSysColor
0x100001448 MapWindowPoints
0x100001450 BeginPaint
0x100001458 ShowWindow
0x100001460 PostMessageW
0x100001468 SetWindowPos
0x100001470 LoadImageW
0x100001478 GetDesktopWindow
0x100001480 SetFocus
0x100001488 SetWindowLongW
0x100001490 GetWindowLongW
0x100001498 GetDlgItem
0x1000014a0 DestroyIcon
0x1000014a8 MoveWindow
0x1000014b0 GetWindowRect
0x1000014b8 GetClientRect
0x1000014c0 ClientToScreen
0x1000014c8 GetSystemMetrics
0x1000014d0 SendMessageW
0x1000014d8 DialogBoxParamW
0x1000014e0 SetForegroundWindow
0x1000014e8 GetDC
0x1000014f0 SetWindowTextW
0x1000014f8 ReleaseDC
0x100001500 SystemParametersInfoW
0x100001508 SendMessageTimeoutW
0x100001510 GetWindowTextW
0x100001518 EnumWindows
0x100001520 MessageBoxW
0x100001530 RegisterWindowMessageW
0x100001538 InflateRect
Library msvcrt.dll:
0x100001558 _vscwprintf
0x100001560 iswspace
0x100001568 memcpy
0x100001570 memset
0x100001578 ?terminate@@YAXXZ
0x100001580 __set_app_type
0x100001588 _fmode
0x100001590 _commode
0x100001598 __setusermatherr
0x1000015a0 _amsg_exit
0x1000015a8 _initterm
0x1000015b0 _acmdln
0x1000015b8 exit
0x1000015c0 _cexit
0x1000015c8 _exit
0x1000015d0 _XcptFilter
0x1000015d8 __C_specific_handler
0x1000015e0 __getmainargs
0x1000015e8 _purecall
0x1000015f0 ??2@YAPEAX_K@Z
0x1000015f8 _wtol
0x100001600 memmove
0x100001608 wcstok
0x100001610 _wcsicmp
0x100001618 ??3@YAXPEAX@Z
0x100001620 _ismbblead
0x100001628 wcschr
0x100001630 _vsnwprintf
Library SHELL32.dll:
0x100001378 CommandLineToArgvW
0x100001380 ShellExecuteExW
0x100001388 SHGetFileInfoW
0x100001390 SHGetStockIconInfo
Library ole32.dll:
0x100001688 CoUninitialize
0x100001690 CoTaskMemFree
0x100001698 CoTaskMemAlloc
0x1000016a0 CoDisconnectObject
0x1000016a8 CoCreateInstance
0x1000016b0 CoInitializeEx
0x1000016b8 CoInitializeSecurity
Library OLEAUT32.dll:
0x100001338 SysStringLen
0x100001340 VariantClear
0x100001348 VariantInit
0x100001350 VariantTimeToSystemTime
0x100001358 SysFreeString
0x100001360 SysAllocString
0x100001368 SystemTimeToVariantTime
Library COMCTL32.dll:
0x1000010a8 ImageList_AddMasked
0x1000010b0 ImageList_Add
0x1000010b8 ImageList_ReplaceIcon
0x1000010c0 ImageList_Destroy
0x1000010c8 ImageList_Create
0x1000010d0 None
0x1000010d8 InitCommonControlsEx
0x1000010e0 None
Library ntdll.dll:
0x100001640 RtlCaptureContext
0x100001648 RtlLookupFunctionEntry
0x100001650 RtlVirtualUnwind
0x100001658 WinSqmAddToStream
0x100001660 RtlAllocateHeap
0x100001668 RtlFreeHeap
0x100001670 RtlGetLastNtStatus
0x100001678 EtwTraceMessage
Library VirtDisk.dll:
Library SXSHARED.dll:
0x1000013a0 SxTracerDebuggerBreak

!This program cannot be run in DOS mode.
`.data
.pdata
@.rsrc
@.reloc
ADVAPI32.dll
ntdll.DLL
KERNEL32.dll
GDI32.dll
USER32.dll
msvcrt.dll
SHELL32.dll
ole32.dll
OLEAUT32.dll
COMCTL32.dll
VirtDisk.dll
SXSHARED.dll
z+z' K
nMH!&}a=b(@
;@5d8xW
g@#q@"X%
/@9}R[4K
qn*sWE
#bdMlH
Q1khLN
H-9&v^^
okIm&@
:qq;\C
qOk'0\
X7UcWV
7+rgSFD
FgkWsO
W(SH"^W
H$l%%u;
"txgm~n
ys}ZJk2SI
aeiouyAEIOUY
GetDfTracingDirectory
EnsureTracingDirectory
DfStopTracing
DfStartTracing
InitializeCOM
_RealMain
GetUiUserAccessLevel
RunDefragUI
FindExistingDefragWindow
BuildBoldFont
GetDateTimeString
GetDayFromBitMap
SafeGetWindowText
SafeSetWindowTextNoBlink
GetUniqueVolumeForPath
CDefragUI::FinalConstruct
CDefragUI::FinalRelease
CDefragUI::CreateInstance
CDefragUI::_Initialize
CDefragUI::_ResetComboSelections
CDefragUI::RunUI
CDefragUI::Shutdown
CDefragUI::_ConnectWMITaskScheduler
CDefragUI::_GetWMIDefragFolder
CDefragUI::_GetWMIDefragTask
CDefragUI::_CreateWMIDefragTask
