Mini Kabibi Habibi

Current Path : C:/Windows/System32/
Upload File :
Current File : C:/Windows/System32/userinitext.dll

MZ����@���	�!�L�!This program cannot be run in DOS mode.

$60�rQm�rQm�rQm�{)��RQm�f:n�pQm�f:i�wQm�rQl�>Qm�f:l�uQm�f:m�sQm�f:e�uQm�f:��sQm�f:o�sQm�RichrQm�PEd�Z܌�" (<�,�


�`A@Z�\��0���@Op@(A��X`.text�'( `.rdata�&@(,@@.data�pT@�.pdata��V@@.didat@�X@�.rsrc0�Z@@.reloc@�`@B����������������@SH��@L��$�H��M��t\L�\$p�…�t#��u"A�ȸ��M�JE��M�ZE�A��A�"I�B(H��t!I�J0H�L$0H�L$xH�L$(H��L�\$ �.3H��@[���������H�\$H�t$WH��@H�
`H3�H�D$0H�AL�I H��H�P���L��@�H�a(H�a0H�L$ �D$ H�e2D�؅�t�؁����N��L�G�H�O E�H�2D��H�L$0H3��"H�\$XH�t$`H��@_�����������H��H�L�RH�T$xL����D$0A��D$4I�BI��
H�D$8H�AH�H�AH�T$(��JH�
�=�BL�RA��BH�lB+��BI�K H�T$0�D$x�D$p�D$ H�b1DH��H���������@UH�l$�H�� H��^H3�H�EH���L��H�EE3�H���H��H�E�H���H�E�H���H�E�H���H�EH�E�H�E�H�H�E�H��tH��H��D8u����H��1��E�H���H�E�H�ExH�E�H�EpH�U�D�E�H�E�H�H�E�H��t
H��D8
u����H�p1�H�EhE3�H�E�H�E`H�D$pH�EXH�D$`H�EPH�D$PH�D$0H�U�I�҉M�H�
d]H�D$(�D$ D�E�H�E�H�D$xH�D$hH�D$X���H�MH3�� H�� ]�����������H�\$3�H�B�A����D��I;�A�W�EG�E��xKH��t&L+�L+�I�H��tA�f��t
f�H��H��u�H��H�A�HE�H��E�A��A��z�f��H��tf�H�\$A�������������L�D$L�L$ SUVWH��(3�H�B�H=���H��W�G���x;H�Z�H��H��L�L$h��H�!/D��xH�H;�wuf�,^�f�,^�z��H��tf�.��H��(_^][��������f�����������H��(L��E3�H��3�H��,D3�3�H��(H�%�,����������������������@SH�� H��-DL�D$0��H��H�b-D��t-H�L$0H�e,DH�L$0��H��,D�;�t3�H�� [��������̄���H�\$UH��$P���H��H�`[H3�H���H��H��.H�L$HH�.DH�d$`H�D$HW�H�D$hL�D$X�D$X0���D$p@H�L$@�D$xH��-D����H�(/H�L$HH��-DH�d$`H�D$HW�H�D$hL�D$X�D$X0���D$p@H�L$@�D$xH�p-D��y`H�h/H�L$HH�L-DH�d$`H�D$HW�H�D$hL�D$X�D$X0���D$p@H�L$@�D$xH�-D��xVH�L$@H�-DA�L�E��BH��H�U+D�d$(H�M�H�8`A�E3�fD�D$ 3��,H���H3��H��$�H�İ]����������H��H�XH�pH�x UH��X���H��H��YH3�H�����H�D$HH��H�D$ H�+/H��A�E3�H�+D3���u6H�L$HH�+DH�y_H�
J/E3ɉt$(E3�f�t$ 3�,H�D$HA�E3�H�D$ H�	YH��H��*D��uiH�L$HH�D$DH�D$(L�L$PH�D$@�D$DE3�H�D$ H�RYH�{*D��u�|$Pu�|$Dt�t$@H�L$HH�L*D�D$@��ƉD$@��uIA�L�E��AH��H��)DH��^H�U�E3ɉt$(H�
