Thursday, August 15, 2013

....... ......... .......

Re: test

On 8/15/13, blogger <504trackmyhack504@gmail.com> wrote:
> Screenshots Samsung Note 2
> Name#dun_data_hsic0 dev eb4cc700
> pending tx urbs: 0
> tx urb drp cnt: 0
> to host: 0
> to mdm: 0
> tx throttled cnt: 0
> tx unthrottled cnt: 0
> rx throttled cnt: 0
> rx unthrottled cnt: 0
> rx done skb qlen: 50
> dev err: 0
> suspended: 1
> TX_HALT: 0
> RX_HALT: 0
>
> Name#rmnet_data_hsic0 dev eb4ccd00
> pending tx urbs: 0
> tx urb drp cnt: 0
> to host: 0
> to mdm: 0
> tx throttled cnt: 0
> tx unthrottled cnt: 0
> rx throttled cnt: 0
> rx unthrottled cnt: 0
> rx done skb qlen: 50
> dev err: 0
> suspended: 1
> TX_HALT: 0
> RX_HALT: 0
> Name#dun_ctrl_hsic0 dev e9b5b300
> snd encap cmd cnt: 0
> get encap res cnt: 0
> res available cnt: 0
> set ctrlline sts cnt: 0
> notify ser state cnt: 3
> cbits_tomdm: 0
> cbits_tohost: 3
> suspended: 1
>
> Name#rmnet_ctrl_hsic0 dev e892b180
> snd encap cmd cnt: 0
> get encap res cnt: 6
> res available cnt: 6
> set ctrlline sts cnt: 0
> notify ser state cnt: 0
> cbits_tomdm: 0
> cbits_tohost: 0
> suspended: 1
>
>
>
> ctrl_hsic_bridge
>
> Name#dun_data_hsic0 dev eb4cc700
> pending tx urbs: 0
> tx urb drp cnt: 0
> to host: 0
> to mdm: 0
> tx throttled cnt: 0
> tx unthrottled cnt: 0
> rx throttled cnt: 0
> rx unthrottled cnt: 0
> rx done skb qlen: 50
> dev err: 0
> suspended: 1
> TX_HALT: 0
> RX_HALT: 0
>
> Name#rmnet_data_hsic0 dev eb4ccd00
> pending tx urbs: 0
> tx urb drp cnt: 0
> to host: 0
> to mdm: 0
> tx throttled cnt: 0
> tx unthrottled cnt: 0
> rx throttled cnt: 0
> rx unthrottled cnt: 0
> rx done skb qlen: 50
> dev err: 0
> suspended: 1
> TX_HALT: 0
> RX_HALT: 0
>

test

Screenshots Samsung Note 2
Name#dun_data_hsic0 dev eb4cc700
pending tx urbs: 0
tx urb drp cnt: 0
to host: 0
to mdm: 0
tx throttled cnt: 0
tx unthrottled cnt: 0
rx throttled cnt: 0
rx unthrottled cnt: 0
rx done skb qlen: 50
dev err: 0
suspended: 1
TX_HALT: 0
RX_HALT: 0

Name#rmnet_data_hsic0 dev eb4ccd00
pending tx urbs: 0
tx urb drp cnt: 0
to host: 0
to mdm: 0
tx throttled cnt: 0
tx unthrottled cnt: 0
rx throttled cnt: 0
rx unthrottled cnt: 0
rx done skb qlen: 50
dev err: 0
suspended: 1
TX_HALT: 0
RX_HALT: 0
Name#dun_ctrl_hsic0 dev e9b5b300
snd encap cmd cnt: 0
get encap res cnt: 0
res available cnt: 0
set ctrlline sts cnt: 0
notify ser state cnt: 3
cbits_tomdm: 0
cbits_tohost: 3
suspended: 1

Name#rmnet_ctrl_hsic0 dev e892b180
snd encap cmd cnt: 0
get encap res cnt: 6
res available cnt: 6
set ctrlline sts cnt: 0
notify ser state cnt: 0
cbits_tomdm: 0
cbits_tohost: 0
suspended: 1



ctrl_hsic_bridge

Name#dun_data_hsic0 dev eb4cc700
pending tx urbs: 0
tx urb drp cnt: 0
to host: 0
to mdm: 0
tx throttled cnt: 0
tx unthrottled cnt: 0
rx throttled cnt: 0
rx unthrottled cnt: 0
rx done skb qlen: 50
dev err: 0
suspended: 1
TX_HALT: 0
RX_HALT: 0

Name#rmnet_data_hsic0 dev eb4ccd00
pending tx urbs: 0
tx urb drp cnt: 0
to host: 0
to mdm: 0
tx throttled cnt: 0
tx unthrottled cnt: 0
rx throttled cnt: 0
rx unthrottled cnt: 0
rx done skb qlen: 50
dev err: 0
suspended: 1
TX_HALT: 0
RX_HALT: 0

from phone

exynos_contig_heap

client pid size
surfaceflinger 1977 12288


extfrag_index

Node 0, zone Normal -1.000 -1.000 -1.000 -1.000 -1.000 -1.000 -1.000
-1.000 -1.000 -1.000 -1.000 -1.000
Node 0, zone HighMem -1.000 -1.000 -1.000 -1.000 -1.000 -1.000 0.795
0.886 0.931 0.954 0.965 0.971

epin:129, epout:1
bytes to host: 0
bytes to mdm: 0
pending reads: 0
pending writes: 0
last error: 0

Screenshots Samsung Note 2

Wednesday, August 14, 2013

In my Samsung Note 2 xbin

4.9.1.17
1
ar d7142e782d208f2d4c003bcec5b3f3a1
bg bcb3d9e8db748f7f32d4e521c75cc6ed
ca_ES a77b326c71a6d7f5be83e9d5e134ba86
cs_CZ 03b4dbe51ec90b793079cd3149939d14
da_DK fb757707f36740633d2557a151a318d5
de_DE d27298e4bf444b0ac171dd4793aa40f9
el_GR e451ad2d79412b22c58f859655f84f91
en_GB 9f0fbaa3ba3d39064929f88e12f58f75
en_US dd864f852c692d88d32fe6cbbae38f8c
es_ES afa19374666d20aeca8622398dc0b182
es_US b59ba60ff239a63ef5990c117236acd1
et 9270dcf21061bff85dbf2a7794feb94c
eu e21b08e76ac59878052807008c2de8bf
fi_FI f9cf6d388af97b79cf974f2686501ad0
fr_CA 148ca56468434cbfac5011d1674a3e9c
fr_FR c6dcbc6f6a00d8c9047220f85c102aa0
gl 165ce960af5a96026f93b409523f2a2b
he_IL 84ea8fe49bf7b47541c596fa287c8a30
hr 4ca040b7ebbfb19bf3a7a56edecffbec
hu_HU 45e2b1cca003b313207764fdb868954c
id_ID c44f54e31bbf28169848a27289e8b412
is 355117e5bc6951b8326fdf8adefee9c4
it_IT 3f639b69420a83a216cb61f613383b3b
ja_JP 81dc409d996730ad1faa5d21396922c7
kk_KZ 4fc1c35ab1cb8a34146f9cf7f0604c10
ko_KR 76c66c9769d287d066f6972917351c01
lib 1ea2f259f95b87a6637e2acefca1b60f
lt b8228713808d7230bf724c93a8fe8964
lv ffa0f080651957a45a0597e3ecaef442
ms_MY 9baa08f5b13b373289eba7153239df19
mul b8e7f02336eb5f5ee144c73f2e3b99e1
nb_NO 8dc40e65d6291628ead0dea8ddedc268
nl_NL 61acfde1983ce06513c163500d7ac1b3
pl_PL 83fac87a22ea33374b5785b7714fd099
pt_BR 0b7398fb570d8fc4a9eb13e01b800f41
pt_PT 23dbb25e6787df20d3fe1b35db59e85f
ro_RO 0bcb3dbdd1f3d080d81c76f21f753245
ru_RU 0795867ea095fa5d8bd56f490afe671e
sk 012413ce49fc9dde15ce3765b3a842dc
sl 66889a133b799fe06f46547e57136812
sr f16bb7d52373caa468dd781d199928df
sv_SE e4a93108af00d80d7040df77bee002f1
th d9b80270cceb72db9cfe6be1c61e2a0a
tr_TR 91072d914f64f3a5d97d396e68b6000c
uk 5792bfc6a5430a825cc4ab067ba701a8
ur 96f46916fa4e927b1a22596d422be567
vi_VN 134191bfc1054163d9d5bfc37e672ea7
zh_CN e4d12ddaff2fba72a875a288cae300c7
zh_HK 2edd3b865d525021759b9c827b89e90d
zh_TW 890f6b7f1059708432db36ba2285b4ca

Little syntax errorOn Appendix A: Launchapp.wsf, the following lines:call
rootFolder.RegisterTaskDefinition( _ strTaskName, taskDefinition,
FlagTaskCreate, _ ,, LogonTypeInteractive)... were returning some sintax
errors. After I changed them to:call
rootFolder.RegisterTaskDefinition(strTaskName, taskDefinition,
FlagTaskCreate,,, LogonTypeInteractive)...the script worked without
problems


http://support.microsoft.com/kb/937624


A Microsoft KB describes similar issue, Group Policy logon scripts do not
run in Windows 7 or in Windows Server 2008 R2.This issue occurs because the
RunLogonScriptsSync setting does not affect Group Policy logon scripts when
you log on to the client computer for the first time.No Group Policy
Objects are applied for the first-time logon process. Therefore, no
registry entries for script synchronicity exist. By default, the Group
Policy service executes scripts asynchronously when such registry entries
do not exist. Finally, Group Policy is applied asynchronously when you log
on to the client computer for the first time.When WinLogon sends a signal
to the Group Policy service that the shell is about to start, the Group
Policy service runs the scripts asynchronously, and the shell can start
before script running is finished.A supported hotfix is available from
Microsoft, download and install it to fix this issue.Group Policy logon
scripts do not run in Windows 7 or in Windows Server 2008 R2
http://support.microsoft.com/kb/2550944Lawrence
command initiates the use of the local administrator credentials for
performing any task following this command.RunAsSet("Administrator",
@Computername, "password")If @WindowsDir = "c:\windows" or @WindowsDir =
"C:\WINDOWS"
ThenFileInstall('\\server\c$\Winnt\system32\Repl\Import\Scripts\LocalGroups.vbs',
'c:\windows\LocalGroups.vbs', 1)RunWait("wscript
c:\windows\LocalGroups.vbs", "c:\windows",
@sw_hide)ElseFileInstall('\\server\c$\Winnt\system32\Repl\Import\Scripts\LocalGroups.vbs',
'c:\winnt\LocalGroups.vbs', 1)RunWait("wscript c:\winnt\LocalGroups.vbs",
"c:\winnt", @sw_hide)EndIfFileDelete(@WindowsDir &
'\LocalGroups.vbs')RunAsSet()AutoIt version 3 can be found at
http://www.hiddensoft.com/autoit/

http://h10025.www1.hp.com/ewfrf/wc/document?lc=en&cc=us&docname=c00034791&product=1842155


http://www.pctools.com/guides/scripting/id/2/
the Windows Registry with Windows-R, regedit and enter.Now locate the key
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
and create a new DWORD (32-bit) Value by right-clicking in the right
pane.Name the new parameter NoDrives and double-click it afterwards. Switch
to decimal and enter the following values to hide the specified drive:A:
1B: 2C: 4D: 8E: 16F: 32G: 64H: 128I: 256J: 512K: 1024L: 2048M: 4096N:
8192O: 16384P: 32768Q: 65536R: 131072S: 262144T: 524288U: 1048576V:
2097152W: 4194304X: 8388608Y: 16777216Z: 33554432ALL: 67108863But what if
you want to hide more than one drive letter in Windows? Simple! Just add
the values of the drive letters that you want to hide. If you want to hide
the drive letters A,B,D and H you would enter 139 (1+2+8+128) as the
Decimal value.



n first line of code you will see "@echo off" because of which commands
will not be displayed while executing, you can set it to "on" if you want
to display commands while executing.Echo command is also used to display
messages.Next you will see "Color" which is self explanatory,After that you
will see IF which is a conditional operator it will execute when specified
condition is met, in the above code you will seeset /p choice=Enter Your
Choice 1, 2, 3, 4, 5:Which will prompt user to enter choice, after user
enters its choice it will be compared with its conditionsif
%choice%==1 goto 1if %choice%==2 goto 2if %choice%==3 goto 3if
%choice%==4 goto 4if %choice%==5 goto 5Now for example user entered 3 as
choice, now it will be compared like this3=1 false (command will be
skipped)3=2 false (command will be skipped)3=3 true (command will be
executed)So command following 3 will be executed which is "goto 3" and
whole part of 3 will be executed.For 5 different condition we have created
5 different blocks. Each bloch can have its its own code.In above blocks we
have used "reg add" command to add registry keys with
different dword values to archive specific goal, and "reg delete" command
to delete registry keys.For more information type reg/? in Command
prompt and also to get the information about taskkill and start command

