�����JFIF��XX����������    $.' ",#(7),01444'9=82<.342  2!!22222222222222222222222222222222222222222222222222�����"����4���������������������������� ���������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������,�PG"Z_�4�˷����kjز�Z�,F+��_z�,�© �����zh6�٨�ic�fu������������������������������������#ډb���_�N��?�����������wQ���5-�~�I���8���������������������������������TK<5o�Iv-������������������k�_U_������������������������������~b�M��d��������Ӝ�U�Hh��?]��E�w��Q���k�{��_}qFW7HTՑ��Y��F�����?_�'ϔ��_�Ջt������������������������=||I �����6�έ"�����D���/[�k�9����Y�8������ds|\���Ҿp6�Ҵ���]��.����6���z<�v��@]�i%������������������������$j��~����g��J>��no����pM[me�i$[�����������s�o�ᘨ�˸ nɜG-�ĨU�ycP���3.DB�li�;���������������������hj���x����7Z^�N�h��������N3u{�:j�����x�힞��#M��&��jL P@��_���� P�������������������&��o8��������9������@Sz���6�t7#O�ߋ �����s}Yf�T������lmr����Z)'N��k�۞p�����w\�T���������������ȯ?�8`���O��i{wﭹW�[�r�� ��Q4F�׊������3m&L�=��h3�������z~��#����\�l :�F,j@�� ʱ�wQT����8�"kJO����6�֚l������������������}����R�>ډK���]��y����&����p�}b������;N�1�m�r$����|��7�>e�@���B�TM*-i�H��g�D�)� E�m�|�ؘbҗ�a���Ҿ����������������t4�����o���G��*oCN�rP���Q��@z,|?W[0���������:�n,j���WiE��W������$~/�hp\��?��{(�0���+�Y8rΟ�+����>S-S���������������VN;���}�s?.����� w��9��˟<���Mq4�Wv'������{)0�1mB����V����W[��������8�/<� �%���wT^�5���b��)iM� p�g�N�&ݝ������������VO~��q���u���9��� ����!��J27�����$����O-���! �:���%H��� ـ�������y�ΠM=t{!S�� �oK8�������t<����è��������:a��������[������ա�H���~��w��Qz`�p����o�^ ������Q��n����� �,uu�C��$ ^���,�������8�#��:�6��e�|~�����������!�3��3.�\0�����q��o�4`.|� ����y�Q�`~;�d�ׯ,��O�Zw�������`73�v�܋�<�����Ȏ�� ـ4k��5�K�a�u�=9Yd��$>x�A�&�� j0� ���vF��� Y���|�y��� ~�6�@c��1vOp��������Ig�����4��l�OD�����L����� R���c���j�_�uX�6��3?nk��Wy�f;^*B� ��@���~a�`��Eu�������+�����6�L��.ü>��}y���}_�O�6�͐�:�Yr���G�X��kG������l^w����������~㒶sy���Iu�!���� W ��X��N�7BV��O��!X�2����wvG�R�f�T#�����t�/?���%8�^�W�aT����G�cL�M���I��(J����1~�8�?aT ���]����AS�E��(��*E}� 2������#I/�׍qz��^t�̔���������b�Yz4x����t�){ OH�����+(E��A&�N�������XT��o��"�XC����'���)}�J�z�p� ����~5�}�^����+�6����w��c��Q�|�Lp�d�H��}�(�.|����k��c4^�����"�����Z?ȕ ��a<�������L�!0�39C� �Eu�����C�F�Ew�ç ;�n?�*o���B�8�bʝ���'#Rqf����M}7����]�������s2tcS{�\icTx;�\��7K���P������ʇ Z O-��~�������c>"��?��������P�����E��O�8��@�8��G��Q�g�a�Վ���󁶠��䧘��_%#r�>�����1�z�a���eb��qcP��ѵ��n���#L��� =��׀t� L�7�`�����V����A{�C:�g���e@�����w1 Xp�3�c3�ġ�������p��M"'-�@n4���fG���B3�DJ�8[Jo�ߐ���gK)ƛ��$���� �������8�3�����+���� �����6�ʻ���� ���S�kI�*KZlT _`�������?��K�����QK�d���������B`�s}�>���`������*�>��,*@J�d�oF*�����弝��O}�k��s��]��y�ߘ�������c1G�V���<=�7��7����6��q�PT��tXԀ�!9*4�4Tހ���3XΛex�46�������Y��D ����� ����BdemDa����\�_l,����G�/���֌7���Y�](�xTt^%�GE�����4�}bT����ڹ�����;��Y)���B�Q��u��>J/J ���⮶.�XԄ��j�ݳ������+E��d ���r�5�_D�����1 ���o�� �B�x�΢�#����<��W�����8���R6�@���g�M�.��� dr�D��>(otU��@�x=��~v���2� ӣ�d�oBd�����3�eO�6�㣷����������ݜ�6��6Y��Qz`����S��{���\P��~z m5{J/L��1������<�e�ͅPu���b�]�ϔ��������'�������f�b� Zpw��c`"��i���BD@:)ִ�:�]��h���v�E��w���T�l�������P����"Ju�}��وV ��J��G6��. J/�Qgl߭�e�����@�z�Zev2u����)]կ���������7x�������s�M�-<ɯ�c��r��v�����@��$�ޮ}lk���a����'����>x��O\�Z������Fu>������ck#��&:��`�$��ai�>2Δ����l���oF[h�������lE�ܺ�Π���k:)���`������� $[6�����9�����kOw�\|�����8}������ބ:��񶐕��������I�A1/���=�2[�,�!��.}gN#�u����b���� ~���������݊��}34q�����d�E��L��������c��$���"�[q�U�硬g^��%B ��z���r�p�������J�ru%v\h�����1Y�ne`������ǥ:g����pQM~�^��Xi� ��`S�:V2������9.�P���V������?B�k�� ��������AEvw%�_�9C�Q����wKekP�ؠ�\������;Io d�{ ߞo�c1eP�����\� `����E=���@K<�Y��������eڼ�J����w����{av�F�'�M�@��������������/J��+9p����|]���������Iw &`���8���&�M�hg���[�{�������Xj���%��Ӓ�������������������$��(�����ʹN�������<>�I���RY�����K2�NPlL�ɀ�)��&e��������B+ь����(������������������� � �JTx����_?EZ� }@���� 6�U���뙢ط�z��dWI��n` D����噥�[��uV��"�G&�����Ú����2�g�}&m���������������������?ċ���"����Om#�������������������������� ��{���������������������ON��"S�X���Ne��ysQ���@�������������Fn��Vg�����dX�~nj����������������������]J�<�K]:����FW���b�������62����������=��5f����JKw����bf�X������������������������55��~J �%^�������:�-�QIE��P��v�nZum� z � ~ə ���� ���ة����;�f��\v�������g�8�1��f2�������������������������4;�V���ǔ�)�������������������9���1\������������������������������c��v�/'Ƞ�w������������������$�4�R-��t����������������������������������� e�6�/�ġ �̕Ecy�J���u�B���<�W�ַ~�w[B1L۲�-JS΂�{���΃�������������������������������������������A��20�c#���������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������@���� 0!1@AP"#2Q`$3V�%45a6�FRUq����� ������^7ׅ,$n��������+��F�`��2X'��0vM��p�L=�������5��8������u�p~���.�`r�����\����O��,ư�0oS ��_�M�����l���4�kv\JSd���x���SW�<��Ae�IX����������$I���w�:S���y���›R��9�Q[���,�5�;�@]�%���u�@ *ro�lbI �� ��+���%m:�͇ZV�����u�̉����θau<�fc�.����{�4Ա� �Q����*�Sm��8\ujqs]{kN���)qO�y�_*dJ�b�7���yQqI&9�ԌK!�M}�R�;�������S�T���1���i[U�ɵz�]��U)V�S6���3$K{��ߊ<�(� E]Զ[ǼENg�����'�\?#)Dkf��J���o��v���'�%ƞ�&K�u��!��b�35LX�Ϸ��63$K�a�;�9>,R��W��3�3� d�JeTYE.Mϧ��-�o�j3+y��y^�c�������VO�9NV\nd�1 ��!͕_)a�v;����թ�M�lWR1��)El��P;��yوÏ�u 3�k�5Pr6<�⒲l�!˞*��u־�n�!�l:����UNW ��%��Chx8vL'��X�@��*��)���̮��ˍ��� ����D-M�+J�U�kvK����+�x8��cY������?�Ԡ��~3mo��|�u@[XeY�C�\Kp�x8�oC�C�&����N�~3-H���� ��MX�s�u<`���~"WL��$8ξ��3���a�)|:@�m�\���^�`�@ҷ)�5p+��6���p�%i)P M���ngc�����#0Aruz���RL+xSS?���ʮ}()#�t��mˇ!��0}}y����<�e� �-ή�Ԩ��X������ MF���ԙ~l L.3���}�V뽺�v������멬��Nl�)�2����^�Iq��a��M��qG��T�����c3#������3U�Ǎ���}��לS�|qa��ڃ�+���-��2�f����/��bz��ڐ�� �ݼ[2�ç����k�X�2�* �Z�d���J�G����M*9W���s{��w���T��x��y,�in�O�v��]���n����P�$��JB@=4�OTI�n��e�22a\����q�d���%�$��(���:���: /*�K[PR�fr\nڙdN���F�n�$�4��[�� U�zƶ����� �mʋ���,�ao�u 3�z� �x��Kn����\[��VFmbE;�_U��&V�Gg�]L�۪&#n%�$ɯ��dG���D�TI=�%+AB�Ru#��b4�1�»x�cs�YzڙJG��f��Il���d�eF'T� iA��T���uC�$����Y��H?����[!G`}���ͪ� �纤Hv\������j�Ex�K���!���OiƸ�Yj�+u-<���'q����uN�*�r\��+�]���<�wOZ.fp�ێ��,-*)V?j-kÊ#�`�r��dV����(�ݽBk�����G�ƛk�QmUڗe��Z���f}|����8�8��a���i��3'J�����~G_�^���d�8w������ R�`(�~�.��u���l�s+g�bv���W���lGc}��u���afE~1�Ue������Z�0�8�=e�� f@/�jqEKQQ�J���oN��J���W5~M>$6�Lt�;$ʳ{���^��6�{����v6���ķܰg�V�cnn �~z�x�«�,2�u�?cE+Ș�H؎�%�Za�)���X>uW�Tz�Nyo����s���FQƤ��$��*�&�LLXL)�1�" L��eO��ɟ�9=���:t��Z���c��Ž���Y?�ӭV�wv�~,Y��r�ۗ�|�y��GaF�����C�����.�+� ���v1���fήJ�����]�S��T��B��n5sW}y�$��~z�'�c ��8 ��� ,! �p��VN�S��N�N�q��y8z˱�A��4��*��'������2n<�s���^ǧ˭P�Jޮɏ�U�G�L�J�*#��<�V��t7�8����TĜ>��i}K%,���)[��z�21z ?�N�i�n1?T�I�R#��m-�����������������1����lA�`��fT5+��ܐ�c�q՝��ʐ��,���3�f2U�եmab��#ŠdQ�y>\��)�SLY����w#��.���ʑ�f��� ,"+�w�~�N�'�c�O�3F�������N<���)j��&��,-� �љ���֊�_�zS���TǦ����w�>��?�������n��U仆�V���e�����0���$�C�d���rP �m�׈e�Xm�Vu� �L��.�bֹ��� �[Դaզ���*��\y�8�Է:�Ez\�0�Kq�C b��̘��cө���Q��=0Y��s�N��S.����3.���O�o:���#���v7�[#߫ ��5�܎�L���Er4���9n��COWlG�^��0k�%<���ZB���aB_���������'=��{i�v�l�$�uC���mƎҝ{�c㱼�y]���W�i ��ߧc��m�H� m�"�"�����;Y�ߝ�Z�Ǔ�����:S#��|}�y�,/k�Ld� TA�(�AI$+I3��;Y*���Z��}|��ӧO��d�v��..#:n��f>�>���ȶI�TX��� 8��y����"d�R�|�)0���=���n4��6ⲑ�+��r<�O�܂~zh�z����7ܓ�HH�Ga롏���nCo�>������a ���~]���R���̲c?�6(�q�;5%� |�uj�~z8R�=X��I�V=�|{v�Gj\gc��q����z�؋%M�ߍ����1y��#��@f^���^�>N������#x#۹��6�Y~�?�dfPO��{��P�4��V��u1E1J �*|���%����JN��`eWu�zk M6���q t[�� ��g�G���v��WIG��u_ft����5�j�"�Y�:T��ɐ���*�;� e5���4����q$C��2d�}���� _S�L#m�Yp��O�.�C�;��c����Hi#֩%+) �Ӎ��ƲV���SYź��g |���tj��3�8���r|���V��1#;.SQ�A[���S������#���`n�+���$��$�I �P\[�@�s��(�ED�z���P��])8�G#��0B��[ى��X�II�q<��9�~[Z멜�Z�⊔IWU&A>�P~�#��dp<�?����7���c��'~���5 ��+$���lx@�M�dm��n<=e�dyX��?{�|Aef ,|n3�<~z�ƃ�uۧ�����P��Y,�ӥQ�*g�#먙R�\���;T��i,��[9Qi歉����c>]9�� ��"�c��P�� �Md?٥��If�ت�u��k��/����F��9�c*9��Ǎ:�ØF���z�n*�@|I�ށ9����N3{'��[�'ͬ�Ҳ4��#}��!�V� Fu��,�,mTIk���v C�7v���B�6k�T9��1�*l� '~��ƞF��lU��'�M ����][ΩũJ_�{�i�I�n��$����L�� j��O�dx�����kza۪��#�E��Cl����x˘�o�����V���ɞ�ljr��)�/,�߬h�L��#��^��L�ф�,íMƁe�̩�NB�L�����iL����q�}��(��q��6IçJ$�W�E$��:������=#����(�K�B����zђ <��K(�N�۫K�w��^O{!����)��H���>x�������lx�?>Պ�+�>�W���,Ly!_�D���Ō�l���Q�!�[ �S����J��1��Ɛ�Y}��b,+�Lo�x�ɓ)����=�y�oh�@�꥟/��I��ѭ=��P�y9��� �ۍYӘ�e+�p�Jnϱ?V\SO%�(�t� ���=?MR�[Ș�����d�/ ��n�l��B�7j� ��!�;ӥ�/�[-���A�>��dN�sLj ��,ɪv��=1c�.SQ�O3�U���ƀ�ܽ�E����������̻��9G�ϷD�7(�}��Ävӌ\��y�_0[w ���<΍>����a_��[0+�L��F.�޺��f�>oN�T����q;���y\��bՃ��y�jH�<|q-eɏ�_?_9+P���Hp$�����[ux�K w�Mw��N�ی'$Y2�=��q���KB��P��~�������Yul:�[<����F1�2�O���5=d����]Y�sw:���Ϯ���E��j,_Q��X��z`H1,#II ��d�wr��P˂@�ZJV����y$�\y�{}��^~���[:N����ߌ�U�������O��d�����ؾe��${p>G��3c���Ė�lʌ�� ת��[��`ϱ�-W����dg�I��ig2��� ��}s ��ؤ(%#sS@���~���3�X�nRG�~\jc3�v��ӍL��M[JB�T��s3}��j�Nʖ��W����;7���ç?=X�F=-�=����q�ߚ���#���='�c��7���ڑW�I(O+=:uxq�������������e2�zi+�kuG�R��������0�&e�n���iT^J����~\jy���p'dtG��s����O��3����9* �b#Ɋ�� p������[Bws�T�>d4�ۧs���nv�n���U���_�~,�v����ƜJ1��s�� �QIz���)�(lv8M���U=�;����56��G���s#�K���MP�=��LvyGd��}�VwWBF�'�à �?MH�U�g2�� ����!�p�7Q��j��ڴ����=��j�u��� Jn�A s���uM������e��Ɔ�Ҕ�!)�'��8Ϣ�ٔ���ޝ(��Vp���צ֖d=�IC�J�Ǡ{q������kԭ�߸���i��@K����u�|�p=..�*+����x�����z[Aqġ#s2a�Ɗ���RR�)*HRsi�~�a &f��M��P����-K�L@��Z��Xy�'x�{}��Zm+���:�)�) IJ�-i�u���� ���ܒH��'��L(7�y�GӜq���� j��� 6ߌg1�g�o���,kر���tY�?W,���p���e���f�OQS��!K�۟cҒA�|ս�j�>��=⬒��˧L[�� �߿2JaB~R��u�:��Q�] �0H~���]�7��Ƽ�I���(�}��cq '�ήET���q�?f�ab���ӥvr� �)o��-Q��_'����ᴎo��K������;��V���o��%���~OK ����*��b�f:���-ťIR��`B�5!RB@���ï�� �u �̯e\�_U�_������� g�ES��3��������QT��a�����x����U<~�c?�*�#]�MW,[8O�a�x��]�1bC|踤�P��lw5V%�)�{t�<��d��5���0i�XSU��m:��Z�┵�i�"��1�^B�-��P�hJ��&)O��*�D��c�W��vM��)����}���P��ܗ-q����\mmζZ-l@�}��a��E�6��F�@��&Sg@���ݚ�M����� ȹ 4����#p�\H����dYDo�H���"��\��..R�B�H�z_�/5˘����6��KhJR��P�mƶi�m���3��,#c�co��q�a)*P�t����R�m�k�7x�D�E�\Y�閣_X�<���~�)���c[[�BP����6�Yq���S��0����%_����;��Àv�~�| VS؇ ��'O0��F0��\���U�-�d@�����7�SJ*z��3n��y��P����O����������m�~�P�3|Y��ʉr#�C�<�G~�.,! ���bqx���h~0=��!ǫ�jy����l��O,�[B��~��|9��ٱ����Xly�#�i�B��g%�S��������tˋ���e���ې��\[d�t)��.+u�|1 ������#�~Oj����hS�%��i.�~X���I�H�m��0n���c�1uE�q��cF�RF�o���7� �O�ꮧ� ���ۛ{��ʛi5�rw?׌#Qn�TW��~?y$��m\�\o����%W� ?=>S�N@�� �Ʈ���R����N�)�r"C�:��:����� �����#��qb��Y�. �6[��2K����2u�Ǧ�HYR��Q�MV��� �G�$��Q+.>�����nNH��q�^��� ����q��mM��V��D�+�-�#*�U�̒ ���p욳��u:�������IB���m����PV@O���r[b= �� ��1U�E��_Nm�yKbN�O���U�}�the�`�|6֮P>�\2�P�V���I�D�i�P�O;�9�r�mAHG�W�S]��J*�_�G��+kP�2����Ka�Z���H�'K�x�W�MZ%�O�YD�Rc+o��?�q��Ghm��d�S�oh�\�D�|:W������UA�Qc yT�q��������~^�H��/��#p�CZ���T�I�1�ӏT����4��"�ČZ�����}��`w�#�*,ʹ�� ��0�i��課�Om�*�da��^gJ݅{���l�e9uF#T�ֲ��̲�ٞC"�q���ߍ ոޑ�o#�XZTp����@ o�8��(jd��xw�]�,f���`~��|,s��^����f�1���t��|��m�򸄭/ctr��5s��7�9Q�4�H1꠲BB@�l9@���C�����+�wp�xu�£Yc�9��?`@#�o�mH�s2��)�=��2�.�l����jg�9$�Y�S�%*L������R�Y������7Z���,*=�䷘$�������arm�o�ϰ���UW.|�r�uf����IGw�t����Zwo��~5 ��YյhO+=8fF�)�W�7�L9lM�̘·Y���֘YLf�큹�pRF���99.A �"wz��=E\Z���'a� 2��Ǚ�#;�'}�G���*��l��^"q��+2FQ� hj��kŦ��${���ޮ-�T�٭cf�|�3#~�RJ����t��$b�(R��(����r���dx� >U b�&9,>���%E\� Ά�e�$��'�q't��*�א���ެ�b��-|d���SB�O�O��$�R+�H�)�܎�K��1m`;�J�2�Y~9��O�g8=vqD`K[�F)k�[���1m޼c��n���]s�k�z$@��)!I �x՝"v��9=�ZA=`Ɠi �:�E��)`�7��vI��}d�YI�_ �o�:ob���o ���3Q��&D&�2=�� �Ά��;>�h����y.