�.�D$ E�A�%+��H������H�t$xH�D$x�L$XH�D$`E3�H�D$hE3�H�D$03҉L$(H�L$XH�t$ H�,wD��t@L�T-3ҹH��)DH��H��tH��H��)DH��H��(DH���H3��L��$�I�[I�s I�{(I��]������������H�\$WH�� ��H��H��'D��H��H�\$0H�� _������������H��H�X�PWH��@3��@�H�XH�@H��H�D$ E3�H��-D�KH��H��(D��t2��[H�L$`H�D$0H�D$(L�L$XE3�H�|$ H��-H�}(D��u�|$Xu�L$0H��f�\O��H�L$`H�K(D��H�\$PH��@_������������������@SH��H�PVH3�H��$p3�H�L$@A�,3��BH�D$0��H�D$(L�L$@D�C�D$ ,3�H�ruD��t��$��CE؋�H��$pH3��H�Ā[����������������������@SH�� 3�L�	-�JH��'DH��H��tH��H��'DH��H��&DH�� [�����������H��H�XH�pH�xL�` UAVAWH������H��PH�?UH3�H��@E3�H�M�3�A��E�Gd�13��E�hH�D$pE�OH�D$T�D$TH�D$0L�},H�E0W�H�D$(H��,H��L�|$ D$`H��&DH�T��E�gE�w�����T$TL��,H�M0�L�����yOH�
�,H�n'D�=�S��H�E�H�D$(H��3�D$ H�
�SE3�E3�������H�
�,H�'DD9%ySv4H�D$P�|$PH�EH��4H�E�L�eH�D$(E3�E3�D�t$ H����H�D$`E3�H�D$HH�U0H�E�E3�H�D$@3�L�|$8L�|$0D�|$(D�|$ H�a%D��u{H��$D��H�
S,H�|&DH��$D����=�R��H�`$DL�eH�m3�D$PH��H�D$PH�EH�E�H�D$(D�t$ ���E3�L�
#,3�A�PH�V%DH��H��uf�=ZRvSH�),H�EH�EH��#DE3�L�e(�D$PH�2H�D$PE3�H�E H��H�E�H�D$(D�d$ �I��`�D9%�QvSH��+H�E'H�EH��#DE3�L�e(�D$PH��2H�D$PE3�H�E H��H�E�H�D$(D�d$ ���H��$DD9%�QL��v9H��+H�E/H�EH�h2H�E�E3�H�D$(E3�H���D$ ���H��H�$D����=teH��"D��H�
�+H��$D�=Q��H��"DL�eH�u1�D$PH�D$PH�EH�E�H�D$(�D$ �9H�
+H�P$D��=�Pv+H�E�H�D$(H�&0�D$ E3�E3�H������@�D9%sPv]H��#DE3�H�EI+�L�e(H�D$XH�J0H�D$XE3�H�EH��@�ƉD$PH�D$PH�E H�E�H�D$(D�d$ �X�H��H��!DH�L$`H��tH��!DH�L$hH��tH��!D@��H��@H3��L��$PI�[ I�s(I�{0M�c8I��A_A^]�����������H��H�XH�pH�xUH�h�H��H�*PH3�H�EG3�H�E�H�D$0L�A*H�E�}�H�D$(H��'�wH�|$ D�O�u�H��H��!D�M�L�E���H�}�H�.EωM��H�(oD�U�D�OH�M�D����tfD;	uD9It@��A;�uA�ً�N��vOH�E�D�E�H�E'H�
�NH�E�L�M/H�E7E3�H�E�U�H�D$(H��0E3��t$ H�u?���H�M���NH��td��vS�H��/f�E�E3�H�E�H�E/H�E'E3��AH�
HN�E�H�E�H�E7H�EH�D$(�t$ H�u?�k�H�M�H�DnD��H�MGH3���L��$�I�[I�sI�{ I��]�����������������H��H�XH�pH�xUATAUAVAWH�����H��H�cNH3�H���E3�A�A��L�d$XE��L�d$HL�d$PD�d$@D�d$A�����tg�����u^H�
x(H�� D�=UMv+H�D$`E3�H�D$(H��,E3��D$ H�
-M�l�3�3�H�]D2��H�D$A��L�L$@H�D$ L�D$PH�T$HH��lD��u#L�t$HM����H�
0(H�a D�L9d$H��D8d$@u�H�DDA����H�L$PH�����H�U�D��H��D��u`H�T$PH�E�H+�H�M�H�����H��t�
f��tf�H��I+�u�H��H�A�HE�fD� uH���у�zH��DA���TH�M�H�2D��L�u�@��u5eH�%`H�T$PD���H�
�'H�gD�E�{��H����9��������H���D��H���H��D��uNH���H���H+�H���H�����H��t�
f��tf�H��I+�u�H��H�A�HE�fD� �
���H�&RH���D�d$(E3�E3�fD�l$ 3����uH�
�&H��D�D$A��D�l$(H��Qf�E3�f��E3�f��3�f�L$ H�L$H�q@��L�t$H�F�{�H�RDD������u���@���)L�d$0H�D$XD�l$(E3�E��H�D$ 3ҹ�I��H�pD3�L���A�L9d$Xtc��H�<D�؅�t<��@H��DH��H��tL�L$XL����L�t$ H�����H�L$XH��D�N��H��D�؅�tl��@H��DH��H��tE��L�t$ L����H������t.H��t)A�E3�H��3�H��DH��H�/DH�L$HH��iDH�L$PH���+���H�liD����H�L$PH��tH�QiDA��H���H3���L��$�I�[0I�s8I�{@I��A_A^A]A\]����������@SH�� H�
�O3�H��O�KRH�D��tDE3�H�
�$3�H��DH��H��t$H��$H��H�fDH��t	���#H��H�� [�����������H�\$UH�l$�H��H��HH3�H�EO�H�|D���3�H�VDH��H�'Df;�����H�t$���E'�
E$E3���E3�f�E+H���/$�EGH�E�H�D$@H�E�H�D$8H�d$0E�\$(�#�d$ �M?E/H�D���QH�M�H�E/�D$(H�UA�H�D$ E3��E�1�E�3H��DH�M�H��DH�E�E3�H�D$@H��#H�E�E3�H�D$8H��H�d$0�\$(�d$ H��D����H�M�H�E�H�D$(L�MH�E�E�E3�H�D$ H��#H�,D��u%H�EL�E�L+��F�A+�u	H��E��u��uLH�M�H�E��D$(H�#A�H�D$ E3�H��D��uE3ɍH[E3�3�H�_DH�M�H��D�H�MOH3���	H��$�H��]�����������������H��8�=-G��H�D$XA�E3�H�D$ H��"H��H�'D��ub!D$@L�L$PH�L$XH�D$HH�D$(H�'#H�D$@�D$HE3�H�D$ H��D��u
9D$@���MLH�L$XH��D�%�F�/LH��8�����������H�\$WH�� H��3��,�����tVH��H�
�"��E3�3�H��DH��H��t0H��"H��H��DH��t��H��H��D��H�\$0H�� _����������������������H�\$H�t$WH��H�7EH3�H��$eH�%`L�\"3�H�L$`D����SK�F�����H���H�T$`H��H��DH�\$@H�D$XH�D$8�{H�\$0H��"�|$(E3�E3��\$ H��H��D��ukH�L$XH�`DH�D$PE3�H�D$@H�T$`H�D$XE3�H�D$8H��H�\$0�|$(�{�|$ H�BD��uH�L$XH�
D9|$PDߋ�H��$H3��WL��$I�[I�sI��_������������������̸�����������H��(��t��u0H�
,C���"H�
>CH�%6C�%CH�HD�H��(����������@SH�� Hc��L����I¹H��f9Ht�f9Hu�HP�P�3�3�H�D$PA�A�H�ӉI��H�D��t;�H��х�t�€<\t��u���ʸ;�t+��QD��H�H���
�H�� [����������H��H�XH�pH�xUATAUAVAWH��8���H��H��BH3�H���H��D�M�E3��U�H�
IA��E��M��D��H��DH��HH��tH9;t	H�[H��u�H��uM� �J H��DH��H����H�8H��DH�
�H-a��CL�{H�KH��H�C�CH�xD+C=`��8H�^D�CL�M�H�E�H���H�D$ �=���E3��E�D����t H���H;�r�U�H�H;�v	H;�w+��A��M��uE��H���ID�L��{��H�
A�a�3Ʌ���9
�@�����D�q�E��'A���E�Ȓ'ND���E��i��E�E�T���tJD��L�����H��DBD5�I��A�M��I�FA�E�D#�M�L#�u�D�}�D��L�M�E3�3�H�M���E3�u$H�M�E3�3�H�PDH�M���AE��D�m�H�
Q@3��)@H�B@H�#DH�
G@�b�E3�����E����='@�NH�@H� @�7H�@H#�H;@� ���H�n�E�E���E��E��C�E��C�E�H���HD�D�u�H�E�H��!A�lju���L�e��}���E�
!M�A���!E�H�E�H�D$xH�E�H�D$pH�E�H�D$hH�E�H�D$`H�E�H�D$XH�E�H�D$PH�E�H�D$HH�E�H�D$@H�E�H�D$8H�E�H�D$0H�E�H�D$(H�E�H�D$ ���H�=?�;H�@H�
?�$H�?H#�H;�>�
�CH�^�E��C�E�A���D�u�A�lju�ɉ}�#M��؉M�H�E�H�Ex�H�Ep#M�H�E�H�E`E��H�E��M�H�EPH���H�E��E�
H�E@HD�H��H�EhH�EXH�EHH��D8u���H�M0�E8H�� H�E�D�E<H�E H�
$>H�E�H�E(H�EE3�H�E�H�EH�EH�E�H�E�H�E�H�D$(�D$ H�EH�E����H�
�=3���=H��=H��DE3�E��t��t��H�)DE3�D�CH�
DH��DH���H3���L��$�I�[0I�s8I�{@I��A_A^A]A\]�����������H��8H�L$8L�X�d$ D�ʺ�j���H��8����������H��8H�L$8A��E3�D�L$ 3��@���H��8����������������H��8�jL�
�
L�`�D$(H�T$ H��H�
E��H��
DH��8�����������ff�H;
�<uH��f����u�H���B������@SH�� H��3�{
H��z
�,H�Ⱥ	�H�� [H�%��������H�L$H��H�
�=�_H��>H�D$HE3�H�T$PH�L$H�0H�D$@H�|$@tBH�D$8H�D$XH�D$0H�D$`H�D$(H�g=H�D$ L�L$@L�D$HH�T$P3��
�#H��=H�H�0>H��=H��H��=H�>H��<H��$�H��=�_<	��Y<�c<�Hk�H�
[<H��Hk�H�
C<H�\;H��Hk�H�
(<H�I;H��Hk�H�
-;H�Lh�Hk�H�
 ;H�LhH�
\
�[���H�Ĉ�������%�
������%
������H�*Z�H�L$H�T$L�D$L�L$ H��hfD$ fL$0fT$@f\$PH��H�
�"�v���foD$ foL$0foT$@fo\$PH�L$pH�T$xL��$�L��$�H��h���������H��Y�H�L$H�T$L�D$L�L$ H��hfD$ fL$0fT$@f\$PH��H�
("���foD$ foL$0foT$@fo\$PH�L$pH�T$xL��$�L��$�H��h���������H�,Y�u���������H�"Y�c���������H�Y�Q���������H��X�?������������H��(M�A8H��I����H��(��������@SE�H��A��L��A�L��tA�@McP��L�Hc�L#�Ic�J�H�C�HH�C�Dt�D���L�L3�I��[�1���������%�������%������������������������������ff���pq�r��p��C��C��C�uAD�.e eFeZeje~e��8f f�b�bN`�a�aba�a�e`bDb�aha�`r`�a�b�`^`2b�`�`Rb:`a0a�a�b�brb�e�aa�`Ba�effzaRab�e�`�a `�e�f�f�d�de
e�7��7���PP� " '�'*�*`+�,�,�3@4�7pACRYPT32.dllWINSTA.dll\Registry\Machine\System\CurrentControlSet\Control\GraphicsDrivers\DetectDisplay\Registry\Machine\System\CurrentControlSet\Control\GraphicsDrivers\NewDisplay\Registry\Machine\System\CurrentControlSet\Control\GraphicsDrivers\InvalidDisplayRasAutodialNewLogonUserCLSID\{16d12736-7a9e-4765-bec6-f301d679caaa}%SystemRoot%\System32\RunDll32.exe %SystemRoot%\System32\rover.dll,RunMonitorvmappletSoftware\Microsoft\Windows\CurrentVersion\Runctfmon.exeShellDesktopSwitchEventShellAppRuntimeSOFTWARE\Microsoft\Windows NT\CurrentVersion\WinlogonShellAppRuntime.exeUSERINIT: StringCchCopy failed
USERINIT: RegGetValue failed with error: %d. Setting default value
USERINIT: CreateProcess failed with error: %lu
UserInitExt.dllLocal\ShellStartupEventCouldnt open the eventCreated ShellStartupEvent successfullyWaiting for ShellStartupEvent to get triggeredUSERINIT: ShellAppRuntime did not launch within 5 minutes
USERINIT: An error occurred while waiting on ShellAppRuntime to start: %lu
EnableShellAppRuntimeUSERINIT: Logging off session since LaunchShellAppRuntime failed! 