CDefragUI::_UpdateWMIDefragTaskFromDef
CDefragUI::_WriteNewCommandLine
CDefragUI::_WriteNewTaskTrigger
CDefragUI::_VerifyCommandLine
CDefragUI::_VerifyTaskTriggers
CDefragUI::_TaskDialogCallbackProc
CDefragUI::_ShowInvalidTriggerWarning
CDefragUI::_InvalidTriggersHandler
CDefragUI::_OverwriteExistingTask
CDefragUI::_GetTaskInfo
CDefragUI::_GetHourFromTimeString
CDefragUI::_GetDateTimeFromTimeString
CDefragUI::_GetExpectedNextRunTime
CDefragUI::_GetTimeAfterSeconds
CDefragUI::_Register
CDefragUI::_Unregister
CDefragUI::_SetInitialParameters
CDefragUI::_SetSelectionTimerRunning
CDefragUI::_InitializeTaskInformation
FillRectClr
ShellExecuteWithElevate
GetIconOf
InsertStatusListItem
CDefragUI::ChangeNotification
CDefragUI::_Init_VolumeStatusList
CDefragUI::_OnInit_MainDlgProc
CDefragUI::_OnClose_MainDlgProc
CDefragUI::_PopulateTaskSchedInfo
CDefragUI::_OnPaint_MainDlgProc
CDefragUI::UpdateCurrentState_MainDlgProc
CDefragUI::_InvokeBackgroundOperation
CDefragUI::_OnDefragNow_MainDlgProc
CDefragUI::_OnAnalyzeNow_MainDlgProc
CDefragUI::_OnHelp_MainDlgProc
CDefragUI::_LaunchHelp
CDefragUI::_RelaunchElevated
CDefragUI::_OnModifySchedule_MainDlgProc
CDefragUI::_OnSelectionChanged
CDefragUI::_DestroyChildWindows
CDefragUI::CheckForEngineThread
CDefragUI::_ReRegisterEngine
CDefragUI::DoOperation
CDefragUI::_PopulateVolumeEntries
CDefragUI::CreateInitialVolumeList
CDefragUI::UpdateVolumeEntries
CDefragUI::IdentifyVolumesForSchedule
InsertListItem
CreateBitmap
CreateColorBitmap
CreateCheckBoxImagelist
CloseThemeData
DrawThemeBackgroundEx
GetThemePartSize
OpenThemeData
CDefragUI::_OnDestroy_AdvOptsDlgProc
CDefragUI::_OnInit_AdvOptsDlgProc
CDefragUI::_OnPaint_AdvOptsDlgProc
CDefragUI::_OnOK_AdvOptsDlgProc
CDefragUI::_OnCancel_AdvOptsDlgProc
CDefragUI::_SetSelectAllState
CDefragUI::_SetAllVolumeStates
CDefragUI::_ToggleVolumeState
CDefragUI::_VolumeChangeRequest
CDefragUI::_GetFocusedVolume
CDefragUI::_UpdateOKButtonState
CDefragUI::_OnKeyDownAdvOptsDlgProc
CDefragUI::_OnClickItemAdvOptsDlgProc
CDefragUI::_OnCheckDisabled_AdvOptsDlgProc
CDefragUI::_OnCheckEnabled_AdvOptsDlgProc
CDefragUI::_SetVolumeBools
CDefragUI::_EnableOKButton
CDefragUI::_PopulateVolumeList
CDefragUI::_OnInit_SchedDlgProc
CDefragUI::_OnDestroy_SchedDlgProc
CDefragUI::_OnPaint_SchedDlgProc
CDefragUI::_OnCmbFreq_SchedDlgProc
CDefragUI::_OnCmbDays_SchedDlgProc
CDefragUI::_OnCmbTime_SchedDlgProc
CDefragUI::_OnOK_SchedDlgProc
CDefragUI::_OnCheckSchedule
CDefragUI::_OnCancel_SchedDlgProc
CDefragUI::_OnSelectDisks
CDefragUI::_SetEnableSchedule
CDefragUI::_FillHoursCombo
CDefragUI::_FillRegBackupFrequency
CDefragUI::_FillDaysCombos
CDefragUI::_GetDefaultCALID
CDefragUI::_FillComboWithDays
FAILED[TRACK]
FAILED
SxAllocateEventTraceProp
SxGet0XLogFileCount
SxCompressLogFile
SxMergeExtraLogs
SxRotateLogs
SxStartTracing
SxEnableTraceDefault
SxEnableTraceCustom
SxStopTracing
SxRegReadDWORD
SxGetUserAccessLevelForHandle
SxGetUniqueVolumeForPath
::GetVolumePathName( strPath, STRING_CCH_PARAM( wszRootPath ) )
::GetVolumeNameForVolumeMountPoint( wszRootPath, STRING_CCH_PARAM( wszVolume ) )
::GetVolumeNameForVolumeMountPoint( wszVolume, pwszUnique, cchUnique )
SxGetWinSatVolume
SxQueryVolumeDefragAppropriate
SxGetDiskExts
SxQueryDeviceForDynamicVirtualDisk
SxQueryDeviceRandomReadDiskScore
SxQueryDeviceDefragAppropriate
SafeSetDlgItemTextNoBlink
SafeGetDlgItemText
SafeSetWindowLongPtr
SxShowLuaMessage
dfrgui.pdb
;OQPMB}
rUXY;W
Fi[^Fc\l[ls;
gmp]ln
qchch_n
g_g]js
Pclno[f;ffi]
Chn_lh_nIj_h;
Chn_lh_nIj_hOlf;
Chn_lh_nL_[^@cf_
Chn_lh_n=fim_B[h^f_
BNNJL?;>
