????

Your IP : 216.73.216.136


Current Path : C:/Windows/System32/
Upload File :
Current File : C:/Windows/System32/userinitext.dll

MZ����@���	�!�L�!This program cannot be run in DOS mode.

$�Cˉ�"�ڛ"�ڛ"�ڒZ6څ"��R�۝"��R�ۘ"�ڛ"���"��R�ۜ"��R�ۚ"��R�۝"��RZښ"��R�ۚ"��Rich�"��PEd�u��k�" 0��)�


��`APW�Y|�0�t�HNp@8HA@�U`.text6 0 `.rdata�"@0@@@.data@pp@�.pdatat��@@.didat@��@�.rsrc0��@@.relocH��@B��������q�^�=�H�\$WH��@L��$�H��M��tfH�\$p�…�t#��u"A�ȸ��M�KE��I�[E�A��A�#I�C(H��t+I�p�^�=�I�K0H�L$0H�L$xH�L$(H��H�\$ �3H�\$PH��@_����������H��H�L�BH�T$xE3���D$0A��D$4I�@I��
H�D$8H�._H�H�$_H�T$(��JH�
�=L�B�BA�E3��BH�j@+��BH�
�^H�T$0�D$h�D$p�D$ H��1DH��H�������������L�D$L�L$ SVWAVH��(H�B�3�L��H=���v�W�H��t8f��3H�r���H��L�L$hH��1D��xH�H;�wu��z�fA�v��H��(A^_^[�����������f�����������q��60�H��(L��E3�H��3�H�r/D3�3�H��(H�%N/��������������q0R^G'�@SH�� H�30DL�D$0��H��H�"0D��t-H�L$0H�%/DH�L$0��H�j/D�;�t3�H�� [��������̄���H�\$UH��$P���H��H��]H3�H���H��H�l1H�L$HH��0DH�d$`H�D$HW�H�D$hL�D$X�D$X0���D$p@H�L$@�D$xH�T0D����H��1H�L$HH�,0DH�d$`H�D$HW�H�D$hL�D$X�D$X0���D$p@H�L$@�D$xH��/D��y`H��1H�L$HH��/DH�d$`H�D$HW�H�D$hL�D$X�D$X0���D$p@H�L$@�D$xH��/D��x`H�L$@H��/DA�L�E��BH��H�.DA�I�p�Sb�ؓ�d$(H�M�H�XbE3�3�fD�D$ �_/H���H3��H��$�H�İ]��������H�\$H�|$UH��$`���H��H��[H3�H�����H�D$PH��H�D$ H��[H��A�E3�H��-D��ujH�L$PH�D$DH�D$(L�L$HH�D$@�D$DE3�H�D$ H��[H��-D��u�|$Hu�|$Dt�d$@H�L$PH��-D�D$@�3��D$@��uTA�L�E��AH��H��,DI�p
�|k�	Ѓd$(H�U�H�aH�
�0E3��D$ E�A�.��H����H�d$xH�D$x�H�D$`H�D$h�L$XH�D$0E3ɉL$(E3�H�d$ H�L$X3�H�#zD��t@L�;03ҹH�-DH��H��tH��H��,DH��H��+DH���H3���L��$�I�[I�{ I��]���������������qC�z����H�\$WH�� ��H��H��*D��H��H�\$0H�� _�������������H��H�X�PWH��@3��@�H�XH�@H��H�D$ E3�H��/D�KH��H��+D��t2��[H�L$`H�D$0H�D$(L�L$XE3�H�|$ H��/H��+D��u�|$Xu�L$0H��f�\O��H�L$`H�{+D��H�\$PH��@_����������q0R^G'�@SH��H��XH3�H��$p3�H�L$@A�,3��>H�D$0��H�D$(L�L$@D�C�D$ ,3�H�bxD��t��$��CE؋�H��$pH3��.H�Ā[��������������qH�V�>�@SH�� 3�L��.�JH��*DH��H��tH��H��*DH��H��)DH�� [�����������H��H�XH�pH�xUAVAWH������H��PH��WH3�H��@E3�H�M�3�A��E�Fd�13��E�hH�D$pE�NH�D$T�D$TH�D$0L�Q.H�E0W�H�D$(H�f.H��L�t$ D$`H��)DE�~�؅����L$TA����H�A�I;��UL+�L�
�.H�E0L+�H�U0I�H��tA�f��t
f�H��H��u�H��H�B�HE�fD�0���H�
�.H�*DD9=~Vv.H�D$P�\$PH�EH��6H�E�L�}H�D$(�D$ ��H�D$`E3�H�D$HH�U0H�E�E3�H�D$@3�L�t$8L�t$0D�t$(D�t$ H��(D����H��'D��H�
:.H�c)DH��'D���/�=�U��H��'DL�}H�|5�D$PH�D$PH�EH�E�H�D$(�D$ �BH��tfD�u0H�
V-H��(D�=kU�qH�E�H�D$(H�:4�D$ ����OE3�L�
�-3�A�PH�$(DH��H��u]�=UvJH��-H�EH�EH��&DH�P4L�}(�D$PH�D$PH�E H�E�H�D$(D�|$ �p�������D9=�TvJH��-H�E'H�EH�g&DH��4L�}(�D$PH�D$PH�E H�E�H�D$(D�|$ ����H�x'DD9=\TH��v0H�H-H�E/H�EH�@4H�E�H�D$(�D$ ����H��H�'D����=taH��%D��H�
_-H�`'D�=�SvzH��%DL�}H�Z3�D$PH�D$PH�EH�E�H�D$(�D$ �9H�
�,H�
'D��=�Sv"H�E�H�D$(H�2�D$ �	��@�D9=YSvTH�`&DH�O2H�EH+�L�}(H�D$XH�D$XH�E@�ljD$PH�D$PH�E H�E�H�D$(D�|$ ��H��H��$DH�L$`H��tH��$DH�L$hH��tH��$D@��H��@H3���L��$PI�[ I�s(I�{0I��A_A^]��q�T���H��H�XH�pH�xUATAUAVAWH������H��@H��RH3�H��0E3�H�D$pH�D$0L�,A�L�d$hH�D$DL�d$PH�D$(H�d)H��L�d$XA�}D�d$@E�M�|$pA��D�d$AE��D�d$DL�d$ H��$D�L$DL�D$`��L�d$`H��/AẺL$D��H��qD�T$DD��H�L$`��tfD;)uD9itA��A;�uA�݋�QA�A;�vGH�D$B�T$tH�E�H�Z2H�D$tD�D$BH�E�H�E�H�D$(�|$ L�m�H�}����H�L$`�9QH��t\A;�vK�H��1f�D$HH�D$HH�E�H�E��A�D$xH�D$xH�E�H�E�H�D$(�|$ H�}���H�L$`H�qD��tY�#�����uPH�
�*H�5$D�=�PvH�E�H�D$(H�^/�D$ �6�3�3�H��!D2��
H�D$A��L�L$@H�D$ L�D$XH�T$PH�hpD��u#L�t$PM����H�
z*H��#D�L9d$P��D8d$@uA��H��!DA����H�L$XH�����H��D��H�'"D��ufH�T$XH��H+�H��H�����H��t�
f��tf�H��I+�u�H��H�A�HE�fD� uH���у�zH�5!DA���bH��H��!D��L��@��u5eH�%`H�
�)H�T$XD���H��"D�E�{��H�� ��������H�UD��H�� H�4!D��uHH�� H�EH+�H�MH�����H��t�
f��tf�H��I+�u�H��H�A�HE�fD� �
���I�p�Sb�ؓH�UH�MD�d$(E3�E3�fD�l$ 3�
"��uH�
2)H��!D�D$A��f�f��fA�I�p�Sb�ؓH��TE3�D�l$(E3�f�L$ 3�H�L$P��!@��L�t$P�F�{�H��DD���R�����u���@����L�d$0H�D$hD�l$(E3�E��H�D$ 3ҹ�I��H��D3�L�EA�L9d$h����H��D�؅�t9��@H�\DH��H��tL�L$hL�E�L�t$ H����H�L$hH�0D��t.H��t)A�E3�H��3�H��DH��H��DH�L$PH�-mDH�L$XH���h���H�mD�W�����H��D��t���@H��DH��H���n���E��L�t$ L�E�H������U���H�L$XH��tH��lDA��H��0H3��oL��$@I�[0I�s8I�{@I��A_A^A]A\]�������qi�g�P�@SH�� H�
�R3�H��R�KRH�pD��tNE3�H�

'3�H��DH��H��t.H�'H��H��DH��tI�p�Vuy����YH��H�� [���������q0R^G'�H�\$UH�l$�H��H��KH3�H�EO�H��D���3�H��DH��H��Df;����"H��&�!��E'�
e&E3���!E3�f�E+H���O&�EGH�E�H�D$@H�E�H�D$8H�d$0E�\$(
&�d$ �M?E/H�HD���QH�M�H�E/�D$(H�UA�H�D$ E3��E�1�E�3H�,DH�M�H�$DH�E�E3�H�D$@H�&H�E�E3�H�D$8H��H�d$0�\$(�d$ H��D����H�M�H�E�H�D$(L�MH�E�E�E3�H�D$ H��%H��D��u%H�EL�E�L+��F�A+�u	H��E��u��uLH�M�H�E��D$(H��%A�H�D$ E3�H�BD��uE3ɍH[E3�3�H��DH�M�H�D�H�MOH3��aH��$�H��]���������q0R^G'�H��8�=�I��H�D$XA�E3�H�D$ H�%H��H��D��ub!D$@L�L$PH�L$XH�D$HH�D$(H�G%H�D$@�D$HE3�H�D$ H�KD��u
9D$@���OH�L$XH�ID�%]I��NH��8���q�4�/ȱH�\$WH�� H��3��,�����t`H��H�
�$��E3�3�H�GDH��H��t:H��$H��H�9DH��tI�pH�V�>��H��H�
D��H�\$0H�� _����q0R^G'�H�\$H�t$WH��H�HH3�H��$eH�%`L�|$3�H�L$`D����SK�������H���H�T$`H��H�DH�\$@H�D$XH�D$8�{H�\$0H��$�|$(E3�E3��\$ H��H��D��ukH�L$XH��DH�D$PE3�H�D$@H�T$`H�D$XE3�H�D$8H��H�\$0�|$(�{�|$ H�rD��uH�L$XH��D9|$PDߋ�H��$H3���L��$I�[I�sI��_�����������q0R^G'Ӹ���q:_0#�@�H��HH��FH3�H�D$0��������H�=tFH�UF@��D$ t�J�)W�L�
RFL�+FH�4�H�L$ �?FH�@D��uEL�F�PH�
FE�H�D�"H�
�EH�%�E�%�EH��D�H�L$0H3��H��H��������H�\$H�L$UH��H��`H�eL�E�ڹH�S#H�tD��tiH�MH��t`H�C#H�lDH��tHH�
C���E�H�M�H�M�e�H�M�H�
�H�M��E��E��]�I�p
R0'��H�M���H�\$xH��`]��������@UH��H��`H�eL�EH��"�H��D��teH�MH��t\H��"H��DH��tDH�
����E�H�M�H�MH�e�H�MЃ��M�M��E��E�I�p
R0'��H�M���H��`]����������������q�����H��8�B"L�
�L�8"�D$(H�T$ H��H�
��H��DH��8�����������ff�H;
)DuH��f����u�H���B������@SH�� H��3�{H��b�H�Ⱥ	�H�� [H�%q�����H�L$H��H�
E�GH�FH�D$HE3�H�T$PH�L$H� H�D$@H�|$@tBH�D$8H�D$XH�D$0H�D$`H�D$(H��DH�D$ L�L$@L�D$HH�T$P3���#H�:EH�H��EH�)EH��H�EH�wEH��CH��$�H��D��C	���C��C�Hk�H�
�CH��Hk�H�
�CH��BH��Hk�H�
�CH��BH��Hk�H�
�BH�Lh�Hk�H�
�BH�LhH�
,�[���H�Ĉ�������H�b�H�L$H�T$L�D$L�L$ H��hfD$ fL$0fT$@f\$PH��H�
�'���foD$ foL$0foT$@fo\$PH�L$pH�T$xL��$�L��$�H��h���������H��a�H�L$H�T$L�D$L�L$ H��hfD$ fL$0fT$@f\$PH��H�
 '����foD$ foL$0foT$@fo\$PH�L$pH�T$xL��$�L��$�H��h���������H�a�u���������H�
a�c���������H�a�Q���������H��`�?������������H��(M�A8H��I����H��(��������@SE�H��A��L��A�L��tA�@McP��L�Hc�L#�Ic�J�H�C�HH�C�Dt�D���L�L3�I��[�I���������%}�������������������������������������������������ff�����������������������ff��%Zq��q�8@p��C��C��C�u�D��C��C��C��a�ab"b�a6b���bjbl_]�_D^r^�]�^Tb_�^�^�^ ^F]*]�^]�]�^�_T^�]�\p]�]�]
_>_*_X_f^�]�]�]2^
^^]�^�^�\�b�a�a�a�a�/�0��/�00�00��
 