USERINIT: Logging off session since WinStationGetInitialApplication failed! 
USERINIT: Failed to set working directory %ws for SessionId %u
USERINIT: Failed to start ctfmon.exe in TS Single App mode ! 
imm32.dllImmDisableIMEctfmon.exe /nSoftware\Microsoft\Windows\CurrentVersion\RunonceKeyboard Layout\ToggleHotkeySystem\CurrentControlSet\Control\Terminal ServerTSAppCompattsappcmp.dllTermsrvCheckNewIniFilesSoftware\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\%dSoftware\Microsoft\Windows\CurrentVersion\Explorer�?,�3?M���g1
��<unknown>Z܌(T@Z܌
p@T@@Z܌$�V�BZ܌�V�BETW0��+���LaunchShellAppRuntime�LaunchShellAppRuntime�LaunchShellAppRuntimeI�LaunchShellAppRuntimeShellAppRuntimeReadyTime
functionReturnValue
+�LaunchShellAppRuntimemsglasterror�*�LaunchShellAppRuntimeGetLastError()*�LaunchShellAppRuntimeGetLastError()�LaunchShellAppRuntimemsg+�LaunchShellAppRuntimemsglasterror�*�LaunchShellAppRuntimeregReturnValueG�LaunchShellAppRuntimepropertyValue->TypepropertyValue->u.ulValL�LaunchShellAppRuntimewinStationReturnValue�regEnableShellAppRuntime@�AssertWithArgsassertVersionrvatimestampimageSizeimageNamecounttotalHitsoriginatingBinarybucketArgument1bucketArgument2ModuleCollectionGlobalCollection@uAssertassertVersionrvatimestampimageSizeimageNamecounttotalHitsModuleCollectionGlobalCollection��g�јS���S
FY&Microsoft.Windows.Security.UserInit�$m�F���
�Ur%TelemetryAssertsPOω�G�����v��|��v�N����[�z+TelemetryAssertDiagTrackRSDSy���!FҠD�-i���userinitext.pdbGCTL`.text`�$.text$mn�7.text$mn$00@(.rdata$brc(A�.idata$5�C.00cfg�CX.gfidsD.giats D`.rdata�O.rdata$zETW0�O�.rdata$zETW1|S�.rdata$zETW2T.rdata$zETW9T�.rdata$zzzdbg�V�.xdata�X@.didat$2�X .didat$3Y@.didat$4HY�.didat$6�YH.didat$7@Z�.edata\|.idata$2�].idata$3�]�.idata$4 `�.idata$6p�.data$brc�p�.datapq8.bss��.pdata�@.didat$5��.rsrc$01���.rsrc$02 y���!FҠD�-i���q���*zJ��HZ܌4Bp
`P0r0d4rp070�B20.4YVP07�/	tYdX4WTP07�

4
2p4
rp	0007p7
&�q&tp&do&4n&j��P07@)	td4P07�7
&t &d&4&����P07� 4P07�b$d%4$"p077
&t\&d[&4Z&T����P07�$P07��0 D�v�Y�Y0D�v�YZHY�YtY�Y�Y\Y�CryptProtectData1WinStationFreeMemoryeWinStationQueryInformationW<WinStationGetConnectionProperty2WinStationFreePropertyValueAWinStationGetInitialApplicationZ܌�ZhZ�Z�Z`+� 'P*P� "�*��'�,�Z	[&[0[D[T[u[�[�[�[�[�[	
USERINITEXT.dllCreateExplorerSessionKeyDisplayMessageAndExitWindowsImmWorkerIsSubDesktopSessionIsTSAppCompatOnLoadRemoteFontsAndInitMiscWorkerPerformXForestLogonCheckProcesRemoteSessionInitialCommandProcessTermSrvIniFilesSetShellDesktopSwitchEventSetupHotKeyForKeyboardLayoutUserinitExt�_.`XC�^chB^&c�A�^Pc@B�^zc(B�^�cB�_�c(C�]�c`A@_d�B@^&d�A�_FdC0^jd�AX^�d�A _�d�B�_e�C�]�e(Ax_PfC�]rf�A�]�fpA.e eFeZeje~e��8f f�b�bN`�a�aba�a�e`bDb�aha�`r`�a�b�`^`2b�`�`Rb:`a0a�a�b�brb�e�aa�`Ba�effzaRab�e�`�a `�e�f�f�d�de