bnnj4))om(cgad_ica[[(]ig)mnm)cg[a](dja
;P;OQPMB}
UXY;W;X
D$0H!\$8H!\$(H
H9D$@u
L9d$0H
WATAUH
H!!\$0H
SUVWATAUAVAWH
9u0t`L;
T9u uOD;
D9l$Pt
uiD9l$Pt
A_A^A]A\_^][
p WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
A_A^A]A\_^]
@SUVWATH
A\_^][
VWAUAVAWH
f9\$tH
f9\$XA
A_A^A]_^
UVWATAUAVAWH
A_A^A]A\_^]
UVWATAUAVAWH
D$DfD9w
t$Df9D$"t
A_A^A]A\_^]
x ATAUAWH
A_A]A\
UVWAVAWH
pA_A^_^]
WATAUH
89:u&9z
A]A\_
t$ WATAWH
tIH!w(
WATAUAVAWH
A_A^A]A\_
@SUVWATAUAVAWH
D$XD+\$`D
D$lD+D$dA
d$0+D$@E3
A_A^A]A\_^][
UVWATAUAVAWH
A_A^A]A\_^]
WATAUAVAWH
t9P8t
A_A^A]A\_
UVWATAUAVAWH
t#L9l$0H
D9|$8t
L9l$0f
L9l$0I
A_A^A]A\_^]
H!D$8H
x ATAVAWH
A_A^A\
x ATAUAVH
A^A]A\
t$ WATAUAVAWH
A_A^A]A\_
\$ UVWATAUAVAWH
A_A^A]A\_^]
P9|$8t
|$8H9L$0L
UVWATAUAVAWH
SP9D$Ht
H9L$@L
SX9D$Ht
D$HH9L$@L
A9L$8u
A9D$4u
A9D$<u
CDA9D$@uQ
T$LH;Q
A9D$8u
S`9D$Ht
D$HH9L$@L
Sh9D$Ht
D$HH9L$@L
D$X|SL
D$(D9C0A
A_A^A]A\_^]
VWATAVAWH
A_A^A\_^
WATAUAVAWH
D!d$(f
A_A^A]A\_
SUVWATAUAVAWH
A_A^A]A\_^][
VWATAUAVH
D9nxt*E
A^A]A\_^
D$$uYL
WATAUH
WATAUH
D$$fA;
u$9B(u
p WATAVH
+D$@E3
Gh9oht0A
UVWATAUH
A]A\_^]
x ATAUAVH
A^A]A\
t$ WATAUAVAWH
D$P|xL
A_A^A]A\_
t$ WATAUAVAWH
\$PD9u
A_A^A]A\_
l$ VWAUAVAWH
A_A^A]_^
D$<uQD9vpt
H9s(tEH
@SUVWATAUAVAWH
A_A^A]A\_^][
UVWATAUH
A]A\_^]
WATAUAVAWH
D9d$8t
l$Tt3H
A_A^A]A\_
SUVWATH
d$@uJI;
A\_^][
l$ VWATH
L$ SUVWH
H!t$0!t$(!t$@D
L$H|]H
l$ VWATAVAW
uTD8d$XuMH
|CD9d$Hu<H
A_A^A\_^
H WATAUH
fD9,HA
u"fD9/t
UVWATAUH
A]A\_^]
x ATAUAVH
A^A]A\
p WATAUAVAWH
A_A^A]A\_
L$ SWH
WATAUAVAWH
A_A^A]A\_
LcA<E3
u*9Q<|%
ConvertStringSecurityDescriptorToSecurityDescriptorW
RegCreateKeyExW
CloseTrace
GetTraceLoggerHandle
GetTraceEnableLevel
GetTraceEnableFlags
RegisterTraceGuidsW
UnregisterTraceGuids
RegCloseKey
OpenProcessToken
TraceMessage
ADVAPI32.dll
GetFileAttributesW
DeleteFileW
CreateDirectoryW
GetLastError
LocalFree
GetCommandLineW
RegisterApplicationRestart
HeapSetInformation
GetProcessHeap
SetErrorMode
GetCurrentProcess
CreateEventW
WaitForSingleObject
SetLastError
GetDateFormatW
GetTimeFormatW
GetVolumeNameForVolumeMountPointW
InitializeCriticalSection
DeleteCriticalSection
SetEvent
CloseHandle
EnterCriticalSection
LeaveCriticalSection
SystemTimeToFileTime
FileTimeToSystemTime
InterlockedPopEntrySList
InterlockedPushEntrySList
RtlCaptureStackBackTrace
InitializeSListHead
GetVolumeInformationW
GetDriveTypeW
CreateThread
GetCalendarInfoW
GetLocalTime
LoadLibraryW
GetProcAddress
FreeLibrary
FormatMessageW
GetLocaleInfoW
KERNEL32.dll
CreateFontIndirectW
DeleteObject
GetDeviceCaps
SetBkColor
ExtTextOutW
SetTextColor
CreateDIBSection
CreateCompatibleDC
SetLayout
SelectObject
GdiFlush
DeleteDC
GDI32.dll
RegisterWindowMessageW
ChangeWindowMessageFilter
MessageBoxW
EnumWindows
GetWindowTextW
SendMessageTimeoutW
SystemParametersInfoW
ReleaseDC
SetWindowTextW
SetForegroundWindow
DialogBoxParamW
SendMessageW
GetSystemMetrics
ClientToScreen
GetClientRect
GetWindowRect
MoveWindow
DestroyIcon
GetDlgItem
GetWindowLongW
SetWindowLongW
SetFocus
GetDesktopWindow
LoadImageW
SetWindowPos
PostMessageW
ShowWindow
BeginPaint
MapWindowPoints
GetSysColor
EndPaint
SetWindowLongPtrW
EndDialog
EnableWindow
DestroyWindow
GetWindowLongPtrW
GetSysColorBrush
KillTimer
SetTimer
InflateRect
OffsetRect
DrawFrameControl
CheckDlgButton
IsDlgButtonChecked
LoadStringW
USER32.dll
??3@YAXPEAX@Z
_wcsicmp
wcstok
memmove
??2@YAPEAX_K@Z
_purecall
__getmainargs
__C_specific_handler
_XcptFilter
_ismbblead
_cexit
_acmdln
_initterm
_amsg_exit
__setusermatherr
_commode
_fmode
__set_app_type
msvcrt.dll
?terminate@@YAXXZ
CommandLineToArgvW
ShellExecuteExW
SHGetFileInfoW
SHGetStockIconInfo
SHELL32.dll
CoInitializeEx