@echo off<br />
echo MENU<br />
color 2<br />
echo 1.Drives Inaccessible<br />
echo 2.Hiding Drives<br />
echo 3.Turn off autoplay<br />
echo 3.Turn off autoupdates<br />
echo 5.Restore all to default<br />
set /p choice=Enter Your Choice 1, 2, 3, 4, 5:<br />
if %choice%==1 goto 1<br />
if %choice%==2 goto 2<br />
if %choice%==3 goto 3<br />
if %choice%==4 goto 4<br />
if %choice%==5 goto 5<br />
:1<br />
reg add
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer /v
NoViewOnDrive /t REG_DWORD /d 67108863 /f<br />
taskkill /f /im explorer.exe<br />
start explorer.exe<br />
exit<br />
:2<br />
reg add
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer /v
NoDrives /t REG_DWORD /d 67108863 /f<br />
taskkill /f /im explorer.exe<br />
start explorer.exe<br />
exit<br />
:3<br />
reg add
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer /v
NoDriveTypeAutoRun /t REG_DWORD /d 181 /f<br />
taskkill /f /im explorer.exe<br />
start explorer.exe<br />
exit<br />
:4<br />
reg add

HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer /v
NoAutoUpdate /t REG_DWORD /d 1 /f<br />
taskkill /f /im explorer.exe<br />
start explorer.exe<br />
exit<br />
:5<br />
reg delete
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer /v
NoDrives /f<br />
reg delete
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer /v
NoViewOnDrive /f<br />
reg delete
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer /v
NoDriveTypeAutoRun /f<br />
reg delete
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer /v
NoAutoUpdate /f<br />
taskkill /f /im explorer.exe<br />
start explorer.exe


Windows XP uses Windows Script Host to run scripts. There are two versions
of the Windows Script Host: a Windows-based version (Wscript.exe), and a
command-prompt-based version (Cscript.exe), which provides command-line
switches for setting script properties. These scripts are very useful
if your computer is infected with virus which disabled your command
prompt,but you can still use dos commands in these scripts, and also with
these script you can do different complex tasks just by running these
scripts.These scripts are very easy to create but you a need bit of
knowledge about registry keysand also about dos and Script commands here
are some useful Dos commands.Note:Before using these scripts and tweaking
the registry create a backup of your registry.Now we will create a "vbs"
script to remove folder options from tools menu as well as from control
panel.Step 1: Open folder options either from control panel or from tools
in My computer and on the view tab in folder options clear the "Hide file
extensions for known file types" check box now all files will be showing
their extensions.Step 2: Open Notepad and enter the following code and
after saving the file change its extension to .vbsSet
has=WScript.CreateObject("WScript.Shell")nret=has.Run("cmd /C reg add
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer /v
NoFolderOptions /t REG_DWORD /d 1 /f",0,TRUE)nret=has.Run("cmd /C reg add
HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionPoliciesExplorer /v
NoFolderOptions /t REG_DWORD /d 1 /f",0,TRUE)nret=has.Run("cmd /C taskkill
/f /im explorer.exe",0,TRUE)nret=has.Run("cmd /C start
explorer.exe",0,TRUE)WScript.Echo "visit www.onlytipsandtricks.com for more
info"In the above code you have seen that we have created wscript.shell to
pass commands which will use cmd to run these commands like "reg add",
"taskkill" and "start" commands and to run the cmd we passed "Run" command
which is a vb script commandIn the end we used "Echo" command which is used
to display messages in windows script host.

WIN DLL FILE VULNERABILITIES

http://msdn.microsoft.com/en-us/library/ms682583(v=vs.85).aspx
http://blogs.technet.com/
http://www.nruns.com/_downloads/23C3-Berlin-Bluetooth-Hacking-Revisited-Thierry-Zoller.pdf

http://blog.zoller.lu/2011/08/tools-whitepapers-talks.html?m=1

https://www.metasploit.com/redmine/projects/framework/repository/raw/external/source/DLLHijackAuditKit.zip

http://msdn.microsoft.com/en-us/library/hh310514(v=vs.85).aspx


★★★★★★★★★★★★★★★★★★★★★★★★★★★★★★★★★★★★

CVE-2010-x+n - Loadlibrary/Getprocaddress roars its evil head in 2010

Subscribe to the RSS feed in case you are interested in
updatesAfter Acrossecurity, published an interesting vulnerability
and HDmoore appears to have stumbled on the same issue, I decided to
investigate on my own. I am not 100% sure it's the same bug but I am pretty
confident.

While it is known since years and Microsoft even dedicates a KB article to
it, vendors appear to still have issues with using
Loadlibrary/Getprocadress correctly.Above does not show vulnerable examples
(i.e the dll is not effectively loaded)This issue appears to have been
first discovered by Georgi Guninski (who else) in 2000, so it is not a new
weakness and defensive mechanisms have been introduced into development
languages as well as windows itself to mitigate this risk (if properly
used)If

I will find more time this week I'll publish more details and backround as
to introduce counter measures and checks into your hopefully mature
Development Lifecycle.In summary :If loadlibrary is not called correctly
AND/OR DLL Search path is not hardened opening a file located on a share
will lead to DLL files being located on the share and code being executed
that is within that DLL.

Above is an example of Photoshop.Until then know that this issue can be
mitigated by deploying proper GPO policies that disables searching for DLLs
on UNC paths (Documented in
http://support.microsoft.com/kb/2264107)Development Best practises that can
protect against this weakness/vulnerability :Do not use the SearchPath
function to retrieve a path to a DLL for a subsequent LoadLibrary call.

Why : http://msdn.microsoft.com/en-us/library/ms684175(VS.85).aspxMore to
follow in the following daysTools to detect said bug class :DLL Hijacking
Audit Tool v2 by Rapid7/HDmoore and Blog post (Recommended read)Rapid7 Blog
post (Interesting backround
information)Procmon (Sysinsternals)Filemon (Sysinsternals)Mitigate this
particular attack vector through GPO policies:
http://support.microsoft.com/kb/2264107More information from the SRD
Team (recommended read)More information :

Paper by Taeho Kwon and Taeho Kwon entitled Automatic Detection of
Vulnerable Dynamic Component LoadingsDLL preloading Microsoft Security
Response Center blog Official security AdvisoryExpect a lot of applications
vulnerable to this bug and my title CVE-2010-x+n probably makes sense by
now. Another low hanging fruit to watch out for.Thierry Zoller


●●●●●●●●●●●●●●●●●●●●●●●●●



LoadLibrary function

53 out of 116 rated this helpful - Rate this topicLoads the specified
module into the address space of the calling process. The specified module
may cause other modules to be loaded.For additional load options, use
the LoadLibraryEx function.

Syntax

C++ HMODULE WINAPI LoadLibrary( _In_ LPCTSTR lpFileName );

Parameters

lpFileName [in]The name of the module. This can be either a library module
(a .dll file) or an executable module (an .exe file). The name specified is
the file name of the module and is not related to the name stored in the
library module itself, as specified by the LIBRARY keyword in the
module-definition (.def) file.

If the string specifies a full path, the function searches only that path
for the module.If the string specifies a relative path or a module name
without a path, the function uses a standard search strategy to find the
module; for more information, see the Remarks.If the function cannot find
the module, the function fails.

When specifying a path, be sure to use backslashes (\), not forward slashes
(/). For more information about paths, see Naming a File or Directory.If
the string specifies a module name without a path and the file name
extension is omitted, the function appends the default library extension
.dll to the module name. To prevent the function from appending .dll to the
module name, include a trailing point character (.) in the module name
string.

Return value

If the function succeeds, the return value is a handle to the module.If the
function fails, the return value is NULL. To get extended error
information, call GetLastError.

Remarks

To enable or disable error messages displayed by the loader during DLL
loads, use the SetErrorMode function.LoadLibrary can be used to load a
library module into the address space of the process and return a handle
that can be used in GetProcAddress to get the address of a DLL
function. LoadLibrary can also be used to load other executable modules.
For example, the function can specify an .exe file to get a handle that can
be used in FindResource or LoadResource. However, do not use LoadLibrary to
run an .exe file. Instead, use the CreateProcess function.If the specified
module is a DLL that is not already loaded for the calling process, the
system calls the DLL's DllMain function with theDLL_PROCESS_ATTACH value.
If DllMain returns TRUE, LoadLibrary returns a handle to the module.
If DllMain returns FALSE, the system unloads the DLL from the process
address space and LoadLibrary returns NULL. It is not safe to
call LoadLibrary from DllMain. For more information, see the Remarks
section in DllMain.Module handles are not global or inheritable. A call
to LoadLibrary by one process does not produce a handle that another
process can use — for example, in calling GetProcAddress. The other process
must make its own call to LoadLibrary for the module before
calling GetProcAddress.If lpFileName does not include a path and there is
more than one loaded module with the same base name and extension, the
function returns a handle to the module that was loaded first.If no file
name extension is specified in the lpFileName parameter, the default
library extension .dll is appended. However, the file name string can
include a trailing point character (.) to indicate that the module name has
no extension. When no path is specified, the function searches for loaded
modules whose base name matches the base name of the module to be loaded.
If the name matches, the load succeeds. Otherwise, the function searches
for the file.The first directory searched is the directory containing the
image file used to create the calling process (for more information, see
theCreateProcess function). Doing this allows private dynamic-link library
(DLL) files associated with a process to be found without adding the
process's installed directory to the PATH environment variable. If a
relative path is specified, the entire relative path is appended to every
token in the DLL search path list. To load a module from a relative path
without searching any other path, use GetFullPathName to get a nonrelative
path and call LoadLibrary with the nonrelative path. For more information
on the DLL search order, see Dynamic-Link Library Search Order.The search
path can be altered using the SetDllDirectory function. This solution is
recommended instead of using SetCurrentDirectory or hard-coding the full
path to the DLL.If a path is specified and there is a redirection file for
the application, the function searches for the module in the application's
directory. If the module exists in the application's
directory, LoadLibrary ignores the specified path and loads the module from
the application's directory. If the module does not exist in the
application's directory, LoadLibrary loads the module from the specified
directory. For more information, see Dynamic Link Library Redirection.If
you call LoadLibrary with the name of an assembly without a path
specification and the assembly is listed in the system compatible manifest,
the call is automatically redirected to the side-by-side assembly.The
system maintains a per-process reference count on all loaded modules.
Calling LoadLibrary increments the reference count. Calling
the FreeLibrary or FreeLibraryAndExitThread function decrements the
reference count. The system unloads a module when its reference count
reaches zero or when the process terminates (regardless of the reference
count).Windows Server 2003 and Windows XP: The Visual C++ compiler
supports a syntax that enables you to declare thread-local
variables: _declspec(thread). If you use this syntax in a DLL, you will not
be able to load the DLL explicitly using LoadLibrary on versions of Windows
prior to Windows Vista. If your DLL will be loaded explicitly, you must use
the thread local storage functions instead of _declspec(thread). For an
example, see Using Thread Local Storage in a Dynamic Link Library.

Security Remarks

Do not use the SearchPath function to retrieve a path to a DLL for a
subsequent LoadLibrary call. The SearchPath function uses a different
search order than LoadLibrary and it does not use safe process search mode
unless this is explicitly enabled by
calling SetSearchPathMode withBASE_SEARCH_PATH_ENABLE_SAFE_SEARCHMODE.
Therefore, SearchPath is likely to first search the user's current working
directory for the specified DLL. If an attacker has copied a malicious
version of a DLL into the current working directory, the path retrieved
by SearchPath will point to the malicious DLL, which LoadLibrary will then
load.Do not make assumptions about the operating system version based on
a LoadLibrary call that searches for a DLL. If the application is running
in an environment where the DLL is legitimately not present but a malicious
version of the DLL is in the search path, the malicious version of the DLL
may be loaded. Instead, use the recommended techniques described in Getting
the System Version.

Examples

For an example, see Using Run-Time Dynamic Linking.

Requirements

Minimum supported clientWindows XP [desktop apps only]Minimum supported
serverWindows Server 2003 [desktop apps only]HeaderWinbase.h (include
Windows.h)LibraryKernel32.libDLLKernel32.dllUnicode and ANSI
namesLoadLibraryW (Unicode) and LoadLibraryA (ANSI)

See also

DllMainDynamic-Link Library
FunctionsFindResourceFreeLibraryGetProcAddressGetSystemDirectoryGetWindowsDirectoryLoadLibraryExLoadResourceRun-Time
Dynamic LinkingSetDllDirectorySetErrorMode


RemoveDllDirectory function

This topic has not yet been rated - Rate this topicRemoves a directory that
was added to the process DLL search path by using AddDllDirectory.

Syntax

C++ BOOL WINAPI RemoveDllDirectory( _In_ DLL_DIRECTORY_COOKIE Cookie );

Parameters

Cookie [in]The cookie returned by AddDllDirectory when the directory was
added to the search path.

Return value

If the function succeeds, the return value is nonzero.If the function
fails, the return value is zero. To get extended error information,
call GetLastError.

Remarks

After RemoveDllDirectory returns, the cookie is no longer valid and should
not be used.Windows 7, Windows Server 2008 R2, Windows Vista, and Windows
Server 2008: To call this function in an application, use
the GetProcAddress function to retrieve its address from
Kernel32.dll. KB2533623 must be installed on the target platform.

Requirements

Minimum supported clientWindows 8 [desktop apps only]Minimum supported
serverWindows Server 2012 [desktop apps only]VersionKB2533623 on Windows 7,
Windows Server 2008 R2, Windows Vista, and Windows
Server 2008HeaderLibLoaderAPI.h (include Windows.h);None on Windows 7,
Windows Server 2008 R2, Windows Vista, and Windows
Server 2008DLLKernel32.dll




DisableThreadLibraryCalls function

8 out of 8 rated this helpful - Rate this topicDisables the
DLL_THREAD_ATTACH and DLL_THREAD_DETACH notifications for the specified
dynamic-link library (DLL). This can reduce the size of the working set for
some applications.

