<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v3" manifestVersion="1.0" copyright="Copyright (c) Microsoft Corporation. All Rights Reserved.">
  <assemblyIdentity name="Microsoft-Windows-PerformanceToolsGui" version="10.0.26100.8521" processorArchitecture="amd64" language="neutral" buildType="release" publicKeyToken="31bf3856ad364e35" versionScope="nonSxS" />
  <dependency discoverable="no" resourceType="Resources">
    <dependentAssembly dependencyType="prerequisite">
      <assemblyIdentity name="Microsoft-Windows-PerformanceToolsGui.Resources" version="10.0.26100.8521" processorArchitecture="amd64" language="*" buildType="release" publicKeyToken="31bf3856ad364e35" />
    </dependentAssembly>
  </dependency>
  <file name="sysmon.ocx" destinationPath="$(runtime.system32)\" sourceName="sysmon.ocx" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>erq1/I/Lcf/dKCTNgbgqPyQOJxCUVyVC2ns/tJdj+fo=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="sysmon.ocx.mun" destinationPath="$(runtime.windows)\SystemResources\" sourceName="sysmon.ocx.mun" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>ltheki0tCk192peqb6OlVKp8S4U0K8iDH7u2isM8iTQ=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="wvc.dll" destinationPath="$(runtime.system32)\" sourceName="wvc.dll" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>pIAxM41Lk3LI4gUX+srzMDeEcc3zgWiYi2wOsEI2cQ8=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="wdc.dll" destinationPath="$(runtime.system32)\" sourceName="wdc.dll" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>TLiXIBMf3nEuqyDJ8juR3ARhjwieltmFV05oZIf4boI=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="wdc.dll.mun" destinationPath="$(runtime.windows)\SystemResources\" sourceName="wdc.dll.mun" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>0Gm8LCEZQX8jA2tAchV1KQf6QoRmqXrh4ZuLcGRD6jM=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="perfmon.msc" destinationPath="$(runtime.system32)\" sourceName="perfmon.msc" importPath="$(build.nttree)\MSCFiles_LN\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>AryXLHRxcendwVd1OOTqzUF4gsNAhvBC/6no8Y54maI=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="perfmon.exe" destinationPath="$(runtime.system32)\" sourceName="perfmon.exe" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>w0QFFGKq+chfGPb+OpsKmA5KVmaRD+XQ1/LoeKbNcMk=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="resmon.exe" destinationPath="$(runtime.system32)\" sourceName="resmon.exe" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>2S99MVe84F7VrVjnqHQzZyBQQ8s+tB8YT69Q7BY9Mwc=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <memberships>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories.Explorer" version="10.0.26100.8521" publicKeyToken="31bf3856ad364e35" typeName="Shortcut" />
      <categoryInstance subcategory="Performance Monitor\$(runtime.startMenu)\Programs\Administrative Tools">
        <shortCut arguments="/s" description="@%systemroot%\system32\Wdc.dll,-10025" destinationName="Performance Monitor.lnk" destinationPath="$(runtime.startMenu)\Programs\Administrative Tools" displayResource="$(runtime.system32)\wdc.dll,10021" iconPath="$(runtime.system32)\wdc.dll,-108" targetPath="$(runtime.system32)\perfmon.msc" windowStyle="normal" />
      </categoryInstance>
    </categoryMembership>
    <categoryMembership>
      <id name="Microsoft.Windows.Categories.Explorer" version="10.0.26100.8521" publicKeyToken="31bf3856ad364e35" typeName="Shortcut" />
      <categoryInstance subcategory="Resource Monitor\$(runtime.StartMenu)\Programs\Administrative Tools">
        <shortCut arguments="/res" description="@%systemroot%\system32\wdc.dll,-10031" destinationName="Resource Monitor.lnk" destinationPath="$(runtime.StartMenu)\Programs\Administrative Tools" displayResource="$(runtime.system32)\wdc.dll,10030" iconPath="$(runtime.system32)\wdc.dll,-108" targetPath="$(runtime.system32)\perfmon.exe" windowStyle="normal" />
      </categoryInstance>
    </categoryMembership>
  </memberships>
  <taskScheduler>
    <Task xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">
      <RegistrationInfo>
        <Author>$(@%systemroot%\system32\wdc.dll,-10041)</Author>
        <Version>1.0</Version>
        <Source>$(@%systemroot%\system32\wdc.dll,-10042)</Source>
        <URI>Microsoft\Windows\Task Manager\Interactive</URI>
        <Description>$(@%systemroot%\system32\wdc.dll,-10043)</Description>
        <SecurityDescriptor>O:BAG:BAD:P(A;;FA;;;BA)(A;;FA;;;SY)(A;;FR;;;IU)</SecurityDescriptor>