CoInitializeSecurity
CoCreateInstance
CoUninitialize
CoTaskMemFree
CoTaskMemAlloc
CoDisconnectObject
ole32.dll
OLEAUT32.dll
InitCommonControlsEx
ImageList_Create
ImageList_Destroy
ImageList_ReplaceIcon
ImageList_Add
ImageList_AddMasked
COMCTL32.dll
RtlFreeHeap
RtlAllocateHeap
WinSqmAddToStream
RtlVirtualUnwind
RtlLookupFunctionEntry
RtlCaptureContext
ntdll.dll
GetStorageDependencyInformation
VirtDisk.dll
SxTracerGetThreadContextRetail
SxTracerShouldTrackFailure
SxTracerDebuggerBreak
SXSHARED.dll
ControlTraceW
StartTraceW
EnableTrace
CheckTokenMembership
GetTokenInformation
RegOpenKeyExW
CreateWellKnownSid
RegQueryValueExW
DuplicateToken
GetStartupInfoW
SetUnhandledExceptionFilter
GetModuleHandleW
QueryPerformanceCounter
GetTickCount
GetCurrentThreadId
GetCurrentProcessId
GetSystemTimeAsFileTime
TerminateProcess
UnhandledExceptionFilter
FindFirstFileW
FindNextFileW
FindClose
CreateFileW
DeviceIoControl
MoveFileExW
ExpandEnvironmentStringsW
GetVolumePathNameW
LoadLibraryExW
SetDlgItemTextW
GetDlgItemTextW
wcschr
_vsnwprintf
_vscwprintf
iswspace
EtwTraceMessage
RtlGetLastNtStatus
memset
memcpy
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
version="1.0.0.0"
processorArchitecture="amd64"
name="Microsoft.Windows.lhdfrgui"
type="win32"
<description>manifest file for dfrgui</description>
<dependency>
<dependentAssembly>
<assemblyIdentity
type="win32"
name="Microsoft.Windows.Common-Controls"
version="6.0.0.0"
processorArchitecture="amd64"
publicKeyToken="6595b64144ccf1df"
language="*"
/>
</dependentAssembly>
</dependency>
<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
<security>
<requestedPrivileges>
<requestedExecutionLevel
level="asInvoker"
uiAccess="false"
/>
</requestedPrivileges>
</security>
</trustInfo>
<application xmlns="urn:schemas-microsoft-com:asm.v3">
<windowsSettings>
<dpiAware xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</dpiAware>
<autoElevate xmlns="http://schemas.microsoft.com/SMI/2005/WindowsSettings">true</autoElevate>
</windowsSettings>
</application>
</assembly>
OiCCPPhotoshop ICC profile
AHXLXN
9C3J3W
J'\'Gg
v m2=:
KPIDATx
nNddt$
G] tPw
7x<h448
$HqB`q{1
" K.{e
<o3!&Y
.z#&eV
wUK2qUZ
|OOOZS7
tPJa5q
g=yUk8sU@
moS5)U
BiW|QD
<s^.26
zO\DD\
]VF<]8
_/oT9a
GyI~v."
\D]\q2!
I7gm"PJ
d{J@@Sa
(fHSZFK<
gu\nyq
pmeyiXS
;-<n/r;
dJES\nMF
&v5p'(J
=G1?sj
-Sr^IYc
Q]CmuY
jTUYYDW
ER,`0%N
/9tdS:
!-"-f6
K-H06
-/>s^.
G[~,w?
m3Lw^=
'W6FSO8
v!n5Qb+6wW
SP0+YZ
c tYv.
Mk]\d1
?~T^e[`
s$* *h
&#!jR&
qwa)Fr<8j
T3DnOR
o6C"61
3zUkv?
RV.2^X
O@k8F|
\vbbb!
*%%%%%%%%
muzZziA
gvv}v}m
oo~wwwwv
aYYQA@2Jwwg
/'++2**5
OG?FF>=93^
'+$+$"5WGG?>VB22
+$,+#.WGG?W7>=23
$,$+#5
GG??>=24
/*$,+#.WO
?W7=:3
OGG??>2:
-_G
#$%%%%%-&
mu}vvy
;A2]~~
'+**3_?GF>B2
/$,#%WG??E42
/+$+,
OG?>B3
7'*$+%WGW7;3
.&&.&&.&&&&)
rbrbrbry
"'+zoooovoi
"'+4;4;
"""4?G5
=WOV
IDATx^
i-_v//
T1,PUL
W* z_qm
H#soIV
$3aonl
5t|IN
[Z9`G;g
$?mPEiA
`PB0(q
@0(&3("
JR.I8%
6;O|72
c?8ex[7
e%B|Q&
Pp*vXJ
.MMi[YX
<5i`UQA[TT
KBui1Ui=
PZD (
'Y5xe4
qkY@xQVY
Tp8`hb
AAX8J=
B0hI7A
9T#X(=
~>T|OTy
*^+.p"
Wf;bn_
Aq#R<8
Sdb@!
3<+JC2
V 7`1r
\*~.-?
]0thO|
<JP|)>
R?x%hS
}+H}O^y^
v}LR&`(
UwNSva
atAFh7
3ZBkFs
fh66C3~
los4^K
4g7bsA
h|ws2&\
\8;<tj
f/Q~]Z}
BT)7c4p3J
09iPQY
{3/b7+
B<6\A3
Z&7lSJ
p']q <
t%<KV`q
zrSSOnjf
L"$f56D
{[[(ml
f:&DO
f8p.7(
e.p)u"
1Qa%&)
vV!sg9
?#sG52
<|+oM"
@Ne-ZwZ
8~dvo6
>"ho6B
9CMg.:
yw=s8
Y_d|kf{+
66N&6>A6)7
7brm/|,
5XDp;S
|_:f{,F
E;Od{Q
l|SAR(
H7w<uu
Co0tk$z
M)GHR9
<k \}3
`Z.nYe
>g,Igf
,FXJ)6e
8gM`J6
lybmff
} 1dQ%
f}Im/$
1:x=`0^v
hc3Dii
NG1[as
GY6l!!x7h
Swf`*]
oaobop
}.a/b/
)@ru['
9NwdGe
A.:6a]
pj4v4"0
,+QN6U
_JVd[);K0
^l?K+v)
Ru`Gc
!`%Xm!