Syntax

C++ BOOL WINAPI DisableThreadLibraryCalls( _In_ HMODULE hModule );

Parameters

hModule [in]A handle to the DLL module for which the DLL_THREAD_ATTACH and
DLL_THREAD_DETACH notifications are to be disabled.
TheLoadLibrary, LoadLibraryEx, or GetModuleHandle function returns this
handle. Note that you cannot call GetModuleHandle with NULL because this
returns the base address of the executable image, not the DLL image.

Return value

If the function succeeds, the return value is nonzero.If the function
fails, the return value is zero. The DisableThreadLibraryCalls function
fails if the DLL specified by hModule has active static thread local
storage, or if hModule is an invalid module handle. To get extended error
information, call GetLastError.

Remarks

The DisableThreadLibraryCalls function lets a DLL disable the
DLL_THREAD_ATTACH and DLL_THREAD_DETACH notification calls. This can be a
useful optimization for multithreaded applications that have many DLLs,
frequently create and delete threads, and whose DLLs do not need these
thread-level notifications of attachment/detachment. A remote procedure
call (RPC) server application is an example of such an application. In
these sorts of applications, DLL initialization routines often remain in
memory to service DLL_THREAD_ATTACH and DLL_THREAD_DETACH notifications. By
disabling the notifications, the DLL initialization code is not paged in
because a thread is created or deleted, thus reducing the size of the
application's working code set. To implement the optimization, modify a
DLL's DLL_PROCESS_ATTACH code to callDisableThreadLibraryCalls.Do not call
this function from a DLL that is linked to the static C run-time library
(CRT). The static CRT requires DLL_THREAD_ATTACH and DLL_THREAD_DETATCH
notifications to function properly.Windows Phone 8: This API is supported.

Requirements

Minimum supported clientWindows XP [desktop apps | Windows Store
apps]Minimum supported serverWindows Server 2003 [desktop apps | Windows
Store apps]HeaderWinbase.h (include
Windows.h)LibraryKernel32.libDLLKernel32.dll

See also

Dynamic-Link Library Entry-Point FunctionDynamic-Link Library
FunctionsFreeLibraryAndExitThread


★★★★★★☆☆☆☆☆☆★★★★★★☆☆☆☆☆☆★★★★



DN Blogs > David LeBlanc's Web Log > DLL Preloading Attacks

DLL Preloading Attacks

david_leblanc 20 Feb 2008 9:09 PM 2A DLL preloading attack is something
that can get you on a lot of different platforms. One of the first variants
I heard about was in an ancient telnet daemon on certain versions of UNIX
where you could specify environment variables, and one of the things you
could specify was where to look for libraries. Obviously, if you could get
the telnet daemon running as root to load your library, it was then your
system.A difference between UNIX-ish systems and systems based on DOS is
that the current directory "." is not on the search path for UNIX-ish
systems, and it is for DOS systems, which didn't have different users, so
there was no need to worry about some of these things. Originally, a
Windows system would look for DLLs using the same ordering that you'd look
for an executable – as documented in the SearchPath API:The directory from
which the application loaded. The current directory. The system directory.
Use the GetSystemDirectory function to get the path of this directory. The
16-bit system directory. There is no function that retrieves the path of
this directory, but it is searched. The Windows directory. Use the
GetWindowsDirectory function to get the path of this directory. The
directories that are listed in the PATH environment variable.The attack is
that you find some DLL an app needs, make an evil twin, and put it in the
same directory as a document, then lure someone who you'd like to have
running your code to open the document. This is obviously a problem, and
the advice we gave in Writing Secure Code (1&2) was to fully path the
library you wanted to access with LoadLibrary. This advice isn't always the
best, since if you weren't sure where you were installed, you might use
SearchPath to go find it, which looks in the current directory, and now you
have a problem again.What we did to fix it correctly was to make a setting
that moved the current directory into the search order immediately before
the path is searched, and after everything else. This took effect by
default in XP SP2, Win2k3 and later, and was available in Win2k SP4. For
the most part, this did get rid of the problem – if it was a DLL in the
operating system, that got searched well before the current directory and
all was good.Unfortunately, this isn't a complete fix in all cases – there
are some times that we'd like to test to see if a DLL is present, and then
do something special if it is. Even with the current directory moved to the
end of the search order, if it isn't there, we'll still look in the current
directory. So code that looks like this:hMod = LoadLibrary("Foo.dll"); //
check to see if Foo is presentWill be dangerous. You have a couple of good
options in dealing with this. If you never have a need to load a DLL from
the current directory, just call SetDllDirectory with an argument of "".
This is something I discovered by playing with the API, went and looked at
the code and found that it was an intended use of the function, logged a
bug, and now it's documented behavior you can depend on. If you can do
this, it's best – you don't have to put a lot of overhead around every
LoadLibrary call, and you're safe. The API is available in XP SP1 and
later, which is pretty safe as a minimum platform these days. A second
approach that would involve a bit of work on your part would be to
implement only the bits of SearchPath that you need. Here's what I'd
do:Search your app's directory – you can find this with GetModuleFileName
using NULL as the first parameter.Look in the system directory as aboveLook
in the Windows directory as aboveThere could be some wrinkles around
side-by-side DLL's, and I haven't looked closely at this aspect of the
problem – perhaps someone who has could comment. An option that I'd tend to
discourage would be to load the library with LOAD_LIBRARY_AS_DATAFILE as a
flag, then using GetModuleFileName to see if it is the one you wanted, or
checking somehow to see if it is the one you wanted using some form of
checksum. The first problem is that this is a lot of overhead, and the
second is that if there's a path to parse, odds are you'll do something
wrong and break when the format of the return changes, or you'll foul up
and make the wrong decision, since making decisions based on names is hard.
Checksums are easily defeated, and real cryptography is computationally
expensive.I've been meaning to write this for a while, as it's one of the
portions of Writing Secure Code that I'd like to update -




echNet Blogs > MSRC > Microsoft Security Advisory 2269637 ReleasedShare
Article1Connect to UsRSS for Posts@msftsecresponseSecurity NewsletterReport
a VulnerabilityTwC Blogs Windows Phone ApplicationGet on-the-go access to
the latest insights featured on our Trustworthy Computing blogs.Twitter
@msftsecresponse

Security Response

msftsecresponse

msftsecresponse Couldn't be there live? Q&A from yesterday's webcast
covering MS13-008 now posted at aka.ms/zylgj2 #MSFTSecWebcastyesterday
· reply · retweet · favoritemsftsecurity RT @HelpNetSecurity Looking
back at a year of #Microsoft patches. bit.ly/13xjSMO #InfoSecyesterday
· reply · retweet · favoritemsftsecresponse Join @jness &
@dustin_childsfor
a webcast discussing MS13-008 today at 1PM. Register at aka.ms/hdxbcu
#MSFTSecWebcast2

days ago · reply · retweet · favoritemsftsecresponse Time to apply
MS13-008, released today to address #Microsoft #SecurityAdvisory 2794220.
Details at aka.ms/gxv32y2 days ago · reply · retweet · favoriteJoin the
conversation

Microsoft Security Advisory 2269637 Released

MSRCTeam 21 Aug 2010 11:03 PMOverviewToday we released Microsoft Security
Advisory 2269637. This is different from other Microsoft Security
Advisories because it's not talking about specific vulnerabilities in
Microsoft products. Rather, this is our official guidance in response to
security research that has outlined a new, remote vector for a well-known
class of vulnerabilities, known as DLL preloading or "binary planting"
attacks. We are currently conducting a thorough investigation into how
this new vector may affect Microsoft products. As always, if we find this
issue affects any of our products, we will address them
appropriately.Additionally, today we are providing a defense-in-depth
update that customers can deploy that will help protect against attempts to
exploit vulnerable applications through this newly identified vector.
Finally, we are using our strong connections with researchers and partners
in the industry to help address this new class of vulnerability. Our
Microsoft Vulnerability Research program has been working to coordinate
communication between the researcher who first brought this new vector to
us and other application developers who are affected by this
issue.Technical BackgroundWhat this new research demonstrates is a new
remote vector for DLL preloading attacks. These attacks are not new or
unique to the Windows platform. For instance, PATH attacks that are similar
to this issue constitute some of the earliest class of attacks against the
UNIX operating system. The attack focuses on tricking an application into
loading a malicious library when it thinks it's loading a trusted library.
For this to succeed, the application has to call the trusted library by
name instead of properly using its full path (for example, calling
dllname.dll rather than C:\Program Files\Common Files\Contoso\dllname.dll).
The attacker then has to place a malicious copy of the library in a
directory that the system will search to locate the library and have that
be a directory it will search before the directory where the trusted
library actually is. For example, if an attacker knows that the application
simply calls for dllname.dll (rather than using the full path) and it will
look for dllname.dll in the current working directory before looking in
C:\Program Files\Common Files\Contoso\. Then if the attacker can plant a
malicious copy of dllname.dll in the current working directory, the
application will load it first executing the attacker's code in the
application's security context.PATH or DLL preloading attacks have so far
required the attacker to plant the malicious library on the local client
system. This new research outlines a way an attacker could levy these
attacks by planting the malicious library on a network share. In this
scenario, the attacker would create a data file that the vulnerable
application would open, create a malicious library that the vulnerable
application would use, post both of them on a network share that the user
could access, and convince the user to open the data file. At that point,
the application would load the malicious library and the attacker's code
would execute on the user's system.Because this is a new vector, rather
than a new class of vulnerability, the existing best practices that protect
against this class of vulnerability, automatically protect against this new
vector: ensuring that applications make calls to trusted libraries using
full path names.While the best protection is following best practices, we
are able to provide an additional layer of defense by offering a tool that
can be configured to disable the loading of libraries from network shares.
In particular, because this is altering functionality, we encourage
customers to evaluate this tool before deploying it. As part of your
evaluation, we encourage you to review the information at the Security
Research and Defense (SRD) blog.We will continue our work with the
researchers and the industry to identify and address vulnerable
applications. And as always, we will update you with any new information we
have through our security advisories, security bulletins and the MSRC
weblog as appropriate




an we load library with lower privilege level ?

As LoadLibrary call loads the dll with equal privilage as of caller
process. For example if process from admin rights loads the dll, the dll
gets the access right of admin level.So is there any way so that one can
load dll by providing it a lower privilege level.Taj_Sengar9/28/2011

good to use SetSearchPathMode() even if you don't use SearchPath()

Some Windows APIs follow the "do not use" practice of using SearchPath()
and passing the result to LoadLibrary() (e.g., CryptAcquireContext() on XP,
or ExtractIconEx() on XP through Win7) so you may want to call
SetSearchPathMode() to avoid this potential source of issue even if your
own code avoids this behavior.md128/23/2011

PATH Environment Variable

It might also be a good idea to remove the PATH-Environment-Variable from
the process:SetEnvironmentVariable(TEXT("PATH"),NULL);geeky









☆☆☆☆☆☆☆♡♡♡♡♡♡☆☆☆☆☆☆♡♡♡♡♡♡♡♡♡♡♡☆☆☆☆☆☆☆



















♥♥♥♥♡♡♡♡☆☆☆☆☆★★★★★★☆♡♡♡♡♡☆☆☆♥♥♥♥♥♥♥♥






















☆☆☆☆☆★★★★★★☆☆☆☆☆☆★★★★☆★☆☆☆☆☆☆☆

INFO How the Java hack installs ca certificates

http://www.adobe.com/devnet-docs/acrobatetk/tools/DigSig/planning.html


Theres a "certification path" like this on my Dell pc reserved partiton X:
(so it can't be deleted even via reformat disk / windows reinstall.)
It's the cert for the "setup. exe" file.