      </RegistrationInfo>
      <Settings>
        <Enabled>true</Enabled>
        <MultipleInstancesPolicy>Parallel</MultipleInstancesPolicy>
        <AllowStartOnDemand>true</AllowStartOnDemand>
        <DisallowStartIfOnBatteries>false</DisallowStartIfOnBatteries>
        <StopIfGoingOnBatteries>false</StopIfGoingOnBatteries>
        <ExecutionTimeLimit>PT0S</ExecutionTimeLimit>
        <Hidden>true</Hidden>
        <Priority>5</Priority>
        <UseUnifiedSchedulingEngine>true</UseUnifiedSchedulingEngine>
      </Settings>
      <Principals>
        <Principal id="Users">
          <GroupId>S-1-5-4</GroupId>
          <RunLevel>LeastPrivilege</RunLevel>
        </Principal>
      </Principals>
      <Actions Context="Users">
        <ComHandler>
          <ClassId>{855fec53-d2e4-4999-9e87-3414e9cf0ff4}</ClassId>
          <Data>$(Arg0)</Data>
        </ComHandler>
      </Actions>
    </Task>
  </taskScheduler>
  <registryKeys>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{855fec53-d2e4-4999-9e87-3414e9cf0ff4}">
      <registryValue name="" valueType="REG_SZ" value="RunTask" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{855fec53-d2e4-4999-9e87-3414e9cf0ff4}\InProcServer32">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\system32\wdc.dll" />
      <registryValue name="ThreadingModel" valueType="REG_SZ" value="Apartment" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\Software\Microsoft\PLA">
      <registryValue name="Report" valueType="REG_EXPAND_SZ" value="system\System Diagnostics" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\Software\Microsoft\PLA\Templates">
      <registryValue name="{7478EF63-8C46-11d1-8D99-00A0C913CAD4}" valueType="REG_EXPAND_SZ" value="%systemroot%\PLA\system\System Performance.xml" />
      <registryValue name="{7478EF61-8C46-11d1-8D99-00A0C913CAD4}" valueType="REG_EXPAND_SZ" value="%systemroot%\PLA\system\System Diagnostics.xml" />
      <registryValue name="{7478EF62-8C46-11d1-8D99-00A0C913CAD4}" valueType="REG_EXPAND_SZ" value="@%systemroot%\system32\wdc.dll,templates.xml" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\{7478EF61-8C46-11d1-8D99-00A0C913CAD4}">
      <registryValue name="NameString" valueType="REG_SZ" value="Performance Monitor" />
      <registryValue name="NameStringIndirect" valueType="REG_EXPAND_SZ" value="@%systemroot%\system32\wdc.dll,-10021" />
      <registryValue name="About" valueType="REG_SZ" value="{7478EF69-8C46-11d1-8D99-00A0C913CAD4}" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\{7478EF61-8C46-11d1-8D99-00A0C913CAD4}\NodeTypes">
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\{7478EF61-8C46-11d1-8D99-00A0C913CAD4}\NodeTypes\{7478EF63-8C46-11d1-8D99-00A0C913CAD4}">
      <registryValue name="" valueType="REG_SZ" value="Root Node" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\{7478EF61-8C46-11d1-8D99-00A0C913CAD4}\StandAlone">
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\{7478EF65-8C46-11d1-8D99-00A0C913CAD4}">
      <registryValue name="NameString" valueType="REG_SZ" value="Performance Monitor Extension" />
      <registryValue name="NameStringIndirect" valueType="REG_EXPAND_SZ" value="@%systemroot%\system32\wdc.dll,-10022" />
      <registryValue name="About" valueType="REG_SZ" value="{7478EF69-8C46-11d1-8D99-00A0C913CAD4}" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\{7478EF65-8C46-11d1-8D99-00A0C913CAD4}\NodeTypes">
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\{7478EF65-8C46-11d1-8D99-00A0C913CAD4}\NodeTypes\{7478EF63-8C46-11d1-8D99-00A0C913CAD4}">
      <registryValue name="" valueType="REG_SZ" value="Root Node" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\NodeTypes\{476e6448-aaff-11d0-b944-00c04fd8d5b0}\Extensions\NameSpace">
      <registryValue name="{7478EF65-8C46-11d1-8D99-00A0C913CAD4}" valueType="REG_EXPAND_SZ" value="Performance Monitor" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\NodeTypes\{99829bf6-ba10-42f1-aca1-1dcd47b9fe80}\Extensions\NameSpace">
      <registryValue name="{7478EF65-8C46-11d1-8D99-00A0C913CAD4}" valueType="REG_EXPAND_SZ" value="Performance Monitor" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{7478EF61-8C46-11d1-8D99-00A0C913CAD4}">
      <registryValue name="" valueType="REG_SZ" value="ComponentData Class" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{7478EF61-8C46-11d1-8D99-00A0C913CAD4}\InprocServer32">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\wdc.dll" />