*ⅥS������Ӭ�+q&����j|UƧ�����}���J0��WW< ۋS�)jQR�j���Ư��rN)�Gű�4Ѷ(�S)Ǣ�8��i��W52���No˓� ۍ%�5brOn�L�;�n��\G����=�^U�dI���8$�&���h��'���+�(������cȁ߫k�l��S^���cƗjԌE�ꭔ��gF���Ȓ��@���}O���*;e�v�WV���YJ\�]X'5��ղ�k�F��b 6R�o՜m��i N�i�����>J����?��lPm�U��}>_Z&�KK��q�r��I�D�Չ~�q�3fL�:S�e>���E���-G���{L�6p�e,8��������QI��h��a�Xa��U�A'���ʂ���s�+טIjP�-��y�8ۈZ?J$��W�P� ��R�s�]��|�l(�ԓ��sƊi��o(��S0���Y� 8�T97.�����WiL��c�~�dxc�E|�2!�X�K�Ƙਫ਼�$((�6�~|d9u+�qd�^3�89��Y�6L�.I�����?���iI�q���9�)O/뚅����O���X��X�V��ZF[�یgQ�L��K1���RҖr@v�#��X�l��F���Нy�S�8�7�kF!A��sM���^rkp�jP�DyS$N���q���nxҍ!U�f�!eh�i�2�m����`�Y�I�9r�6� �TF���C}/�y�^���Η���5d�'��9A-��J��>{�_l+�`��A���[�'��յ�ϛ#w:݅�%��X�}�&�PSt�Q�"�-��\縵�/����$Ɨh�Xb�*�y��BS����;W�ջ_mc�����vt?2}1�;qS�d�d~u:2k5�2�R�~�z+|HE!)�Ǟl��7`��0�<�,�2*���Hl-��x�^����'_TV�gZA�'j� ^�2Ϊ��N7t�����?w�� �x1��f��Iz�C-Ȗ��K�^q�;���-W�DvT�7��8�Z�������� hK�(P:��Q- �8�n�Z���܃e貾�<�1�YT<�,�����"�6{�/ �?�͟��|1�:�#g��W�>$����d��J��d�B���=��jf[��%rE^��il:��B���x���Sּ�1հ��,�=��*�7 fcG��#q� �eh?��2�7�����,�!7x��6�n�LC�4x��},Geǝ�tC.��vS �F�43��zz\��;QYC,6����~;RYS/6���|2���5���v��T��i����������mlv��������&� �nRh^ejR�LG�f���? �ۉҬܦƩ��|��Ȱ����>3����!v��i�ʯ�>�v��オ�X3e���_1z�Kȗ\<������!�8���V��]��?b�k41�Re��T�q��mz��TiOʦ�Z��Xq���L������q"+���2ۨ��8}�&N7XU7Ap�d�X��~�׿��&4e�o�F��� �H�����O���č�c�� 懴�6���͉��+)��v;j��ݷ�� �UV�� i��� j���Y9GdÒJ1��詞�����V?h��l�����l�cGs�ځ�������y�Ac������\V3�? �� ܙg�>qH�S,�E�W�[�㺨�uch�⍸�O�}���a��>�q�6�n6�����N6�q��������N� ���! 1AQaq�0@����"2BRb�#Pr���3C`��Scst���$4D���%Td���� ?�����N����a��3��m���C���w��������xA�m�q�m����m������$����4n淿t'��C"w��zU=D�\R+w�p+Y�T�&�պ@��ƃ��3ޯ?�Aﶂ��aŘ���@-�����Q�=���9D��ռ�ѻ@��M�V��P��܅�G5�f�Y<�u=,EC)�<�Fy'�"�&�չ�X~f��l�KԆV��?�� �W�N����=(� �;���{�r����ٌ�Y���h{�١������jW����P���Tc�����X�K�r��}���w�R��%��?���E��m�� �Y�q|����\lEE4����r���}�lsI�Y������f�$�=�d�yO����p�����yBj8jU�o�/�S��?�U��*������ˍ�0�������u�q�m [�?f����a�� )Q�>����6#������� ?����0UQ����,IX���(6ڵ[�DI�MNލ�c&���υ�j\��X�R|,4��� j������T�hA�e��^���d���b<����n�� �즇�=!���3�^�`j�h�ȓr��jẕ�c�,ٞX����-����a�ﶔ���#�$��]w�O��Ӫ�1y%��L�Y<�wg#�ǝ�̗`�x�xa�t�w��»1���o7o5��>�m뭛C���Uƃߜ}�C���y1Xνm�F8�jI���]����H���ۺиE@I�i;r�8ӭ�����V�F�Շ| ��&?�3|x�B�MuS�Ge�=Ӕ�#BE5G������Y!z��_e��q�р/W>|-�Ci߇�t�1ޯќd�R3�u��g�=0 5��[?�#͏��q�cf���H��{ ?u�=?�?ǯ���}Z��z���hmΔ�BFTW�����<�q��(v� ��!��z���iW]*�J�V�z��gX֧A�q�&��/w���u�gYӘa���; �i=����g:��?2�dž6�ى�k�4�>�Pxs����}������G�9���3 ���)gG�R<>r h�$��'nc�h�P��Bj��J�ҧH� -��N1���N��?��~��}-q!=��_2hc�M��l�vY%UE�@|�v����M2�.Y[|y�"Eï��K�ZF,�ɯ?,q�?v�M 80jx�"�;�9vk�����+ ֧�� �ȺU��?�%�vcV��mA�6��Qg^M�����A}�3�nl� QRN�l8�kkn�'�����(��M�7m9و�q���%ޟ���*h$Zk"��$�9��: �?U8�Sl��,,|ɒ��xH(ѷ����Gn�/Q�4�P��G�%��Ա8�N��!� �&�7�;���eKM7�4��9R/%����l�c>�x;������>��C�:�����t��h?aKX�bhe�ᜋ^�$�Iհ �hr7%F$�E��Fd���t��5���+�(M6�t����Ü�UU|zW�=a�Ts�Tg������dqP�Q����b'�m���1{|Y����X�N��b �P~��F^F:����k6�"�j!�� �I�r�`��1&�-$�Bevk:y���#y�w��I0��x��=D�4��tU���P�ZH��ڠ底taP��6����b>�xa�����Q�#� WeF��ŮNj�p�J* mQ�N�����*I�-*�ȩ�F�g�3 �5��V�ʊ�ɮ�a��5F���O@{���NX��?����H�]3��1�Ri_u��������ѕ�� ����0��� F��~��:60�p�͈�S��qX#a�5>���`�o&+�<2�D����: �������ڝ�$�nP���*)�N�|y�Ej�F�5ټ�e���ihy�Z �>���k�bH�a�v��h�-#���!�Po=@k̆IEN��@��}Ll?j�O������߭�ʞ���Q|A07x���wt!xf���I2?Z��<ץ�T���cU�j��]���陎Ltl �}5�ϓ��$�,��O�mˊ�;�@O��jE��j(�ا,��LX���LO���Ц�90�O �.����a��nA���7������j4 ��W��_ٓ���zW�jcB������y՗+EM�)d���N�g6�y1_x��p�$Lv�:��9�"z��p���ʙ$��^��JԼ*�ϭ����o���=x�Lj�6�J��u82�A�H�3$�ٕ@�=Vv�]�'�qEz�;I˼��)��=��ɯ���x �/�W(V���p�����$ �m�������u�����񶤑Oqˎ�T����r��㠚x�sr�GC��byp�G��1ߠ�w e�8�$⿄����/�M{*}��W�]˷.�CK\�ުx���/$�WP�w���r� |i���&�}�{�X� �>��$-��l���?-z���g����lΆ���(F���h�vS*���b���߲ڡn,|)mrH[���a�3�ר�[1��3o_�U�3�TC�$��(�=�)0�kgP���� ��u�^=��4 �WYCҸ:��vQ�ר�X�à��tk�m,�t*��^�,�}D*�� �"(�I��9R����>`�`��[~Q]�#af��i6l��8���6�:,s�s�N6�j"�A4���IuQ��6E,�GnH��zS�HO�uk�5$�I�4��ؤ�Q9�@��C����wp��BGv[]�u�Ov����0I4���\��y�����Q�Ѹ��~>Z��8�T��a��q�ޣ;z��a���/��S��I:�ܫ_�|������>=Z����8:�S��U�I�J��"IY���8%b8���H��:�QO�6�;7�I�S��J��ҌAά3��>c���E+&jf$eC+�z�;��V����� �r���ʺ������my�e���aQ�f&��6�ND���.:��NT�vm�<- u���ǝ\MvZY�N�NT��-A�>jr!S��n�O 1�3�Ns�%�3D@���`������ܟ 1�^c<���� �a�ɽ�̲�Xë#�w�|y�cW�=�9I*H8�p�^(4���՗�k��arOcW�tO�\�ƍR��8����'�K���I�Q�����?5�>[�}��yU�ײ -h��=��% q�ThG�2�)���"ו3]�!kB��*p�FDl�A���,�eEi�H�f�Ps�����5�H:�Փ~�H�0Dت�D�I����h�F3�������c��2���E��9�H��5�zԑ�ʚ�i�X�=:m�xg�hd(�v����׊�9iS��O��d@0ڽ���:�p�5�h-��t�&���X�q�ӕ,��ie�|���7A�2���O%P��E��htj��Y1��w�Ѓ!����  ���� ࢽ��My�7�\�a�@�ţ�J ��4�Ȼ�F�@o�̒?4�wx��)��]�P��~�����u�����5�����7X ��9��^ܩ�U;Iꭆ 5 �������eK2�7(�{|��Y׎ �V��\"���Z�1� Z�����}��(�Ǝ"�1S���_�vE30>���p;� ΝD��%x�W�?W?v����o�^V�i�d��r[��/&>�~`�9Wh��y�;���R���� ;;ɮT��?����r$�g1�K����A��C��c��K��l:�'��3 c�ﳯ*"t8�~l��)���m��+U,z��`(��>yJ�?����h>��]��v��ЍG*�{`��;y]��I�T� ;c��NU�fo¾h���/$���|NS���1�S�"�H��V���T���4��uhǜ�]�v;���5�͠x��'C\�SBpl���h}�N����� A�Bx���%��ޭ�l��/����T��w�ʽ]D�=����K���ž�r㻠l4�S�O?=�k �M:� ��c�C�a�#ha���)�ѐxc�s���gP�iG���{+���x���Q���I= �� z��ԫ+ �8"�k�ñ�j=|����c ��y��CF��/���*9ж�h{ �?4�o� ��k�m�Q�N�x��;�Y��4膚�a�w?�6�>�e]�����Q�r�:����g�,i"�����ԩA��*M�<�G��b�if��l^M��5�� �Ҩ�{����6J��ZJ�����P�*�����Y���ݛu�_4�9�I8�7���������,^ToR���m4�H��?�N�S�ѕw��/S��甍�@�9H�S�T��t�ƻ���ʒU��*{Xs�@����f������֒Li�K{H�w^���������Ϥm�tq���s� ���ք��f:��o~s��g�r��ט� �S�ѱC�e]�x���a��) ���(b-$(�j>�7q�B?ӕ�F��hV25r[7 Y� }L�R��}����*sg+��x�r�2�U=�*'WS��ZDW]�WǞ�<��叓���{�$�9Ou4��y�90-�1�'*D`�c�^o?(�9��u���ݐ��'PI&� f�Jݮ�������:wS����jfP1F:X �H�9dԯ����˝[�_54 �}*;@�ܨ�� ð�yn�T���?�ןd�#���4rG�ͨ��H�1�|-#���Mr�S3��G�3�����)�.᧏3v�z֑��r����$G"�`j �1t��x0<Ɔ�Wh6�y�6��,œ�Ga��gA����y��b��)���h�D��ß�_�m��ü �gG;��e�v��ݝ�nQ� ��C����-�*��o���y�a��M��I�>�<���]obD��"�:���G�A��-\%LT�8���c�)��+y76���o�Q�#*{�(F�⽕�y����=���rW�\p���۩�c���A���^e6��K������ʐ�cVf5$�'->���ՉN"���F�"�UQ@�f��Gb~��#�&�M=��8�ט�JNu9��D��[̤�s�o�~������� G��9T�tW^g5y$b��Y'��س�Ǵ�=��U-2 #�MC�t(�i� �lj�@Q 5�̣i�*�O����s�x�K�f��}\��M{E�V�{�υ��Ƈ�����);�H����I��fe�Lȣr�2��>��W��I�Ȃ6������i��k�� �5�YOxȺ����>��Y�f5'��|��H+��98pj�n�.O�y�������jY��~��i�w'������l�;�s�2��Y��:'lg�ꥴ)o#'Sa�a�K��Z� �m��}�`169�n���"���x��I ��*+� }F<��cГ���F�P�������ֹ*�PqX�x۩��,� ��N�� �4<-����%����:��7����W���u�`����� $�?�I��&����o��o��`v�>��P��"��l���4��5'�Z�gE���8���?��[�X�7(��.Q�-��*���ތL@̲����v��.5���[��=�t\+�CNܛ��,g�SQnH����}*F�G16���&:�t��4ُ"A��̣��$�b �|����#rs��a�����T�� ]�<�j��B�S�('$�ɻ� �wP;�/�n��?�ݜ��x�F��yUn�~mL*-�������Xf�wd^�a�}��f�,=t�׵i�.2/wpN�Ep8�OР���•��R�FJ� 55TZ��T �ɭ�<��]��/�0�r�@�f��V��V����Nz�G��^���7hZi����k��3�,kN�e|�vg�1{9]_i��X5y7� 8e]�U����'�-2,���e"����]ot�I��Y_��n�(JҼ��1�O ]bXc���Nu�No��pS���Q_���_�?i�~�x h5d'�(qw52] ��'ޤ�q��o1�R!���`ywy�A4u���h<קy���\[~�4�\ X�Wt/� 6�����n�F�a8��f���z �3$�t(���q��q�x��^�XWeN'p<-v�!�{�(>ӽDP7��ո0�y)�e$ٕv�Ih'Q�EA�m*�H��RI��=:��� ���4牢) �%_iN�ݧ�l]� �Nt���G��H�L��� ɱ�g<���1V�,�J~�ٹ�"K��Q�� 9�HS�9�?@��k����r�;we݁�]I�!{ �@�G�[�"��`���J:�n]�{�cA�E����V��ʆ���#��U9�6����j�#Y�m\��q�e4h�B�7��C�������d<�?J����1g:ٳ���=Y���D�p�ц� ׈ǔ��1�]26؜oS�'��9�V�FVu�P�h�9�xc�oq�X��p�o�5��Ա5$�9W�V(�[Ak�aY錎qf;�'�[�|���b�6�Ck��)��#a#a˙��8���=äh�4��2��C��4tm^ �n'c����]GQ$[Wҿ��i���vN�{Fu ��1�gx��1┷���N�m��{j-,��x�� Ūm�ЧS�[�s���Gna���䑴�� x�p 8<������97�Q���ϴ�v�aϚG��Rt�Һ׈�f^\r��WH�JU�7Z���y)�vg=����n��4�_)y��D'y�6�]�c�5̪��\� �PF�k����&�c;��cq�$~T�7j ���nç]�<�g ":�to�t}�159�<�/�8������m�b�K#g'I'.W������6��I/��>v��\�MN��g���m�A�yQL�4u�Lj�j9��#44�t��l^�}L����n��R��!��t��±]��r��h6ٍ>�yҏ�N��fU�� ���� Fm@�8}�/u��jb9������he:A�y�ծw��GpΧh�5����l}�3p468��)U��d��c����;Us/�֔�YX�1�O2��uq�s��`hwg�r~�{ R��mhN��؎*q 42�*th��>�#���E����#��Hv�O����q�}������6�e��\�,Wk�#���X��b>��p}�դ��3���T5��†��6��[��@��P�y*n��|'f�֧>�lư΂�̺����SU�'*�q�p�_S�����M�� '��c�6������m�� ySʨ;M��r���Ƌ�m�Kxo,���Gm�P��A�G�:��i��w�9�}M(�^�V��$ǒ�ѽ�9���|���� �a����J�SQ�a���r�B;����}���ٻ֢�2�%U���c�#�g���N�a�ݕ�'�v�[�OY'��3L�3�;,p�]@�S��{ls��X�'���c�jw��k'a�.��}�}&�� �dP�*�bK=ɍ!����;3n�gΊU�ߴmt�'*{,=SzfD� A��ko~�G�aoq�_mi}#�m�������P�Xhύ�����mxǍ�΂���巿zf��Q���c���|kc�����?���W��Y�$���_Lv����l߶��c���`?����l�j�ݲˏ!V��6����U�Ђ(A���4y)H���p�Z_�x��>���e���R��$�/�`^'3qˏ�-&Q�=?��CFVR �D�fV�9��{�8g�������n�h�(P"��6�[�D���< E�����~0<@�`�G�6����Hг�cc�� �c�K.5��D��d�B���`?�XQ��2��ٿyqo&+�1^� DW�0�ꊩ���G�#��Q�nL3��c���������/��x ��1�1�[y�x�პCW��C�c�UĨ80�m�e�4.{�m��u���I=��f�����0QRls9���f���������9���~f�����Ǩ��a�"@�8���ȁ�Q����#c�ic������G��$���G���r/$W�(��W���V�"��m�7�[m�A�m����bo��D� j����۳� l���^�k�h׽����� ��#� iXn�v��eT�k�a�^Y�4�BN���ĕ���0������� !01@Q"2AaPq3BR�������?�����@4�Q�����T3,���㺠�W�[=JK�Ϟ���2�r^7��vc�:�9 �E�ߴ�w�S#d���Ix��u��:��Hp��9E!�� V 2;73|F��9Y���*ʬ�F��D����u&���y؟��^EA��A��(ɩ���^��GV:ݜDy�`��Jr29ܾ�㝉��[���E;Fzx��YG��U�e�Y�C���� ����v-tx����I�sם�Ę�q��Eb�+P\ :>�i�C'�;�����k|z�رn�y]�#ǿb��Q��������w�����(�r|ӹs��[�D��2v-%��@;�8<a���[\o[ϧw��I!��*0�krs)�[�J9^��ʜ��p1)� "��/_>��o��<1����A�E�y^�C��`�x1'ܣn�p��s`l���fQ��):�l����b>�Me�jH^?�kl3(�z:���1ŠK&?Q�~�{�ٺ�h�y���/�[��V�|6��}�KbX����mn[-��7�5q�94�������dm���c^���h� X��5��<�eޘ>G���-�}�دB�ޟ� ��|�rt�M��V+�]�c?�-#ڛ��^ǂ}���Lkr���O��u�>�-D�ry� D?:ޞ�U��ǜ�7�V��?瓮�"�#���r��չģVR;�n���/_� ؉v�ݶe5d�b9��/O��009�G���5n�W����JpA�*�r9�>�1��.[t���s�F���nQ� V 77R�]�ɫ8����_0<՜�IF�u(v��4��F�k�3��E)��N:��yڮe��P�`�1}�$WS��J�SQ�N�j��ٺ��޵�#l���ј(�5=��5�lǏmoW�v-�1����v,W�mn��߀$x�<����v�j(����c]��@#��1������Ǔ���o'��u+����;G�#�޸��v-lη��/(`i⣍Pm^����ԯ̾9Z��F��������n��1��� ��]�[��)�'�������:�֪�W��FC����� �B9،!?���]��V��A�Վ�M��b�w��G F>_DȬ0¤�#�QR�[V��kz���m�w�"��9ZG�7'[��=�Q����j8R?�zf�\a�=��O�U����*oB�A�|G���2�54 �p��.w7� �� ���&������ξxGHp� B%��$g�����t�Џ򤵍z���HN�u�Я�-�'4��0���;_���3������� !01"@AQa2Pq#3BR�������?����ʩca��en��^��8���<�u#��m*08r��y�N"�<�Ѳ0��@\�p��� �����Kv�D��J8�Fҽ� �f�Y��-m�ybX�NP����}�!*8t(�OqѢ��Q�wW�K��ZD��Δ^e��!� ��B�K��p~�����e*l}z#9ң�k���q#�Ft�o��S�R����-�w�!�S���Ӥß|M�l޶V��!eˈ�8Y���c�ЮM2��tk���� ������J�fS����Ö*i/2�����n]�k�\���|4yX�8��U�P.���Ы[���l��@"�t�<������5�lF���vU�����W��W��;�b�cД^6[#7@vU�xgZv��F�6��Q,K�v��� �+Ъ��n��Ǣ��Ft���8��0��c�@�!�Zq s�v�t�;#](B��-�nῃ~���3g������5�J�%���O������n�kB�ĺ�.r��+���#�N$?�q�/�s�6��p��a����a��J/��M�8��6�ܰ"�*������ɗud"\w���aT(����[��F��U՛����RT�b���n�*��6���O��SJ�.�ij<�v�MT��R\c��5l�sZB>F��<7�;EA��{��E���Ö��1U/�#��d1�a�n.1ě����0�ʾR�h��|�R��Ao�3�m3 ��%�� ���28Q�� ��y��φ���H�To�7�lW>����#i`�q���c����a��� �m,B�-j����݋�'mR1Ήt�>��V��p���s�0IbI�C.���1R�ea�����]H�6�����������4B>��o��](��$B���m�����a�!=���?�B� K�Ǿ+�Ծ"�n���K��*��+��[T#�{�E�J�S����Q�����s�5�:�U�\wĐ�f�3����܆&�)�����I���Ԇw��E T�lrTf6Q|R�h:��[K�� �z��c֧�G�C��%\��_�a��84��HcO�bi��ؖV��7H �)*ģK~Xhչ0��4?�0��� �E<���}3���#���u�?�� ��|g�S�6ꊤ�|�I#Hڛ� �ա��w�X��9��7���Ŀ%�SL��y6č��|�F�a 8���b���$�sק�h���b9RAu7�˨p�Č�_\*w��묦��F ����4D~�f����|(�"m���NK��i�S�>�$d7SlA��/�²����SL��|6N�}���S�˯���g��]6��; �#�.��<���q'Q�1|KQ$�����񛩶"�$r�b:���N8�w@��8$�� �AjfG|~�9F ���Y��ʺ��Bwؒ������M:I岎�G��`s�YV5����6��A �b:�W���G�q%l�����F��H���7�������Fsv7���k�� 403WebShell
403Webshell
Server IP : 103.30.72.248  /  Your IP : 216.73.216.61
Web Server : Microsoft-IIS/10.0
System : Windows NT WIN-CARKG80MF9A 10.0 build 17763 (Windows Server 2019) AMD64
User : IUSR ( 0)
PHP Version : 8.2.7
Disable Function : NONE
MySQL : OFF  |  cURL : ON  |  WGET : OFF  |  Perl : OFF  |  Python : OFF  |  Sudo : OFF  |  Pkexec : OFF
Directory :  C:/Windows/System32/en-US/