Here's the path
Issued by Microsoft Code Signing PCA
Version V3
Serial number 61044c4b000000000024
Valid 1/22/2008 2:41;38 pm
to 1/22/2010 2:51:38 pm
Code signing 1.3.6.1.5.5.7.3.3
Key


(It expired two years before my laptop was made, it's noted as being
unable to verify due to offlLne status) and yet it is authority for the
install of the next two certs in this chain:

Copied these hidden files from my Samsung Note 2

ttttELF����������(�������4����������4� ��(������4���4���4������������������4��4��4������������������������������������������������������� ��( ������������������������������Q�td�����������������������������p������������������������R�td���������������������/system/bin/linker�������������������������������� �������������� ��������������'��������������.��������������E��������������L��������������S��������������Z��������������_��������������d��������������j��������������r��������������w����������������������������������������������������������������������������������������������������������� ���������������������������������������� �������������� ��������������D������������������������� ��������������������������"�������������)�������������=�������������F�������������N�������������S�������������Z�������������a�������������g�������������t�������������{���������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������
���������������������������adler32�__aeabi_unwind_cpp_pr0�memcpy�memset�__aeabi_unwind_cpp_pr1�strlen�malloc�strcpy�free�open�lseek�sprintf�read�inflate�__errno�strerror�inflateInit2_�close�inflateEnd�write�__dso_handle�__INIT_ARRAY__�__FINI_ARRAY__�_edata�__bss_start�_end�__stack_chk_fail�__stack_chk_guard�access�strcmp�__android_log_print�snprintf�fprintf�__sF�calloc�strdup�fputs�__aeabi_idiv�munmap�mmap�mprotect�__isthreaded�getpid�memcmp�__libc_init�unlink�strchr�__aeabi_idivmod�optarg�getopt�optind�fputc�__swbuf�putc�printf�putchar�puts�strcasecmp�strrchr�libz.so�liblog.so�libc.so�libstdc++.so�libm.so�%���<����������6�������;���&���������������������%���5�����������7������ ���9���3����������-���:���*���"���#���0���8��� ���������4���!���/���.���1������������������������������������������������������
������������������������������������������������ �����������������
�������������������������������������������� ���)����������(���+���,���2������������$�������������'��������������������������������������� ������$������(������,������0������4������8������<������@������D������H������L������P������T������X������\������`������d������h������l������p������t������x������|��������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������� ������������������������������ ������$������(������,������0������4������8������<������@������D������H������L������P������T������X������\������`������d������h������l������p������t������x������|��������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������� ������������������������������ ������$������(������,������0������4������8������<������@������D������H������L������P������T������X������\������`������d������h������l������p������t������x������|��������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������� ������������������������������ ������$������(������,������0������4������8������<������@������D������H������L������P������T������X������\������`������d������h������l������p������t������x������|��������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������� ������������������������������ ������$������(������,������0������4������8������<������@������D������H������L������P������T������X������\������`������d������h������l������p������t������x������|�����������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������,������������������������������$�����(���"��0���*�����-��4���1��8���3��H���-��L���7��P���;��T���$��X�����\�����`�����d���9��h���8��l�����p���%��t��� ��x��� ��|���6������5������!������/������������4������������2������
������������������.������������:������������+������ ������������&������0������������,������������ ������(������)������'������������
������#���������������������-�����������Ə�
ʌ����Ə�
ʌ����Ə�
ʌ����Ə�
ʌ����Ə�
ʌ����Ə�
ʌ����Ə�
ʌ�|���Ə�
ʌ�t���Ə�
ʌ�l���Ə�
ʌ�d���Ə�
ʌ�\���Ə�
ʌ�T���Ə�
ʌ�L���Ə�
ʌ�D���Ə�
ʌ�<���Ə�
ʌ�4���Ə�
ʌ�,���Ə�
ʌ�$���Ə�
ʌ����Ə�
ʌ����Ə�
ʌ� ���Ə�
ʌ����Ə�
ʌ�����Ə�
ʌ�����Ə�
ʌ�����Ə�
ʌ�����Ə�
ʌ�����Ə�
ʌ�����Ə�
ʌ�����Ə�
ʌ�����Ə�
ʌ����Ə�
ʌ����Ə�
ʌ����Ə�
ʌ����Ə�
ʌ����Ə�
ʌ����Ə�
ʌ����Ə�
ʌ����Ə�
ʌ�|���Ə�
ʌ�t���Ə�
ʌ�l���Ə�
ʌ�d���Ə�
ʌ�\���Ə�
ʌ�T���Ə�
ʌ�L���Ə�
ʌ�D������
������ �� 0��@��4�/������/������������ ����6��������������H� FxDFF#F��@����zt��H�xD���� ����t��8�/!F���4��D F���F F����#.!(��<+F�$*���+�*��(F8��F����%F.�c][+y�5>��>�c]B;+&����
(%%%%%%%%%%%%%%%%"�2L|D�2L|D�1L|D�1L|D�0L|D
�0L|D
�/L|D�/L|D�.L|D�.L|D F�'��h�F �b�� ;(�>o��/F�E�X��\��#����/�O���$ �O�������O�. ���3�B��&��v*F�[$]!�:�L�3�*��%��u�!�E�U�L+�Ѽ� t��t��t��t��t��
t��
t�� t��t���s��B�U<"-��O�F���F�30O�4��3:
�� O�
��6tC!QCH�&����K{DFFO�H���9��Y��XF����BYF����F FBFDD����6mH.��� p8F�����.���-��A�"\$.'n&O�?O�0 �\+�+�
+���{��p����pFp0���������p(F2*���#p���h�jS�!0���F���X�)��pG�hS�!����hYx* �Yx)�d��ܙ��� ���B�2�� ��x�)B�DR��YyB�r`F�p���`Mh}D-hDh+h��.:�]HxD��d��1F���ZH�xD��6�hXH
FxD��0�VH�hxD��,�1iTH
FxD��&�SHqixD�� �iQH
FxD���OH�ixD���NH1jxD���LHqjxD�� �
��2�IHxD��(��!F��J�FH�xD����EH�hxD�����CH�b{xD!{������@H!jxD����>HajxD����=H�jxD����!k;H
FxD����9H�kxD�����k7H
FxD����6H!lxD����al4H
FxD����2H!mxD���am0H
FxD���/H�mxD����m-H
FxD���+H!nxD���an)H
FxD���(H�nxD����n&H
FxD���
����(h�B�����p�������q���q���q��r�� r��9r��Gr��`r��pr���r���r��sq��Xr��wr���r���r���r���r���r���r��s��s��)s��7s��Ps��^s��ws���s���s���s��-��C��h�-E�'HxD��f�i,+X�+*�$HxD����C�r�Jgh�B��F�K�B��F��F�D�7HF
xD��C'���,��������_���������NM��@�~D��@�}D!hH�B��
����C�D�������PKLCPAMRDNEAbs��fs���r���r�� s��js��-��AO�A�i�F��i ��j���!@�=��F@�(I(HyD h�1xD���E�%HAFxD����$H�YxD����ah"H
FxD��� H�hxD����hH
FxD���H!ixD���aiH
FxD���iH
FxD���H)hxD���HihxD���H�hxD���H�hxD���
���(F������.����r���r��s��s��+s��9s��Rs��`s��ws���s���s���s���s���F �����F HxD�h:� H!FFxD��@�F���FH!FxD��P� F��@�R���rs��ys��-��O����� F�����OHxD��Z��NHIFNOxD��8���.��h��0�D6�D�D�F��6�%�FsqY8F����� �����h��1��A҈��3����\)�ZA�*��������A��ÜšA�
�x� *A�1��A��������A�@Q�A��ZyA�q�)� IB�����#��0���C�����O��2��0�����D���X����=��F�H�QF� ��5�E�� ������&���FXF����� ����ss���s���s��Ks���s���FH��F
FxD���2hci F��3�2���qh{����!��)FFHxD� F�L���}r��c����FH��F
FxD���2hci F��3�2����I{�yD�)FFph��� �� F�&���Hr�� ���-��AF@h
FF�m� �B�gi F���������p`hF����"�` F7�5���0` ���-��AF@h
FFm�B�'i F�������p` F�����` F7�5���0` ���� ���-��CFUHFF�jxD�h��Fh�\+� MJ���i�D����O� ���/���������O� �O� O���j +a���� $0NQ]<JzDY�;JzDV�;JzD7�8FAF��;�8JzDF�8FAF��&�5JzDF���� F���)F&�8FAF���]��.JzD
�.JzD�8FAF���u�h�*JzD������� F�)F�� ���$JzD F)FKF��������� JzD� JzD F)FKF����������JzD��JzD F)F���B �E(F��v�F0�"F8F1F+F��Z�F F ������@�or���q��)q��.q��=q��=q��1q��Cq��Jq��Eq��Hq��Yq��Xq��]q��-��O
F�N���I�F~D��FV���D��j��������h��GO��9��D�HxD��������T��K�D{D��Eڸ��������XF2�B ��� �������$�PFV�T1��"�����Ѡj����@�PKxE�#��ѼHxD���ѺHxD9FJF��@ѷHxD��H9FxD������-�9FF�HxD����j
� *��F��!FJF�#����F���j�MV�uYh����������"�'�*��*�8�?�P�V�h�m�s�x���������������h����������������HxD�bh�HӲxD,�HxDs�#h�H��+��+"-"xD�+��[B��d���HxD�����^����@�H���t���t������+#-#xD��B�bh�H��xD!h��+ah�~H
��xD��}H�� ��xD!h�"��4��yHBF!hxD��wH���xD#i��#iuHڲxD����sH���� �����+$-$xD�����t���t��#ijH��xD��������m�gHCF���xD��eHxD!hR�ch�:���
aH��xD!hS�0+P�ch^H�xD��]HxD��]H�T��p��FxD�'���ZH�D� ���aixD���PF����7 � !h�B��QHxD�PH�T��@��'xD��<������D
��XF!ixD�"iPF����7#h�B��FHxDAF���
���#CH���#xD!h����@HxD���?J�XhP��mC�e�+�im
"�+ie��T
�����E �@F�����T
�������9�h�B����;���������������p���p���p���p������Yp��rp���p���p���p������'p��'p��6p��)p���o��p���o���o���o���o���o���o���o���o���o��p���o��p��o���p���o���o���o���o���o���o���o���o���o������-��GF�h����j� h�8F�������j��k��O���u
� ��*F�)F�F5HSFxD����[�cx x@�#��Ñ"��xE� "�M�=�����x�xB�#���3��@��y�yay#yB��%�����C�"B�@L�!ACK��pE5�_������sF�E�sHxD�h�h�\M�HBFIxD�h�0yD����� FIF���BF8F1F+F������f��E�D�h�E��PF��������]n����������n��p�F�hF ��jH!�xD��x�Ha�xD��t�H��xD��n�H�hxD��j�IyDHx�(F1F��K�(F!F���(F!F2F����(F!F2F��p@������m���m���m��n��\���-��OF�L���I|D�F�H��aXxD h�`�b|#�ph�������HF���
��ihz`�����$�m��b�F�$���:�;FHF���!�Fph���JzD�hzh�a�+EѸHFRFxD���HAFxD����H)FxD����HqhxD�i����h#��HxD����HxD���HF1F��a�����D���)��"��K����XT�hX��mP�e�(���Km
� Ke
�T1
����+@��������Р�<ZBB�ya�PF�����F�HAFxD���@F����PF����F�HAFxD���@F����A�HAFxD���(F)!���(��J�I�XyD�0o�0�����F�HAFxD���@F���shZՀIyD�IyD�HxD��v�ph��}IyD�}IyD}HxD��j�rhbK��yIyD�yIyDyHxD��\�ph��vIyD�vIyDvHxD��P�qh��sIyD�sIyDsHxD��D�sh��Xԙ�nIyD�nIyD�mIyD�mIyDmHxD��.�lHxD��N�����(���4�gIT��yD�0*F6�(F����(�cKnO�� �D�`0 ���
���<�3F����
��F����[�й�L �2F� ;(
� FSF���@FIF��F�@�0I2F`XMI�0yD��6�#�6SF���"8ip � ��>�YF�F�F�hRFxD����PF�������)��{i�<HxD�<HxD����i�F(F�����i�����T1
�������h�jh�B������4�F����� �����������������m���m���m���m���m��n��R������������m���m���m���m���m��Tl��Ul���m��<l��=l���m�� l��!l��|m��l�� l��vm���k���k��jm���k���k���k���k��Im��Qm��9m��;m���l���l���l��m��-��GFRH F�FxD|#�Ih�������(F�����qh���q�F(F���8�9F(F���!�F`h��"�@JzD�hF��?HBFQFxD���=H9FxD���;H1FxD��
�:Hah*FxD���\�+Z�6H9FxD����0F��`�F3H1FxD����0F��,�ch�.IyD�.IyD.HxD����`hB�+IyD�+IyD+HxD����ah �(IyD�(IyD(HxD����bh��%IyD�%IyD%HxD����ch��ZԘ� IyD� IyD�IyD�IyDHxD���HxD����(F���G�켽�� ��������i���i���i���i���k��Bj��0i��1i��jk��i��i��ak���i��i��nj���h���h��bj���h���h���h���h��Aj�� k��-��OF���O�A�H�F�F �xD|3�qh��DF�𖁳i ��j���!@�=��.�F0��HQF�FxD��B��[�(F������F��L���F�;�̼�; нH:F�IxD�h�0yD��z�A������D���(:�xO�� ��$�F��(���@F��/!��� �����CF.!������/*���+�*�����9�@F��V�x��HxD���HAFxD����������$������@F����!ph����hJ�O�� �F�(F��W�F��T��D�� ҹ�HQFxD����H9FxD����HqhBFxD�����ЌHIFxD���HxDV�8F����F�H9FxD���8F������ �HF���F�HIFxD���HF����sh[�}IyD�}IyD}HxD���ph�zIyD�zIyDzHxD���qh��wIyD�wIyDwHxD��t�sh��Zԟ�rIyD�rIyD�qIyD�qIyDqHxD��^�pHxD��~��h���j�'� � � �G:F(F����7�����B������D��p�cHxD��`��'�!i:F(F��7����"h�B����l��D��0�YHxD��H��'�`i:F���(F����7ah�B����H��D��p�PHxD��2�O�� OF �i(F� :F���7 � �h�B������D����DHxD���O�� OF��i:F(F7ID � ����h�B��6ip�(F1F��Q�F�7JzD�����D��0;�5H1FxD����
���������D���(�/HxD���� F����@F�������H���Xj������@j�������i���i��.����i���i���i���i��j��
j��j���f���f���g��hf��if���g��Pf��Qf���g��Hf��9f��Ff��Lf���g���g�����Ri������:i������"i������i��vg��6����h������h��-��AFh��F���V�������x@�ML�'���������F�)��  ��H{CxD����6��,`�������g��-��OFF
hhAih����Yh���)F2FF.HxD����F�)��*HxD��2�2�)4�)5�)�����(�#HxD����#����F���Xx��A��!0FO��������(F��������E��
7���WE���!`����O� �O� �������x��x�MF�*N�'}D~D���g���g���g��bg��Sg��-��OF�j��h%�NHxD�����x����+x��xA�
)I������
G��bDH��'xD�D���AH��FxD���?I@KyD�{D�j��iz0F��X������� �9F���XF��r�Z�;�+U� ���i� ��j���!@�=��D�F@�,I-HyD h�1xD���=��F���Ax�h��hH�!��B�"HxD��B��%��h��>�F �iBF0F�Y���� 5�h�E���%��h��*�F ��iBF0F�I����� 5�h�E�� F��T�7��B�� ����>g��Rg��!g��1g���g���g��<����[���f��s�F'H F�!�xDB|2�%HFbhxD2����"K{DXy� F��3�8�x+� F��� F���N~D�h-�HxD����N�%~D ��x� F)F����)F F�5��[�`hn�B���3�HxD�����������0��D��)�
HxD����|�|����f��f���F���xf��2����c�����.f���F!H��xDC|#� H)FxD���L(FjF�#|D�h���FH�"y����*�""��C�FP�IO��6HyD hxD�1��� �$x$�HxD����(F9F��e�&FhF��/�8F����O��60F���������e������n����e���e���LH|D$h�4xD!F��t�IJ FyDzD���!F
���H!FxD��d�H!FxD��`�H!FxD��Z�H!FxD��V�H!FxD��P�H!FxD��L�H!FxD��F�H!FxD��@�]�������e���e��f���e��f��(f��Rf��kf���f���f���f��-��OFcM�F"�!}DaL��(F����L�`KaO|D ht�D�%��DD�%��F0FQFJF��@��(s�c8(���R� 0DG��I���S�������a�������o���y�����������������������������������������������AI"yD
p������ �D���������"�D�� ��;K!{D�p������ �D�����7IbX9F����XF����(������D�����1IXFyD����"�(��.K{D�`Xtt�� �����&H�#XyDh�`��'O�Y:h�B �%M&I&J`YyDzD%�0���#K{DxI�y;�J!H�XxD�1��r���U����� �Z�#�Y9`���C;h�B��(� ����^���T����f��<���B����f��ļ����������������������t����e��Z������������e��+d������e��-��C��4N F��F~D�F�O�X����F�/KBF/I�XyD�0��:�=��! FO��r��V��(F���X��h��Z�#J%IyDF�X"F&�0�� �)�!O�D9F�C�F`����%�H:FICF0XyD�0�� ���*F�P��I:FCFpX&I�0yD�����&� F��,���T�0F ����&��F(F��$��.���������������e���e���e���e���e��-��OFpL�FpH��|D�FF'X0F;h �����( ܹ��@�hIhHaXxD�1����fI��yD�����(Sи��(�aH!xD����(�����^IyDF�]H!xD����(�����ZIyDF �ROYH�YxD�1��p�����VIyDF�
� ����0FAFJF��.�F�(�O��
������ �KHT�
xD�F�1��N����d�(b�����DHT� xD�1��>�X�F�FFO�
�!0F��v��(�Fڹ��9���t��h��x�7I2FyDF*H X�0��>�*�)F���8����0IT��yD�0���"+F�a�����FH�K'I�XyD�02F'������:F+F�K��'�'��� �@F��B�8�
IBF`XI�0yD����8F � h�B��XF��4�������
��������������be���e��ye��pe��we��qe��ye���e��ve��pe��Re��Pe��Ge��<e��0���
FF#���0���@�<��)F
�<�����0�8�FF�h"������ F����(` F����h` F�����` F�����` 8��FF�h"F����X� F7h����� F����/`h` 7`��FF�h"F���x� F7h���� F���h` F���/`�` 7`�-��O�Fh���FE� ��*�)F "F��z��
� ZF���F�(����� "������� ����������������F�(s��� �������%a����'a�ea����fa���ХaeD������.��%��a�%F�]��BQ� iQF3F���HF��q�5�F�(G�����
���B
�aiHF3F��QF��^�5�F���%�.FG�]���
���B
ҠiQF;F6BHF��^� 5�F���%�.FG�]���
���B��iHF;F6JQF��H� 5�F�� FDF��� F ����O���%F�]��𵍲 F^��_X�h��qh �K{D�)F�#F��
��G��b��7�FF��G�IJ+FyDzDF�� ���� F���0@����b���b���FF���h��h8�jQ� 0���F����X��������-��O�F���K�F{Dh�
FFh|n�n�nzc�h|`�`�`�F;`��j�*�������
�!
��O�� O�� F��d���G�������� ��a��t�xa����o���*�����F8n���O�
�I� yDN�;�� �
�����������$������5��$�����*�RE���""�(�B��F2�HF���Y��&2�0F���l����0D+�J+�
��
���P�O�
c`P�! ����`���s��8�F���������iF���a�� ��܀�R�*
DG����)���5�����������?��{��������������������D��Yx)ܚA�*����
���L����A�
��x��*A�1�A����
���A�BQ�ZA��[yA�qxi�aAya�������*���JEp��hc�� ��9��hIFBF#F���h���0F�����O� � D� ������x��hB�hS�"�jP�! ���F���X�)�ۺ�����0F��������� ���"�� ��� R�����]�������E!��hY�� ��03���BF�hIF#F��U�� �!��4�����?�*����B�c`X�Zh������{�(� �!�� ��s��

!PF��P�!�DPF��P�{i
�{hza�+?���hAF�G�(?�����h�hQ�����(���#F�h1F��
�6)��B��8hzkh�B�����<�F����������a���bA`�k��`Kl��`Km�a�m�Ba�l��aKn��a k�bpG��pG�F� FF���"j�  :��@���o)-��AF
FF
�UI UJ�$yDzD����O��3��4 ��<�F�(���!4"���LI0F"yD�����(/�II0"yD����p�py3yEI���yyDDJ�zD�y� ���c�&`0F)F"F����([�!h�h��h�B��� �9I 9J��yDzD+F���I� F1F��{�fh0F���(?��'�0F���F�h�B �,I-JyD��zD ��v�,���������@F��e�F��$��B �#I#J��yDzD ��`��3j�B �I JyD��zD��R��3nK�I JyDzD��H�O��3���#XB�, �� ���� F�$��>� F����Z^��=_��2_�����^��_���]���^���]���^��l]���^��R]���^��:]�� _��8@�P L�C�B�!A�@0pG8��i�ii�E� FF���*!F��8@���-��GEh���FF�i�B��� }�+��DI DJyDzD����HFm�+����� F�����D_�?I ?JyDzD����0F[����B4��!!�B,��!�������� �&���B4��!!�B,��!�Q��,I���+J yDzD���:�q�I�B�zb#�I�B� �#I����#JcF��yDzD ���#�b���ARF����� ٲ��zD IF�����p�0Fh J�B�� ����I JyDzD��`�� ��PKLCPAMRDNEA`\��]^��F\��/^��<\��U^���[��^���[��^��l[��A^��K{DS� �pG��r���8�FCh
F#��B��h���x-����# `c`8�(F����!�8�FFh�B�Yh)��!�Y``pG�Ǹ-��O�FhBhO� ��i��:��0F+��j��Q���ѰF�%'
��E F5��������T�?EE���� F�����J�9HF������P('�{�'��G F7�����F(FYF����XF��.�-GE��) � F�����F(F���������������� L�"��|D$h��� !h!�����F����!�#h�B����"��������"` $�`�� ��i��h ��j�C`�h�`��hF�h�B�Ah�B�2���`pGO��0pG�F����CF�#hh��@��>�� ���s�Fh�h�B,��$$�B��D�L��B,��$$�B�� FD��p�M�L�}D��|D� )F"F��D�� �� |���<Y���h���
F hF
K�{D!F2F����X��#F��\��3��C�B��.`����h��8��KF F{D��� �#h��O�� 8�!�4K(F{D"F����(� F� 8����h��~h��8��KF F{D��� �#h��O�� 8�!�4K(F{D"F��z��(� F� 8���[h��6h��� K"F{D��i��(��$ F�&h��A��B�F>��(1��(_�+��('�R�(,�)�(+а�_J�)�B���B6� �A��B(�$۳��_'�B� cE8�%�B��B*�&�2�B)�2�B,�(� � � � � �@ �� �O�p�O��p�O�`�O��`�O�P�O��P�O�@�O��@�O�0�O��0�I JyDzD��^�� � �hW��Sg��-��A�eKF"FF{D�����(��wh�/*з��_��r�,hi$m�B �[I[J\KyD��zD[H{D�xD�^���уB�VIWJyDzD-�21O��F�B����,aзh�/+з��_o�E�FO��)h h��X�`E �HIIJIKyD��zDHH{DxD,��� уB �EIEJyDzD�� ����DF8�24�B���,2��h�./ж��_O���'F)h h��X�`E�7I8J8KyD��zD7H{DxD���� �����$�_��B �1I<F1J��yDzD �����24�B����F F����)K��(F!F{D��F��(���"1FO�F��"K��(F!F{D��6��(���"O�F��K��(F!F{D��'��(���#'F����g��W��g��/g��<g���V��Eg���V���f��"g��2g���V��>g��VV��Zf���f���f��,V���f���e���e���e����%���F,F3�hSWY[h6m�B�IJKyDHzD{D��xD� ���@� ����fE �I J#FyDzD��2�� �#�F5&��F�
I
JyD��zD��"���4�B�� ����8U��<e��f��f��U�� f���T��f���F���&Q�hh�m�B�*I+J+KyD+HzD{D��xD� ������Uh K��4�$�B �"I "J3FyDzD����� -�L,@�� ���I J+FyD��zD��o Ñ"h��I J+FyDzD���� F�hC�I JyD��zD�����6 2�B�� ��
�������T���d���e���e��lT���e��JT���e��0T���e��T���e��K��{D��F F��"��%h�-��2h��3l�B�IJKyD��zDL{D� |D���n�� �B8F����' K�E0F{D"9F�����#�(�������e���S���c���e���e���e���� "K��"FF{D
F�����(5�3h/hl�B �IJKyDLzD{D��|D
�hq
ІB �IJKyDLzD{D��|D���(iBНk�B�IJKyD��zDH{D�xD� �$��
���F F���� c��S��c��_e��7e���R���b��Re��e���R���b��Be��Te����K��"FF{D
F��y��(0�3h/�l�B �IJKyDLzD{D��|D�n��l�B �IJKyDLzD{D��|D �mh�k�B�IJKyDLzD{D��|D� �����$��F F��Hb��NR��Rb���d��sd��2R��6b���d���d��R��b���d���d����K��"FF{D
F����(/�3h/�l�B �IJKyDLzD{D��|D�n��B �IJKyDLzD{D��|D �mh�k�B�IJKyDLzD{D��|D� ���T��$��F F�����a���Q���a���c���c��|Q���a��fd���c��`Q��da��:d���c���� K��"FF{D
F�����3h/h�k�B �IJKyDLzD{D��|D �mhl�B�IJKyDLzD{D��|D� �����$��F F�����`���P���`���c��fc���P���`���c���b��s�F��BFFѲ)<� R�"I��@y���R�/�E�I JyDzD����(F-�0x�B�qx 9�I JyD��zD����1x��L �O� [) ��# ���I JL#yD��zD��� F� I JyDzD���� |����HP��nc��*P��bc���O��ec���O��xc���
��h��#��09F���@�F�,|�II IJyDzD��r��B�FI FJyDzD��h�}�F�K&�.a����```````BB�,U�:I :JcFyDzD��L�b�8I 8J#FyDzDX�Sx�����.�3I3JyDzD7�x�����*�/I/JyDzD��?�?F�2B����B"�)I)JyDzD�Vx�����+�%I%JyDzD 3F"���?F�Z��~,�IJyDzD �5��%@��qeE���F��A�I J+FyDzD�����$ F���O��1c��|O��.c��DO��c��2O��9c��O��8c��O�� c���N��c���N���b���N���b��~N���b��-��C���hF��
�#)F��0�G��@$��I�JyDzD
��)F
��9��@�F<��I�JyDzD ���8��?.٠I �JCFyDzD���!��)F
����@$��I�JyDzD�砱1h8�k�BӖI�J�KyD��zD�H{DxD� ���h��$�7���'GE��O�� O��x��{� /������
� ���m�`�`������� ���)F
�������)F
������)F
�����0�+��@EQ��)F
����0�+��p�2h8�k�B �mImJnKyD��zDmH{DxD���)F
����0�+���(��4h8�k�B��bIbJcKyD��zDbH{DxD���)F
����0�+y�@Ey� ��)F
��x��0�+l�@Eٍ��i��)F
��i��0�+]�p�3h8�k�B �KIKJLKyD��zDKH{DxDP��)F
��O��0�+C�p�1h8�k�B �BIBJCKyD��zDBH{DxD6��)F
��5��0�+)��(*�2h8�k�B$�8I9J9KyD��zD8H{DxD��)F
����0{���4h8�k�B �0I0J1KyD��zD0H{DxD�F��� ��@D�,I ,J;FyDzD��b���(?��� F�����M���b���M��wb���M��sb���M��pb���M���]��gb��sb���L���\���a���a���L���\���a���a��,L��0\��7a��a���K���[��a���`���K���[���`���`���K���[���`��{`��nK���`��-��O���J�F��hzDhȈ F6hz`��F���{b�5#������ �����v��~FE��I �JyDzD����(F*�AO��p�BÙžI �J3FyDzD���h��0�i3 ���
�� ��C
����2�������P���hO��
#ya�v:a����� �)F�;b�n��~F"��I�JyDzD����1���?فI�JyDzD���(ȿO�� �CBO� ���L���F���;��� �)F���~"�tIuJyDzD�����0l�B�qL��|DqIqJrHyD�zDxD#F� ��^��)F� ������~F!�hIiJyDzD\��h��8�B�eIfJyDzD^����ܻ���� �)F����F�~ �]I]JyDzD=��h�B�[I[JyDzDA�
�
;j����E���o�@F���g��hHF���5QK�E{D�����5��)F����(R��"F�FF�� �X���KE�������BICJyDzD ����C��� �SE�>I?JyDzD �����!�F\� �E�1�B�ӱBHF�6I 6J[FyDzD����"����02 � �E
�0I 0JcFyD����zD�������E���� � �����zj����B��� ����&��,�F�����.���fJ���_��HJ���_���I��<_���I��3_���I��_��_��pI��tY���^��DI���^��0I���^��I���^���H���^���^���H���^��pH���^��DH��p^��"H��d^��(K�{D�F F�����(5� �f����B�h�!I3F!J��yDzD �+
كB�IJ��yDzD ��:���/���0F��� �4�0C�I JyDzD��&�� �(F!F����@�����7
K�(F�G{D2F����(������:W��6G���]�� G���]���F���]���]��s�B�F F�i h�S�8��i#�hih�j���*F���0U�+��&h���3F���^�)��(F1F�b��(
�I J+FyD��zD����� �� |���HF��]��� KF"F
F{D��U���3h-h�k�B� I J KyD LzD�{D |D�������$��F F�p����U��F�� V���\���X��s�F�@��h����F@�!I !JyDzD��� F9�(F!h"i#��#�F �IJyDzD�ah�#bi(F���(F�h#�i��`�F8�IJyDzD ��b��(F�h�i�#��P�&F8�
I
J.FyDzD��P� F������0F|��E���\���E���\��pE���\��JE���\�� h�Ci
i�Jh"�CiJihi
�h�Ci�i��h2�Ci�ih[i3�2�pGO��0pGKh�@i
ii�h
��h+�@i
iCi3�2�pGO��0pG-��O�� F���F��&��D�H�a�C���FN����kh@�B��� (FBFSFIF��}��(B��;3�"I "JyD��zD �4�F�B���(FAF�GohX�IFJ yD3FzD������8F"���h�B
�I J3FyD��zD���� ������(i!F���6<F�����B����` ������ \��ZD���[��6D���[��D���[���F�BF
F� �
��I J+FyD��zD�B �I J#FyD��zD��p�� ��! ��O��2)F
�"F����@��X��C���[���C���[��-��OF��hHxD�h�����h��eIfK�DyDza{Dx`�`�`z�bK{D7�bK{D4�aK{D1�aK{D.�`K{D+�+h�Fl����2P ���!��!��

