MZ@ !L!This program cannot be run in DOS mode. $?qQ"Q"Q""Q"U#Q"P"Q"P#Q"Q#Q"Y#Q""Q"S#Q"RichQ"PELr! .5@ @E:Qhp0TP49`.textK,. `.data`@2@.idata< P 4@@.didat `>@.rsrc0p@@@.relocF@B@0A(@Qu ##0''@( .2p23p445509$PCRYPT32.dllWINSTA.dll\Registry\Machine\System\CurrentControlSet\Control\GraphicsDrivers\DetectDisplay\Registry\Machine\System\CurrentControlSet\Control\GraphicsDrivers\NewDisplay\Registry\Machine\System\CurrentControlSet\Control\GraphicsDrivers\InvalidDisplayRasAutodialNewLogonUservmappletSoftware\Microsoft\Windows\CurrentVersion\Runctfmon.exeShellDesktopSwitchEventShellAppRuntimeSOFTWARE\Microsoft\Windows NT\CurrentVersion\WinlogonShellAppRuntime.exeUSERINIT: StringCchCopy failed USERINIT: RegGetValue failed with error: %d. Setting default value USERINIT: CreateProcess failed with error: %lu UserInitExt.dllLocal\ShellStartupEventCouldnt open the eventCreated ShellStartupEvent successfullyWaiting for ShellStartupEvent to get triggeredUSERINIT: ShellAppRuntime did not launch within 5 minutes USERINIT: An error occurred while waiting on ShellAppRuntime to start: %lu EnableShellAppRuntimeUSERINIT: Logging off session since LaunchShellAppRuntime failed! USERINIT: Logging off session since WinStationGetInitialApplication failed! USERINIT: Failed to set working directory %ws for SessionId %u USERINIT: Failed to start ctfmon.exe in TS Single App mode ! imm32.dllImmDisableIMEctfmon.exe /nSoftware\Microsoft\Windows\CurrentVersion\RunonceKeyboard Layout\ToggleHotkeySystem\CurrentControlSet\Control\Terminal ServerTSAppCompattsappcmp.dllTermsrvCheckNewIniFilesSoftware\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\%dSoftware\Microsoft\Windows\CurrentVersion\Explorer?,3?Mg1 ntdll.dllMicrosoftTelemetryAssertTriggeredUMr(HHr Tppr$  $("p88@l P 09ETW0+ LaunchShellAppRuntime LaunchShellAppRuntime LaunchShellAppRuntime ILaunchShellAppRuntimeShellAppRuntimeReadyTime functionReturnValue  +LaunchShellAppRuntimemsglasterror *LaunchShellAppRuntimeGetLastError() *LaunchShellAppRuntimeGetLastError() LaunchShellAppRuntimemsg +LaunchShellAppRuntimemsglasterror *LaunchShellAppRuntimeregReturnValue GLaunchShellAppRuntimepropertyValue->TypepropertyValue->u.ulVal LLaunchShellAppRuntimewinStationReturnValueregEnableShellAppRuntimegјSS FY&Microsoft.Windows.Security.UserInitRSDS较J4Q@tuserinitext.pdbGCTL.rdata$brcL.gfids.giats  .rdataP.rdata$voltmdP.rdata$zETW0`.rdata$zETW1 7.rdata$zETW2D.rdata$zETW9H.rdata$zzzdbg .text".text$mn49@.didat$2t9 .didat$39 .didat$49.didat$6`: .didat$7:.edata@(.data$brc(@.data@.bssP.idata$5Q.00cfgQT.idata$2hR.idata$3|R.idata$4S.idata$6` .didat$5p.rsrc$01p.rsrc$02 较J4Q@t9@rUE(tkM US]W} t*u(tAMHMH Xx MVp tp$u$WSQuRu uQ^_[]$̋U(@3ʼnE@ @V5@W}v𥥥tjY)% @E%$@h@h@h PPt ~* @PQj5@5@PM_3^.̋UMEBEBEB WE3@y@QuAA QyADWA-PWEEP5@5@P_̋Utw QuQWt3f]̋UE Vt>=w7S]3WxEPuWSPx;wu z3f{_[WtM3f^]̋UVWt'E +t<ft f9Nuu_ҁ3f^z] ̋̋UV3Vu uVPVVP^]̋UQEPhPPPtVuPuHP3@;^t3̋U0(@3ʼnEVfSWh@PPj[3PhDž@PQhPPPhPDž@Qy]hPPPhPDž@QxBQhPhBVlP5DWjWjWPQ_[M3^̋U4(@3ʼnESVW3PhVh0@hڋPuaDžPPPVh@Puu tPƉuD$PD$PD$PD$ Pj`ut$t$hQY뱃|$|$uj4Pt$2ۉt$|$$PVPt$PuUT$$P+Ѝt ft fuu3fu憃zV4P2&$PPP؍$Pt$u0d0t$h`Q D$CE$XlD$HVP$`PPuAL$H$X+Ѝt ft fuu3f'5DD$H3ۋSjSSSPQքuhQY3ۋ5D38D$jEPSSSt$(Q֊؋D$D$FD$D@PD$$ul\$$D$ 3QjPQSQhxPD$HhP9t$(t$ VlPt.hj@TPtt$D$Lt$$PhVt$ PPttjjVjPVPPt$`|$t$`WjlPthj@TPtt$D$LSPhV뎃|$t t$`Ë$d_^[3G]̋UEVD3E jR D Pt3VVh`Pt WhVhPt jQ_^]̋U\(@3ʼnEh P<SV3SPtPf;WjY}jYEPfEPS}VSSSh WPjEE1PjSEE3PuPuPEPEPSVSSShWPEEPEPEPSVuPu5MEff;uftfPf;Qufuދu"jEPjSVuPu SSSj[PuP_^[M33@^̋U=@tbVE3PjVhhPu=EuPEEPEPVh,uPu 9EDuP5@^D̋UV3stFSWV39]VhD`Pt%h`WhPt QWdP_[^]̋U(@3ʼnEd0V3dhxjKPx|WdPWPV`PVjVVVhWPuI`P\P`PVjjVVdPWPu`P\uF_M3^3@̋UE 3+t u,%@ @PQ@@@P3@] ̋U(eEVWPhxj\PtR}tLhuhPt8ME܃eMPE EEEEd}Q_^̋U$eEVPhxj\PtP}tJhuhPt6ME܃eMMMPE EEEQ^̋U5u 5$P5uh,P]; (@u6̋Uj8Pu:99 :9CryptProtectData1WinStationFreeMemoryfWinStationQueryInformationW=WinStationGetConnectionProperty2WinStationFreePropertyValueBWinStationGetInitialApplicationr ; ::;4#2'30'# .p4@(p250;I;f;p;;;;;;<"<?< USERINITEXT.dllCreateExplorerSessionKeyDisplayMessageAndExitWindowsImmWorkerIsSubDesktopSessionIsTSAppCompatOnLoadRemoteFontsAndInitMiscWorkerPerformXForestLogonCheckProcesRemoteSessionInitialCommandProcessTermSrvIniFilesSetShellDesktopSwitchEventSetupHotKeyForKeyboardLayoutUserinitExtN@DSystem\CurrentControlSet\Control\Session Manager\Memory ManagementTempPageFile$X2XJXnXX^XXXSUUT&U|UnTXUUjU4USTRUSDTUVS$TU4TSTUTXTU|TTTTTUBUS2YWWXX09lSSPS,VPRPV4PSzVPRVPRVtPXSVPR"WPn>t>z>>>>>>>,?~????00L0a0l0r0}00001(1S1h1o1y11111 222'2-292@2P2y222222223"343;3V3f33333 4474@4O4X4^4d44444444 5.5A5H5X5{555555556)686A6e6t6}666666677 7(7.7>7[7d7o7v777777777777777778 8888)898I8O8Z8`8l8|888888888 99@ 0P 1`00 0000