      <registryValue name="ThreadingModel" valueType="REG_SZ" value="Apartment" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{7478EF65-8C46-11d1-8D99-00A0C913CAD4}">
      <registryValue name="" valueType="REG_SZ" value="ComponentData Class" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{7478EF65-8C46-11d1-8D99-00A0C913CAD4}\InprocServer32">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\wdc.dll" />
      <registryValue name="ThreadingModel" valueType="REG_SZ" value="Apartment" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{7478EF69-8C46-11d1-8D99-00A0C913CAD4}">
      <registryValue name="" valueType="REG_SZ" value="PerformanceAbout Class" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{7478EF69-8C46-11d1-8D99-00A0C913CAD4}\InprocServer32">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\wdc.dll" />
      <registryValue name="ThreadingModel" valueType="REG_SZ" value="Apartment" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{74b077e8-32de-40ab-be4e-65609f575459}">
      <registryValue name="" valueType="REG_SZ" value="Resource Monitor" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{74b077e8-32de-40ab-be4e-65609f575459}\InprocServer32">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\wdc.dll" />
      <registryValue name="ThreadingModel" valueType="REG_SZ" value="Apartment" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C4D2D8E0-D1DD-11CE-940F-008029004347}">
      <registryValue name="" valueType="REG_SZ" value="System Monitor Control" />
      <registryValue name="LocalizedString" valueType="REG_EXPAND_SZ" value="@%systemroot%\system32\sysmon.ocx,-144" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C4D2D8E0-D1DD-11CE-940F-008029004347}\AuxUserType" />
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C4D2D8E0-D1DD-11CE-940F-008029004347}\AuxUserType\2">
      <registryValue name="" valueType="REG_SZ" value="System Monitor" />
      <registryValue name="LocalizedString" valueType="REG_EXPAND_SZ" value="@%systemroot%\system32\sysmon.ocx,-144" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C4D2D8E0-D1DD-11CE-940F-008029004347}\Control" />
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C4D2D8E0-D1DD-11CE-940F-008029004347}\InprocServer32">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\sysmon.ocx" />
      <registryValue name="ThreadingModel" valueType="REG_SZ" value="Apartment" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C4D2D8E0-D1DD-11CE-940F-008029004347}\Insertable" />
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C4D2D8E0-D1DD-11CE-940F-008029004347}\MiscStatus" />
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C4D2D8E0-D1DD-11CE-940F-008029004347}\MiscStatus\1">
      <registryValue name="" valueType="REG_SZ" value="131473" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C4D2D8E0-D1DD-11CE-940F-008029004347}\ProgID">
      <registryValue name="" valueType="REG_SZ" value="Sysmon.3" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C4D2D8E0-D1DD-11CE-940F-008029004347}\TypeLib">
      <registryValue name="" valueType="REG_SZ" value="{1B773E42-2509-11CF-942F-008029004347}" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C4D2D8E0-D1DD-11CE-940F-008029004347}\Version">
      <registryValue name="" valueType="REG_SZ" value="3.7" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C4D2D8E0-D1DD-11CE-940F-008029004347}\VersionIndependentProgID">
      <registryValue name="" valueType="REG_SZ" value="Sysmon" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C3E5D3D2-1A03-11CF-942D-008029004347}">
      <registryValue name="" valueType="REG_SZ" value="System Monitor General Properties" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C3E5D3D2-1A03-11CF-942D-008029004347}\InprocServer32">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\sysmon.ocx" />
      <registryValue name="ThreadingModel" valueType="REG_SZ" value="Apartment" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C3E5D3D3-1A03-11CF-942D-008029004347}">
      <registryValue name="" valueType="REG_SZ" value="System Monitor Graph Properties" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{C3E5D3D3-1A03-11CF-942D-008029004347}\InprocServer32">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\sysmon.ocx" />
      <registryValue name="ThreadingModel" valueType="REG_SZ" value="Apartment" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{CF948561-EDE8-11CE-941E-008029004347}">