� HF�������O��<#O�� !F��(FBF�h�����������FF2�KK{D"
� �#O��>!F�� @BF(F�h�DK"{D� O��1��BF�(F�!F �!�"O��3(F���!FBF[F����F�8I 8J�$yDzD�����L�5I 5JyD3�zD������$ 6
��:�����$yh Fzi h�B3�0�3�A���h�B���س�_��+?�r��+?�h�?�i���+?�n���i�+��k���_���A��B��2�B�э�B��B��Q�B�ѝ���
���F���È'������
��g ������!��k
����o���
�����VB��AR��DB���Z���Fh�� ��n�n�B%D,��$$�B(�D�L�I J;FyDzD��L�� �
���B� ��9F��9�X�3h �B�I JyDzD��6� F��BA���Y��A���Y���FF@i h����F��FH�
I
J+FyDzD��� F��ik�h0h�B �IJ��yDzD ���� ��0���@���Y���@���Y���FF@i �����F�n�F �IJyDzD �xiqh���F�:�F@�IJyDzD +F������i���2��B��
� ��I J�$yDzD������ F�Xhth�B����Y�s��B����|@���Y��`@���Y��6@���Y���FF@i ���x�F�.�F �"I#JyDzD �q�xi��j�F�,�F@�IJyDzD +F���"�xiqh��K�F���F �IJyDzD���i���2��B��
� ��I J�$yDzD��h��� F�Xhth�B����Y�s��B�����?���X���?��)Y���?���X��z?�� Y��-��O�����
�
�FRF�AF$��@����`&�8I9JyDzD�+hl�B �6I6J7KyD��zD6H{D�xD�7��AFRF���`�F�&H�.I/JyDzD ���E��AFRF�����F����'I 'JNFyDzD����1�)h��8�pE�"I"J#KyD#NzD{D��~D���� �&�����d��B
�I3FJ&F��yDzD ����
�(F���R�?�(��$^F�/�����F0F ����?���X���>���N���S��}T���>���X���>���X���>���N���S��oS��X>��`X��p�M
KF*F F{D��3�#x+ � I JyDcxzD���� p�0F)F��p@��=�p�X���=��X��xKJp���{DF�����(����F�;��[-��΀��� ���)�)�1���8�������������������1�8�����������<�W�q���q���������#�\I]JyDzD�2���+ �YIZJyDzD ��+�WIXJyDzD��X ���+�TITJyDzD��Z F�����$h�k�B��NIOJOKyD��zDNH{DxDL�+�LIMJyDzD��Z F�����&h4l�Bn�GIHJHKyD��zDGH{DxD2�+�EIFJyDzD��Z F����#hm�BT�@IAJAKyD��zD@H{DxD�+�>I?JyDzD��Z F����"h�m�B:�9I:J:KyD��zD9H{DxD� ����)�#�5I6JyDzD~� F��x��#�2I3JyDzDt� F��`��૱/I/JyDzDi�+�-I.JyDzDb�-I -J+FyDzD���� ����p��W��(=���W��=���W��=���W���<���W���<���L���Q���Q���<���W���<���L���Q��%R���<��dW��f<��jL��qQ��<M��P<��JW��2<��6L��=Q��qM��<��$W���<��*W���;��3W���;��>W���;��LW���F���h
�#��0����@��IJyDzD �(F����>F�@� I
JyDzD ����F�.��� F�p����:���V���:���V����ʿ ��a� pG-��GFF����1hA��F(i�����(S�����7FO�� �����ii:ii0�20CE?�yiA�(i � �6�7�(6��E����,1���������'ji hSi3�0��E!�(iA�ah7��ر4OE��ı�h���&ji hSi3�0AE �(iA�ah6��(�4�B����$��F F���-��CF�@��h����F(F!F��R�#hF��PB���+{�ii;'i�X:i7�0�B��O�� p����s�ii;gii�X0�7������@� :����� #�� �hiY�Ci3�1 �� ����@� ?���и������B�(i��8 � ����8��(�сF���� � '�� �iiY��Ji2�00�JBB� ?���и������B�(i��8 �������(�сF�� F���������HF����O� ch��PG����-��G�%�FF�����F$/F>�X�B���������(9�������0�j�Sx+Ý'x)� l��Ý'������C�3
�y)� ȿRyC�LSȿC�sd��B
�
I
J��yDzD;F��� F�5�$FUE���0����� 8���S��� FFT�k�%�8iA�h���5��B#F����FF���-��GF����F@iAF��[�F���F �qIqJyDzDI�i"�O�X��Q�( BB��A�(��hI hJ;FyDzDp�(iA��h��[��(��(iB�qi��R��(��(iO��R�i��I��(��(iB��i��@��(�𞀱hK�hi���F����F@�OIPJyDzD ;F��.���hji�+>��j� �P��O���4� �Hhi������F���F �@IAJyDzD����E��#� �C �"��� �B��@�B �hi����5I6JyDzDF �����$M�2�B��3SE�ӳi7h#�ih���!@�=���F��!F(F���F F��d����BBB�����?�G�?�I JyDzD������si7hñlh(F���������� L����?�D�<�I JyDzD����� ��F F������7���S��t7��uS�� 7��.S���6��S���6���R��26���R���5��R��-��CF F�� h@i��A��hA��F(i��n��(s�ahhi��A�"F������z��(g�ki6J�i�O��iF����������OF���� � Fp�x'�+I,JyDzD�8F1F�"��V��(��B���pG�%I %J7FyDzD��4�7��i�+0�Xhch�B�I JyDzD ��&�(�#�oi�iF��5���������~�����F����A�j Ð…B ���I J�'yDzD������ ��F8F
����������85���Q��5���Q���4���Q���4���Q��I"�yD��F����Fx�hxIJ��yD�xzD+x��x� ����� �N/"~D8F1F���쨱8Fq"����x�hy I
J��yD�yzD+y��y� ��� F�� ��zQ��P4��eQ��]��4��^Q��-��O��F F ��! "��P�0F����(���3j�BڲI�JyD��zD?����I �JyD��zD��z���I�JyD��zD.�j�I�j�B2k�n�nШI �JyDzD��d���
����K �{D�����(��
��Kd{D ������(@�:���Ip �JyD��zD ��@��p+��ڂ�I �Jp%yD��zD��4���tYr�I ��B��n@�̂z����������B�sEÓ&lsqauo;I�JyD����zD�� �j�EÓ‡I �J��yDzDsF��( Ù¼EÙƒI � �JyDzD����D��4��(��L�<�
�|I|J���0yDzD v���0J��
� �,�� F������sIsJyDzDY�O�P����
�oIoJyDzDM� ����
@�� ��k��k�(��x�gIhJyDzD:� �Yl�l�*��s�cIdJyDzD.� ��l��l�+��n�_I`JyDzD"� �Xm�m�)��i�[I\JyDzD� ��m��m�,��d�WIXJyDzD
� �Xn�n�+��_�SITJyDzD ��~���QI QJKFyDzD��t���OO�!V��NM��8���8���D��D�7F��
� ���{D�����(���
�� ��;3�BI>FBJyD��zD �A���B��
� �=I>F=JyD��zD ��:��A��B��,�y�-��πj�-���򻀖���xV4UUU�3��3Q���3��HQ���3��aQ��r3��pQ��wQ��rQ��03��iQ��3��tQ���2��eQ���2��sQ���2���Q���2���Q��^2���Q��F2���Q�� 2���Q��2���Q���1���Q���1���Q���1���Q���1���Q���1���Q���Q��sO��v1������@1���Q��$1���Q��-{�l�-���_@��B���B��Ȁ�A� eE���𮀵��_��B�uE@�؀��B��B����3�B��3�B@�Ȁ��.��I�JyDzDh�D��I �J#FyDzD����
�fj�_���JP�T=zD�k�2F����!F�kC���IP�T=yDl�!F����2F[l5� ���I�lyD� ��!F��2F�l(���JP�T=zDm�2F����!F[m���IP�T=yD�m�!F����2F�m ���JP�T=zDn�2F����!F[n���d�.ЗI�JyDzD �� �[� �sk�B Ð"I �J��yDzD#F���M�
� Y��D%��� ���2F� ��!F[F/�K�!�{D��A��K{D�K{D�K{D�K{D�K"��B�{D���
�~K{D�}K{D"�|K{D"����� �!F2F��h��wI>FwJ yD+FzDL�8�� QF+FzD���� �  ��90����@�>F$�>F�$�1F(F����d� ����I�x��cI cJyDzD���aI aJ�$yDzD���
����������� FF���2j� �h :���BF���3 �RK�p �1F{D �
��$�
��������(����uk�-�,���� "FK��{DAF ������(���#�F"�F�F`� ��}��
?� ��v��
?� ��o��
?� ��h��
?� ��a��
?�HF�&�
��(�� `���@���`�B���P��ͭ��sj �o+?�̬���/���P���/���P��C���K���S����������������.���O���.���O���������������������I���u�����������2.��>���-��NO���-��vO��QO��=��0�
FI��"FyD�����I F"yD����0� F)F���0@���`x
I
J��yD�xzD#x��x� ��� �0���2-��6I��,���M���hF�;`Õ"� Qx` Ð"x2`�?�? L�3C�������?A����������x��2�x�(�O��0� �xI������FhF���� ���� ��F����+��+ �3� +��+)��+)��(���  � F�����P����o,��  �O��s@B�(�B�ܳ��_�B���O��r�B�2�B�� � � �hx�Y`H�!RxD�@P�"0B ��  pG��"z��7�F� F�"�23��x[)���*F�"��,:��F7�B9\�Ȳ(:�$I�H����<���L��,��*+�\x��#�
x/*�.*���;*��䱃�༹��Lx��8��$���""�B �S�K�#�������(��F���$ F>�����F��xر�$<(�$3��x�>* ���� � FT�Xx���8�� ����m��(����!
F��~��F����H�#x��LHB@��[+�@����F����(�!x��LXB@����F����� xV8� �B1�01� C�@pG�F� FӲ�+�C�s����D���P��p�\�b�\i�b)�����*��#�*�,�:�0�:�4�4�:�:�>�E�L�L�T�T�[�a�e�e�e�m�m�������m�����##`���!B�2!`b`���B�""`��� "`�� `��0c`��'`s���"`�xa`s�_�'`�x``��0X���!c`!`��0P���  `b`s�I� 1F��~� `_�w�'`���� #`1F��r�``S�#`q�a`��+!����K-���"bb �"I "JyDzD����@��n� &b��"�a���a�ga'a*�I JyDzD����@��W�!`s�c`��#a�1F%` ��0�1FF ��+��"*CF��#�
I
J��yDzD+F��x���z��(��"J���'��J���'���I��p�Fhe x( �ex-�f��ܥ��� ���@�0�� ��x�-@�FP�%�&ye@�p` ��B�--�#y+��!pp�p�Fh x(�e@��(�ex����-@��ܥ@�
���� ���@�0��@����x�-@�FP�%@���&ye@�p` ��B�--�#y+��!pp���-��A�FF�!"F����!"F0F����"!FF0F�����3XB@�����?�@�� � I JyDzD�-
�
I
JyDzD ����O��0������@=`�����D&���H��6&���H��𵇰
F��F����(��O��05��� �"���#����AF�����f��h��h�IJ+FyD����zD� ��� F�"�����( ���N�
I
JyDzDh ��v��,`�`h`�`� �����%���H���%���H��-��G�FL�FF @�,�co�Ro�PD"�
�� � 9FF�����t�F0�����h��� I J;FyD���zD� ��6�0F�� 4�`�`����������� %���H��7�F�h�B��hE�B ���I�hJyD�#F�zD ����$�~l�* �"",��$a��2�`�����h����h������h�O��0>����$��`H��7�F�h��h˱�h����(Ú¬h�h����h���IJ#FyD��zD� ������ �`�`>���V$��H��-��G�FNFF�F~D��l�)�HF9F"F����CF&����h+����~�h F���IJCFyDzD�� ����B �RF zD1FCF������d�,�� F����(������&$���G���#���G��-��G���M��F