ei_vsnwprintfmsvcrt.dll%RegQueryValueExW
SetLastErrorGetCurrentProcessExpandEnvironmentStringsW$GetUserDefaultLangIDEventUnregisterRegGetValueWRegOpenKeyExW1OpenProcessToken6WaitForSingleObjectLocalAllocOpenEventW.RegSetValueExW	RegDeleteTreeWCreateEventWEventSetInformation	FormatMessageWGetTickCount64GetLastErrorRegCreateKeyExW)SetEventCloseHandleLoadStringWEventRegisterSetCurrentDirectoryWGetProcAddressLocalFree	EventWriteTransferCreateProcessWFreeLibraryRegCloseKeyLoadLibraryExWRtlCaptureContext
RtlLookupFunctionEntryRtlVirtualUnwindUnhandledExceptionFilterSetUnhandledExceptionFilterPTerminateProcessapi-ms-win-core-registry-l1-1-0.dllapi-ms-win-core-errorhandling-l1-1-0.dllapi-ms-win-core-processthreads-l1-1-0.dllapi-ms-win-core-processenvironment-l1-1-0.dllapi-ms-win-core-localization-l1-2-0.dllapi-ms-win-eventing-provider-l1-1-0.dllUSERENV.dllapi-ms-win-core-synch-l1-1-0.dllapi-ms-win-core-heap-l2-1-0.dllapi-ms-win-core-sysinfo-l1-1-0.dllapi-ms-win-core-handle-l1-1-0.dllapi-ms-win-core-libraryloader-l1-2-0.dllapi-ms-win-core-rtlsupport-l1-1-0.dll�NtOpenKeyrRtlInitUnicodeString�NtClose"DbgPrintntdll.dll�MessageBoxW�SystemParametersInfoWiGetKeyboardLayoutExitWindowsEx�GetSystemMetricseLoadRemoteFontsUSER32.dll�toupperGetModuleFileNameAEventProviderEnabled$ReleaseSRWLockExclusiveAcquireSRWLockExclusiveGetTickCount-SleepResolveDelayLoadedAPIDelayLoadFailureHookapi-ms-win-core-synch-l1-2-0.dllapi-ms-win-core-delayload-l1-1-1.dllapi-ms-win-core-delayload-l1-1-0.dll�memmove�memset�S��S��S�2��-�+�] �f��System\CurrentControlSet\Control\Session Manager\Memory ManagementTempPageFile��V�;�VD�W�[`Xd��V�n�V��W�% W,�(WF@WP`W�@lWP�xW�; WD[ �Wd "�W "'�W '�' W�'*�W*�*X�*L+`W`+�,X�,-W-�- W�-'38X03X3X`3�3X�3�3X�3�3xX484 W@4�5|X�5R6�Xf6�6�X07M7WT7�7�X�7�7�X�5�7��6��6�	7�Z6��� �8�P�h�	�	�h�����MUI�4VS_VERSION_INFO��
4aJ
4aJ?StringFileInfo�040904B0LCompanyNameMicrosoft CorporationfFileDescriptionUserInit Utility Extension DLLn'FileVersion10.0.19041.3636 (WinBuild.160101.0800)8InternalNameUserInitExt�.LegalCopyright� Microsoft Corporation. All rights reserved.HOriginalFilenameUserInitExt.DLLj%ProductNameMicrosoft� Windows� Operating SystemDProductVersion10.0.19041.3636DVarFileInfo$Translation	�����ʛY
�]9TK�(�g�*$$��D[��v�������MUIMUIen-US@��h�������������p�@�x����� �(�0