(4YGxx
UI&N]U
G)*@x%~9~
5`5XE8
B%;XL;PA
MCHOddOHCM
kk_ki"
FHMDO9fkh
DO<0. 
'ODMHR44/ Tke
CXA774/ 5bk,NC
MEY@:770/\aVEM
HEXSA;8=QWEH
MCHOddOHCM
rqrFrqr
rqr rqr
rqr rqr
rqrFrqr
rqr rqr
rqr rqr
rqrFrqr
xxxxxxp
fffffffffffffffffffffffffff
4iyVVVVVVVVVVVVVVVVVVVVVVVVVV
f ,UiqV<4
iiiiifiiiib)qqql~
<fbbb<<<<<<<<<<<<<<&fl1qqq~
lyqlq~
~ylqyL
M^^ll~
fN@No\^ol[f,
fMMMMMM5
8kGGCCGCCGCCGCBBBBBBBC.
a==CC*=
lbtqqx
hGC??>88833..-2l
|RJ[J[lbRG
k_RCRa
44444444444
========@=@
B@BBBBBBBBB
BBBBBB,
-9220-
D`&"CBhA
6hw:H
3'O~zqq
8MBJ4j54
{7VMNb
M&)$ER
TJ4R-clh
.qP@)Aq$)
apdU:4<
#j~iQ\
Yf@*)D
{H!1sv
$*qDRJ
3=tj^'i&
8V$z|b
{ED Q0
_3chx$=
d?AZk5=
rIR)VPJ
3g0>>aZI
Bbhxx(;zt
HHDJR,]
Ojj}|N
x~XL4X
k|G`[H
.$gRIi[
Nnt&&A
|lhxdFJY
><D4FB
^5CV1o
^ jhE+
0}TF8s
7{^o?IQ
Jyd29\
?~n@fs
t:C*es
[u5|BW
.OO1==Mvp
K%VWWY
>44<|,
T,PX]e
v&}bhx
xyq~~que
T"78D6
3S,.-3
/*D>_w
\\uXr<~~y
LGfb9M
B4Es/<Gk
J3(M<O
z+@zTX
X3H@i?
WYY)tL
z\,9\)
S|mDR(
[IDAT7
//a*72
Y2qt8Jw
H?*pUn@
@6H.3b
C= a*U
gIL)ZDyj^
IIIeCCCs@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@w@@@7
ihdY\\Y4\\[
qrofWWU$efb
qrm\[ZX
cca]SSS
ffcgSSR
oomaWWV
}~{|^_^
qroQ[ZZ
wxvetsr
^^\0kkhWoolknnkkihdY\\Y4\\[
l|||lyyyluuvlrrsloopl
wxwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwww
wsw77ssws
w77ssws
w77sw77w7sw7ssw77swwww
pp4pwwc3
RRuwu7
{;{{;{
A%%gu3
GGGVwww
;;;{;{
{;{;{{;;;
A%%'s;
{ppt6RRR
qaCG6ugS
5%arws{{{
qaacRW
pprSecWs
;pwRW%'
{qvSpsScrq
us{;{y
V4qe7q
5vv5sg
7wewgat7q;
7u7%5w'Wr
7wwwcew'q{
{{7waeu7%ur
7wwsvuw'q{
wWwqv7Wr8
7wsegwwgu
www7u'Wrs
7wu7ugw7
Hwvww7wwu8
wwwgwV
wsWuw7w
wwwsvwv
wwvwwwww;
wuwwuwWw;
ww7wwrw
xwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwwx
7773sss{s{s{ssssssss{s{s{ss{
1@!d6w
;33133;;
5 Pt4w+;
1aapqg3
CCCCGs
7RSe4w3
u%%cCs{
{7SCt5gs
Wrwsu7s
wu4tvVq
{wvw757r
Wsuvvwq
7wv5sVs
WwWwvwq
wv7rW7s
{HwwWwWs{
wvwwgs
wwwwwww
7vwGWW3
wwwwwwwwwwwwwwwwwwwwwwwwwwwwww
wxwwwwwwwx7wwwwwwwwwwww
{{{{{{{{
Tvwq;;
t5cq;{{
qwavS{
sw6t;{
1wwww;
wwwwwwwwwwwwwwwwwwwwwwp
xxxxwx
44';{;{
qgS{{yx
wwwwwwwwww
333333;{
55555555555'55'
5'5''''5''5''''''''&&&&&&&&&&&&&&&&&&&&&&&&&&''''55
vrAALLLLLLLLALALLALLALLLLLLrLLLLLLLLLLLLNLNLLNLNLNLLNLLNLLNLNLNLNLNLNLLLLLLLLLLLLrLALLLLLAAAAAALALAAAr|
qkhhkm
ph]BBBBB^mq
>B\kqqqqqqqqqqq
qqqqqqqqqqqqqqqq
>]kpqqqqqqqqqqqq
qqqmqqmqqqqqpqq
pqppq_
&%$!$&5
>gjqppoqpoqjqjqjqjqjqppmoqqpqppqppqppoqppqoA
ppppppppp1
Bjopppoppppmoqjpmpppkppppkopppoppopppoqoo@
pppppnppnpnd
!$%&&
8gjoopjjjjjjpjmjjjjjjjkjjjpkjjjjpjjpjooooL
pnpnpnnnnnpnnpnp3
$$%&5
Zjooooopjjjjjjjjjkokooojjjjjjjjjjjjjjoo@
npnnpnpnnnnene
!!$%'&
ZdjjjoojjjjjjjojoooooojjjjjooojjjjjjooX
pnnnnpnnnneneeeoeneoe
$$%%
Zdjejddodojdjjjjjjjjjjjjjjjjjjjjjjjdj[4
nnpnnpnnnnnennonepeneoene
[dededddoddjddddj[dj[jdj[jdj[jddjddddX
nnnnnnnnnpeneneneneneee
$$&'
[fdddddddddddj[jdjddjdjdjdjdddj[dj[j[A
nnnnnnnnnneneneneeeeeene3
!!'!-eedddddddddd[ddddd[dd[d[[d[[o[djdddd3
nnnnnnnnnnnnnneneeneneeee[
`ddedededdddddjdd[jd[o[odo[od[o[d[d[[N
nnnnnnnenenenepeeenenee0
0cceddcddddddddddddd[dd[d[[d[o[dd[o[o3
nnnnnnnnnnnneenneeeeeee-
cecdcdccddddddddddddd[o[o[o[od[d[od[X
nnnnnenenneeeneneenee0
0cccccceccccddddddddddjd[oddddd[odd[d[4
nnnnnnnnnnnnnnneneeneeeeed0
0[cccccceeccdccdcdddddd[d[ddd[d[ddd[ddd3
nnnnnnnnnenneneeeeneedcddcccccccceeccccdcdcdcdddddddddddddd[d[ddd[L
nnnnnnnennennenneec[``YYYYYY`Y`[cceccccccdcdddddddddddd[dddo[d[d3
nnnnnnnnennnneene[<:::::::::::Y[ceecceedccccccdcddddddddd[dddo[P
nnnnnnnnnnnnne[0
-:Ycceccecededcdcddddddddddddd[d[3
nnnnnnennee
0<cceececcdeccdcccdcddddddddddo3
!!$$&!