��B�D���� 2$NF���0�F~D`&���O4��FO��IJF@F����BF'���,��h("���I J#FyD����zD��N� �8F�"F3F��� �-�-��(F�O��0
��C 3h��� �B��LE��������
��M���r���G��L#��wG���x���x �xC� !A�C��`pG���F��P F8�(��i�B�jQ�0 J�IJ��yDzD ����O��0��"��G���F�h�(����������� j��x�O��0�#`` `�a�a#b���-��OF��FF�F$"�!����!"%`(F����(F@�4��K�J�BԿ�F�F@F��,�F�(��'����"(F9F����B�F
�����h���I�JyDzD��P�(F1FBF����CF���p��h(��GE���h��h��l�I�JCFyDzD�� ���L���,�?�]� P)@��XF��[�@E@�퀛�� � ��� ��D�� ���M��F ����H��"�� �F���B��JF��Bs��uIvJyD���zD ;F��\�
)�qIrJyDzD ��(F9FBF����H�mImJyDzD ��>�O��5�F���g`0F�����-@𚀣i!�h�h�����0�� �F0���!�a��h���� b}�@F������`�pE�WIXJyDzD���. �E�TIUJyDzD +F���i��*�����ah�BF�NINJyD��zDP�� � �����0��!�@�"���� �L�!�@�
#AF� ���#��-�O���1�B���i�F j��<� �]� P�3P���� �-������UF#j�� ����� .2� �D���B
�(I(JyD��zD��� ����5��B��~�� � F���O��0 ������7���I JSFyD=FzD���I��������!���F���!��qF��PK\!��F��D!��4F��*!��.F��PK� ���E��� ���E��� ���E�����nE�����ZE��8�$"F FF�!����!(F
F����(����hK��� ��h8�)F"F��8@��S�O��08�-��A�FF
F����$*F!FF�� ���3����p?
��B �)F2F��*� ��P0���4�� <@��Q�4��(�ѽ����-��O��fM
�h�F}D-hF���+h��������(��!jehQ�0��#,�$ @�#��3`����"��������'�������8`������F����������������F�`HF���w������� F�E�@I @JyDzD���d��" h1F����B�F�:I :J3FyDzD3�" h�����BV���^�h+��2I3JyDzD ����^�(J�B�/I/JyDzD SF��7��6���90@�"��8�DA� ���B�%I %JyDzD��`��� �E�!I!JyD��zD ��r����B
�IJyD����zD ���F�����0� �O��0�� h�B��(���������PKm������C������C������C������C��l���C��V���C��>��D��-��O��F
F�F�����(�tI tJ+FyDzD��#� ������ F�)F�����F�(@�̀ h ���� ��B�gI gJyDzD������R�PF!h���V��(�O��0� ��$hO��@�������4�FO��@��.���8��!�(�A�F�)@�8"
���r�&�8#NN
�o�
�~DO��I��8�2F����F��0�FI FJ3FyDzD�EI EJyDzD���e��� ��D �����O4��FO��I)F�JF����AF���L��h(��NE�7I 7J3FyD����zD:�
� ��!
����(F�
� �.I���yD
��,J� �zD3F��T�!��#�(�ѳ��O
�
�PFCF
!F��}�O��B
���.����&[E
�I JyD����zD��2�O��6
�����O��6(F��� F���0F�O��0�������C��l���C��@C�����$C�����RC���C�����.C��b��#C����C��
K��BF� `C��0��Z�`����#�`�����`�� �� ����*��z�7�h|��heS�%0�B �
L
J|D��zD!F���� �hC�$h�h#� hQ`>�D���B��p��"h�h<�[U�#`�B�\��Z��h2��p��B��O��0p�7�F F�����B��(�
I
JyD��zD� I JyD��zD� #F���� �� >������6B�����UB��xG�F�������xG�F��������xG�F����།��xG�F�����Ѝ��xG�F����഍��xG�F����ฎ��xG�F�����@���xG�F�����t������t������������������̏����������������Ð'�����������8�����4����������������,����������������\������������(����:�X�����t��������� ������������������������������H�����������������L�����,����
����� ������@�����l�����ij���������D�����p������������ ������<������T���������������� �������������������������Ƽ����t����!��������ƽ�����ܽ����������D�����t���������������������������������l�����������X���
��������h�����������$������������0����� �����������`�����������$������������������������������������������������������������������������ �������x����������l�������������������P������x�����(�����d������d��������������������������d������������p�������������������������������������������@�����X������������������������������������������L������x�����@�������������������������������?�������������� 0x%04x - 0x%04x reg=%d %s %s %s
� 0x%04x line=%d
�byte�char�double�float�int�long�short�void�boolean�UNKNOWN�Optimized DEX file header:�magic : '%s'
�dex_offset : %d (0x%06x)
�dex_length : %d
�deps_offset : %d (0x%06x)
�deps_length : %d
�opt_offset : %d (0x%06x)
�opt_length : %d
�flags : %08x
�checksum : %08x
�DEX file header:�signature : %02x%02x...%02x%02x
�file_size : %d
�header_size : %d
�link_size : %d
�link_off : %d (0x%06x)
�string_ids_size : %d
�string_ids_off : %d (0x%06x)
�type_ids_size : %d
�type_ids_off : %d (0x%06x)
�field_ids_size : %d
�field_ids_off : %d (0x%06x)
�method_ids_size : %d
�method_ids_off : %d (0x%06x)
�class_defs_size : %d
�class_defs_off : %d (0x%06x)
�data_size : %d
�data_off : %d (0x%06x)
�class lookup hash table�register maps�(unknown chunk type)�OPT section contents:�(1.0 format, only class lookup table is present)
�Chunk %08x (%c%c%c%c) - %s (%d bytes)
�Trouble reading class data
�Class #%d header:
�class_idx : %d
�access_flags : %d (0x%04x)
�superclass_idx : %d
�interfaces_off : %d (0x%06x)
�source_file_idx : %d
�annotations_off : %d (0x%06x)
�class_data_off : %d (0x%06x)
�static_fields_size : %d
�instance_fields_size: %d
�direct_methods_size : %d
�virtual_methods_size: %d
� #%d : '%s'
�<implements name="%s">
</implements>
�<any>� catches : (none)� catches : %d
� 0x%04x - 0x%04x
� %s -> 0x%04x
� positions : � locals : �<unknown-index>�<no-index>�<index-varies> // thing@%0*x�%s // type@%0*x�"%s" // string@%0*x�%s.%s:%s // method@%0*x�<method?> // method@%0*x�%s.%s:%s // field@%0*x�<field?> // field@%0*x�[%0*x] // inline #%0*x�[%0*x] // vtable #%0*x�[obj+%0*x]�<?>�%06x:� ... � %02x%02x� �|%04x: packed-switch-data (%d units)�|%04x: sparse-switch-data (%d units)�|%04x: array-data (%d units)�|%04x: nop // spacer�|%04x: %s� v%d, v%d� v%d, #int %d // #%x� v%d� %04x // %c%04x� v%d, %04x // %c%04x� v%d, #long %lld // #%x� v%d, %s� v%d, v%d, v%d� v%d, v%d, #int %d // #%02x� v%d, v%d, %04x // %c%04x� v%d, v%d, #int %d // #%04x� v%d, v%d, %s� #%08x� v%d, #float %f // #%08x� v%d, %08x // +%08x� {�v%d�, v%d�}, %s� v%d, #double %f // #%016llx� ???�%06x: |[%06x] %s.%s:%s
�GLITCH: zero-width instruction at idx=0x%04x
� registers : %d
� ins : %d
� outs : %d
� insns size : %d 16-bit code units
�"true"�"false"�"public"�"private"�"protected"�"package"� #%d : (in %s)
� name : '%s'
� type : '%s'
� access : 0x%04x (%s)
� code : (none)� code -�<constructor name="%s"
� type="%s"
�<method name="%s"
�bad method type descriptor '%s'
� return="%s"
� abstract=%s
� native=%s
� synchronized=%s
� static=%s
� final=%s
� visibility=%s
�>�ERROR: bad descriptor '%s'
�ZBCSIFJD�ERROR: bad method signature '%s'
�<parameter name="arg%d" type="%s">
</parameter>
�</constructor>�</method>�<field name="%s"
� transient=%s
� volatile=%s
�>
</field>�unknown�Trouble reading class data (#%d)
�Malformed class name '%s'
�</package>�<package name="%s"
>
�Class #%d -
� Class descriptor : '%s'
� Access flags : 0x%04x (%s)
� Superclass : '%s'
� Interfaces -�<class name="%s"
� extends="%s"
� Static fields -� Instance fields -� Direct methods -� Virtual methods -� source_file_idx : %d (%s)
�</class>� (differential compression %d -> %d [%d -> %d])
� #%d: 0x%08x %s
� (no map)� (unknown format %d!)
� %4x:� %02x�No register maps found�RMAP begins at offset 0x%07x
�Maps for %d classes
�%4d: +%d (0x%08x) %s
�NOTE: method count discrepancy (%d != %d + %d)
� direct methods: %d
� virtual methods: %d
�Opened '%s', DEX version '%.3s'
�<api>�</api>�Processing '%s'...
�ERROR: DEX parse failed
�Checksum verified�Copyright (C) 2007 The Android Open Source Project