Upload File :
current_dir [ Writeable ] document_root [ Writeable ]

 

Command :


[ Back ]     

Current File : C:/Windows/System32/en-US//tdh.dll.mui
MZ����@���	�!�L�!This program cannot be run in DOS mode.

$�<ߵ�R���R���R�Ы����R�ЫP���R�Rich��R�PEL�!
�

��@ ��8.rdata�@@.rsrc� �@@	_��
T88	_��$��8.rdata8x.rdata$zzzdbg �.rsrc$01�#X�.rsrc$02 m���p2�E��hEďJ�-&G~����^�	_����0�H����������(��@��X��p��������������������0���H���`���x�	�	�	�	�	�	�	�			 	0	@	P	`	p	�	��#���$���*l�14�896�p?��,F�	��O���bL��m��:
�D��
������\��5�<�����|�w�MUICOUNTERS.XSD
EVENTS.XSDWINMETA.XML�����N��
�6�R�]��������:͕���MUIen-USNot found :  '%1'.+MessageId not found in string table : '%1'.%Duplicate string Id specified : '%1'.9For Provider '%1' attribute resourceFileName is required.8For Provider '%1' attribute messageFileName is required.SProvider '%1', parameter file name cannot be specified without a message file name.)Duplicate provider name specified : '%1'.0Duplicate provider GUID '%1' in provider : '%2'.+Duplicate provider symbol specified : '%1'.UInvalid value %1!u!(0x%1!x!) specified for level '%2'. Values 0 thru 15 are reserved.!Duplicate level name used : '%1'.:Duplicate level value %1!u!(0x%1!x!) used in level : '%2'.#Duplicate level symbol used : '%1'.JInvalid value %1!u!(0x%1!x!) specified for task '%2'. Value 0 is reserved. Duplicate task name used : '%1'.PA8Duplicate task value %1!u!(0x%1!x!) used in task : '%2'."Duplicate task symbol used : '%1'.-Duplicate event guid '%1' used for task '%2'.cInvalid value %1!u!(0x%1!x!) specified for opcode '%2'. Opcode values should be between 10 and 239."Duplicate opcode name used : '%1'.<Duplicate opcode value %1!u!(0x%1!x!) used in opcode : '%2'.$Duplicate opcode symbol used : '%1'.wInvalid value %1!u!(0x%1!x!) specified for channel '%2'. Values for user-defined channels should be between 16 and 255.]Channel '%1' is the 9th channel for this provider.  Only 8 channels allowed for one provider./Duplicate channel Id '%1' used in channel '%2'.GDuplicate channel name used : '%1'. Channel names are case-insensitive.<Duplicate channel value %1!u!(0x%1!x!) used in channel '%2'.4Duplicate channel symbol '%1' used for channel '%2'.@Duplicate property name : '%1' specified within template - '%2'.MFor property '%1', property '%2' referenced by attribute count was not found.OFor property '%1', property '%2' referenced by attribute length was not found..KFor property '%1', property '%2' referenced by attribute count is a struct.LFor property '%1', property '%2' referenced by attribute length is a struct.DFor property '%1', with inType win:Binary, length must be specified.>For property '%1', length is not allowed for the given inType.dFor event '%1', with Id %2!u!(0x%2!x!), too many keywords specified. Maximum keywords allowed is 48.LFor event '%1', Id %2!u!(0x%2!x!) was specified which is bigger than USHORT.FTwo events have the same Id %1!u!(0x%1!x!) and Version %2!u!(0x%2!x!).#Duplicate event symbol used : '%1'.jFor event '%1', with Id %2!u!(0x%2!x!), win:EventlogClassic keyword is not allowed with any other keyword.IFor event '%1', with Id %2!u!(0x%2!x!), version attribute is not allowed.IFor event '%1', with Id %2!u!(0x%2!x!), channel attribute is not allowed.HFor event '%1', with Id %2!u!(0x%2!x!), opcode attribute is not allowed.RFor keyword '%1', 'mask' attribute is invalid. One and only one bit should be set.TFor keyword '%1', with mask 0x%2!I64x!, mask bit can only be one of the low 48 bits."Duplicate keyword name used: '%1'.7Duplicate keyword mask 0x%1!I64x! used in keyword '%2'.3Duplicate keyword symbol '%1' used in keyword '%2'. Duplicate template Id '%1' used.aFailed to load msxml6.dll. Please ensure that MSXML 6.0 is installed on the system and try again. Failed to CoCreate Schema cache.*Failed trying to add schema file to cache.*Failed to add schema to schema collection.,Failed to set async property on DOMDocument.*Failed to query IXMLDOMDocument interface.FMSXML Schema Validation Error 0x%1!x!. At Line=%2!d!, Column=%3!d!, %4PA,OutType : '%1' is invalid for InType : '%2'.InType : '%1' not found.Duplicate map name used: '%1'.2Only one bit may be set in bit map : '%1' 0x%2!x!.�Automatic string Id generation logic can only support 16 event providers. Beyond that, string Ids must be explicitly assigned using <message> entries.�Duplicate message ID was specified - 0x%1!x!. This can happen when an auto-generated messageId conflicts with those explicitly specified using a <messageTable> or a .mc file.$Duplicate Filter Symbol used : '%1'.GTwo Filters have the same Id:%1!u!(0x%1!x!) and Version:%2!u!(0x%2!x!).OUserData not allowed for template with TId '%1', since it is a filter template.^Struct not allowed for property '%1' of template with TId '%2', since it is a filter template.]Array not allowed for property '%1' of template with TId '%2', since it is a filter template.PAJMap not allowed for template with TId '%1', since it is a filter template.iAttribute outType is required for property '%1' of template with TId '%2', since it is a filter template."Duplicate Filter Name used : '%1'.LRequired attribute 'chid' is missing for the channel element with name '%1'.OFor channel '%1', value of attribute 'access' is not a valid SDDL string: '%2'.IA <message> element has reference to a non-existent <string> entry: '%1'.BTwo <message> entries are referring the same <string> entry: '%1'.AFor Template with TId '%1', only one <binary> element is allowed..Two <message> entries have the same MId: '%1'.mFor event '%1', with Id %2!u!(0x%2!x!), attribute 'message' is required, since it logged to an Admin Channel.�For event '%1', with Id %2!u!(0x%2!x!), level must be specified and it should be one of Critical, Error, Warning, or Informational, since it is logged to an Admin Channel.1Two <message> entries have the same symbol: '%1'.EThe instrumentation node is either missing or in the wrong namespace.LFor <data> element '%1', the prefix of '%2' is not in the winmeta namespace.�For <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', attribute 'field' is not allowed, since provider is userMode.�For <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', attribute 'struct' is required, since provider is kernelMode.�For <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', attribute 'field' is required, since provider is kernelMode.xFor <counterSet> element '%1', under <provider> '%2', child element <structs> is required, since provider is kernelMode.yFor <counterSet> element '%1', under <provider> '%2', child element <structs> is not allowed, since provider is userMode.VFor <provider> element '%1', attribute symbol is required, since provider is userMode.[For <provider> element '%1', attribute symbol is not allowed, since provider is kernelMode.�For <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', 'id' cannot be greater than 63 since provider is kernelMode.�For <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', attribute 'aggregate' is not allowed since the parent counterSet has either single or multiple instances.For <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', attribute 'baseID' is required. Here is the list of counter types that require a baseID and the required types of their base counters:

  perf_average_bulk
  perf_average_timer
    Base: perf_average_base

  perf_100nsec_multi_timer
  perf_100nsec_multi_timer_inv
  perf_counter_multi_timer
  perf_counter_multi_timer_inv
    Base: perf_counter_multi_base

  perf_raw_fraction
    Base: perf_raw_base

  perf_large_raw_fraction
  perf_precision_system_timer
  perf_precision_100ns_timer
    Base: perf_large_raw_base

  perf_sample_fraction
    Base: perf_sample_base
QString table references not allowed. Please inline the value of the string: '%1'.7For Map '%1', duplicate value %2!u!(0x%2!x!) specified.5For Pattern Map '%1', duplicate value '%2' specified.�For template '%1', invalid Custom Xml specified. Custom Xml must have a top-level element and it should be in its own namespace.  Also, the value of property inserts should not be greater than the number of top-level properties in the template : %2.�The <events> node is either missing or in the wrong namespace. The <events> node must be present under <instrumentation> node and should be in the following namespace: 'http://schemas.microsoft.com/win/2004/08/events'.dFor property '%1', inType must be one of UInt8, UInt16, UInt32, or HexInt32, since map is specified.PAsFor property '%1', property '%2' referenced by attribute count must have inType UInt8, UInt16, UInt32, or HexInt32.[For property '%1', property '%2' referenced by attribute count cannot have attribute count.tFor property '%1', property '%2' referenced by attribute length must have inType UInt8, UInt16, UInt32, or HexInt32.]For property '%1', property '%2' referenced by attribute length cannot have attribute length.�For event '%1', with Id %2!u!(0x%2!x!), a property insert in the event message is referencing a non-existent property. Event only has %3!u! properties: '%4'.nFor event '%1', with Id %2!u!(0x%2!x!), format specification fields are not allowed in property inserts: '%3'.BLength of Channel Name must be between 1 and 256 characters: '%1'.�Invalid Channel Name: %1. Following characters are not allowed in a channel name: ascii value <31, double quote, '>','<','&','|','\',''',':','*', and '?'.CLength of Provider Name must be between 1 and 256 characters: '%1'.�Invalid Provider Name: %1. Following characters are not allowed in a Provider name: ascii value <31, double quote, '>','<','&','|','\',''',':','*', and '?'.!Failed to set selection language."Failed to set selection namespace.JFailed trying to parse file %1, and failed to retrieve reason for failure.*Unknown error 0x%1!x! received from msxml._This element is referenced by %1!u! other element(s). Please remove references before deleting.Specify a name for the map.~For <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', attributes 'perfTimeID' and 'perfFreqID' are required, and the counters referenced by those attributes should be of type perf_counter_large_rawcount. This rule applies to counters of following types:

  perf_counter_obj_time_queuelen_type
  perf_obj_time_timer
  perf_elapsed_time
  perf_precision_object_timer
iFor <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', attribute 'multiCounterID' is required, and the counter referenced by that attribute should be of type perf_counter_rawcount. This rule applies to following counter types: 

  perf_counter_multi_timer
  perf_counter_multi_timer_inv
  perf_100nsec_multi_timer
  perf_100nsec_multi_timer_inv
�Two providers have defined a channel with duplicate name : '%1'. A given channel name can only be defined by one provider, other providers should use <importChannel> element to refer an existing channel.�Two or more events logging to legacy 'System', 'Security' or 'Application' channels are referencing the same message string '%1'. Give each such event a unique message string.�String '%1' is given Id %2!u!(0x%2!x!) in a .mc file. Change the Id of this string to be the same as that of the event referencing this string, since the event is logging to 'System', 'Security' or 'Application' channel.�String '%1' is explicitly assigned Id %2!u!(0x%2!x!) using a <message> element. Change the Id of this string to be the same as that of the event referencing this string, since the event is logging to 'System', 'Security' or 'Application' channel.tFor event '%1', with Id %2!u!(0x%2!x!), since Opcode '%3' is local to Task '%4', event must reference the Task '%4'.nFor event '%1', with Id %2!u!(0x%2!x!), Opcode '%3' is local to Task '%4', but event is referencing Task '%5'.�For event '%1', with Id %2!u!(0x%2!x!), Opcode '%3' is global, and its value collides with that of local Opcode '%4' of the Task '%5' that the event is referencing.3Duplicate Id %1!u!(0x%1!x!) used in Counter : '%2'.*Duplicate Uri '%1' used in Counter : '%2'.;Duplicate Name '%1' used in Counter with Id %2!u!(0x%2!x!).-Duplicate Symbol '%1' used in Counter : '%2'..Duplicate Guid '%1' used in CounterSet : '%2'.-Duplicate Uri '%1' used in CounterSet : '%2'.&Duplicate CounterSet Name used : '%1'.PA0Duplicate Symbol '%1' used in CounterSet : '%2'.Map '%1' cannot be empty.7Missing Attribute 'id' on one of the <string> elements.6For String with Id '%1', attribute 'value' is missing.*Duplicate Counter Struct Name used : '%1'.uFor <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', BaseId value refers to a non-existent counter.yFor <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', PerfTimeId value refers to a non-existent counter.yFor <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', PerfFreqId value refers to a non-existent counter.}For <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', MultiCounterId value refers to a non-existent counter.sFor <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', BaseId is not allowed for this counter type.wFor <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', PerfTimeId is not allowed for this counter type.wFor <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', PerfFreqId is not allowed for this counter type.{For <counter> element with Id %1!u!(0x%1!x!), under <counterSet> '%2', MultiCounterId is not allowed for this counter type.�Failed to acquire Schema Version. This can be due to one of the following reasons:

1. The <counters> node is either missing or in the wrong namespace.
2. The <counters> node does not have the schemaVersion attribute.
3. The schemaVersion attribute value is a malformed floating point string.

If this is a legacy manifest and the error was received from ctrpp.exe,
run ctrpp.exe with -legacy switch. It is recommended to always use
ECMangen.exe to create counter manifests to ensure validity.PA�Unrecognized Counter manifest version. Highest major version supported is %1!u!. Try fixing the version or get the latest copy of the tool.ZAttribute 'resourceBase' is not allowed on <provider> element beginning schemaVersion 2.0.�For CounterSet '%1', bad nameID %2!u!(0x%2!x!) was specified. nameID attribute is required, and must be globally unique. In addition, Resource Ids in the file must be either all odd or all even.�For CounterSet '%1', bad descriptionID %2!u!(0x%2!x!) was specified. descriptionID attribute is required, and must be globally unique. In addition, Resource Ids in the file must be either all odd or all even.�For Counter '%1', bad nameID %2!u!(0x%2!x!) was specified. nameID attribute is required, and must be globally unique. In addition, Resource Ids in the file must be either all odd or all even.�For Counter '%1', bad descriptionID %2!u!(0x%2!x!) was specified. descriptionID attribute is required, and must be globally unique. In addition, Resource Ids in the file must be either all odd or all even.WInvalid task message for task '%1'. Insertion strings are not allowed in task messages.[Invalid opcode message for task '%1'. Insertion strings are not allowed in opcode messages.]Invalid channel message for task '%1'. Insertion strings are not allowed in channel messages.]Invalid keyword message for task '%1'. Insertion strings are not allowed in keyword messages.mString '%1' in the string table for locale '%2' does not exist in the string table for all the other locales.hInvalid Provider Name: %1. When controlGuid is specified, provider name must end with the provider guid.zFor event '%1', with Id %2!u!(0x%2!x!), the 'EventLogClassic' keyword cannot be used together with 'name' or 'attributes'.tFor template '%1', invalid tags specified. Tags is a 28-bit value, i.e. it must be less than 268435456 (0x10000000).tFor property '%1', invalid tags specified. Tags is a 28-bit value, i.e. it must be less than 268435456 (0x10000000).�4VS_VERSION_INFO��
cE
cE?�StringFileInfo�040904B0LCompanyNameMicrosoft Corporation^FileDescriptionEvent Trace Helper Libraryh$FileVersion10.0.17763.1 (WinBuild.160101.0800)0InternalNametdh.dll�.LegalCopyright� Microsoft Corporation. All rights reserved.@OriginalFilenametdh.dll.muij%ProductNameMicrosoft� Windows� Operating System>
ProductVersion10.0.17763.1DVarFileInfo$Translation	�<xs:schema targetNamespace="http://schemas.microsoft.com/win/2005/12/counters" elementFormDefault="qualified" xmlns:man="http://schemas.microsoft.com/win/2005/12/counters" xmlns:xs="http://www.w3.org/2001/XMLSchema">

  <xs:simpleType name="GUIDType">
    <xs:restriction base="xs:string">
      <xs:pattern value="\{[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}\}"/>
    </xs:restriction>
  </xs:simpleType>

  <xs:simpleType name="HexInt32Type">
    <xs:annotation>
      <xs:documentation>Hex 1-8 digits in size</xs:documentation>
    </xs:annotation>
    <xs:restriction base="xs:string">
      <xs:pattern value="0[xX][0-9A-Fa-f]{1,8}"/>
    </xs:restriction>
  </xs:simpleType>

  <xs:simpleType name="UInt32Type">
    <xs:annotation>
      <xs:documentation>Hex 1-8 digits in size or unsignedInt</xs:documentation>
    </xs:annotation>
    <xs:union memberTypes="xs:unsignedInt man:HexInt32Type"/>
  </xs:simpleType>

  <xs:simpleType name="CSymbolType">
    <xs:annotation>
      <xs:documentation>A Valid C Symbol or an empty string</xs:documentation>
    </xs:annotation>
    <xs:restriction base="xs:string">
      <xs:pattern value="()|([_a-zA-Z][_0-9a-zA-Z]*)"/>
    </xs:restriction>
  </xs:simpleType>

  <xs:complexType name="struct">
    <xs:simpleContent>
      <xs:extension base="xs:string">
        <xs:attribute name="name" type="man:CSymbolType" use="required"/>
        <xs:attribute name="type" type="man:CSymbolType" use="required"/>
      </xs:extension>
    </xs:simpleContent>
  </xs:complexType>

  <xs:complexType name="structs">
    <xs:choice minOccurs="1" maxOccurs="unbounded">
      <xs:element name="struct" type="man:struct"/>
    </xs:choice>
  </xs:complexType>
  
  <xs:complexType name="counterAttribute">
    <xs:simpleContent>
      <xs:extension base="xs:string">
        <xs:attribute name="name" use="required">
          <xs:simpleType>
            <xs:restriction base="xs:string">
              <xs:enumeration value="reference"/>
              <xs:enumeration value="noDisplay"/>
              <xs:enumeration value="noDigitGrouping"/>
              <xs:enumeration value="displayAsHex"/>
              <xs:enumeration value="displayAsReal"/>
            </xs:restriction>
          </xs:simpleType>
        </xs:attribute>
      </xs:extension>
    </xs:simpleContent>
  </xs:complexType>
  
  <xs:complexType name="counterAttributes">
    <xs:choice minOccurs="1" maxOccurs="5">
      <xs:element name="counterAttribute" type="man:counterAttribute"/>
    </xs:choice>
  </xs:complexType>
  
  <xs:complexType name="counter">
    <xs:choice minOccurs="0" maxOccurs="1">
      <xs:element name="counterAttributes" type="man:counterAttributes">
        <xs:key name="uniqueCounterAttributeName">
          <xs:annotation>
            <xs:documentation>
              Only five counterAttribute elements allowed, they should all be unique.
            </xs:documentation>
          </xs:annotation>
          <xs:selector xpath="./man:counterAttribute"/>
          <xs:field xpath="@name"/>
        </xs:key>
      </xs:element>
    </xs:choice>
    <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
    <xs:attribute name="id" type="man:UInt32Type" use="required"/>
    <xs:attribute name="uri" type="xs:anyURI" use="required"/>
    <xs:attribute name="name" use="optional">
      <xs:annotation>
        <xs:documentation>
            This attribute is required for schemaVersion &gt;= 2.0.
        </xs:documentation>
      </xs:annotation>
      <xs:simpleType>
        <xs:restriction base="xs:string">
          <xs:maxLength value="1023"/>
        </xs:restriction>
      </xs:simpleType>
    </xs:attribute>
    <xs:attribute name="nameID" type="man:UInt32Type" use="optional">
      <xs:annotation>
        <xs:documentation>
            Resource ID of the name string. This attribute is required
            for schemaVersion &gt;= 2.0. It is not allowed for older versions.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
    <xs:attribute name="description" type="xs:string" use="optional">
      <xs:annotation>
        <xs:documentation>
            This attribute is required for schemaVersion &gt;= 2.0.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
    <xs:attribute name="descriptionID" type="man:UInt32Type" use="optional">
      <xs:annotation>
        <xs:documentation>
            Resource ID of the description string. This attribute is required
            for schemaVersion &gt;= 2.0. It is not allowed for older versions.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
    <xs:attribute name="type" use="required">
      <xs:simpleType>
        <xs:restriction base="xs:string">
          <xs:enumeration value="perf_counter_counter"/>
          <xs:enumeration value="perf_counter_timer"/>
          <xs:enumeration value="perf_counter_queuelen_type"/>
          <xs:enumeration value="perf_counter_large_queuelen_type"/>
          <xs:enumeration value="perf_counter_100ns_queuelen_type"/>
          <xs:enumeration value="perf_counter_obj_time_queuelen_type"/>
          <xs:enumeration value="perf_counter_bulk_count"/>
          <xs:enumeration value="perf_counter_text"/>
          <xs:enumeration value="perf_counter_rawcount"/>
          <xs:enumeration value="perf_counter_large_rawcount"/>
          <xs:enumeration value="perf_counter_rawcount_hex"/>
          <xs:enumeration value="perf_counter_large_rawcount_hex"/>
          <xs:enumeration value="perf_sample_fraction"/>
          <xs:enumeration value="perf_sample_counter"/>
          <xs:enumeration value="perf_counter_timer_inv"/>
          <xs:enumeration value="perf_sample_base"/>
          <xs:enumeration value="perf_average_timer"/>
          <xs:enumeration value="perf_average_base"/>
          <xs:enumeration value="perf_average_bulk"/>
          <xs:enumeration value="perf_obj_time_timer"/>
          <xs:enumeration value="perf_100nsec_timer"/>
          <xs:enumeration value="perf_100nsec_timer_inv"/>
          <xs:enumeration value="perf_counter_multi_timer"/>
          <xs:enumeration value="perf_counter_multi_timer_inv"/>
          <xs:enumeration value="perf_counter_multi_base"/>
          <xs:enumeration value="perf_100nsec_multi_timer"/>
          <xs:enumeration value="perf_100nsec_multi_timer_inv"/>
          <xs:enumeration value="perf_raw_fraction"/>
          <xs:enumeration value="perf_large_raw_fraction"/>
          <xs:enumeration value="perf_raw_base"/>
          <xs:enumeration value="perf_large_raw_base"/>
          <xs:enumeration value="perf_elapsed_time"/>
          <xs:enumeration value="perf_counter_delta"/>
          <xs:enumeration value="perf_counter_large_delta"/>
          <xs:enumeration value="perf_precision_system_timer"/>
          <xs:enumeration value="perf_precision_100ns_timer"/>
          <xs:enumeration value="perf_precision_object_timer"/>
          <xs:enumeration value="perf_counter_composite"/>
        </xs:restriction>
      </xs:simpleType>
    </xs:attribute>
    <xs:attribute name="baseID" type="man:UInt32Type" use="optional"/>
    <xs:attribute name="detailLevel" use="required">
      <xs:simpleType>
        <xs:restriction base="xs:string">
          <xs:enumeration value="standard"/>
          <xs:enumeration value="advanced"/>
        </xs:restriction>
      </xs:simpleType>
    </xs:attribute>
    <xs:attribute name="defaultScale" use="optional" default="0">
      <xs:simpleType>
        <xs:restriction base="xs:integer">
          <xs:minInclusive value="-10"/>
          <xs:maxInclusive value="10"/>
        </xs:restriction>
      </xs:simpleType>
    </xs:attribute>
    <xs:attribute name="aggregate" use="optional">
      <xs:simpleType>
        <xs:restriction base="xs:string">
          <xs:enumeration value="sum"/>
          <xs:enumeration value="avg"/>
          <xs:enumeration value="max"/>
          <xs:enumeration value="min"/>
          <xs:enumeration value="undefined"/>
        </xs:restriction>
      </xs:simpleType>
    </xs:attribute>
    <xs:attribute name="perfTimeID" type="man:UInt32Type" use="optional"/>
    <xs:attribute name="perfFreqID" type="man:UInt32Type" use="optional"/>
    <xs:attribute name="multiCounterID" type="man:UInt32Type" use="optional"/>
    <xs:attribute name="struct" type="man:CSymbolType" use="optional">
      <xs:annotation>
        <xs:documentation>
          If providerType=userMode, required.
          If providerType=kernelMode, not allowed.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
    <xs:attribute name="field" type="man:CSymbolType" use="optional">
      <xs:annotation>
        <xs:documentation>
          If providerType=userMode, required.
          If providerType=kernelMode, not allowed.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
  </xs:complexType>

  <xs:complexType name="counterSet">
    <xs:sequence>
      <xs:element name="structs" type="man:structs" minOccurs="0" maxOccurs="1">
        <xs:annotation>
          <xs:documentation>
            If providerType=userMode, required.
            If providerType=kernelMode, not allowed.
          </xs:documentation>
        </xs:annotation>
      </xs:element>
      <xs:element name="counter" type="man:counter" minOccurs="1" maxOccurs="unbounded"/>
    </xs:sequence>
    <xs:attribute name="symbol" type="man:CSymbolType" use="required"/>
    <xs:attribute name="guid" type="man:GUIDType" use="required"/>
    <xs:attribute name="uri" type="xs:anyURI" use="required"/>
    <xs:attribute name="name" use="required">
      <xs:simpleType>
        <xs:restriction base="xs:string">
          <xs:maxLength value="1023"/>
        </xs:restriction>
      </xs:simpleType>
    </xs:attribute>
    <xs:attribute name="nameID" type="man:UInt32Type" use="optional">
      <xs:annotation>
        <xs:documentation>
            Resource ID of the name string. This attribute is required
            for schemaVersion &gt;= 2.0, and not allowed for older versions.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
    <xs:attribute name="description" use="required"/>
    <xs:attribute name="descriptionID" type="man:UInt32Type" use="optional">
      <xs:annotation>
        <xs:documentation>
            Resource ID of the description string. This attribute is required
            for schemaVersion &gt;= 2.0, and not allowed for older versions.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
    <xs:attribute name="instances" use="optional" default="single">
      <xs:simpleType>
        <xs:restriction base="xs:string">
          <xs:enumeration value="single"/>
          <xs:enumeration value="multiple"/>
          <xs:enumeration value="globalAggregate"/>
          <xs:enumeration value="multipleAggregate"/>
          <xs:enumeration value="globalAggregateHistory"/>
        </xs:restriction>
      </xs:simpleType>
    </xs:attribute>
  </xs:complexType>
  
  <xs:complexType name="provider">
    <xs:choice minOccurs="0" maxOccurs="unbounded">
        <xs:element name="counterSet" type="man:counterSet"/>
    </xs:choice>
    <xs:attribute name="symbol" type="man:CSymbolType" use="optional">
      <xs:annotation>
        <xs:documentation>
          Provider Symbol is required for User Mode providers.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
    <xs:attribute name="callback" use="optional" default="default">
      <xs:simpleType>
        <xs:restriction base="xs:string">
          <xs:enumeration value="custom"/>
          <xs:enumeration value="default"/>
        </xs:restriction>
      </xs:simpleType>
    </xs:attribute>
    <xs:attribute name="providerGuid" type="man:GUIDType" use="required"/>
    <xs:attribute name="applicationIdentity" type="xs:string" use="required"/>
    <xs:attribute name="providerType" use="optional" default="userMode">
      <xs:simpleType>
        <xs:restriction base="xs:string">
          <xs:enumeration value="userMode"/>
          <xs:enumeration value="kernelMode"/>
        </xs:restriction>
      </xs:simpleType>
    </xs:attribute>
    <xs:attribute name="providerName" type="xs:string" use="optional" default="Counters"/>
    <xs:attribute name="resourceBase" type="man:UInt32Type" use="optional">
      <xs:annotation>
        <xs:documentation>
            This attribute is not allowed for schemaVersion &gt;= 2.0.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
  </xs:complexType>
  
