<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<assembly xmlns="urn:schemas-microsoft-com:asm.v3" manifestVersion="1.0" copyright="Copyright (c) Microsoft Corporation. All Rights Reserved.">
  <assemblyIdentity name="Microsoft-Windows-NetTrace-Netsh-Helper" version="10.0.26100.8521" processorArchitecture="wow64" language="neutral" buildType="release" publicKeyToken="31bf3856ad364e35" versionScope="nonSxS" />
  <file name="nettrace.dll" destinationPath="$(runtime.system32)\" sourceName="nettrace.dll" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>KE2ZbkYAvFUVqgnsdXnJYTYyrYYLLOTei0ak1MqdXLs=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="correngine.dll" destinationPath="$(runtime.system32)\" sourceName="correngine.dll" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>7JIEutKMrnlT8oadhnkU0z/1ZSAY3QFGX6QAoeppWys=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <file name="nettracehelper.dll" destinationPath="$(runtime.system32)\" sourceName="nettracehelper.dll" importPath="$(build.nttree)\" sourcePath=".\">
    <securityDescriptor name="WRP_FILE_DEFAULT_SDDL" />
    <asmv2:hash xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#">
      <dsig:Transforms>
        <dsig:Transform Algorithm="urn:schemas-microsoft-com:HashTransforms.Identity" />
      </dsig:Transforms>
      <dsig:DigestMethod Algorithm="http://www.w3.org/2000/09/xmldsig#sha256" />
      <dsig:DigestValue>u1z7LiWH3/UUhoTP5qCFlldeyiiCwKrasa4Tl8olyz8=</dsig:DigestValue>
    </asmv2:hash>
  </file>
  <registryKeys>
    <registryKey keyName="HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\NetSh">
      <registryValue name="nettrace" valueType="REG_SZ" value="nettrace.dll" />
    </registryKey>
  </registryKeys>
  <taskScheduler>
    <Task xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task">
      <RegistrationInfo>
        <URI>\Microsoft\Windows\NetTrace\GatherNetworkInfo</URI>
      </RegistrationInfo>
      <Triggers>
        <TimeTrigger>
          <StartBoundary>2000-01-01T00:00:00</StartBoundary>
          <EndBoundary>2000-01-01T00:00:01</EndBoundary>
          <Enabled>true</Enabled>
        </TimeTrigger>
      </Triggers>
      <Settings>
        <DeleteExpiredTaskAfter>PT0S</DeleteExpiredTaskAfter>
        <UseUnifiedSchedulingEngine>true</UseUnifiedSchedulingEngine>
      </Settings>
      <Principals>
        <Principal id="Users">
          <GroupId>S-1-5-4</GroupId>
          <RunLevel>LeastPrivilege</RunLevel>
        </Principal>
      </Principals>
      <Actions Context="Users">
        <Exec>
          <Command>cmd</Command>
        </Exec>
      </Actions>
    </Task>
  </taskScheduler>
  <trustInfo>
    <security>
      <accessControl>
        <securityDescriptorDefinitions>
          <securityDescriptorDefinition name="WRP_REGKEY_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;CI;GA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;CI;GR;;;SY)(A;CI;GR;;;BA)(A;CI;GR;;;BU)(A;CI;GR;;;S-1-15-2-1)(A;CI;GR;;;S-1-15-3-1024-1065365936-1281604716-3511738428-1654721687-432734479-3232135806-4053264122-3456934681)" operationHint="replace" />
          <securityDescriptorDefinition name="WRP_FILE_DEFAULT_SDDL" sddl="O:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464G:S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464D:P(A;;FA;;;S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464)(A;;GRGX;;;BA)(A;;GRGX;;;SY)(A;;GRGX;;;BU)(A;;GRGX;;;S-1-15-2-1)(A;;GRGX;;;S-1-15-2-2)S:(AU;FASA;0x000D0116;;;WD)" operationHint="replace" description="Default SDDL for Windows Resource Protected file" />
        </securityDescriptorDefinitions>
      </accessControl>
    </security>
  </trustInfo>
  <instrumentation xmlns:ut="http://manifests.microsoft.com/win/2004/08/windows/networkevents" xmlns:win="http://manifests.microsoft.com/win/2004/08/windows/events" xmlns:xs="http://www.w3.org/2001/XMLSchema">
    <events xmlns="http://schemas.microsoft.com/win/2004/08/events">
      <provider guid="{83ED54F0-4D48-4E45-B16E-726FFD1FA4AF}" message="$(string.EventProviderName)" messageFileName="%windir%\system32\nettrace.dll" name="Microsoft-Windows-Networking-Correlation" resourceFileName="%windir%\system32\nettrace.dll" symbol="CORRELATION_PROVIDER">
        <channels>
          <channel chid="c1" enabled="false" message="$(string.DiagnosticChannel.Name)" name="Microsoft-Windows-Networking-Correlation/Diagnostic" type="Analytic" />
        </channels>
      </provider>
      <provider guid="{a148cf02-be6d-5f08-94e3-b68de60d8422}" message="$(string.ConfigurationChangeProviderName)" messageFileName="%windir%\system32\nettracehelper.dll" name="Microsoft-Windows-Configuration-Change-Monitor" parameterFileName="%windir%\system32\nettracehelper.dll" resourceFileName="%windir%\system32\nettracehelper.dll" symbol="ConfigurationChangeMonitor">
        <channels>
          <importChannel chid="chidSystem" name="System" />
        </channels>
      </provider>
      <cmi />
    </events>
  </instrumentation>
  <localization>
    <resources culture="en-US">
      <stringTable>
        <string id="EventProviderName" value="Microsoft-Windows-Networking-Correlation" />
        <string id="DiagnosticChannel.Name" value="Microsoft-Windows-Networking-Correlation/Diagnostic" />
        <string id="evtActivityStart" value="Source Provider: %1 Context: %2" />
        <string id="evtActivityStop" value="Source Provider: %1 Context: %2" />
        <string id="evtActivityTransfer" value="Source Provider: %1 Context: %2" />
        <string id="evtDummy" value="Dummy event for standard level enumeration" />
        <string id="event_EVENT_CONFIGURATION_CHANGED" value="A configuration change was made by - sid = %1; command line = %2; the calling process chain = %3, %4, %5 %6, %7, %8, %9, %10, %11, %12." />
        <string id="ConfigurationChangeProviderName" value="Netsh" />
      </stringTable>
    </resources>
  </localization>
</assembly>