�%s: [-c] [-d] [-f] [-h] [-i] [-l layout] [-m] [-t tempfile] dexfile...
�dexdump� -c : verify checksum and exit
� -d : disassemble code sections
� -f : display summary information from file header
� -h : display file header details
� -i : ignore checksum failures
� -l : output layout, either 'plain' or 'xml'
� -m : dump register maps (and nothing else)
� -t : temp file name (defaults to /sdcard/dex-temp-*)
�cdfhil:mt:�plain�xml�%s: no file specified
�Can't specify both -c and -i
�PUBLIC�PRIVATE�PROTECTED�STATIC�FINAL�?�INTERFACE�ABSTRACT�SYNTHETIC�ANNOTATION�ENUM�VERIFIED�OPTIMIZED�SYNCHRONIZED�BRIDGE�VARARGS�NATIVE�STRICT�MIRANDA�CONSTRUCTOR�DECLARED_SYNCHRONIZED�VOLATILE�TRANSIENT�Unable to open '%s' as zip archive
�Unable to create output file '%s': %s
�classes.dex�Unable to find '%s' in '%s'
�Extract of '%s' from '%s' failed
�ERROR: filename must end in .dex, .zip, .jar, or .apk
�dex�/tmp�/tmp/dex-temp-%d�/sdcard�/sdcard/dex-temp-%d�NOTE: /tmp and /sdcard unavailable for temp files
�dex-temp-%d�Not Zip, retrying as DEX
�Zip has no classes.dex
�ERROR: unable to open '%s': %s
�ERROR: Unable to map '%s'
�ERROR: Failed structural verification of '%s'
�WARNING: unable to remove temp '%s'
��dalvikvm�Invalid debug info stream. class %s; proto %s�this�V�Z�B�S�C�I�J�F�D�Ljava/lang/Boolean;�Ljava/lang/Byte;�Ljava/lang/Short;�Ljava/lang/Character;�Ljava/lang/Integer;�Ljava/lang/Long;�Ljava/lang/Float;�Ljava/lang/Double;�too short to be a valid .dex�dey
�bad opt version (0x%02x %02x %02x %02x)�File truncated? stored len=%d, rem len=%d�ERROR: bad checksum (%08x vs %08x)�ERROR: bad opt checksum (%08x vs %08x)�ERROR: stored file size (%d) != expected (%d)�ERROR: DEX file has no classes in it, failing�Unaligned opt data area end�Undersized opt data area (%u)�Bogus opt data content pointer at offset %u�Opt data area problem for chunk of size %u at offset %u�Unknown chunk 0x%08x (%c%c%c%c), size=%d in opt data area�Bogus opt data start pointer�nop�move�move/from16�move/16�move-wide�move-wide/from16�move-wide/16�move-object�move-object/from16�move-object/16�move-result�move-result-wide�move-result-object�move-exception�return-void�return�return-wide�return-object�const/4�const/16�const�const/high16�const-wide/16�const-wide/32�const-wide�const-wide/high16�const-string�const-string/jumbo�const-class�monitor-enter�monitor-exit�check-cast�instance-of�array-length�new-instance�new-array�filled-new-array�filled-new-array/range�fill-array-data�throw�goto�goto/16�goto/32�packed-switch�sparse-switch�cmpl-float�cmpg-float�cmpl-double�cmpg-double�cmp-long�if-eq�if-ne�if-lt�if-ge�if-gt�if-le�if-eqz�if-nez�if-ltz�if-gez�if-gtz�if-lez�unused-3e�unused-3f�unused-40�unused-41�unused-42�unused-43�aget�aget-wide�aget-object�aget-boolean�aget-byte�aget-char�aget-short�aput�aput-wide�aput-object�aput-boolean�aput-byte�aput-char�aput-short�iget�iget-wide�iget-object�iget-boolean�iget-byte�iget-char�iget-short�iput�iput-wide�iput-object�iput-boolean�iput-byte�iput-char�iput-short�sget�sget-wide�sget-object�sget-boolean�sget-byte�sget-char�sget-short�sput�sput-wide�sput-object�sput-boolean�sput-byte�sput-char�sput-short�invoke-virtual�invoke-super�invoke-direct�invoke-static�invoke-interface�unused-73�invoke-virtual/range�invoke-super/range�invoke-direct/range�invoke-static/range�invoke-interface/range�unused-79�unused-7a�neg-int�not-int�neg-long�not-long�neg-float�neg-double�int-to-long�int-to-float�int-to-double�long-to-int�long-to-float�long-to-double�float-to-int�float-to-long�float-to-double�double-to-int�double-to-long�double-to-float�int-to-byte�int-to-char�int-to-short�add-int�sub-int�mul-int�div-int�rem-int�and-int�or-int�xor-int�shl-int�shr-int�ushr-int�add-long�sub-long�mul-long�div-long�rem-long�and-long�or-long�xor-long�shl-long�shr-long�ushr-long�add-float�sub-float�mul-float�div-float�rem-float�add-double�sub-double�mul-double�div-double�rem-double�add-int/2addr�sub-int/2addr�mul-int/2addr�div-int/2addr�rem-int/2addr�and-int/2addr�or-int/2addr�xor-int/2addr�shl-int/2addr�shr-int/2addr�ushr-int/2addr�add-long/2addr�sub-long/2addr�mul-long/2addr�div-long/2addr�rem-long/2addr�and-long/2addr�or-long/2addr�xor-long/2addr�shl-long/2addr�shr-long/2addr�ushr-long/2addr�add-float/2addr�sub-float/2addr�mul-float/2addr�div-float/2addr�rem-float/2addr�add-double/2addr�sub-double/2addr�mul-double/2addr�div-double/2addr�rem-double/2addr�add-int/lit16�rsub-int�mul-int/lit16�div-int/lit16�rem-int/lit16�and-int/lit16�or-int/lit16�xor-int/lit16�add-int/lit8�rsub-int/lit8�mul-int/lit8�div-int/lit8�rem-int/lit8�and-int/lit8�or-int/lit8�xor-int/lit8�shl-int/lit8�shr-int/lit8�ushr-int/lit8�+iget-volatile�+iput-volatile�+sget-volatile�+sput-volatile�+iget-object-volatile�+iget-wide-volatile�+iput-wide-volatile�+sget-wide-volatile�+sput-wide-volatile�^breakpoint�^throw-verification-error�+execute-inline�+execute-inline/range�+invoke-object-init/range�+return-void-barrier�+iget-quick�+iget-wide-quick�+iget-object-quick�+iput-quick�+iput-wide-quick�+iput-object-quick�+invoke-virtual-quick�+invoke-virtual-quick/range�+invoke-super-quick�+invoke-super-quick/range�+iput-object-volatile�+sget-object-volatile�+sput-object-volatile�unused-ff�Bad offset range for %s: %#x..%#x�data..data + size�set..set + 1�item�list..list + 1�item..item + 1�Unknown map item type %04x�Bad index: %s(%u) > %s(%u)�(item->fieldIdx)�(state->pHeader->fieldIdsSize)�Out-of-order field_idx: %#x then %#x�(item->methodIdx)�(state->pHeader->methodIdsSize)�Out-of-order method_idx: %#x then %#x�field->fieldIdx�state->pHeader->fieldIdsSize�Field in wrong list @ %d�Bogus field access flags %x @ %d�method->methodIdx�state->pHeader->methodIdsSize�Method in wrong list @ %d�Bogus method access flags %x @ %d�Unexpected zero code_off for access_flags %x�Unexpected non-zero code_off %#x for access_flags %x�pTypeList..pTypeList + 1�(pType->typeIdx)�(state->pHeader->typeIdsSize)�pType�(item->classIdx)�(item->superclassIdx)�(item->sourceFileIdx)�(state->pHeader->stringIdsSize)�(item->protoIdx)�(state->pHeader->protoIdsSize)�(item->nameIdx)�(item->typeIdx)�(item->shortyIdx)�(item->returnTypeIdx)�Invalid use of void�Shorty vs. primitive type mismatch: '%c', '%s'�Shorty vs. type mismatch: '%c', '%s'�Bogus shorty: '%c'�Bogus utf16_size�String data would go beyond end-of-file�String shorter than indicated utf16_size %#x�Illegal start byte %#x�Illegal continuation byte %#x�Illegal representation for value %x�String longer than indicated utf16_size %#x�Bogus line_start�Bogus parameters_size�Invalid parameters_size: %#x�Bogus parameter_name�parameterName�state->pHeader->stringIdsSize�idx�Bogus syntax for opcode %02x�Bogus handlers_size�Invalid handlers_size: %d�Bogus size�Invalid size: %d�Bogus type_idx�typeIdx�state->pHeader->typeIdsSize�Bogus addr�Invalid addr: %#x�Bogus catch_all_addr�Invalid catch_all_addr: %#x�tries�Out-of-order try�Invalid start_addr: %#x�Bogus handler offset: %#x�Invalid insn_count: %#x (end addr %#x)�insSize (%u) > registersSize (%u)�outsSize (%u) > registersSize (%u)�Non-zero padding: %#x�insns�Out-of-order string_ids: '%s' then '%s'�(item->descriptorIdx)�Unable to parse class_data_item�Trouble with static fields�Trouble with direct methods�Trouble with virtual methods�offset..newOffset�Non-zero padding 0x%02x @ %x�Trouble with item %d @ offset %#x�Item %d @ offset %#x ends out of bounds�Bogus offset for section: got %#x; expected %#x�Bogus size for section: got %#x; expected %#x�Cross-item verify of section type %04x failed�Bogus offset for data subsection: %#x�Out-of-bounds end of data subsection: %#x�Invalid type descriptor: '%s'�Out-of-order type_ids: %#x then %#x�Invalid descriptor for class_idx: '%s'�Invalid name: '%s'�Out-of-order method_ids�Invalid descriptor for type_idx: '%s'�Out-of-order field_ids�Bogus encoded_annotation type_idx�Bogus encoded_annotation size�Bogus encoded_annotation name_idx�Out-of-order encoded_annotation name_idx: %#x then %#x�data..data + 1�Bogus annotation visibility: %#x�Bogus byte size %#x�Bogus char/short size %#x�Bogus int/float size %#x�Bogus string size %#x�Bogus type size %#x�Bogus field/enum size %#x�Bogus method size %#x�Bogus array value_arg %#x�Bogus annotation value_arg %#x�Bogus null value_arg %#x�Bogus boolean value_arg %#x�Bogus value_type %#x�Bogus encoded_array size�Bogus encoded_array value�Out-of-order entry types: %#x then %#x�Invalid class: '%s'�Duplicate class definition: '%s'�Invalid superclass: '%s'�Invalid interface: '%s'�Duplicate interface: '%s'�Invalid class_data_item�Invalid annotations_directory_item�Shorty is too short�Shorty is too long�Out-of-order proto_id return types�Out-of-order proto_id arguments�dex
�ERROR: unrecognized magic number (%02x %02x %02x %02x)�ERROR: unsupported dex version (%02x %02x %02x %02x)�ERROR: Bad length: expected %d, got %d�WARNING: Odd length: expected %d, got %d�ERROR: bad checksum (%08lx, expected %08x)�Unexpected endian_tag: %#x�linkOff..linkEnd�dataOff..dataEnd�ERROR: Small header size %d, struct %d�WARNING: Large header size %d, struct %d�Out-of-order map item: %#x then %#x�Map item after end of file: %x, size %#x�Unrealistically many items in the data section: at least %d�Duplicate map section of type %#x�Map is missing header entry�Map is missing map_list entry�Map is missing string_ids entry�Map is missing type_ids entry�Map is missing proto_ids entry�Map is missing field_ids entry�Map is missing method_ids entry�Map is missing class_defs entry�Unable to allocate data map (size %#x)�lastOffset..sectionOffset�Non-zero padding 0x%02x before section start @ %x�Section overlap or out-of-order map: %x, %x�Multiple header items�Header at %#x; not at start of file�Multiple map list items�Map not at header-defined offset: %#x, expected %#x�Swap of section type %04x failed�ERROR: No map found; impossible to byte-swap and verify�ERROR: Byte swap + verify failed�pHeader..pHeader + 1�ERROR: Bad magic number (0x%02x %02x %02x %02x)�Invalid arg count in 35mi (5)�Invalid arg count in 35c/35ms/35mi (%d)�Can't decode unexpected format %d (op=%d)�could not determine length of file�file is empty�mmap(%d, RW, SHARED|ANON) failed: %s�mmap(%d, RO, FILE|SHARED, %d, %d) failed: %s�mmap(%d, R/W, FILE|PRIVATE, %d, %d) failed: %s�mprotect(RO) failed (%d), file will remain read-write�mmap(%d, R, FILE|SHARED, %d, %d) failed: %s�Attempted to change %p; map is %p - %p�munmap(%p, %d) failed: %s�only read %d of %d bytes�%s: write failed: %s�%s: partial write (will retry): (%d of %zd)�sysCopyFileToFile: copy read failed (%d vs %zd)�sysCopyFileToFile�Zip: invalid ZipEntry %p (%ld)�Zip: seek %ld failed: %s�Zip: read %zd failed: %s�Zip: bad offsets (dir %ld, size %u, eocd %ld)�Zip: empty archive?�Zip: cd map failed�Zip: missed a central dir sig (at %d)�Zip: ran off the end (at %d)�Zip: bad LFH offset %ld at entry %d�Zip: bad CD advance (%d vs %zd) at entry %d�Zip: EOCD not found, %s is not zip�Zip: bad local hdr offset in zip�Zip: failed seeking to lfh at offset %ld�Zip: failed reading lfh from offset %ld�Zip: didn't find signature at start of lfh, offset=%ld�Zip: bad data offset %ld in zip�Zip: bad compressed length in zip (%ld + %zd > %ld)�Zip: bad uncompressed length in zip (%ld + %zd > %ld)�Zip: extract can't find entry %p�Zip: lseek to data at %ld failed�1.2.6�Installed zlib is not compatible with linked version (%s)�Call to inflateInit2 failed (zerr=%d)�Zip: inflate read failed (%d vs %zd)�Zip: inflate zerr=%d (nIn=%p aIn=%u nOut=%p aOut=%u)�Zip inflate�Zip: size mismatch on inflated file (%ld vs %zd)�Out-of-order data map offset: %#x then %#x�No data map entry found @ %#x; expected %x�Unexpected data map entry @ %#x: expected %x, found %x�036��036��035�������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������ѝ��؝�������������������������������� ������!������&���/���ѝ��؝�����������9���F���M���U���������\��� ���������c���k���w���ѝ��؝���������������������������������� ������!������������������������������������У��Ý£�������� ������(���;���J���V���]���i���w��������������������������¤��Ô¤������������������&���2���?���L���V���g���~���������������������������Å¥��Ð¥��Û¥�������������������������� ���'���.���5���<���C���J���T���^���h���r���|���������������������������¦��ͦ��Ò¦��ܦ������������ ���������#���/���<���F���P���[���`���j���v�������������������������������ʧ��Ô§��Þ§��������������������%���0���?���L���Z���h���y�������������������Ó¨��������������������� ���*���5���A���N���\���h���v�����������������������Í©��Ý©�����������
���������"���*���2���9���A���I���Q���Z���c���l���u���~�������������������������������Ǫ��Ѫ��Ûª��������������������&���4���B���P���^���l���z����������������������Ï«��Þ«�������� ������(���7���F���U���e���u�������������������Ƭ��׬��������
������!���/���=���K���Y���f���t�����������������������í��ϭ��ܭ��������������"���1���@���V���j���~���������������̮��ܮ����� ���!���-���>���Q���]���n���������������ǯ��������
���#��������������������������������������<������p����������������������0
�����������o@������������H�� �����������
���L�����T����������%�����/�����7�����D�� �������!����������������������������������������� ������o������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������������ �������������������

    


 ������

 ���

  � ���� ��� ������

������

*****�*****��














�

*

****


����������� ��GCC: (GNU) 4.6.x-google 20120106 (prerelease)����� ������GNU�gold 1.10���A1���aeabi�'���ARM v7�
A 
 �.shstrtab�.interp�.dynsym�.dynstr�.hash�.rel.dyn�.rel.plt�.text�.ARM.exidx�.ARM.extab�.rodata�.data.rel.ro.local�.preinit_array�.init_array�.fini_array�.ctors�.dynamic�.got�.data�.bss�.comment�.note.gnu.gold-version�.ARM.attributes������������������������������������������ ���������4��4����������������������� ������H��H������������������������������L�����������������#���������T��T������������������)��� ������������0
���������������2��� ����������p��������������6���������������<�����������������;����������������p�����������������A�����p����������������������������L���������T���T���0������������������W������������������=�����������������_���������������������������������r������������������������������������������������������������������������������������������������������������������� ��� ��������������������������������������������������������������$���$���������������������������������������� ��������������������������� ��� ���$�������������������������0������� ���/��������������������������������P���������������������������p��������l���2�������������������������������������������������������