  <xs:complexType name="counters">
    <xs:choice minOccurs="1" maxOccurs="1">
      <xs:element name="provider" type="man:provider"/>
    </xs:choice>
    <xs:attribute name="schemaVersion" type="xs:string" use="required"/>
  </xs:complexType>
  
  <xs:element name="counters" type="man:counters">
    <xs:key name="uniqueCounterSetGUID">
      <xs:annotation>
        <xs:documentation>
          Counter Set GUID should be unique across the entire document. The
          counter set registration fails if the GUID is already registered.
          To update a counter set that is registered, you must first
          uninstall the counter set and register it again.
        </xs:documentation>
      </xs:annotation>
      <xs:selector xpath="./man:provider/man:counterSet"/>
      <xs:field xpath="@guid"/>
    </xs:key>
  </xs:element>
  
</xs:schema>
<xs:schema targetNamespace="http://schemas.microsoft.com/win/2004/08/events" elementFormDefault="qualified" xmlns:man="http://schemas.microsoft.com/win/2004/08/events" xmlns:xs="http://www.w3.org/2001/XMLSchema">
  <xs:simpleType name="GUIDType">
    <xs:annotation>
      <xs:documentation>
        A globally unique identifier in Registry format.
        e.g. {12345678-4321-ABCD-1234-9ABCDEF012345678}.
        Use GUIDGen.exe or UUIDGen.exe to create a GUID.
      </xs:documentation>
    </xs:annotation>
    <xs:restriction base="xs:string">
      <xs:pattern value="\{[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}\}"/>
    </xs:restriction>
  </xs:simpleType>
  <xs:simpleType name="CSymbolType">
    <xs:annotation>
      <xs:documentation>
        Symbol is used for code-generation. It should be a valid C Symbol or an empty string.
      </xs:documentation>
    </xs:annotation>
    <xs:restriction base="xs:string">
      <xs:pattern value="()|([_a-zA-Z][_0-9a-zA-Z]*)"/>
    </xs:restriction>
  </xs:simpleType>
  <xs:simpleType name="NamespaceType">
    <xs:annotation>
      <xs:documentation>
        Is used for code-generation on namespaces which should be valid C++ symbols.
        E.g. Namespace1._Namespace2.Namespace2
      </xs:documentation>
    </xs:annotation>
    <xs:restriction base="xs:string">
      <xs:pattern value="([_a-zA-Z][_0-9a-zA-Z]*\.)*[_a-zA-Z][_0-9a-zA-Z]*"/>
    </xs:restriction>
  </xs:simpleType>  
  <xs:simpleType name="HexInt8Type">
    <xs:annotation>
      <xs:documentation> Hex 1-2 digits in size</xs:documentation>
    </xs:annotation>
    <xs:restriction base="xs:string">
      <xs:pattern value="0[xX][0-9A-Fa-f]{1,2}"/>
    </xs:restriction>
  </xs:simpleType>
  <xs:simpleType name="HexInt16Type">
    <xs:annotation>
      <xs:documentation> Hex 1-4 digits in size</xs:documentation>
    </xs:annotation>
    <xs:restriction base="xs:string">
      <xs:pattern value="0[xX][0-9A-Fa-f]{1,4}"/>
    </xs:restriction>
  </xs:simpleType>
  <xs:simpleType name="HexInt32Type">
    <xs:annotation>
      <xs:documentation> Hex 1-8 digits in size</xs:documentation>
    </xs:annotation>
    <xs:restriction base="xs:string">
      <xs:pattern value="0[xX][0-9A-Fa-f]{1,8}"/>
    </xs:restriction>
  </xs:simpleType>
  <xs:simpleType name="HexInt64Type">
    <xs:annotation>
      <xs:documentation>Hex 1-16 digits in size.</xs:documentation>
    </xs:annotation>
    <xs:restriction base="xs:string">
      <xs:pattern value="0[xX][0-9A-Fa-f]{1,16}"/>
    </xs:restriction>
  </xs:simpleType>
  <xs:simpleType name="UInt8Type">
    <xs:annotation>
      <xs:documentation> Hex 1-2 digits in size or unsignedByte</xs:documentation>
    </xs:annotation>
    <xs:union memberTypes="xs:unsignedByte man:HexInt8Type"/>
  </xs:simpleType>
  <xs:simpleType name="UInt16Type">
    <xs:annotation>
      <xs:documentation> Hex 1-4 digits in size or unsignedShort</xs:documentation>
    </xs:annotation>
    <xs:union memberTypes="xs:unsignedShort man:HexInt16Type"/>
  </xs:simpleType>
  <xs:simpleType name="UInt32Type">
    <xs:annotation>
      <xs:documentation>UnsignedInt or Hex 1-8 digits in size.</xs:documentation>
    </xs:annotation>
    <xs:union memberTypes="xs:unsignedInt man:HexInt32Type"/>
  </xs:simpleType>
  <xs:simpleType name="UInt64Type">
    <xs:annotation>
      <xs:documentation> Hex 1-16 digits in size or unsignedLong</xs:documentation>
    </xs:annotation>
    <xs:union memberTypes="xs:unsignedLong man:HexInt64Type"/>
  </xs:simpleType>
  <xs:simpleType name="LengthType">
    <xs:annotation>
      <xs:documentation> Length property name string or unsignedShort</xs:documentation>
    </xs:annotation>
    <xs:union memberTypes="xs:unsignedShort xs:string"/>
  </xs:simpleType>
  <xs:simpleType name="CountType">
    <xs:annotation>
      <xs:documentation> Count property name string or unsignedShort</xs:documentation>
    </xs:annotation>
    <xs:union memberTypes="xs:unsignedShort xs:string"/>
  </xs:simpleType>

  <xs:simpleType name="strTableRef">
    <xs:annotation>
      <xs:documentation>
        Value of this attribute should be of the form $(string.stringTableId),
        where stringTableId is the 'id' attribute of a &lt;string&gt; element
        defined in the &lt;stringTable&gt; section. Or it could be of the form
        $(mc.mcSymbolId), where mcSymbolId is the symbol of a message string
        defined in a .mc file.
      </xs:documentation>
    </xs:annotation>
    <xs:restriction base="xs:string">
      <xs:pattern value="(\$\([Ss]tring\..*\))|(\$\([Mm][Cc]\..*\))"/>
    </xs:restriction>
  </xs:simpleType>

  <xs:simpleType name="filePath">
    <xs:annotation>
      <xs:documentation>
        A fully-qualified path to a file. Standard Windows environment variables are
        allowed. Typically, the file is of type .exe, .dll, or .sys.
      </xs:documentation>
    </xs:annotation>
    <xs:restriction base="xs:string">
    </xs:restriction>
  </xs:simpleType>

  <xs:complexType name="FilterType" mixed="true">
    <xs:simpleContent>
      <xs:extension base="xs:string">
        <xs:attribute name="value" type="man:UInt8Type" use="required"/>
        <xs:attribute name="version" type="man:UInt8Type" use="optional"/>
        <xs:attribute name="name" type="xs:QName" use="required"/>
        <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
        <xs:attribute name="message" type="man:strTableRef" use="optional"/>
        <xs:attribute name="tid" type="xs:token" use="optional"/>
      </xs:extension>
    </xs:simpleContent>
  </xs:complexType>

  <xs:complexType name="FilterListType" mixed="true">
    <xs:sequence>
      <xs:element name="filter" type="man:FilterType" minOccurs="0" maxOccurs="unbounded"/>
    </xs:sequence>
  </xs:complexType>

  <xs:complexType name="KeywordType" mixed="true">
    <xs:simpleContent>
      <xs:extension base="xs:string">
        <xs:attribute name="name" type="xs:QName" use="required">
          <xs:annotation>
            <xs:documentation>
              Each keyword must have a unique name, which is used to reference the keyword
              from the events section of the manifest.
            </xs:documentation>
          </xs:annotation>
        </xs:attribute>
        <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
        <xs:attribute name="mask" type="man:HexInt64Type" use="required">
          <xs:annotation>
            <xs:documentation>
              Mask is a 64-bit value, in which, only one bit is set. Mask value cannot be zero.
              Leftmost 16 bits of the mask are reserved for use by winmeta.xml.
            </xs:documentation>
          </xs:annotation>
        </xs:attribute>
        <xs:attribute name="message" type="man:strTableRef" use="optional"/>
        <xs:anyAttribute namespace="##other" processContents="lax"/>
      </xs:extension>
    </xs:simpleContent>
  </xs:complexType>

  <xs:complexType name="KeywordListType">
    <xs:annotation>
      <xs:documentation>
        Use keywords to group events together. At run-time, it is possible to enable
        events belonging to only certain groups (i.e. keywords). This is one way to
        filter out unwanted events at the time of logging.
      </xs:documentation>
    </xs:annotation>
    <xs:sequence>
      <xs:element name="keyword" type="man:KeywordType" minOccurs="0" maxOccurs="unbounded"/>
    </xs:sequence>
  </xs:complexType>

  <xs:complexType name="OpcodeType" mixed="true">
    <xs:simpleContent>
      <xs:extension base="xs:string">
        <xs:attribute name="name" type="xs:QName" use="required"/>
        <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
        <xs:attribute name="value" type="man:UInt8Type" use="required"/>
        <xs:attribute name="mofValue" type="man:UInt8Type" use="optional"/>
        <xs:attribute name="message" type="man:strTableRef" use="optional"/>
        <xs:anyAttribute namespace="##other" processContents="lax"/>
      </xs:extension>
    </xs:simpleContent>
  </xs:complexType>

  <xs:complexType name="OpcodeListType">
    <xs:annotation>
      <xs:documentation>
        Use opcodes, in conjunction with a task, to describe different milestones within
        an activity.
      </xs:documentation>
    </xs:annotation>
    <xs:sequence>
      <xs:element name="opcode" type="man:OpcodeType" minOccurs="0" maxOccurs="unbounded"/>
    </xs:sequence>
  </xs:complexType>

  <xs:complexType name="LevelType" mixed="true">
    <xs:simpleContent>
      <xs:extension base="xs:string">
        <xs:attribute name="name" type="xs:QName" use="required"/>
        <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
        <xs:attribute name="value" type="man:UInt8Type" use="required"/>
        <xs:attribute name="message" type="man:strTableRef" use="optional"/>
        <xs:anyAttribute namespace="##other" processContents="lax"/>
      </xs:extension>
    </xs:simpleContent>
  </xs:complexType>

  <xs:complexType name="LevelListType">
    <xs:annotation>
      <xs:documentation>
        Use levels to control the verbosity of events during logging. At run-time,
        a provider can be enabled with a certain level value, and only events with
        a level value less than or equal to the specified value will get logged.
      </xs:documentation>
    </xs:annotation>
    <xs:sequence>
      <xs:element name="level" type="man:LevelType" minOccurs="0" maxOccurs="unbounded"/>
    </xs:sequence>
  </xs:complexType>

  <xs:complexType name="TaskType" mixed="true">
    <xs:sequence>
        <xs:element name="opcodes" type="man:OpcodeListType" minOccurs="0"/>
    </xs:sequence>
    <xs:attribute name="name" type="xs:QName" use="required"/>
    <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
    <xs:attribute name="value" type="man:UInt16Type" use="required"/>
    <xs:attribute name="eventGUID" type="man:GUIDType" use="optional"/>
    <xs:attribute name="message" type="man:strTableRef" use="optional"/>
    <xs:anyAttribute namespace="##other" processContents="lax"/>
  </xs:complexType>

  <xs:complexType name="TaskListType">
    <xs:annotation>
      <xs:documentation>
        Use tasks to describe an activity. Use opcodes to describe each unit of work
        within an activity.
      </xs:documentation>
    </xs:annotation>
    <xs:sequence>
      <xs:element name="task" type="man:TaskType" minOccurs="0" maxOccurs="unbounded"/>
    </xs:sequence>
  </xs:complexType>

  <xs:complexType name="StringTableType">
    <xs:choice minOccurs="0" maxOccurs="unbounded">
      <xs:element name="string">
        <xs:complexType mixed="true">
          <xs:attribute name="id" type="xs:string" use="required"/>
          <xs:attribute name="value" type="xs:string" use="required"/>
          <xs:attribute name="stringType" type="xs:string" use="optional"/>
        </xs:complexType>
      </xs:element>
    </xs:choice>
    <xs:anyAttribute namespace="##other" processContents="lax"/>
  </xs:complexType>

  <xs:complexType name="ChannelLoggingType">
    <xs:annotation>
      <xs:documentation>Channel logging config</xs:documentation>
    </xs:annotation>
    <xs:sequence minOccurs="0">
      <xs:element name="autoBackup" type="xs:boolean" minOccurs="0"/>
      <xs:element name="retention" type="xs:boolean" default="false" minOccurs="0"/>
      <xs:element name="maxSize" type="man:UInt64Type" default="1048576" minOccurs="0"/>
      <xs:any namespace="##other" processContents="lax" minOccurs="0" maxOccurs="unbounded"/>
    </xs:sequence>
    <xs:anyAttribute namespace="##other" processContents="lax"/>
  </xs:complexType>

  <xs:complexType name="ChannelPublishingType">
    <xs:annotation>
      <xs:documentation>Channel publishing config</xs:documentation>
    </xs:annotation>
    <xs:sequence minOccurs="0">
      <xs:element name="level" type="man:UInt8Type" default="0" minOccurs="0"/>
      <xs:element name="keywords" type="man:UInt64Type" default="0" minOccurs="0"/>
      <xs:element name="controlGuid" type="man:GUIDType" minOccurs="0"/>
      <xs:element name="bufferSize" type="man:UInt32Type" minOccurs="0">
        <xs:annotation>
          <xs:documentation>Amount of memory allocated for the session buffers (KB)</xs:documentation>
        </xs:annotation>
      </xs:element>
      <xs:element name="fileMax" type="man:UInt32Type" minOccurs="0">
        <xs:annotation>
          <xs:documentation>Number of etl files to create across enablement</xs:documentation>
        </xs:annotation>
      </xs:element>
      <xs:element name="minBuffers" type="man:UInt32Type" minOccurs="0">
        <xs:annotation>
          <xs:documentation>Minimum number of session buffers</xs:documentation>
        </xs:annotation>
      </xs:element>
      <xs:element name="maxBuffers" type="man:UInt32Type" minOccurs="0">
        <xs:annotation>
          <xs:documentation>Maximum number of session buffers</xs:documentation>
        </xs:annotation>
      </xs:element>
      <xs:element name="latency" type="man:UInt32Type" minOccurs="0">
        <xs:annotation>
          <xs:documentation>Buffer flush interval (sec)</xs:documentation>
        </xs:annotation>
      </xs:element>
      <xs:element name="clockType" default="SystemTime" minOccurs="0">
        <xs:annotation>
          <xs:documentation>Clock resolution</xs:documentation>
        </xs:annotation>
        <xs:simpleType>
          <xs:restriction base="xs:string">
            <xs:enumeration value="SystemTime"/>
            <xs:enumeration value="QPC"/>
          </xs:restriction>
        </xs:simpleType>
      </xs:element>
      <xs:element name="sidType" minOccurs="0">
        <xs:simpleType>
          <xs:restriction base="xs:string">
            <xs:enumeration value="None"/>
            <xs:enumeration value="Publishing"/>
          </xs:restriction>
        </xs:simpleType>
      </xs:element>
      <xs:any namespace="##other" processContents="lax" minOccurs="0" maxOccurs="unbounded"/>
    </xs:sequence>
    <xs:anyAttribute namespace="##other" processContents="lax"/>
  </xs:complexType>

  <xs:complexType name="ChannelType" mixed="true">
    <xs:sequence>
      <xs:element name="logging" type="man:ChannelLoggingType" minOccurs="0"/>
      <xs:element name="publishing" type="man:ChannelPublishingType" minOccurs="0"/>
      <xs:any namespace="##other" processContents="lax" minOccurs="0" maxOccurs="unbounded"/>
    </xs:sequence>
    <xs:attribute name="name" type="xs:anyURI" use="required"/>
    <xs:attribute name="chid" type="xs:token" use="optional"/>
    <xs:attribute name="type" use="required">
      <xs:simpleType>
        <xs:restriction base="xs:string">
          <xs:enumeration value="Admin"/>
          <xs:enumeration value="Operational"/>
          <xs:enumeration value="Analytic"/>
          <xs:enumeration value="Debug"/>
        </xs:restriction>
      </xs:simpleType>
    </xs:attribute>
    <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
    <xs:attribute name="access" type="xs:string" use="optional"/>
    <xs:attribute name="isolation" use="optional">
      <xs:annotation>
        <xs:documentation>Default publishing session/security if not specified explicitly by the channel access attribute.</xs:documentation>
      </xs:annotation>
      <xs:simpleType>
        <xs:restriction base="xs:string">
          <xs:enumeration value="Application"/>
          <xs:enumeration value="System"/>
          <xs:enumeration value="Custom"/>
        </xs:restriction>
      </xs:simpleType>
    </xs:attribute>
    <xs:attribute name="enabled" type="xs:boolean" use="optional" default="false"/>
    <xs:attribute name="value" type="man:UInt8Type" use="optional"/>
    <xs:attribute name="message" type="man:strTableRef" use="optional"/>
    <xs:anyAttribute namespace="##other" processContents="lax"/>
  </xs:complexType>

  <xs:complexType name="ChannelListType">
    <xs:annotation>
      <xs:documentation>
        Use channels to describe the destinations for your events. Each channel you
        define here will show up in the Windows Event Viewer.
      </xs:documentation>
    </xs:annotation>
    <xs:choice minOccurs="0" maxOccurs="unbounded">
      <xs:element name="importChannel" type="man:ImportChannelType"/>
      <xs:element name="channel" type="man:ChannelType"/>
      <xs:any namespace="##other" processContents="lax"/>
    </xs:choice>
    <xs:anyAttribute namespace="##other"/>
  </xs:complexType>