<ceceeceecdecdedcdcddddddd[d[[4
<ceeeeeeecedecdedcdcdddddddddX
<`efeeeceececccdedcdcdcddddd[L
<[fecneeeeededecdedcdcdcdddd3
<cefeeecdeeececceccdcdddcddW{
<afeeeeeeeeeedededcedecdcdd3
=cfffneeeeeeeeeecedecdedcdW
=affeeeeeeeeeeeeeeedecdedd\
=afffneneeeeeeeeeeeedecdeX
<afffneeneeeeoeeeeeeedeedL
9bfffeneeneeeeeeeoeeeedc3
fnneeneneeeoeeedeee[
fnneeneeeeeeeeeeed@
% 8a
fnnnnnnnpnnnoeoeoe[
!!!!!' ?l
nnpnnnnnnoA
! !!!'"6l
pnnnpnnpeW
% !!!!'"6i
nnnnes
! ! !!'"2l
' ! ! !!!&%/l
'! ! ! !! !!%&i
5! ! ! ! !!!%&l
5!!!! ! !! !!%'
5!!!!!! !!! !%'
5!!!!!!!! !!!%(
""!!!!!!!!!!#
""#"$!!!!!!!#
"%$$!##!!!!!#
%$%#####!#!!#
7'5%%#%######!#"
%%%%%%%"#####
%%%%%%#%%####
5&%&%%%%#%#%##
&&%&%%&%%%%%%
&%&%&&%&%%%%%
5&''&%&%&%&%&%
&'&'&'&&&%&%&
&&'&&&%'%&%&%
'&&'''''''&&&
5&''&'&&&&&%'&
5'''''''''''&'
'''''''''''''
5'''H''H''''''
'H'''''''
MMMMMMMMM
a___HHHHHHHHHHH_HHH_HHHHIHHIIIIIIII_IIIII`_III_IIIIIIIIHHHHHHHHHHH_HH_HHHHHHam
qGBBGhnv
!_luvuvvv
vvvvvuwww
EluuuuuvuvvvvvvvvvvvvuuuuuuuuuwwqI
\suusuuusuuquuuuuuquuuususususs^
sssssstss
=sqsssqquqquqqqqqquqqququqsqssqP
)-/8-]sqqqqqqqqqqqqqqqqqquqqqqqqqqZ
srtstrsrrtt;
pqqqqqqqqqqqqqqqqqqqqqqqqqqq]R
rsrrtrst;
ppppqpqpqqqqqqqeqqqqqqqqqqqpZ
qrrrtD
,//!pppppppqppqqq]qqqeq]qq]q]qpY
rsrrrrrrrrp
Yrpppppppppp]qqq]qpqq]qpqpp]I
rrrrrrrrD
)5+;prprpppppppppppppp]qppp]q]qY
rrrrrrrrrr=
))++)!drpppppppppppppp]qpq]p]qppp]y
rrrrrrrrtY
=prprrptpppppppppqpp]qpqp]q]pZ
rrrrrtrrrrr[AYdtprppprpptpppppppppppp]qpqpq]R
rrrrrrprrrdrrprrpprpppppppppppppqpp]q]]Z
rrrrrrD========>[drrptpprpppppppppppqppqY
=drprpprpprpppppppppppp]x
drrprtptppppppppppppq]Y
crrrppppptprppppppppp]y
cprrrrrtpppprppppppppZ
crrrprprptprprppppppY
[rrrrrtprprtpprprpppI
crrrrrprrrpprptppprY
crrrrrrrptptprpprrpx
[frrrtrrrrprrptpppY
rrrrrrrrrrprrtp~
rrrtrrrrrrptpZ
ttrrttr]
))))-50K
sttstpb
))),50F
))))60C
))))52C
%*-))))))))52@
%+-))))))))52@
'./,)))))-)/2@
'6/--,-)-))5/<
'6/---,-),)/5$
(7/-------)/5$
(95-/------/8$
?:5/5//----/5$
5/5/2///-58%
555/5/2//56
655555/5/87
77555555277#
7588585558M#
7858855858:&
888588585M:&
8588885858
7885858588
L4.....+.+..3L
---------*--*-*-*-*-*-*------**-**************)*****-*-
B=====AAAAAABBBBBBBBBBBBBBBABBBBBBBAABBAAAAAAAAA===
\K9OU\efffffffffffff
}}}}}}
0OYeeeeeeeeeeeeeeefeff\
||f|ec|c
0Pee\eddeddedefdeefebj
Vx||c|s|csff|fbfbfbf7
L`bdd\\\d\\d\d\d`b`Y
rsssssbsbbbTrbababr1
N``````d`\````````_l
CvsrsbsTbbraabaaaaa0
Ma````_`_`_````_`_Y
TrsrbrbraabaaaaaaaJ
#%.`______`R``_`_`RRM
>vrrrsasasaaaaaa_aa
7_______R`M`R`M`RMZ
Wrrbrsasaasaaaaaava0
8M_______RRRRM`RRMM
<rrrsrQrraaTaaaaaaa____`M_Ma_____R`_``M`MMj
VvrrrrrTrrraraarva_J3378JR_________M_`M_N