      <registryValue name="" valueType="REG_SZ" value="System Monitor Data Properties" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{CF948561-EDE8-11CE-941E-008029004347}\InprocServer32">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\sysmon.ocx" />
      <registryValue name="ThreadingModel" valueType="REG_SZ" value="Apartment" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{E49741E9-93A8-4AB1-8E96-BF4482282E9C}">
      <registryValue name="" valueType="REG_SZ" value="System Monitor Appearance Properties" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{E49741E9-93A8-4AB1-8E96-BF4482282E9C}\InprocServer32">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\sysmon.ocx" />
      <registryValue name="ThreadingModel" valueType="REG_SZ" value="Apartment" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{0CF32AA1-7571-11D0-93C4-00AA00A3DDEA}">
      <registryValue name="" valueType="REG_SZ" value="System Monitor Source Properties" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\CLSID\{0CF32AA1-7571-11D0-93C4-00AA00A3DDEA}\InprocServer32">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\System32\sysmon.ocx" />
      <registryValue name="ThreadingModel" valueType="REG_SZ" value="Apartment" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\PerfFile">
      <registryValue name="" valueType="REG_SZ" value="System Monitor File" />
      <registryValue name="FriendlyTypeName" valueType="REG_EXPAND_SZ" value="@%SystemRoot%\system32\wdc.dll,-10023" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\PerfFile\DefaultIcon">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\system32\wdc.dll,-10024" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\PerfFile\shell\open\command">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\system32\mmc.exe %systemroot%\system32\perfmon.msc /F &quot;%1&quot;" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\.perfmoncfg">
      <registryValue name="" valueType="REG_SZ" value="Diagnostic.Perfmon.Config" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Diagnostic.Perfmon.Config">
      <registryValue name="" valueType="REG_SZ" value="Performance Monitor Configuration" />
      <registryValue name="FriendlyTypeName" valueType="REG_EXPAND_SZ" value="@%SystemRoot%\system32\wdc.dll,-10037" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Diagnostic.Perfmon.Config\DefaultIcon">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\system32\wdc.dll,-10038" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Diagnostic.Perfmon.Config\shell\open\command">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\system32\perfmon /sys /load &quot;%1&quot;" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\.resmoncfg">
      <registryValue name="" valueType="REG_SZ" value="Diagnostic.Resmon.Config" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Diagnostic.Resmon.Config">
      <registryValue name="" valueType="REG_SZ" value="Resource Monitor Configuration" />
      <registryValue name="FriendlyTypeName" valueType="REG_EXPAND_SZ" value="@%SystemRoot%\system32\wdc.dll,-10039" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Diagnostic.Resmon.Config\DefaultIcon">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\system32\wdc.dll,-10040" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Diagnostic.Resmon.Config\shell\open\command">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\system32\perfmon /res /load &quot;%1&quot;" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\.blg">
      <registryValue name="" valueType="REG_SZ" value="Diagnostic.Perfmon.Document" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Diagnostic.Perfmon.Document">
      <registryValue name="" valueType="REG_SZ" value="Performance Monitor File" />
      <registryValue name="FriendlyTypeName" valueType="REG_EXPAND_SZ" value="@%SystemRoot%\system32\wdc.dll,-10023" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Diagnostic.Perfmon.Document\DefaultIcon">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\system32\wdc.dll,-10024" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Diagnostic.Perfmon.Document\shell\open\command">
      <registryValue name="" valueType="REG_EXPAND_SZ" value="%SystemRoot%\system32\perfmon /sys /open &quot;%1&quot;" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Sysmon">
      <registryValue name="" valueType="REG_SZ" value="System Monitor Control" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Sysmon\CLSID">
      <registryValue name="" valueType="REG_SZ" value="{C4D2D8E0-D1DD-11CE-940F-008029004347}" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Sysmon\CurVer">
