Mini Kabibi Habibi
MZ� �� � @ � � � �!�L�!This program cannot be run in DOS mode.
$ ��{���ܲ�ܲ�ܦ�ݶ�ܦ�ݰ�ܦ�ݺ�ܻ�ܑ�ܲ��?�ܦ�ݳ�ܦ�ݖ�ܦ��ܳ�ܦ�ݳ��Rich��� PE L �F�~ � ! � 8 �� �
4� @A p� D� � � � �* � D �@ T 0 � � @ �� � .text {� � `.data T � � @ �.idata v � � @ @.didat 4 � � @ �.rsrc � � @ @.reloc D � � @ B �p��k � � `� x� 2
n �= � `� �� r8
n $ *- P7 L� D ȭ2OR`J�)<� �� ]������ +H` � � P8 X8 � ���@ @� � � u 4 @G `E @G PG �G �H �I �J �J �K U @X �k �� Г �� @� � �� � � � �� � � � `� �� @� P� p� � `� �� �� � � 0� p� �� �� �� `� � � `� p� p� � 0 �
0 0 � � � � ` @ � ! 0# `# �( @- . p. �. p/ �/ �0 1 �1 �1 �4 �4 09 : �; P< �< p= > �> �> 0? @ �@ @A �A B @B pB �B �D E `F �F �H �I `J �J �J �N �Q �R �R `S �S T @T �T �T `U �U V �V �V PW �W 0X �X Y �Y �Y `Z �Z 0[ �[ �[ P\ �\ �\ ] �] @^ �^ �^ �^ �^ �^ �^ �^ �^ P` `` Pd `e �j �j �j Pk �k �l n pr �r �r �r �s t Py �� Ё � p� CRYPTBASE.dll api-ms-win-security-lsalookup-l1-1-0.dll api-ms-win-security-lsapolicy-l1-1-0.dll \ S E C U R I T Y \ L S A _ A U T H E N T I C A T I O N _ I N I T I A L I Z E D /ÿ(�8G���a�qjEntered AddCredential
Principal = %wZ
PackageName = %wZ
AddCredentials API Ret = %x
Entered QueryCredentialsAttributes
Entered SecpSetCredentialsAttributes
Credential = %I64X:%I64X
SetCredentialsAttributes scRet = %x
QueryContextAttributes
Context = %I64X:%I64X
QueryContextAttributes scRet = %x
SetContextAttributes
SetContextAttributes scRet = %x
GetUserInfo
GetUserInfo scRet = %x
EnumeratePackages
Enumerate scRet = %x
QueryPackageInfo
QueryPackageInfo scRet = %x
EnumLogonSession
EnumLogonSession scRet = %x
GetLogonSessionData
GetLogonSessionData scRet = %x
GetBinding(%x)
GetBinding scRet = %x
AddPackage
AddPackage scRet = %x
Internal Callback, request = %d
Error %x in LPC to LSA
Breaking connection for process %x
PolicyChangeNotify
PolicyChangeNotify scRet = %x
Entered ChangeAccountPassword
ChangeAccountPassword API Ret = %x
SspipProcessSecurityContext: Extra buffers with NULL input
SspipProcessSecurityContext: Extra buffers count too large: %lu vs %lu
SspipProcessSecurityContext: InputBuffer %lu changed: %lu, %p, %lu
SspipProcessSecurityContext: Too many input buffers: %lu
SspipProcessSecurityContext: Null input buffers passed
SspipProcessSecurityContext: Too many output buffers: %lu
SspipProcessSecurityContext: Null output buffers passed
SspipProcessSecurityContext: Failed RPC call: 0x%lx
SspipProcessSecurityContext: Output buffers count too large: %lu vs %lu
SspipProcessSecurityContext: Output buffer %lu too small: %lu vs %lu
SspipProcessSecurityContext: Replaced context handle %p:%p
SspipProcessSecurityContext: Failed API call: 0x%lx
GetUserName
GetUserName returned %x
@ @ @ @ @ @ D
t a r g e t n a m e Freeing local LSA alloc %x
Freeing RPC alloc %x
Freeing VM %x
Error printing message: Bad ComponentName
Error printing message
Could not open security event %ws, %x
Failed NtQueryEvent on %ws, %x
Connecting to LSA
Error 0x%08x getting LSA state
Detected HVSI Container - Enabling LSA Proxy
s s p i c l i . d l l Security DLL initialized
SSPICLI Could not get package TLS slot
Could not initialize critsec, %x
Could not initialize Logon32, %x
Could not initialize VM list, %x
Security DLL unbinding
\ D e v i c e \ K s e c D D l s a s s p i r p c n c a l r p c S Y S T E M \ C u r r e n t C o n t r o l S e t \ C o n t r o l \ L s a \ M S V 1 _ 0 D i s a b l e H o s t T o T a r g e t l o c a l h o s t Adding binding for %ws
Compare package %ws
Compare package %ws (%p)
Snapping new-style package %d, %ws
SpUserModeInitialize Snapping DLL for package %#x, %ws
Got binding info for %d : %ws
S y s t e m \ C u r r e n t C o n t r o l S e t \ C o n t r o l \ S e c u r i t y P r o v i d e r s S e c u r i t y P r o v i d e r s , SecpResolveSspiBinding: Failed loading %ws: %lu
SecpResolveSspiBinding: GetModuleFileNameW failed for %ws: %lu
SecpLoadSspiPackages SecpReadPackageList %#x
S y s t e m \ C u r r e n t C o n t r o l S e t \ C o n t r o l \ L s a \ S s p i C a c h e N a m e Bad cache entry %ws:%ws
Out of memory allocating %x
C o m m e n t C a p a b i l i t i e s R p c I d V e r s i o n T y p e T o k e n S i z e Added ANSI entrypoints for %ws
Duplicate package, %ws
Loading SSPI DLL %ws
Deferring SSPI DLL %ws
InitSecurityInterfaceW InitSecurityInterfaceA Snapping Packages from DLL %ws
Snapped wide package %ws
Added ANSI entrypoints for %s
Snapped ansi package %ws
T i m e S y s t e m \ C u r r e n t C o n t r o l S e t \ C o n t r o l \ S e c u r i t y P r o v i d e r s \ S a s l P r o f i l e s N U L L NULL LsaInitializeSecurityContextCommon failed to locate package %p : %p, error %#x -- deleting handle
LsaAcceptSecurityContext failed to locate package %p : %p, error %#x -- deleting handle
Impersonating %ws[%p]
Failed to impersonate handle %p, return %x
Failed to revert handle %p, return %x
S y s t e m \ C u r r e n t C o n t r o l S e t \ C o n t r o l \ L s a P r o t e c t e d U s e r L e v e l ChangeAccountPasswordW( %ws, %ws, %ws , ...)
ChangeAccountPasswordCommon returns %x
AcquireCredentialHandleW( ..., %ws, %d, ...)
AcquireCredentialHandleA( ..., %s, %d, ...)
AcquireCredentialsHandleCommon: Security Package %ws is manipulating dwLower value inappropriately
returned %p when %p expected.
AcquireCredentialsHandleCommon returns %x, handle %p : %p
AddCredentialsW( ..., %ws, %d, ...)
AddCredentialsA returns %x, handle is %p : %p
AddCredentialsA( ..., %ws, %d, ...)
<