`
`

p
�#
`$
�&
�'
 (
p)
�)�+p,�/�ACRYPT32.dllWINSTA.dll\Registry\Machine\System\CurrentControlSet\Control\GraphicsDrivers\DetectDisplay\Registry\Machine\System\CurrentControlSet\Control\GraphicsDrivers\NewDisplay\Registry\Machine\System\CurrentControlSet\Control\GraphicsDrivers\InvalidDisplayRasAutodialNewLogonUservmappletSoftware\Microsoft\Windows\CurrentVersion\Runctfmon.exeShellDesktopSwitchEventShellAppRuntimeSOFTWARE\Microsoft\Windows NT\CurrentVersion\WinlogonShellAppRuntime.exeUSERINIT: StringCchCopy failed
USERINIT: RegGetValue failed with error: %d. Setting default value
USERINIT: CreateProcess failed with error: %lu
UserInitExt.dllLocal\ShellStartupEventCouldnt open the eventCreated ShellStartupEvent successfullyWaiting for ShellStartupEvent to get triggeredUSERINIT: ShellAppRuntime did not launch within 5 minutes
USERINIT: An error occurred while waiting on ShellAppRuntime to start: %lu
EnableShellAppRuntimeUSERINIT: Logging off session since LaunchShellAppRuntime failed! 
USERINIT: Logging off session since WinStationGetInitialApplication failed! 
USERINIT: Failed to set working directory %ws for SessionId %u
USERINIT: Failed to start ctfmon.exe in TS Single App mode ! 
imm32.dllImmDisableIMEctfmon.exe /nSoftware\Microsoft\Windows\CurrentVersion\RunonceKeyboard Layout\ToggleHotkeySystem\CurrentControlSet\Control\Terminal ServerTSAppCompattsappcmp.dllTermsrvCheckNewIniFilesSoftware\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\%dSoftware\Microsoft\Windows\CurrentVersion\Explorer�?,�3?M���g1
��ntdll.dllMicrosoftTelemetryAssertTriggeredUMu��k(�Q�Qu��k
p�Q�Qu��k$TTu��k<T<TETW0��+���LaunchShellAppRuntime�LaunchShellAppRuntime�LaunchShellAppRuntimeI�LaunchShellAppRuntimeShellAppRuntimeReadyTime
functionReturnValue
+�LaunchShellAppRuntimemsglasterror�*�LaunchShellAppRuntimeGetLastError()*�LaunchShellAppRuntimeGetLastError()�LaunchShellAppRuntimemsg+�LaunchShellAppRuntimemsglasterror�*�LaunchShellAppRuntimeregReturnValueG�LaunchShellAppRuntimepropertyValue->TypepropertyValue->u.ulValL�LaunchShellAppRuntimewinStationReturnValue�regEnableShellAppRuntime��g�јS���S
FY&Microsoft.Windows.Security.UserInitRSDS���u0=0���ߓ�userinitext.pdbGCTLP.textP�.text$mn06.text$mn$00@H.rdata$brcHA@.idata$5�C(.00cfg�CX.gfidsD.giatsDx
.rdata�N.rdata$zETW0�N�.rdata$zETW1EQ7.rdata$zETW2|Q.rdata$zETW9�Q�.rdata$zzzdbg@Tx.xdata�U@.didat$2�U .didat$3V@.didat$4XV�.didat$6WH.didat$7PW�.edataYh.idata$2�Z.idata$3�Z@.idata$4�\.idata$6p@.data$brc@p�.dataq@.bss�t.pdata�@.didat$5��.rsrc$01���.rsrc$02 ���u0=0���ߓ�Ѡ��^��@'�u��kB�
p`0