  <xs:complexType name="DataDefinitionType" mixed="true">
    <xs:simpleContent>
      <xs:extension base="xs:string">
        <xs:attribute name="name" type="xs:string" use="required"/>
        <xs:attribute name="inType" type="xs:QName" use="required"/>
        <xs:attribute name="outType" type="xs:QName" use="optional"/>
        <xs:attribute name="map" type="xs:string" use="optional"/>
        <xs:attribute name="length" type="man:LengthType" use="optional"/>
        <xs:attribute name="count" type="man:CountType" use="optional"/>
        <xs:attribute name="tags" type="man:UInt32Type" use="optional">
          <xs:annotation>
            <xs:documentation>
              Tags is a 28-bit user-defined metadata value applied to this property. The
              event producer and consumer coordinate to define the semantics of the tags
              value. During event processing on Windows 10 Fall Creators Update (2017) or
              later, this value can be retrieved from the EVENT_PROPERTY_INFO Tags field.
            </xs:documentation>
          </xs:annotation>
        </xs:attribute>
        <xs:anyAttribute namespace="##other" processContents="lax"/>
      </xs:extension>
    </xs:simpleContent>
  </xs:complexType>

  <xs:complexType name="StructDefinitionType" mixed="true">
    <xs:sequence>
      <xs:element name="data" type="man:DataDefinitionType" maxOccurs="unbounded"/>
    </xs:sequence>
    <xs:attribute name="name" type="xs:string" use="required"/>
    <xs:attribute name="count" type="man:CountType" use="optional"/>
    <xs:attribute name="tags" type="man:UInt32Type" use="optional">
      <xs:annotation>
        <xs:documentation>
          Tags is a 28-bit user-defined metadata value applied to this property. The
          event producer and consumer coordinate to define the semantics of the tags
          value. During event processing on Windows 10 Fall Creators Update (2017) or
          later, this value can be retrieved from the EVENT_PROPERTY_INFO Tags field.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
    <xs:anyAttribute namespace="##other" processContents="lax"/>
  </xs:complexType>

  <xs:complexType name="XmlType">
    <xs:sequence>
      <xs:any namespace="##other" processContents="lax" minOccurs="0" maxOccurs="unbounded"/>
    </xs:sequence>
  </xs:complexType>

  <xs:complexType name="TemplateItemType">
    <xs:sequence maxOccurs="unbounded">
      <xs:choice minOccurs="0" maxOccurs="unbounded">
        <xs:element name="data" type="man:DataDefinitionType"/>
        <xs:element name="struct" type="man:StructDefinitionType"/>
      </xs:choice>
      <xs:element name="binary" minOccurs="0">
        <xs:annotation>
          <xs:documentation>Represents binary data in classic eventlog API</xs:documentation>
        </xs:annotation>
        <xs:complexType>
          <xs:attribute name="name" type="xs:string" use="optional"/>
        </xs:complexType>
      </xs:element>
      <xs:element name="UserData" type="man:XmlType" minOccurs="0"/>
    </xs:sequence>
    <xs:attribute name="tid" type="xs:token" use="required"/>
    <xs:attribute name="name" type="xs:string" use="optional"/>
    <xs:attribute name="tags" type="man:UInt32Type" use="optional">
      <xs:annotation>
        <xs:documentation>
          Tags is a 28-bit user-defined metadata value applied to each event that uses
          this template. The event producer and consumer coordinate to define the
          semantics of the tags value. During event processing on Windows 10 Fall
          Creators Update (2017) or later, this value can be retrieved from the
          TRACE_EVENT_INFO Tags field.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
    <xs:anyAttribute namespace="##other" processContents="lax"/>
  </xs:complexType>

  <xs:complexType name="TemplateListType">
    <xs:annotation>
      <xs:documentation>
        Use templates to describe the payload logged by an event. Different events can
        share a template.
      </xs:documentation>
    </xs:annotation>
    <xs:sequence>
      <xs:element name="template" type="man:TemplateItemType" minOccurs="0" maxOccurs="unbounded"/>
    </xs:sequence>
  </xs:complexType>

  <xs:complexType name="XmlTypeListType">
    <xs:sequence>
      <xs:element name="xmlType" minOccurs="0" maxOccurs="unbounded">
        <xs:complexType>
          <xs:complexContent>
            <xs:extension base="man:XmlType">
              <xs:attribute name="name" type="xs:QName" use="required"/>
              <xs:attribute name="value" type="xs:string" use="required"/>
              <xs:attribute name="symbol" type="man:CSymbolType" use="required"/>
            </xs:extension>
          </xs:complexContent>
        </xs:complexType>
      </xs:element>
    </xs:sequence>
  </xs:complexType>

  <xs:complexType name="OutputType">
    <xs:simpleContent>
      <xs:extension base="xs:string">
        <xs:attribute name="default" type="xs:boolean" use="optional"/>
        <xs:attribute name="xmlType" type="xs:QName" use="required"/>
      </xs:extension>
    </xs:simpleContent>
  </xs:complexType>

  <xs:complexType name="InputType">
    <xs:sequence>
      <xs:element name="description" type="xs:string"/>
      <xs:element name="outType" type="man:OutputType" minOccurs="0" maxOccurs="unbounded"/>
      <xs:any namespace="##other" processContents="lax" minOccurs="0" maxOccurs="unbounded"/>
    </xs:sequence>
    <xs:attribute name="name" type="xs:QName" use="required"/>
    <xs:attribute name="value" type="xs:string" use="required"/>
    <xs:attribute name="symbol" type="man:CSymbolType" use="required"/>
  </xs:complexType>

  <xs:complexType name="TypeListType">
    <xs:choice maxOccurs="unbounded">
      <xs:element name="xmlTypes" type="man:XmlTypeListType"/>
      <xs:element name="inTypes" type="man:InputTypeListType"/>
      <xs:any namespace="##other" processContents="lax" minOccurs="0"/>
    </xs:choice>
  </xs:complexType>

  <xs:complexType name="InputTypeListType">
    <xs:sequence>
      <xs:element name="inType" type="man:InputType" maxOccurs="unbounded"/>
    </xs:sequence>
  </xs:complexType>

  <xs:simpleType name="QNameList">
    <xs:list itemType="xs:QName"/>
  </xs:simpleType>

  <xs:complexType name="ImportChannelType" mixed="true">
    <xs:simpleContent>
      <xs:extension base="xs:string">
        <xs:attribute name="chid" type="xs:token" use="optional"/>
        <xs:attribute name="name" type="xs:anyURI" use="required"/>
        <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
      </xs:extension>
    </xs:simpleContent>
  </xs:complexType>

  <xs:complexType name="EventDefinitionType">
    <xs:simpleContent>
      <xs:extension base="xs:string">
        <xs:attribute name="value" type="man:UInt32Type" use="required">
          <xs:annotation>
            <xs:documentation>
              Also referred to as the Event-Id. A manifest-based ETW event is uniquely
              identified by the {Provider-Guid,Event-Id,Event-Version} tuple.
            </xs:documentation>
          </xs:annotation>
        </xs:attribute>
        <xs:attribute name="name" type="xs:string" use="optional">
          <xs:annotation>
            <xs:documentation>
              Non-localized event name. During event processing on Windows 10 Fall
              Creators Update (2017) or later, this value can be retrieved from the
              TRACE_EVENT_INFO EventNameOffset field.
            </xs:documentation>
          </xs:annotation>
        </xs:attribute>
        <xs:attribute name="attributes" type="xs:string" use="optional">
          <xs:annotation>
            <xs:documentation>
              Non-localized event attributes. This should be a semicolon-delimited list of
              name=value attributes associated with the event. During event processing on
              Windows 10 Fall Creators Update (2017) or later, this value can be retrieved
              from the TRACE_EVENT_INFO EventAttributesOffset field.

              Defined attributes include:
              FILE=Filename of source code associated with event;
              LINE=Line number of source code associated with event;
              COL=Column of source code associated with event;
              FUNC=Function name associated with event;
              MJ=Major component associated with event;
              MN=Minor component associated with event.
              Values containing semicolons or double-quotes should be quoted using
              double-quotes; double-quotes within the value should be doubled. Example:
              attributes='FILE=source.cpp;LINE=123;MJ="Value; ""Quoted"""'

              Note that most of these attributes are intended for use with tool-generated
              manifests and may not be appropriate for use with hand-maintained manifests. For
              example, the FILE ane LINE attributes are not generally appropriate for use in
              a hand-maintained manifest, since a single event might be emitted from multiple
              source code locations and the source code locations will change over time. The
              FILE and LINE attributes are intended for use in cases where the manifest is
              regenerated (with a new GUID) by a code generation tool each time the source
              code changes.
          </xs:documentation>
          </xs:annotation>
        </xs:attribute>
        <xs:attribute name="level" type="xs:QName" use="optional">
          <xs:annotation>
            <xs:documentation>
              Reference to a &lt;level&gt; element defined in the &lt;levels&gt; section.
              Refer to a level by its attribute 'name'.
            </xs:documentation>
          </xs:annotation>
        </xs:attribute>
        <xs:attribute name="template" type="xs:token" use="optional"/>
        <xs:attribute name="channel" type="xs:token" use="optional"/>
        <xs:attribute name="keywords" type="man:QNameList" use="optional"/>
        <xs:attribute name="task" type="xs:QName" use="optional"/>
        <xs:attribute name="opcode" type="xs:QName" use="optional"/>
        <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
        <xs:attribute name="version" type="man:UInt8Type" use="optional">
          <xs:annotation>
            <xs:documentation>
              Increment the version of an event if its template is modified.
            </xs:documentation>
          </xs:annotation>
        </xs:attribute>
        <xs:attribute name="message" type="man:strTableRef" use="optional"/>
        <xs:attribute name="notLogged" type="xs:boolean" use="optional" default="false">
          <xs:annotation>
            <xs:documentation>
              Use this to indicate that this event has been removed and will not be logged
              by this version of the provider. The description of the event should be retained
              in this manifest so that if an etl file collected from an older version of the
              provider on a different machine is brought to this machine, it can be correctly
              decoded on this machine.
            </xs:documentation>
          </xs:annotation>
        </xs:attribute>
        <xs:attribute name="suppressProjection" type="xs:boolean" use="optional" default="false">
          <xs:annotation>
            <xs:documentation>
              Use this to indicate if the template associated with this event contains 
              valid WinRT types i.e. the event payload fields can come from arguments
              of projected WinRT methods. Ignore this attribute if the component which
              is hosting the provider does not use WinRT projection APIs to log the event.
            </xs:documentation>
          </xs:annotation>
        </xs:attribute>            
      </xs:extension>
    </xs:simpleContent>
  </xs:complexType>

  <xs:complexType name="MapType">
    <xs:choice maxOccurs="unbounded">
      <xs:element name="valueMap" type="man:ValueMapType"/>
      <xs:element name="bitMap" type="man:BitMapType"/>
    </xs:choice>
  </xs:complexType>

  <xs:complexType name="ValueMapType">
    <xs:sequence>
      <xs:element name="map" type="man:ValueMapValueType" maxOccurs="unbounded"/>
    </xs:sequence>
    <xs:attribute name="name" type="xs:string" use="required"/>
    <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
  </xs:complexType>

  <xs:complexType name="ValueMapValueType" mixed="true">
    <xs:simpleContent>
      <xs:extension base="xs:string">
        <xs:attribute name="value" type="man:UInt32Type" use="required"/>
        <xs:attribute name="message" type="man:strTableRef" use="required"/>
        <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
      </xs:extension>
    </xs:simpleContent>
  </xs:complexType>

  <xs:complexType name="BitMapType">
    <xs:sequence>
      <xs:element name="map" type="man:BitMapValueType" maxOccurs="unbounded"/>
    </xs:sequence>
    <xs:attribute name="name" type="xs:string" use="required"/>
    <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
  </xs:complexType>

  <xs:complexType name="BitMapValueType" mixed="true">
    <xs:simpleContent>
      <xs:extension base="xs:string">
        <xs:attribute name="value" type="man:HexInt32Type" use="required"/>
        <xs:attribute name="message" type="man:strTableRef" use="required"/>
        <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
      </xs:extension>
    </xs:simpleContent>
  </xs:complexType>

  <xs:complexType name="NamedQueryType">
    <xs:sequence>
      <xs:element name="patternMaps" type="man:PatternMapListType" minOccurs="0"/>
      <xs:any namespace="##other" processContents="lax" minOccurs="0" maxOccurs="unbounded"/>
    </xs:sequence>
    <xs:anyAttribute namespace="##other" processContents="lax"/>
  </xs:complexType>

  <xs:complexType name="PatternMapListType">
    <xs:sequence>
      <xs:element name="patternMap" type="man:PatternMapType" maxOccurs="unbounded"/>
    </xs:sequence>
  </xs:complexType>

  <xs:complexType name="PatternMapType">
    <xs:sequence>
      <xs:element name="map" type="man:PatternMapValueType" maxOccurs="unbounded"/>
    </xs:sequence>
    <xs:attribute name="name" type="xs:QName" use="required"/>
    <xs:attribute name="format" type="xs:anyURI" use="required"/>
    <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
  </xs:complexType>

  <xs:complexType name="PatternMapValueType">
    <xs:simpleContent>
      <xs:extension base="xs:string">
        <xs:attribute name="name" type="xs:string" use="required"/>
        <xs:attribute name="value" type="xs:string" use="required"/>
      </xs:extension>
    </xs:simpleContent>
  </xs:complexType>

  <xs:complexType name="DefinitionType">
    <xs:annotation>
      <xs:documentation>
        List all events logged by the provider in this section.
      </xs:documentation>
    </xs:annotation>
    <xs:choice minOccurs="0" maxOccurs="unbounded">
      <xs:element name="event" type="man:EventDefinitionType"/>
    </xs:choice>
  </xs:complexType>

  <xs:complexType name="TraitsType">
    <xs:annotation>
      <xs:documentation>
        Specifies values for this provider's provider traits. The provider traits
        consist of a small binary blob that is registered with the ETW runtime via
        EventSetInformation and included with each call to EventWrite. The traits
        blob contains information about a provider's name, decode GUID, and group
        GUID.
        When provider traits are needed (i.e. when the provider has different values
        for its control GUID and its decode GUID or when the traits element is
        present), the MC tool's -um or -km codegen will generate a provider traits
        blob, will generate code to automatically register the blob as part of
        EventRegister, and will include the blob in each call to EventWrite.
      </xs:documentation>
    </xs:annotation>
    <xs:attribute name="includeName" type="xs:boolean" use="optional">
      <xs:annotation>
        <xs:documentation>
          Optional. Default is false. If true, the provider's name will be included
          in the provider traits. If false, the provider's name will be left blank
          to reduce the size of the trace file. Including the provider name makes it
          possible to filter an event by provider name.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
    <xs:attribute name="groupGuid" type="man:GUIDType" use="optional">
      <xs:annotation>
        <xs:documentation>
          Optional. Specifies that this provider is a member of the specified provider
          group. By default, the provider is not a member of any provider group.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
  </xs:complexType>

  <xs:complexType name="ProviderType">
    <xs:choice minOccurs="0" maxOccurs="unbounded">
      <xs:element name="channels" type="man:ChannelListType"/>
      <xs:element name="levels" type="man:LevelListType"/>
      <xs:element name="tasks" type="man:TaskListType"/>
      <xs:element name="opcodes" type="man:OpcodeListType"/>
      <xs:element name="keywords" type="man:KeywordListType"/>
      <xs:element name="maps" type="man:MapType"/>
      <xs:element name="namedQueries" type="man:NamedQueryType"/>
      <xs:element name="templates" type="man:TemplateListType"/>
      <xs:element name="events" type="man:DefinitionType"/>
      <xs:element name="filters" type="man:FilterListType"/>
      <xs:element name="traits" type="man:TraitsType"/>
      <xs:any namespace="##other" processContents="lax"/>
    </xs:choice>
    <xs:attribute name="name" type="xs:anyURI" use="required"/>
    <xs:attribute name="namespace" type="man:NamespaceType" use="optional"/>
    <xs:attribute name="guid" type="man:GUIDType" use="required"/>
    <xs:attribute name="controlGuid" type="man:GUIDType" use="optional">
      <xs:annotation>
        <xs:documentation>
          A manifest-based ETW provider has a decode GUID (used to locate the manifest)
          and a control GUID (used to enable the provider or filter events). Normally,
          the same GUID (the provider guid) is used for both decode and control.
          If distinct values are needed for the decode and control GUIDs, set the
          "guid" attribute to the decode GUID and set the "controlGuid" attribute to the
          control GUID. Note that to avoid provider name conflicts, if the controlGuid
          attribute is used, the provider name must end with the decode guid, e.g.

            guid="{54bab802-bb0b-4b4a-9ce9-7360a0120b3e}"
            name="MyProvider.54bab802bb0b4b4a9ce97360a0120b3e"
            controlGuid="{74d557d9-4a8e-4a3f-9a32-3f1a0eab71ba}"
  
          If a provider uses distinct decode and control GUIDs, the resulting traces may
          not decode properly when decoded on Windows versions prior to Windows 10
          Fall Creators Update (2017).