      <registryValue name="" valueType="REG_SZ" value="Sysmon.3" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Sysmon.3">
      <registryValue name="" valueType="REG_SZ" value="System Monitor Control" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Sysmon.3\CLSID">
      <registryValue name="" valueType="REG_SZ" value="{C4D2D8E0-D1DD-11CE-940F-008029004347}" />
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\Sysmon.3\Insertable">
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\TypeLib\{1B773E42-2509-11CF-942F-008029004347}">
      <securityDescriptor name="WRP_REGKEY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\TypeLib\{1B773E42-2509-11CF-942F-008029004347}\3.7">
      <registryValue name="" valueType="REG_SZ" value="System Monitor Control" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\TypeLib\{1B773E42-2509-11CF-942F-008029004347}\3.7\0" />
    <registryKey keyName="HKEY_CLASSES_ROOT\TypeLib\{1B773E42-2509-11CF-942F-008029004347}\3.7\0\win64">
      <registryValue name="" valueType="REG_SZ" value="$(runtime.system32)\sysmon.ocx" />
    </registryKey>
    <registryKey keyName="HKEY_CLASSES_ROOT\TypeLib\{1B773E42-2509-11CF-942F-008029004347}\3.7\FLAGS">
      <registryValue name="" valueType="REG_SZ" value="0" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellCompatibility\InboxApp">
      <registryValue name="F2F852BA90DD4456_Performance_Monitor_lnk_amd64.lnk" valueType="REG_EXPAND_SZ" value="$(runtime.startMenu)\Programs\Administrative Tools\Performance Monitor.lnk" />
      <securityDescriptor name="SHORTCUT_REGISTRY_DEFAULT_SDDL" />
    </registryKey>
    <registryKey keyName="HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellCompatibility\InboxApp">
      <registryValue name="F2F872BD2FAC6E88_Resource_Monitor_lnk_amd64.lnk" valueType="REG_EXPAND_SZ" value="$(runtime.StartMenu)\Programs\Administrative Tools\Resource Monitor.lnk" />
      <securityDescriptor name="SHORTCUT_REGISTRY_DEFAULT_SDDL" />
    </registryKey>
  </registryKeys>
  <trustInfo>
    <security>
      <accessControl>
        <securityDescriptorDefinitions>
          <securityDescriptorDefinition name="WRP_REGKEY_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;CI;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;CI;GR;;;SY)(A;CI;GR;;;BA)(A;CI;GR;;;BU)(A;CI;GR;;;S-1-15-2-1)(A;CI;GR;;;S-1-15-3-1024-1065365936-1281604716-3511738428-1654721687-432734479-3232135806-4053264122-3456934681)" operationHint="replace" />
          <securityDescriptorDefinition name="WRP_FILE_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;;FA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;GRGX;;;BA)(A;;GRGX;;;SY)(A;;GRGX;;;BU)(A;;GRGX;;;S-1-15-2-1)(A;;GRGX;;;S-1-15-2-2)S:(AU;FASA;0x000D0116;;;WD)" operationHint="replace" description="Default SDDL for Windows Resource Protected file" />
          <securityDescriptorDefinition name="SHORTCUT_FILE_DEFAULT_SDDL" sddl="O:SYG:SYD:AIS:AI" operationHint="replace" />
          <securityDescriptorDefinition name="SHORTCUT_REGISTRY_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;CI;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;CI;GR;;;SY)(A;CI;GR;;;BA)(A;CI;GR;;;BU)(A;CI;GR;;;S-1-15-2-1)(A;CI;GR;;;S-1-15-3-1024-1065365936-1281604716-3511738428-1654721687-432734479-3232135806-4053264122-3456934681)" operationHint="replace" />
        </securityDescriptorDefinitions>
      </accessControl>
    </security>
  </trustInfo>
  <localization>
    <resources culture="en-US">
      <stringTable>
        <string id="destinationPerfmon" value="Performance Monitor" />
        <string id="destinationResmon" value="Resource Monitor" />
      </stringTable>
    </resources>
  </localization>
  <file name="Performance Monitor.lnk" destinationPath="$(runtime.startMenu)\Programs\Administrative Tools\" sourceName="F2F852BA90DD4456_Performance_Monitor_lnk_amd64.lnk" importPath="$(build.nttree)\Shortcuts\">
    <securityDescriptor name="SHORTCUT_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>z6ZYJghQitSmrpqmKbT6RzLGzUc0uAGvJ4u2j2Hi4jY=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="Resource Monitor.lnk" destinationPath="$(runtime.StartMenu)\Programs\Administrative Tools\" sourceName="F2F872BD2FAC6E88_Resource_Monitor_lnk_amd64.lnk" importPath="$(build.nttree)\Shortcuts\">
    <securityDescriptor name="SHORTCUT_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>g30/Ou/h136j3t9yxQsDGmY4ubX98nnrX71kF6TUMuo=</dsig:DigestValue>
    </asmv2:hash>
  </file>
</assembly>