4

rp�B20.4YVPH/�+tX4WTPH/�

4
2p4
rp	00H/p3"tp"do"4n"j��PH/@7
&t�&d�&4�&�����PH/0 4PH/�b$d%4$"pH/�H/04�P		�P��0Dpv�VW Dxv�(VWXV�V�V�V�VlV�CryptProtectData1WinStationFreeMemoryfWinStationQueryInformationW=WinStationGetConnectionProperty2WinStationFreePropertyValueBWinStationGetInitialApplicationu��k�WxW�W�W (��#`�&` p�'`$p)XX6X@XTXdX�X�X�X�X�XY	
USERINITEXT.dllCreateExplorerSessionKeyDisplayMessageAndExitWindowsImmWorkerIsSubDesktopSessionIsTSAppCompatOnLoadRemoteFontsAndInitMiscWorkerPerformXForestLogonCheckProcesRemoteSessionInitialCommandProcessTermSrvIniFilesSetShellDesktopSwitchEventSetupHotKeyForKeyboardLayoutUserinitExt�\�\HC�[�_�B[�_�A�[``B�[2`HB�[``0Bp\�` C�Z�`�A8\�`�B8[�`�A`\�`C(["a�AP[DaB\na�B�\�a`C�ZHbHA�Z�b�A�Z�b�A�a�ab"b�a6b���bjbl_]�_D^r^�]�^Tb_�^�^�^ ^F]*]�^]�]�^�_T^�]�\p]�]�]
_>_*_X_f^�]�]�]2^
^^]�^�^�\�b�a�a�a�av_vsnwprintfmsvcrt.dll%RegQueryValueExW
SetLastErrorGetCurrentProcessExpandEnvironmentStringsW$GetUserDefaultLangIDEventUnregisterRegGetValueWRegOpenKeyExW3OpenProcessToken6WaitForSingleObjectLocalAllocOpenEventW.RegSetValueExW	RegDeleteTreeWCreateEventWEventSetInformation	FormatMessageWGetTickCount64GetLastErrorRegCreateKeyExW)SetEventCloseHandleLoadStringWEventRegisterSetCurrentDirectoryWGetProcAddressLocalFree	EventWriteTransferCreateProcessW
FreeLibraryRegCloseKeyLoadLibraryExWRtlCaptureContextRtlLookupFunctionEntryRtlVirtualUnwindUnhandledExceptionFilterSetUnhandledExceptionFilterTTerminateProcessapi-ms-win-core-registry-l1-1-0.dllapi-ms-win-core-errorhandling-l1-1-0.dllapi-ms-win-core-processthreads-l1-1-0.dllapi-ms-win-core-processenvironment-l1-1-0.dllapi-ms-win-core-localization-l1-2-0.dllapi-ms-win-eventing-provider-l1-1-0.dllUSERENV.dllapi-ms-win-core-synch-l1-1-0.dllapi-ms-win-core-heap-l2-1-0.dllapi-ms-win-core-sysinfo-l1-1-0.dllapi-ms-win-core-handle-l1-1-0.dllapi-ms-win-core-libraryloader-l1-2-0.dllapi-ms-win-core-rtlsupport-l1-1-0.dll�NtOpenKey~RtlInitUnicodeStringNtClose"DbgPrintntdll.dll�MessageBoxW�SystemParametersInfoWjGetKeyboardLayoutExitWindowsEx�GetSystemMetricsfLoadRemoteFontsUSER32.dllGetModuleHandleExAResolveDelayLoadedAPIDelayLoadFailureHookapi-ms-win-core-delayload-l1-1-1.dllapi-ms-win-core-delayload-l1-1-0.dll�memsetVQ�2��-�+�] �f��System\CurrentControlSet\Control\Session Manager\Memory ManagementTempPageFile�PT�E\TP�@T�dT �lT�btThK�T`��T�P�T`��TKlTTh�Tp�#�T�#Q$lT`$�& U�&�'8U�'(�T (_)@U�)V*\U\*
+lU+�+xU�+�+8U,.,�U4,h,lTp,�-�U�-j.�U~.�.�UH/e/dTl/�/�U00�U0060�U�-�3/��.�/�!/�r.��� �8�P�h�	�	�h�����MUI�4VS_VERSION_INFO��
!|O
!|O?StringFileInfo�040904B0LCompanyNameMicrosoft CorporationfFileDescriptionUserInit Utility Extension DLLn'FileVersion10.0.20348.2849 (WinBuild.160101.0800)8InternalNameUserInitExt�.LegalCopyright� Microsoft Corporation. All rights reserved.HOriginalFilenameUserInitExt.DLLj%ProductNameMicrosoft� Windows� Operating SystemDProductVersion10.0.20348.2849DVarFileInfo$Translation	�����ʛY
�]9TK�(�g�*$$��D[��v�������MUIMUIen-US@(��h���������(�0�8�����������p����� �(�0