          (Note that distinct decode and control GUIDs are typically used to support
          tool-generated manifests and are generally unnecessary for hand-maintained
          manifests.)
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
    <xs:attribute name="resourceFileName" type="man:filePath" use="optional">
      <xs:annotation>
        <xs:documentation>
          Name of the executable file to which the provider's metadata resource is linked,
          usually the same as the provider's binary.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
    <xs:attribute name="messageFileName" type="man:filePath" use="optional">
      <xs:annotation>
        <xs:documentation>
          Name of the executable file to which the provider's localizable message resource
          is linked, usually the same as the provider's binary.
        </xs:documentation>
      </xs:annotation>
    </xs:attribute>
    <xs:attribute name="parameterFileName" type="man:filePath" use="optional"/>
    <xs:attribute name="helpLink" type="xs:anyURI" use="optional"/>
    <xs:attribute name="symbol" type="man:CSymbolType" use="required"/>
    <xs:attribute name="message" type="man:strTableRef" use="optional"/>
    <xs:attribute name="source" use="optional" default="Xml">
      <xs:simpleType>
        <xs:restriction base="xs:string">
          <xs:enumeration value="Xml"/>
          <xs:enumeration value="Wbem"/>
        </xs:restriction>
      </xs:simpleType>
    </xs:attribute>
    <xs:attribute name="warnOnApplicationCompatibilityError" type="xs:boolean" use="optional" default="false"/>
    <xs:anyAttribute namespace="##other" processContents="lax"/>
  </xs:complexType>

  <xs:complexType name="MetadataType">
    <xs:sequence>
      <xs:element name="channels" type="man:ChannelListType"/>
      <xs:element name="levels" type="man:LevelListType"/>
      <xs:element name="tasks" type="man:TaskListType"/>
      <xs:element name="opcodes" type="man:OpcodeListType" minOccurs="0"/>
      <xs:element name="keywords" type="man:KeywordListType" minOccurs="0"/>
      <xs:element name="types" type="man:TypeListType" minOccurs="0"/>
      <xs:element name="namedQueries" type="man:NamedQueryType" minOccurs="0"/>
      <xs:element name="messageTable" minOccurs="0">
        <xs:complexType>
          <xs:sequence>
            <xs:element name="message" minOccurs="0" maxOccurs="unbounded">
              <xs:complexType>
                <xs:attribute name="value" type="man:UInt32Type" use="required"/>
                <xs:attribute name="mid" type="xs:string" use="optional"/>
                <xs:attribute name="message" type="man:strTableRef" use="required"/>
                <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
              </xs:complexType>
            </xs:element>
          </xs:sequence>
        </xs:complexType>
      </xs:element>
      <xs:any namespace="##other" processContents="lax" minOccurs="0" maxOccurs="unbounded"/>
    </xs:sequence>
    <xs:attribute name="name" type="xs:anyURI" use="required"/>
    <xs:anyAttribute namespace="##other" processContents="lax"/>
  </xs:complexType>

  <xs:complexType name="LocalizationType">
    <xs:choice minOccurs="0" maxOccurs="unbounded">
      <xs:element name="resources">
        <xs:complexType>
          <xs:choice minOccurs="0" maxOccurs="unbounded">
            <xs:element name="stringTable" type="man:StringTableType"/>
          </xs:choice>
          <xs:attribute name="culture" type="xs:string" use="required"/>
          <xs:anyAttribute namespace="##other" processContents="lax"/>
        </xs:complexType>
      </xs:element>
      <xs:any namespace="##other" processContents="lax"/>
    </xs:choice>
    <xs:attribute name="fallbackCulture" type="xs:string" use="optional" default="en-us"/>
    <xs:anyAttribute namespace="##other" processContents="lax"/>
  </xs:complexType>

  <xs:complexType name="EventsType">
    <xs:choice maxOccurs="unbounded">
      <xs:element name="provider" type="man:ProviderType"/>
      <xs:element name="messageTable" minOccurs="0">
        <xs:complexType>
          <xs:sequence>
            <xs:element name="message" minOccurs="0" maxOccurs="unbounded">
              <xs:complexType>
                <xs:attribute name="value" type="xs:string" use="required"/>
                <xs:attribute name="mid" type="xs:string" use="optional"/>
                <xs:attribute name="message" type="man:strTableRef" use="required"/>
                <xs:attribute name="symbol" type="man:CSymbolType" use="optional"/>
              </xs:complexType>
            </xs:element>
          </xs:sequence>
        </xs:complexType>
      </xs:element>
      <xs:any namespace="##other" processContents="lax" minOccurs="0"/>
    </xs:choice>
    <xs:anyAttribute namespace="##other"/>
  </xs:complexType>

  <xs:complexType name="InstrumentationType">
    <xs:choice minOccurs="0" maxOccurs="unbounded">
      <xs:element name="events" type="man:EventsType"/>
      <xs:any namespace="##other" processContents="lax" minOccurs="0" maxOccurs="unbounded"/>
    </xs:choice>
    <xs:anyAttribute namespace="##other" processContents="lax"/>
  </xs:complexType>

  <xs:complexType name="InstrumentationManifestType"/>

  <xs:element name="instrumentationManifest">
    <xs:complexType>
      <xs:complexContent>
        <xs:extension base="man:InstrumentationManifestType">
          <xs:choice maxOccurs="3">
            <xs:choice>
              <xs:element name="metadata" type="man:MetadataType"/>
              <xs:element name="instrumentation" type="man:InstrumentationType"/>
            </xs:choice>
            <xs:element name="localization" type="man:LocalizationType"/>
            <xs:any namespace="##other" processContents="lax" minOccurs="0" maxOccurs="unbounded"/>
          </xs:choice>
        </xs:extension>
      </xs:complexContent>
    </xs:complexType>
  </xs:element>
  <xs:element name="events" type="man:EventsType"/>

</xs:schema>
<instrumentationManifest xmlns="http://schemas.microsoft.com/win/2004/08/events" xmlns:win="http://manifests.microsoft.com/win/2004/08/windows/events" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://schemas.microsoft.com/win/2004/08/events eventman.xsd">
    <metadata name="evt:meta/winTypes">
        <channels>
            <channel name="TraceClassic" type="Debug" symbol="WINEVENT_CHANNEL_CLASSIC_TRACE" value="0" message="$(string.channel.TraceClassic)">
              Events for Classic ETW tracing.
            </channel>
            <channel name="System" type="Admin" symbol="WINEVENT_CHANNEL_GLOBAL_SYSTEM" isolation="System" value="8" message="$(string.channel.System)">
              Events for all installed system services.  This channel is secured to applications running under
              system service accounts or user applications running under local adminstrator privileges.
            </channel>
            <channel name="Application" type="Admin" symbol="WINEVENT_CHANNEL_GLOBAL_APPLICATION" isolation="Application" value="9" message="$(string.channel.Application)">
              Events for all user-level applications.  This channel is not secured and open to any applications.
              Applications which log extensive information should define an application-specific channel.
            </channel>
            <channel name="Security" type="Admin" symbol="WINEVENT_CHANNEL_GLOBAL_SECURITY" isolation="System" value="10" message="$(string.channel.Security)">
              The Windows Audit Log.  For exclusive use of the Windows Local Security Authority.  User events
              may appear as audits if supported by the underlying application.
            </channel>
            <channel name="TraceLogging" type="Debug" symbol="WINEVENT_CHANNEL_TRACELOGGING" value="11" message="$(string.channel.TraceLogging)">
              Event contains provider traits and TraceLogging event metadata.
            </channel>
            <channel name="ProviderMetadata" type="Debug" symbol="WINEVENT_CHANNEL_PROVIDERMETADATA" value="12" message="$(string.channel.ProviderMetadata)">
              Event contains provider traits.
            </channel>
        </channels>

        <!-- Standard Windows system reporting levels -->
        <levels>
            <level name="win:LogAlways" symbol="WINEVENT_LEVEL_LOG_ALWAYS" value="0" message="$(string.level.LogAlways)"> Log Always </level>
            <level name="win:Critical" symbol="WINEVENT_LEVEL_CRITICAL" value="1" message="$(string.level.Critical)"> Only critical errors </level>
            <level name="win:Error" symbol="WINEVENT_LEVEL_ERROR" value="2" message="$(string.level.Error)"> All errors, includes win:Critical </level>
            <level name="win:Warning" symbol="WINEVENT_LEVEL_WARNING" value="3" message="$(string.level.Warning)"> All warnings, includes win:Error </level>
            <level name="win:Informational" symbol="WINEVENT_LEVEL_INFO" value="4" message="$(string.level.Informational)"> All informational content, including win:Warning </level>
            <level name="win:Verbose" symbol="WINEVENT_LEVEL_VERBOSE" value="5" message="$(string.level.Verbose)"> All tracing, including previous levels </level>

            <!-- The following are unused.  They are place holders so that users dont accidentally use those values in their own definitions -->
            <level name="win:ReservedLevel6" symbol="WINEVENT_LEVEL_RESERVED_6" value="6"/>
            <level name="win:ReservedLevel7" symbol="WINEVENT_LEVEL_RESERVED_7" value="7"/>
            <level name="win:ReservedLevel8" symbol="WINEVENT_LEVEL_RESERVED_8" value="8"/>
            <level name="win:ReservedLevel9" symbol="WINEVENT_LEVEL_RESERVED_9" value="9"/>
            <level name="win:ReservedLevel10" symbol="WINEVENT_LEVEL_RESERVED_10" value="10"/>
            <level name="win:ReservedLevel11" symbol="WINEVENT_LEVEL_RESERVED_11" value="11"/>
            <level name="win:ReservedLevel12" symbol="WINEVENT_LEVEL_RESERVED_12" value="12"/>
            <level name="win:ReservedLevel13" symbol="WINEVENT_LEVEL_RESERVED_13" value="13"/>
            <level name="win:ReservedLevel14" symbol="WINEVENT_LEVEL_RESERVED_14" value="14"/>
            <level name="win:ReservedLevel15" symbol="WINEVENT_LEVEL_RESERVED_15" value="15"/>
            <!-- End of reserved values -->
        </levels>

        <!-- Standard Windows system tasks -->
        <tasks>
            <task name="win:None" value="0" symbol="WINEVENT_TASK_NONE" message="$(string.task.None)"> undefined task </task>
        </tasks>

        <!-- Standard Windows system opcodes -->
        <opcodes>
            <opcode name="win:Info" value="0" symbol="WINEVENT_OPCODE_INFO" message="$(string.opcode.Info)"> An informational event </opcode>
            <opcode name="win:Start" value="1" symbol="WINEVENT_OPCODE_START" message="$(string.opcode.Start)"> An activity start event </opcode>
            <opcode name="win:Stop" value="2" symbol="WINEVENT_OPCODE_STOP" message="$(string.opcode.Stop)"> An activity end event </opcode>
            <opcode name="win:DC_Start" value="3" symbol="WINEVENT_OPCODE_DC_START" message="$(string.opcode.DCStart)"> A trace collection start event </opcode>
            <opcode name="win:DC_Stop" value="4" symbol="WINEVENT_OPCODE_DC_STOP" message="$(string.opcode.DCStop)"> A trace collection end event </opcode>
            <opcode name="win:Extension" value="5" symbol="WINEVENT_OPCODE_EXTENSION" message="$(string.opcode.Extension)"> An extensional event </opcode>
            <opcode name="win:Reply" value="6" symbol="WINEVENT_OPCODE_REPLY" message="$(string.opcode.Reply)"> A reply event </opcode>
            <opcode name="win:Resume" value="7" symbol="WINEVENT_OPCODE_RESUME" message="$(string.opcode.Resume)"> An event representing the activity resuming from the suspension </opcode>
            <opcode name="win:Suspend" value="8" symbol="WINEVENT_OPCODE_SUSPEND" message="$(string.opcode.Suspend)"> An event representing the activity is suspended, pending another activity's completion </opcode>
            <opcode name="win:Send" value="9" symbol="WINEVENT_OPCODE_SEND" message="$(string.opcode.Send)"> An event representing the activity is transferred to another component, and can continue to work </opcode>

            <!-- The following are unused.  They are place holders so that users dont accidentally use those values in their own definitions -->
            <opcode name="win:Receive" value="240" symbol="WINEVENT_OPCODE_RECEIVE" message="$(string.opcode.Receive)"> An event representing receiving an activity transfer from another component </opcode>
            <opcode name="win:ReservedOpcode241" symbol="WINEVENT_OPCODE_RESERVED_241" value="241"/>
            <opcode name="win:ReservedOpcode242" symbol="WINEVENT_OPCODE_RESERVED_242" value="242"/>
            <opcode name="win:ReservedOpcode243" symbol="WINEVENT_OPCODE_RESERVED_243" value="243"/>
            <opcode name="win:ReservedOpcode244" symbol="WINEVENT_OPCODE_RESERVED_244" value="244"/>
            <opcode name="win:ReservedOpcode245" symbol="WINEVENT_OPCODE_RESERVED_245" value="245"/>
            <opcode name="win:ReservedOpcode246" symbol="WINEVENT_OPCODE_RESERVED_246" value="246"/>
            <opcode name="win:ReservedOpcode247" symbol="WINEVENT_OPCODE_RESERVED_247" value="247"/>
            <opcode name="win:ReservedOpcode248" symbol="WINEVENT_OPCODE_RESERVED_248" value="248"/>
            <opcode name="win:ReservedOpcode249" symbol="WINEVENT_OPCODE_RESERVED_249" value="249"/>
            <opcode name="win:ReservedOpcode250" symbol="WINEVENT_OPCODE_RESERVED_250" value="250"/>
            <opcode name="win:ReservedOpcode251" symbol="WINEVENT_OPCODE_RESERVED_251" value="251"/>
            <opcode name="win:ReservedOpcode252" symbol="WINEVENT_OPCODE_RESERVED_252" value="252"/>
            <opcode name="win:ReservedOpcode253" symbol="WINEVENT_OPCODE_RESERVED_253" value="253"/>
            <opcode name="win:ReservedOpcode254" symbol="WINEVENT_OPCODE_RESERVED_254" value="254"/>
            <opcode name="win:ReservedOpcode255" symbol="WINEVENT_OPCODE_RESERVED_255" value="255"/>
            <!-- End of reserved values -->
        </opcodes>

        <!-- Standard Windows system keywords -->
        <keywords>
            <keyword name="win:AnyKeyword" mask="0x0" symbol="WINEVT_KEYWORD_ANY" message="$(string.keyword.AnyKeyword)">
                 Wild card value
            </keyword>

            <keyword name="win:ResponseTime" mask="0x1000000000000" symbol="WINEVENT_KEYWORD_RESPONSE_TIME" message="$(string.keyword.ResponseTime)">
                 Attached to all events providing response time information
            </keyword>
            <keyword name="win:ReservedKeyword49" mask="0x2000000000000" symbol="WINEVENT_KEYWORD_RESERVED_49"/>
            <keyword name="win:WDIDiag" mask="0x4000000000000" symbol="WINEVENT_KEYWORD_WDI_DIAG" message="$(string.keyword.WDIDiag)">
                 Attached to all WDI diag events
            </keyword>
            <keyword name="win:SQM" mask="0x8000000000000" symbol="WINEVENT_KEYWORD_SQM" message="$(string.keyword.SQM)">
                 Attached to all SQM events
            </keyword>
            <keyword name="win:AuditFailure" mask="0x10000000000000" symbol="WINEVENT_KEYWORD_AUDIT_FAILURE" message="$(string.keyword.AuditFailure)">
                 Attached to all failed security audits
            </keyword>
            <keyword name="win:AuditSuccess" mask="0x20000000000000" symbol="WINEVENT_KEYWORD_AUDIT_SUCCESS" message="$(string.keyword.AuditSuccess)">
                 Attached to all successful security audits
            </keyword>
            <keyword name="win:CorrelationHint" mask="0x40000000000000" symbol="WINEVENT_KEYWORD_CORRELATION_HINT" message="$(string.keyword.CorrelationHint)">
                 Attached to transfer events where the related Activity ID is a computed value and not a GUID
            </keyword>
            <keyword name="win:EventlogClassic" mask="0x80000000000000" symbol="WINEVENT_KEYWORD_EVENTLOG_CLASSIC" message="$(string.keyword.Classic)">
                 Attached to events raised using classic eventlog API
            </keyword>

            <!-- The following are used to pass channel information.  They are place holders so that users dont accidentally use those values in their own definitions -->
            <keyword name="win:ReservedKeyword56" mask="0x100000000000000" symbol="WINEVENT_KEYWORD_RESERVED_56"/>
            <keyword name="win:ReservedKeyword57" mask="0x200000000000000" symbol="WINEVENT_KEYWORD_RESERVED_57"/>
            <keyword name="win:ReservedKeyword58" mask="0x400000000000000" symbol="WINEVENT_KEYWORD_RESERVED_58"/>
            <keyword name="win:ReservedKeyword59" mask="0x800000000000000" symbol="WINEVENT_KEYWORD_RESERVED_59"/>
            <keyword name="win:ReservedKeyword60" mask="0x1000000000000000" symbol="WINEVENT_KEYWORD_RESERVED_60"/>
            <keyword name="win:ReservedKeyword61" mask="0x2000000000000000" symbol="WINEVENT_KEYWORD_RESERVED_61"/>
            <keyword name="win:ReservedKeyword62" mask="0x4000000000000000" symbol="WINEVENT_KEYWORD_RESERVED_62"/>
            <keyword name="win:ReservedKeyword63" mask="0x8000000000000000" symbol="WINEVENT_KEYWORD_RESERVED_63"/>
            <!-- End of reserved values -->
        </keywords>

