????

Your IP : 18.188.211.44


Current Path : C:/Windows/System32/
Upload File :
Current File : C:/Windows/System32/RmClient.exe

MZ����@���	�!�L�!This program cannot be run in DOS mode.

$
��wN��$N��$N��$���%O��$���%M��$���%]��$���%G��$N��$t��$���%L��$��c$O��$���%O��$RichN��$PEd��:D��"0P�,@


��`� �Hdp0`��8pDT@8HA�.text�#0 `.rdata*@@@@.data�PP@�.pdata�``@@.rsrc0pp@@.reloc8��@B��������H��8H�d$ L�G4D�ʺ+H�g1DH��8����������L��E�K H��HI�c�I�C �I�C�D��L��3�+I�C�H�1DH��H�����������L��fE�K H��HI�c�I�C �
I�C�D��L��3�+I�C�H��0DH��H����������H��HM��tI��I��C�<u�I���A�M��H��2IE�H�d$0L�D$(L�B3D�ʺ+H�D$ H�]0DH��H��������H��XM��tI��I��C�<u�I���A�M��H�T2IE�H�d$@L��$�H�D$8L�L$0L�D$(L��2D�ʺ+H�D$ H��/DH��X����������H�\$WH��PL��$�I��3�D��H��M��tI��H��fA9<Bu�H�E��
M��H�
�1IE�M��tI��C8<u�I���A�H�|$@H��1H�T$8M��H�L$0�+IE�L�D$(E��H�D$ L��1H��H�%/DH�\$`H��P_����������H�\$WH��pL��$�H��3�H��A�
M��tH��H��fA9<Pu�L�U�M��H��$�L��0M��I��IE�H��tH��f9<Au�L�EH��H�|$`H��$�H�D$XL�M1H�D$PLE�L�\$HH��0H�T$@�
L�L$8L�T$0D�ɍQH�D$(H��H�D$ H�5.DH��$�H��p_�����������H��XM��tI��I��C�<u�I���A�M��H� 0IE�H�d$@L��$�H�D$8L�L$0L�D$(L��0D�ʺ+H�D$ H��-DH��X����������H��hL�-0H��H��A�<u�H�d$PH��$�A�-H��E�A�L�D$HH�T$@H��$�L�D$8L�0H�T$0A�Q�H�D$(L�T$ H�,-DH��h�����������H��xM��tI��I��C�<u�I���A�M��H� /A�IE�H�d$`L�T$XL��$�L�L$PL��$�L�T$HL�L$@L��$�L�T$8L�L$0L�D$(L�j/D��A�R'H�D$ H��,DH��x���������H��hH��$�E3�L��H��tH��H��fD9Bu�H�E��
L�D$PH�t.H�L$HL��.H��I��HEº0H�D$@H��$�H�D$8H�D$0H��.D�ʺ+H�D$(
H�D$ H��+DH��h��������H��x�D$`L�=.H��H��A�<u�H�d$PH�T$`A�H��E�A�L�D$HH�T$@H��$�L�D$8L�A.H�T$0A�QH�D$(L�T$ H�W+DH��x������q��vM�H�\$H�t$WH�� A� H�ڃ�t��t�W�Z3�3�@2��3I��H��*DH��H��H��*DH��@��H��*D�CtH�KH��HEىC3�H�{@�sH�\$0H�t$8H�� _��������H��H�XH�pH�x UATAUAVAWH��8���H��H�9H3�H���E3�L��H����H�D$XA��H�D$PE��H�-L�-�>H��>H��>H��8L�5�>L�-�>H��>M�H�CH�D$8H�
���L�l$0H�D$`L�D$`M�vL�l$hA�L�l$(H��H�D$ L�C H��)DH�H��u�D�sE3�A��E3�3�H�
*DA;���H�8I�_L�=�7��H�A����f��-fA��tf�9\u6L���1D�IfA��?t"fA��htI;�tD�rtH�J�?���H��7A��H��I+�u����SM���JH�8)DH��L�D$P�VH��(D��u.H�a7I;��SD�p�IH�)D�V�H�L$PH�D$DA�H�D$ L�D$pD�L$DA��H�Y(D��u0H�7I;���D�p��H��(D��H�T$pL�L$L��D$@�D$LL��p�D$H3�H�D$@H�D$0H�D$HH�D$(H���H�D$ H��'D��t=H�
y6I;�to�Ati�D$@H�I�D$0H��pH�D$(H���H�D$ �����>H�<6I;�t2D�pt,H�(D�H�
6L�
"*�D$ H�I�I���H�T$XI���H�t$X��u,H��5I;�tD�stH�K�P����H��5����/H�����H��5I;�t�CtH�KD������H��5H���tH��H�l'DH�x5I;�t*�H�KH��tH��&DL�kH�H��u�L�=I5���LH�)H��H��'DH�
)H��'DH��H��'DH��H��'D���H���H3��
L��$�I�[0I�s@I�{HI��A_A^A]A\]����������H��H�XH�pH�x UATAUAVAWH������H��PH��4H3�H��@L��3�H�L$@A��]3�H�=k4E3�D�kD�{L�L$0D�|$0E��H�T$@I��������	D�D$@3��L$4�E3�A��E������tw��t@��
�6H�
4H;����A��H�I�VL�
�'D�D$ �T����H�
�3H;����A��H�IL�
�'A�����kH�
�3H;�t�AtH�I���eH�%`�D�D$P��L�|$HH�I0H�X&DH��H��u�X�LD�D$PL�L$0H��D�D$0I������u8H�
&3H�3H;�t�At�H�IL�
'���
��D$P9D$0t H�
�2H��2H;�t�AtӺ뼃?t H�
�2H��2H;�t��At���eH�%`��D�GH�I0H��%DH��H��u�X�:�WH��D�GH��E�OH�D$4�WH�H�D$(L�΋D$TM�ljD$ ��	��eH�%`L��3�H�I0H�%DH��teH�%`L��3�H�I0H��$DI��H��#D3�H�L$@A����D$4A��D$HD�|$4�D$@�\$L��tD��A����L�L$4E��H�T$@I���?��uVH�
�1H�=�1H;�t�AtH�I�PL�
�%�G�A����)H�
\1H;�t�AtH�I��K��H�=:13�����H�
,1H;�t�AtH�I�\$ ����H�

1�������E��tPH;�t�AtH�IL�
%������PH�
�0H;�tA�At;H�IL�
�$����$H;�t�AtH�IL�
�$��\$ ��A��H��@H3��
L��$PI�[8I�s@I�{HI��A_A^A]A\]���������H��H�XH�hVWATAVAWH��`�`E3�H�`�W�M��A��H��L����@�E��t
H��t��rI���u0H�
�/H��/H;�t~�AtxH�IL�
�#����aE3�D�Nj�3�H��!DH��H��uJH��/H��/H;�t0@�xt*H�i!DH�
�/�VL�
�#�D$ H�I��3���H��H�U!DH�D$@H�t$XL��$�H�D$ D��H��I��H�� D��u_H�� D=�tLH�/H�/H;�t2@�xt,H�� D�H�
�.L�
�"�D$ H�I��3��<H��.D�Ǻ�H��D�H�� D����H�
�.H;�tB�At<H�] DH�
y.L�
�"�D$0� �l$(D�t$ H�I���H�
P.A��r�H;��q���@�y�g���H�IL�
L"�!���M���E3�L��$�H�T$@I��H� D��u0H��-H;�����@�x����H��D�"����D��$�M��tE�$H�
�-H;�t �AtH�IL�
�!�#D�D$ ��H��H�kD��L�\$`I�[0I�k8I��A_A^A\_^��������H��H�XH�hVWATAVAWH��`�`E3�H�`�W�M��A��H��L����@�E��t
H��t��rI���u0H�
-H��,H;�t~�AtxH�IL�
!�$���aE3�D�Nj�3�H��DH��H��uJH��,H��,H;�t0@�xt*H�uDH�
�,�V%L�
� �D$ H�I��3���H��H�aDH�D$@H�t$XL��$�H�D$ D��H��I��H��D��u_H�D=�tLH�,H�,H;�t2@�xt,H��D�&H�
�+L�
 �D$ H�I� �3��<H��+D�Ǻ�H��D�H��D����H�
�+H;�tB�At<H�iDH�
�+L�
��D$0�'�l$(D�t$ H�I���H�
\+A��r�H;��q���@�y�g���H�IL�
`�(�
��M���E3�L��$�H�T$@I��H�D��u0H��*H;�����@�x����H��D�)����D��$�M��tE�$H�
�*H;�t �AtH�IL�
��*D�D$ ��H��H�wD��L�\$`I�[0I�k8I��A_A^A\_^��������H�\$H�l$VWATAVAWH��@E3�H��H��E��H����fD99��H���|H�
#*H�*H;�t�AtH�IA�W,L�
2H�t$ ��I��L�|$0E3��D$(@E3����D$ H��A��H��DH��I;���H��)H;�t+�@t%H�uDH�
�)�D$(D�t$ H�I�w���H�CDA���p���H�
])H;�t �AtH�IL�
w�.D�t$ ��I��H�DL�'�E3��D$pE3�H�T$pH��H��D��uCH��(H;�t2�@t,H��DH�
�(L�
��/�D$ H�I��H���H�/��0H�
�(H��(H;�t�AtH�IL�
��+�\�3�L�\$@I�[8I�k@I��A_A^A\_^����������H��H�XH�pH�xL�h UAVAWH�h�H��3��E�L�M�M���]�H�����H����L�uM����I�@�H����v�{h3�D��H�M���
3��}�f9�-H�=�'H�E�L�-�-H��W�H�E�E�uT�I��H��D��u<H�
�'H;�t\�At1H�[DH�
w'�S1L�
��D$ H�I��H�
Y'H;�t �AtH�IL�
��2H�t$ ��H�E�L��H�D$PL�M�H�E�3�H�D$HI�ϋEwL�l$@H�\$8�D$0�\$(H�\$ H�MD��uAH��D��t/H�
�&H;�t�AtH�IL�
��3�D$ ������&�M�A�H�M�H��DH�M�H�rD���0H�
z&H�=s&H;�t�AtH�IH�t$(�T$ �r���L��$I�[ I�s(I�{0M�k8I��A_A^]���������q0R^G'�H��(�MZf9��t3��SHc
?��H����Hȁ9PEu�f9At�f9Au�3����v9���3��ytv	9������&����GH�
H��H��-H��-��%�H�
���%����=s%u
H�
��3�H��(������qH�V�>�H��8��%L��%D�
�%H�q%�%H�
\%H�q%H�D$ ���H%H��8��������H�\$H�t$H�|$AWH��0eH�%0H�X3�3��H��,tH;�u	�������v�ػ��,;�u���o��,��u_��,L�=�H�=�H�|$(�D$ I;�s/��u/H�?tI�p0R^G'�H�H�
o�щD$ H��H�|$(�̅�t�����^$�T,;�uH�YH�
B�V�3,��u	3�H�,H�=&,t4H�
,���t$I�p(�xE.�E3�A�P3�H��+L�
�A��L��#H��#�
�#�w���#�=�#u���=�#u����#�-��#�=�#u	���̃=�#u���t#H�\$@H�t$HH�|$PH��0A_�������q0R^G'�H��(�{H��(������������������������ff�H;
�"uH��f����u�H���r����������q���?��H��(H��8csm�u#�xu�H ���l�v��@�u���3�H��(����������������q0R^G'�H��(H�
�����g3�H��(�������%��������H��3�H�A�H���w<�MZf9u*9Q<|%�y<sHcA<H�H�$�8PEHE�H��H�$�3�H�$H��H�����������@SH�� ��3��H��t(H�����H��t�f9H\u���f�x\�t��H�� [�������%?�������3���������������LcA<E3�L�L��A�@E�XH��I�E��t�PL;�r
�H�L;�rA��H��(E;�r�3��������������H�\$WH�� H��H�=��H���D��t"H+�H��H�����H��t�@$���Ѓ��3�H�\$0H�� _�������������������̸MZf9u HcA<H��8PEu�f9Hu��3���������H�\$ UH��H�� H�eH�2��-�+H�� H;���H�M��H�EH�E�p��H1E�l��H1E�p��H��H1E�`��H�MH3EH3�H�M H�E�%�E H�������H�� H3E H3EH#�H��H;�u
H�3��-�+H��H�
�H�\$HH��H��H�� ]�qqTX���3��������%������%����������@SH�� H��3��H����H�Ⱥ	�H�� [H�%�q�����H�L$H��H�
] �H�H!H�D$HE3�H�T$PH�L$H�H�D$@H�|$@tBH�D$8H�D$XH�D$0H�D$`H�D$(H� H�D$ L�L$@L�D$HH�T$P3���#H�z H�H�� H�i H��H�^ H�� H�(H��$�H�) ��	�����Hk�H�
�H��Hk�H�
�H�TH��Hk�H�
�H�AH��Hk�H�
%H�Lh�Hk�H�
H�LhH�
�
�[���H�Ĉ������������������������������������������������������H��(M�A8H��I����H��(��������@SE�H��A��L��A�L��tA�@McP��L�Hc�L#�Ic�J�H�C�HH�C�Dt�D���L�L3�I��[�I���������%�������%��������ff�����������������������ff��%�����������@UH�� H��H�H�ы�x����H�� ]��������������������@UH�� H��H�3Ɂ8�����H�� ]���P@ Q@8P@C@ C@�C@	u�xC@(C@0C@8C@K.KBKZKrK�K�K�K�K�K�K
L$L8LDLRLbLjLzL�L�L�L�L�LbNDNvN�N�N�N�N�NO~M�M�M�M�MO`MXMPM>M,MMMjMM O�M�M�MN&N@2@3@@2@ 3@ 3@�*@�)@�-@�,. /P�)�*�,P-�-P0�0@2NULLNULL
 RmClient.exe pipename
wmainMsgLoopReceiveSendOpenPipeSpawnProcess�����F���,�$r$�f�F�
4"ܩ����:D�%�D�D�:D�
�D�D�:D�$GGRSDS�H�P�̂a��7_HRmClient.pdbGCTL�".text$mn�2@.text$mn$0003P.text$x@H.rdata$brcHA�.idata$5C(.00cfg@C.CRT$XCAHC.CRT$XCAAPC.CRT$XCZXC.CRT$XIA`C.CRT$XIAAhC.CRT$XIYpC.CRT$XIZxC.gehcont�C8.gfids�C.rdata�Dd.rdata$zzzdbg(G�.xdata�HP.idata$24I.idata$3HI�.idata$4K.idata$6P.data$brcP0.data@P�.bss`�.pdatap�.rsrc$01�p@.rsrc$02 �H�P�̂a��7_H��#� �:<2F�:D�b����

4
�p

4
�p��d42p7
&t�&d�&4�&�����PX2�7
&t�&d�&4�&�����PX2@
T4����
p`
T4r���p`#
#�'#t&#d%#4$# ��PB	t
d	4R�e0%+�,03�,2P	"e0�-..20	

4
2pe0�. /`3 /

4	
2P0HI�KHA�I�L�A`J�M`B�J:N�BK.KBKZKrK�K�K�K�K�K�K
L$L8LDLRLbLjLzL�L�L�L�L�LbNDNvN�N�N�N�N�NO~M�M�M�M�MO`MXMPM>M,MMMjMM O�M�M�MN&NpGetTokenInformation�LookupAccountSidW�CreateProcessAsUserWBUnregisterTraceGuids�RegisterTraceGuidsW"OpenProcessTokenrGetTraceEnableLevelqGetTraceEnableFlagssGetTraceLoggerHandle5TraceMessageADVAPI32.dll�ReadFileVSetNamedPipeHandleState!GetCurrentProcess3WriteFile�CreateFileW�CreateEventW�SleepkGetLastError�WaitForSingleObjectEx�CloseHandlebHeapSetInformation�ResetEvent�GetOverlappedResult�GetSystemWindowsDirectoryWKERNEL32.dll-wprintfZ_XcptFilter�_amsg_exit�__wgetmainargs�__set_app_type?exit_exit�_cexit�__setusermatherr�_initterm^__C_specific_handler0_fmode�_commodemsvcrt.dll4?terminate@@YAXXZ�RtlAllocateHeapRtlFreeHeap�RtlCaptureContext�RtlLookupFunctionEntry=RtlVirtualUnwindntdll.dll�SetUnhandledExceptionFilter�GetModuleHandleW[QueryPerformanceCounter"GetCurrentProcessId&GetCurrentThreadId�GetSystemTimeAsFileTimeGetTickCount�UnhandledExceptionFilter�TerminateProcess�memcpy�memsetP@2��-�+�] �f��4(G<�0G��8G�>@GD�HG�|PG�o\Gx�HG�ohGxpG�hG�DpGP�xG�8�G@��G��"�G�"�%�G�%�'�G�'�)H�)�*(H�*	+(G+�,0H�,-(H ->-hHP-�-(H�-�-(H�- .lH(.m.�H�.-/�Ht/H0�Ht0�0�H�0!2�HX2u2(H|2�2�H33�H 3&3�H03N3\H`3�3\H��(�@�X�p�����	�	�	�hw��s��p�MUI<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<!-- Copyright (c) Microsoft Corporation -->
<assembly xmlns="urn:schemas-microsoft-com:asm.v1" manifestVersion="1.0">
<assemblyIdentity
    version="5.1.0.0"
    processorArchitecture="amd64"
    name="Microsoft.Windows.RestartManager.RMClient"
    type="win32"
/>
<description>Restart Manager Restart Client</description>

<trustInfo xmlns="urn:schemas-microsoft-com:asm.v3">
    <security>
        <requestedPrivileges>
            <requestedExecutionLevel
                level="asInvoker"
                uiAccess="false"
            />
        </requestedPrivileges>
    </security>
</trustInfo>
</assembly>

�4VS_VERSION_INFO��
!|O
!|O?StringFileInfo�040904B0LCompanyNameMicrosoft Corporationn#FileDescriptionRestart Manager LUA Restart Clientn'FileVersion10.0.20348.2849 (WinBuild.160101.0800):
InternalNameRmClient.exe�.LegalCopyright� Microsoft Corporation. All rights reserved.B
OriginalFilenameRmClient.exej%ProductNameMicrosoft� Windows� Operating SystemDProductVersion10.0.20348.2849DVarFileInfo$Translation	������Y�k.<��b8O%isM��*r�4�۩������MUIMUIen-US@,��h��������(�0�8�� �(�0�8�H�`�h�P