rrrsrrrrTrrabara
08Ra_a_____`___Mn
Dtrssrsrrrasrar3
8_a_________`MY
srtrssrrrsarra0
JR_a_a_______M
<trssrssrsssrr/
JRaa__a_____Mi
Xtvrrrsssrrrr/
8Ra_a_a_a___M
zuuurrrrrsrs
8Raaaa__a___k
uuusrsr
8Raaaaa__a_R
8Raaaaava__
8Qsssrrbaa\
8T||ssbraa
&&
8]|uscsba^
6[|sx|srr
&""""&
'##"""%
'###""%
6]~~~|r
&&%%##&
'&&&&#'
&&&&&&&
')&&&&&
&))&)&)
))))&))
'))))))":
'''&'&&
,,++++,+,,,,,,,.,
,,,,,,,,,+++++++++
%5gzzzzyzzzyyzyyzb
%DvttxxxxxxxxxxkL
uunnnnnnr0
Bmkkkllllllllk?
nppmmp@
`jjjikhiiiiiiaR
pppmmr1
<mjjjhjhhhihihE
pppppqpc=cqmjjjjhjhhhihaU
ppppmcccccjjmjjjjjhkhhC
;qmjjjjjjhja
$;mmmmjmjjjhN
<qmmmjmjjj>
<pmmmmjmmhT
7mppmmmmjF
pppprj
"'%%$8
"++%%&H
)++++'H
),,++-H
EddcQQQQQQdQM4MQMQOQQQOQQ9
rrrrrr
"Jokkkkkkh6
^kkjhhjjG=
nnp[/.2okkjjhhK7
[25[ikkkkjkG
\pmmkkK;
\pmmmk4
[ppmo[w
8<<<<CB
A6223331,
7nyyy}0
]]SS^Q
TmYYa?
.ZNMMN
VmmyT55>XQQNK'
9a]X?d
IDATx^
$Z-x0=
H%nDVa
0%H+`}a
`,`cVQ
1?n{CR
F{}knI
wI\>_k
hHu3kb?
x3{<H=
,^dh-q
A%z2!@
A=+K;.
N?S'<l~
>xlZa;
k~K|E.
;??GL~
,o:?^Dz
=^Sk l
_"s_L
#5?}}5
c:?]SV{
|!s_S{
Atj|Gx9
7_77;r[
^cD_Ky
kG h7)=
]4?Gb$
8sB!a^
BfeoGv%=S~*
~N*M}nr]
sr8y>H~
#?5<}~
ly[!3~
;S_4~!
TN1XB)
e[/jy.
0<+`5Zw
(3j@7i
C(8A #
KIIIJ~
{cbHSQ
|I$?s
Ia@HL$p
3#@+ ?
r&_drp.
{kF`N|
c:<UKbh
/2c:^j
yJ4wz-w:
-l*C*E
y^s:fB
1W@}f+
c6v,w<
RzS]Jo
[,Qf>H
?~.~N~
---/!!!8!!!;"!!?
==
====>>>>>>>>>>>>>>>>>>>>>>>>>>>>? A A? @ @ @ @@@@@@@@@@ A A B B B! B B B A A A A A A A A A A A A A B B B B B B B!!!C!!!C!!!C!!!C!!!C"""CB
aaa:trruTTTjUUUtTSS}SSS
\\\~[[[}[ZZ}[ZZ}ZYY|ZYY|ZYY|XYY|YYY|XXX|XXX|XWW|XWW{XWW{WWW{VVV{VVV{VVV{VVVzVUUzVUUzVUUzUUUzUUUzUTTzSTTzSSSzSRRzTTTzTTTyNNNtSQQqKKKe
~~~z;;;
fee0===
zzzeKKK
YYY%555
tttNAAA
kkk:===
~~~zMMM
ddd/777
zyy^EEE
UTT"...
tssJEEE
kjj7A@@
}||oJJJ
___*777
wvvYEDD
SSS!...
oooCAAA
gff4<<<
{{{jJJJ
]\\'544
uuuSAAA
QPP .--
nmm?AAA
~}}{LKK
cbb1666
zyyeGFF
VVV$444
rqqM===
jjj9<<<
}||vLKK
cbb-666
xww]@@@
SSS"---
srrGDCC
hhh6<;;
|{{oIII
]\\)666
vvvW@@@
OOO ---
nnnB@@@
dcc3;;;
zyyhFFF
]\\'000
uttODCC
NMM---
mll><;;
~}}zIII
dcc1666
zzzcDDD
RRR#544
tssLAAA
nnn8>>>
fff,999
~~\HHH
XXX!877
xwwEBAA
qpp5BAA
gff(<<<
[[[ 333
}||AJII
uuu2???
lll'999
___666
www0CCC
iii$AAA
yyy,GGG
ooo!<<<
B@@D.//N,++T)))X)))Y*))X)))X)))X)))X***Y***Y***Y*))Y)))X*))X***Y***Y***Y+**Y+**Y+++Y+++Y+++Y+++Y,++Y.,,Y.,,Z.,,Z.,,Z...Z...Z/..Z/..Z///[/..Z///Z0//[0//[000[111[211[322[433\444\555\555\555\555\444]344\222Z211[222[211[100Z100Z100Z111Z111Z100Y111Y211Y111Z100Z111Y000Y000Y00/X000X000X///X///X///X///W///W///W...X...X...W...W...W,,,W...X,,,X+++X,,,X,,,X&&&T$$$O
vuur,++
lll^%%%
rqqn100
hhhW$$$
vvv|444
mlle+**
qppw333
iii\"""
poos211
ihhX%%%
nmmf&&&
eddS"""
pood&%%
lkkN!