        <!-- Standard Windows & CLR system types -->
        <types xmlns:xs="http://www.w3.org/2001/XMLSchema">
            <xmlTypes>
                 <xmlType name="xs:string" value="1" symbol="WINEVENT_OUT_TYPE_STRING"/>
                 <xmlType name="xs:dateTime" value="2" symbol="WINEVENT_OUT_TYPE_DATE_TIME"/>
                 <xmlType name="xs:byte" value="3" symbol="WINEVENT_OUT_TYPE_BYTE"/>
                 <xmlType name="xs:unsignedByte" value="4" symbol="WINEVENT_OUT_TYPE_UNSIGNED_BYTE"/>
                 <xmlType name="xs:short" value="5" symbol="WINEVENT_OUT_TYPE_SHORT"/>
                 <xmlType name="xs:unsignedShort" value="6" symbol="WINEVENT_OUT_TYPE_UNSIGNED_SHORT"/>
                 <xmlType name="xs:int" value="7" symbol="WINEVENT_OUT_TYPE_INT"/>
                 <xmlType name="xs:unsignedInt" value="8" symbol="WINEVENT_OUT_TYPE_UNSIGNED_INT"/>
                 <xmlType name="xs:long" value="9" symbol="WINEVENT_OUT_TYPE_LONG"/>
                 <xmlType name="xs:unsignedLong" value="10" symbol="WINEVENT_OUT_TYPE_UNSIGNED_LONG"/>
                 <xmlType name="xs:float" value="11" symbol="WINEVENT_OUT_TYPE_FLOAT"/>
                 <xmlType name="xs:double" value="12" symbol="WINEVENT_OUT_TYPE_DOUBLE"/>
                 <xmlType name="xs:boolean" value="13" symbol="WINEVENT_OUT_TYPE_BOOLEAN"/>
                 <xmlType name="xs:GUID" value="14" symbol="WINEVENT_OUT_TYPE_GUID"/>
                 <xmlType name="xs:hexBinary" value="15" symbol="WINEVENT_OUT_TYPE_HEXBINARY"/>
                 <xmlType name="win:HexInt8" value="16" symbol="WINEVENT_OUT_TYPE_HEX_INT8"/>
                 <xmlType name="win:HexInt16" value="17" symbol="WINEVENT_OUT_TYPE_HEX_INT16"/>
                 <xmlType name="win:HexInt32" value="18" symbol="WINEVENT_OUT_TYPE_HEX_INT32"/>
                 <xmlType name="win:HexInt64" value="19" symbol="WINEVENT_OUT_TYPE_HEX_INT64"/>
                 <xmlType name="win:PID" value="20" symbol="WINEVENT_OUT_TYPE_PID"/>
                 <xmlType name="win:TID" value="21" symbol="WINEVENT_OUT_TYPE_TID"/>
                 <xmlType name="win:Port" value="22" symbol="WINEVENT_OUT_TYPE_PORT"/>
                 <xmlType name="win:IPv4" value="23" symbol="WINEVENT_OUT_TYPE_IPV4"/>
                 <xmlType name="win:IPv6" value="24" symbol="WINEVENT_OUT_TYPE_IPV6"/>
                 <xmlType name="win:SocketAddress" value="25" symbol="WINEVENT_OUT_TYPE_SOCKET_ADDRESS"/>
                 <xmlType name="win:CIMDateTime" value="26" symbol="WINEVENT_OUT_TYPE_CIMDATETIME"/>
                 <xmlType name="win:ETWTIME" value="27" symbol="WINEVENT_OUT_TYPE_ETWTIME"/>
                 <xmlType name="win:Xml" value="28" symbol="WINEVENT_OUT_TYPE_XML"/>
                 <xmlType name="win:ErrorCode" value="29" symbol="WINEVENT_OUT_TYPE_ERROR_CODE"/>
                 <xmlType name="win:Win32Error" value="30" symbol="WINEVENT_OUT_TYPE_WIN32_ERROR"/>
                 <xmlType name="win:NTSTATUS" value="31" symbol="WINEVENT_OUT_TYPE_NTSTATUS_ERROR"/>
                 <xmlType name="win:HResult" value="32" symbol="WINEVENT_OUT_TYPE_HRESULT_ERROR"/>
                 <xmlType name="win:DateTimeCultureInsensitive" value="33" symbol="WINEVENT_OUT_TYPE_DATE_TIME_CULTURE_INSENSITIVE"/>
                 <xmlType name="win:Json" value="34" symbol="WINEVENT_OUT_TYPE_JSON"/>
                 <xmlType name="win:Utf8" value="35" symbol="WINEVENT_OUT_TYPE_UTF8"/>
                 <xmlType name="win:Pkcs7WithTypeInfo" value="36" symbol="WINEVENT_OUT_TYPE_PKCS7_WITH_TYPE_INFO"/>
                 <xmlType name="win:CodePointer" value="37" symbol="WINEVENT_OUT_TYPE_CODE_POINTER"/>
            </xmlTypes>
            <inTypes>
                <inType name="win:UnicodeString" value="1" symbol="WINEVENT_TYPE_NULL_TERMINATED_STRING">
                    <description> A string of 16-bit characters. </description>
                    <outType default="true" xmlType="xs:string">UTF-16LE string</outType>
                    <outType xmlType="win:Xml">UTF-16LE XML string</outType>
                    <outType xmlType="win:Json">UTF-16LE JSON string</outType>
                </inType>
                <inType name="win:AnsiString" value="2" symbol="WINEVENT_TYPE_NULL_TERMINATED_ANSI_STRING">
                    <description> A string of 8-bit characters. </description>
                    <outType default="true" xmlType="xs:string">ANSI string</outType>
                    <outType xmlType="win:Xml">XML string; encoding defaults to UTF-8 but may be overridden by an XML encoding attribute</outType>
                    <outType xmlType="win:Json">UTF-8 JSON string</outType>
                    <outType xmlType="win:Utf8">UTF-8 string</outType>
                </inType>
                <inType name="win:Int8" value="3" symbol="WINEVENT_TYPE_INT8">
                    <description> A signed 8-bit integer. </description>
                    <outType default="true" xmlType="xs:byte"/>
                    <outType xmlType="xs:string">ANSI character</outType>
                </inType>
                <inType name="win:UInt8" value="4" symbol="WINEVENT_TYPE_UINT8">
                    <description> An unsigned 8-bit integer. </description>
                    <outType default="true" xmlType="xs:unsignedByte"/>
                    <outType xmlType="win:HexInt8">An integer in hex format</outType>
                    <outType xmlType="xs:string">ANSI character</outType>
                    <outType xmlType="xs:boolean">8-bit Boolean</outType>
                </inType>
                <inType name="win:Int16" value="5" symbol="WINEVENT_TYPE_INT16">
                    <description> A signed 16-bit integer.</description>
                    <outType default="true" xmlType="xs:short"/>
                </inType>
                <inType name="win:UInt16" value="6" symbol="WINEVENT_TYPE_UINT16">
                    <description> An unsigned 16-bit integer </description>
                    <outType default="true" xmlType="xs:unsignedShort"/>
                    <outType xmlType="win:Port">A big-endian Internet Protocol port number</outType>
                    <outType xmlType="win:HexInt16">An integer in hex format</outType>
                    <outType xmlType="xs:string">UTF-16LE character</outType>
                </inType>
                <inType name="win:Int32" value="7" symbol="WINEVENT_TYPE_INT32">
                    <description> A signed 32-bit integer. </description>
                    <outType default="true" xmlType="xs:int"/>
                    <outType xmlType="win:HResult"> A message string corresponding to system HResult error code. </outType>
                </inType>
                <inType name="win:UInt32" value="8" symbol="WINEVENT_TYPE_UINT32">
                    <description> An unsigned 32-bit integer. </description>
                    <outType default="true" xmlType="xs:unsignedInt"/>
                    <outType xmlType="win:PID"/>
                    <outType xmlType="win:TID"/>
                    <outType xmlType="win:IPv4"/>
                    <outType xmlType="win:ETWTIME"> Deprecated; ETWTIME values should use win:UInt64. </outType>
                    <outType xmlType="win:ErrorCode"> Deprecated, same as win:HexInt32. </outType>
                    <outType xmlType="win:Win32Error"> A message string corresponding to system win32 error code. </outType>
                    <outType xmlType="win:NTSTATUS"> A message string corresponding to system NTSTATUS error code. </outType>
                    <outType xmlType="win:HexInt32">An integer in hex format</outType>
                    <outType xmlType="win:CodePointer">An address that can be decoded into a symbol name.</outType>
                </inType>
                <inType name="win:Int64" value="9" symbol="WINEVENT_TYPE_INT64">
                    <description> A signed 64-bit integer. </description>
                    <outType default="true" xmlType="xs:long"/>
                </inType>
                <inType name="win:UInt64" value="10" symbol="WINEVENT_TYPE_UINT64">
                    <description> An unsigned 64-bit integer. </description>
                    <outType default="true" xmlType="xs:unsignedLong"/>
                    <outType xmlType="win:ETWTIME">An ETW timestamp value from an EVENT_RECORD</outType>
                    <outType xmlType="win:HexInt64">An integer in hex format</outType>
                    <outType xmlType="win:CodePointer">An address that can be decoded into a symbol name.</outType>
                </inType>
                <inType name="win:Float" value="11" symbol="WINEVENT_TYPE_FLOAT">
                    <description> An IEEE 4-byte floating-point value </description>
                    <outType default="true" xmlType="xs:float"/>
                </inType>
                <inType name="win:Double" value="12" symbol="WINEVENT_TYPE_DOUBLE">
                    <description> An IEEE 8-byte floating-point value </description>
                    <outType default="true" xmlType="xs:double"/>
                </inType>
                <inType name="win:Boolean" value="13" symbol="WINEVENT_TYPE_BOOL">
                    <description> A 32-bit value where zero is false, nonzero is true. </description>
                    <outType default="true" xmlType="xs:boolean"/>
                </inType>
                <inType name="win:Binary" value="14" symbol="WINEVENT_TYPE_BINARY">
                    <description>Variable size binary data.</description>
                    <outType default="true" xmlType="xs:hexBinary"/>
                    <outType xmlType="win:IPv6">Always 16 bytes.</outType>
                    <outType xmlType="win:SocketAddress"/>
                    <outType xmlType="win:Pkcs7WithTypeInfo">A PKCS#7 message with TraceLogging type information optionally appended immediately after the PKCS#7 data.</outType>
                </inType>
                <inType name="win:GUID" value="15" symbol="WINEVENT_TYPE_GUID">
                    <description> A DCE-compliant 128-bit UUID. XML spec: {12345678-1234-4667-1234-123456789abc}</description>
                    <outType default="true" xmlType="xs:GUID"/>
                </inType>
                <inType name="win:Pointer" value="16" symbol="WINEVENT_TYPE_POINTER">
                    <description> A pointer; sized to the current platform (32-bit or 64-bit). XML spec: hex representation of a pointer</description>
                    <outType default="true" xmlType="win:HexInt64"/>
                    <outType xmlType="win:CodePointer">An address that can be decoded into a symbol name.</outType>
                    <outType xmlType="xs:long">Pointer-sized signed integer, e.g. intptr_t.</outType>
                    <outType xmlType="xs:unsignedLong">Pointer-sized unsigned integer, e.g. uintptr_t.</outType>
                </inType>
                <inType name="win:FILETIME" value="17" symbol="WINEVENT_TYPE_FILETIME">
                    <description> A Windows FILETIME struct. </description>
                    <outType default="true" xmlType="xs:dateTime"/>
                    <outType xmlType="win:DateTimeCultureInsensitive"> DateTime string without any marker related with culture. Ex) Left-To-Right</outType>
                </inType>
                <inType name="win:SYSTEMTIME" value="18" symbol="WINEVENT_TYPE_SYSTEMTIME">
                    <description> A Windows SYSTEMTIME struct.</description>
                    <outType default="true" xmlType="xs:dateTime"/>
                    <outType xmlType="win:DateTimeCultureInsensitive"> DateTime string without any marker related with culture. Ex) Left-To-Right</outType>
                </inType>
                <inType name="win:SID" value="19" symbol="WINEVENT_TYPE_SID">
                    <description> A self-relative Windows SID structure. XML spec: S-1-0-0.</description>
                    <outType default="true" xmlType="xs:string"/>
                </inType>
                <inType name="win:HexInt32" value="20" symbol="WINEVENT_TYPE_HEXINT32">
                    <description> A hexidecimal representation of an unsigned 32-bit integer. </description>
                    <outType default="true" xmlType="win:HexInt32"/>
                    <outType xmlType="win:ErrorCode"> Deprecated, same as win:HexInt32. </outType>
                    <outType xmlType="win:Win32Error"> A message string corresponding to system win32 error code. </outType>
                    <outType xmlType="win:NTSTATUS"> A message string corresponding to system NTSTATUS error code. </outType>
                    <outType xmlType="win:CodePointer">An address that can be decoded into a symbol name.</outType>
                </inType>
                <inType name="win:HexInt64" value="21" symbol="WINEVENT_TYPE_HEXINT64">
                    <description> A hexidecimal representation of an unsigned 64-bit integer. </description>
                    <outType default="true" xmlType="win:HexInt64"/>
                    <outType xmlType="win:CodePointer">An address that can be decoded into a symbol name.</outType>
                </inType>
                <inType name="win:CountedUnicodeString" value="22" symbol="WINEVENT_TYPE_COUNTED_STRING">
                    <description> A 16-bit bytecount followed by a string of 16-bit characters.  Supported in Windows 2018 Fall Update or later. </description>
                    <outType default="true" xmlType="xs:string">UTF-16LE string</outType>
                    <outType xmlType="win:Xml">UTF-16LE XML string</outType>
                    <outType xmlType="win:Json">UTF-16LE JSON string</outType>
                </inType>
                <inType name="win:CountedAnsiString" value="23" symbol="WINEVENT_TYPE_COUNTED_ANSI_STRING">
                    <description> A 16-bit bytecount followed by a string of 8-bit characters.  Supported in Windows 2018 Fall Update or later. </description>
                    <outType default="true" xmlType="xs:string">ANSI string</outType>
                    <outType xmlType="win:Xml">XML string; encoding defaults to UTF-8 but may be overridden by an XML encoding attribute</outType>
                    <outType xmlType="win:Json">UTF-8 JSON string</outType>
                    <outType xmlType="win:Utf8">UTF-8 string</outType>
                </inType>
                <!-- 24 is reserved (TlgInSTRUCT) -->
                <inType name="win:CountedBinary" value="25" symbol="WINEVENT_TYPE_COUNTED_BINARY">
                    <description> A 16-bit bytecount followed by binary data. Supported in Windows 2018 Fall Update or later. </description>
                    <outType default="true" xmlType="xs:hexBinary"/>
                    <outType xmlType="win:IPv6">Always 16 bytes.</outType>
                    <outType xmlType="win:SocketAddress"/>
                    <outType xmlType="win:Pkcs7WithTypeInfo">A PKCS#7 message with TraceLogging type information optionally appended immediately after the PKCS#7 data.</outType>
                </inType>
            </inTypes>
        </types>

        <messageTable>
            <!-- Categories for classic publishers -->
            <message value="1" message="$(string.category.Devices)"/>
            <message value="2" message="$(string.category.Disk)"/>
            <message value="3" message="$(string.category.Printers)"/>
            <message value="4" message="$(string.category.Services)"/>
            <message value="5" message="$(string.category.Shell)"/>
            <message value="6" message="$(string.category.SystemEvent)"/>
            <message value="7" message="$(string.category.Network)"/>

            <!-- Channel names for classic global logs -->
            <message value="256" message="$(string.channel.Application)"/>
            <message value="257" message="$(string.channel.Security)"/>
            <message value="258" message="$(string.channel.System)"/>
        </messageTable>

    </metadata>

    <localization>
        <resources culture="en-US">
            <stringTable>
                <!-- Categories for classic publishers.  THESE MUST START AT ENTRY 0! -->
                <string id="category.Reserved" value="Reserved"/>
                <string id="category.Devices" value="Devices"/>
                <string id="category.Disk" value="Disk"/>
                <string id="category.Printers" value="Printers"/>
                <string id="category.Services" value="Services"/>
                <string id="category.Shell" value="Shell"/>
                <string id="category.SystemEvent" value="System Event"/>
                <string id="category.Network" value="Network"/>

                <string id="level.LogAlways" value="Log Always"/>
                <string id="level.Critical" value="Critical"/>
                <string id="level.Error" value="Error"/>
                <string id="level.Warning" value="Warning"/>
                <string id="level.Informational" value="Information"/>
                <string id="level.Verbose" value="Verbose"/>

                <string id="opcode.Info" value="Info"/>
                <string id="opcode.Start" value="Start"/>
                <string id="opcode.Stop" value="Stop"/>
                <string id="opcode.DCStart" value="DCStart"/>
                <string id="opcode.DCStop" value="DCStop"/>
                <string id="opcode.Extension" value="Extension"/>
                <string id="opcode.Reply" value="Reply"/>
                <string id="opcode.Resume" value="Resume"/>
                <string id="opcode.Suspend" value="Suspend"/>
                <string id="opcode.Send" value="Send"/>
                <string id="opcode.Receive" value="Receive"/>

                <string id="task.None" value="None"/>

                <string id="keyword.AnyKeyword" value="AnyKeyword"/>
                <string id="keyword.ResponseTime" value="Response Time"/>
                <string id="keyword.WDIDiag" value="WDI Diag"/>
                <string id="keyword.SQM" value="SQM"/>
                <string id="keyword.AuditFailure" value="Audit Failure"/>
                <string id="keyword.AuditSuccess" value="Audit Success"/>
                <string id="keyword.CorrelationHint" value="Correlation Hint"/>
                <string id="keyword.Classic" value="Classic"/>

                <string id="channel.TraceClassic" value="TraceClassic"/>
                <string id="channel.System" value="System"/>
                <string id="channel.Application" value="Application"/>
                <string id="channel.Security" value="Security"/>
                <string id="channel.TraceLogging" value="TraceLogging"/>
                <string id="channel.ProviderMetadata" value="ProviderMetadata"/>
            </stringTable>
        </resources>
    </localization>

</instrumentationManifest>
PADPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPADDINGPADDINGXXPAD

Youez - 2016 - github.com/yon3zu
LinuXploit