~}}x222
xww^)))
~}}V,,,
(null)
defragsvc.dll
Volume
blblog
SOFTWARE\Microsoft\Dfrg
TracingMode
BuiltInDefragTracing
Defrag
O:BAG:BAD:P(A;OICI;GA;;;BA)(A;OICI;GA;;;SY)
%SystemRoot%\Logs
Defrag
WindowsDefrag{DD9F21BA-FDA6-45fa-8E43-BCA5F55E87A1}
%windir%\system32\defrag.exe
r%.4u-%.2u-%.2uT%.2u:%.2u:%.2u
erunas
DISK_DEFRAG_HOW_DOES_AUTO_DEFRAG_WORK
1399f42d-c6d4-4716-97a7-612a1f0598e3
mshelp://windows/?id=
%systemroot%\system32\dfrgui.exe
tuxtheme.dll
Button
<NULL>
%s.0.%s
%s.0.?.%s
%s.%d.%s
%s.0.%d.%s
%s.0.1.%s
%ProgramFiles%\
SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinSat
RandomReadDiskScore
\\?\PhysicalDrive%ld
ntdll.dll
kernel32.dll
netmsg.dll
%s%s(0x%08X)
%s%s(0x%08X[0x%08X])
ROOT\CIMV2
Win32_Volume
DefragAnalysis
__Path
DefragRecommended
Microsoft\Windows\Defrag
SELECT * FROM Win32_Volume WHERE DeviceID=
SOFTWARE\Microsoft\Dfrg
DefragDailyTrigger
<?xml version='1.0' encoding='UTF-16' standalone='yes'?> <Task xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task"> <RegistrationInfo> <Source>$(@%systemroot%\system32\defragsvc.dll,-800)</Source> <Author>$(@%systemroot%\system32\defragsvc.dll,-801)</Author> <Description>$(@%systemroot%\system32\defragsvc.dll,-802)</Description> </RegistrationInfo> <Triggers> <CalendarTrigger id="DefragWeeklyTrigger"> <StartBoundary>2005-01-01T01:00:00</StartBoundary> <Enabled>true</Enabled> <ScheduleByWeek> <DaysOfWeek> <Wednesday /> </DaysOfWeek> <WeeksInterval>1</WeeksInterval> </ScheduleByWeek> <RandomDelay>PT2H</RandomDelay> </CalendarTrigger> </Triggers> <Settings> <IdleSettings> <Duration>PT3M</Duration> <WaitTimeout>P7D</WaitTimeout> <StopOnIdleEnd>true</StopOnIdleEnd> <RestartOnIdle>true</Restar
ScheduledDefrag
DefragWeeklyTrigger
DefragMonthlyTrigger
/analyze
/defrag
/cancel
/schedule
/remove
VS_VERSION_INFO
StringFileInfo
040904B0
CompanyName
Microsoft Corporation
FileDescription
Microsoft
Disk Defragmenter
FileVersion
6.1.7600.16385 (win7_rtm.090713-1255)
InternalName
lhdfrgui.exe
LegalCopyright
Microsoft Corporation. All rights reserved.
OriginalFilename
lhdfrgui.exe
ProductName
Microsoft
Windows
Operating System
ProductVersion
6.1.7600.16385
VarFileInfo
Translation
Antivirus Signature
Bkav Clean
Lionic Clean
Elastic malicious (high confidence)
MicroWorld-eScan Clean
ClamAV Clean
FireEye Clean
CAT-QuickHeal Clean
McAfee Artemis!AB792C894FCF
Malwarebytes Clean
VIPRE Clean
Sangfor Trojan.Win32.Agent.V6bh
K7AntiVirus Clean
BitDefender Clean
K7GW Clean
Cybereason Clean
Baidu Clean
Cyren Clean
Symantec Clean
tehtris Clean
ESET-NOD32 Clean
APEX Malicious
Paloalto Clean
Cynet Clean
Kaspersky UDS:DangerousObject.Multi.Generic
Alibaba Clean
NANO-Antivirus Clean
ViRobot Clean
Rising Trojan.Fabookie!8.11C3D (CLOUD)
Emsisoft Clean
F-Secure Clean
DrWeb Clean
Zillya Clean
TrendMicro Clean
McAfee-GW-Edition BehavesLike.Win64.BadFile.hh
Trapmine Clean
CMC Clean
Sophos Clean
Ikarus Clean
Jiangmin Clean
Webroot Clean
Avira Clean
MAX Clean
Antiy-AVL Clean
Gridinsoft Ransom.Win64.Wacatac.oa!s1
Xcitium Clean
Arcabit Clean
SUPERAntiSpyware Clean
ZoneAlarm UDS:DangerousObject.Multi.Generic
GData Clean
Google Clean
AhnLab-V3 Clean
Acronis Clean
BitDefenderTheta Clean
ALYac Clean
TACHYON Clean
DeepInstinct Clean
VBA32 Clean
Cylance unsafe
Panda Clean
Zoner Clean
TrendMicro-HouseCall Clean
Tencent Clean
Yandex Clean
SentinelOne Clean
MaxSecure Clean
Fortinet Clean
AVG Win64:Trojan-gen
Avast Win64:Trojan-gen
CrowdStrike Clean
No IRMA results available.