Mini Kabibi Habibi
LJ9
X�6 99 BK CloseHandleCffi2 = 6 99 3 BK gcffihandleV
X�6 999 BK DestroyEnvironmentBlockuserenv
Win32 core/ = 6 99 3 BK gcffienv1 6 99 BK RegCloseKeyCffi� < X�' X�) X�6 9996 99 B7 6 X�+ = 2 �6 9 '
B= 6 996 9
B6 99
9 X�+ = 2
�9 : = 6 99 3 BK K K gcERROR_SUCCESSWin32ErrorConstantsRegOpenKeyExAC
void*[1]newffi hKeyrootKeyGetRootHKEYFromString
KEY_READRegistrySamConstants
Win32 core( 9 X�+ X�+ L hKey� n 9 B X�6 9 9' B6 9' B6 9' B6 99 9
, ,
B
6 999
X�6 9 96 9' 6 99 B A A4 ) : ) M5�6 9 '
: B 6
9
' : B
6 999
, B 6 999
X �6 9 6
9
B
AX�6 9 96
9
' 6 99 B A
AO� : J 7Failed to enumerate subkeys at index %d. Error: %sinsert
tableRegEnumKeyExAchar[?]GetWin32ErrorString8Failed to query registry key information. Error: %sformatstringERROR_SUCCESSWin32ErrorConstants
Win32 hKeyRegQueryInfoKeyACunsigned long[1]newffi&ErrorInvalid registry key handle. infologger coreIsValid� p 9 B X�6 9 9' B+ L 6 9' B6 9' B6 99 9
,
,
B
6 999
X�6 9 96 9' 6 99 B A A+ L 4 ) : ) M5�6 9 '
: B 6
9
' : B
6 999
, B 6 999
X �6 9 6
9
B
AX�6 9 96
9
' 6 99 B A
AO�L ;Failed to enumerate value names at index %d. Error: %sinsert
tableRegEnumValueAchar[?]GetWin32ErrorString;Failed to query registry key for value info. Error: %sformatstringERROR_SUCCESSWin32ErrorConstants
Win32 hKeyRegQueryInfoKeyACunsigned long[1]newffi7ErrorInvalid registry key handle in GetValueNames. infologger coreIsValid� �9 X�+ L
X�6 B X�+ L 6 9' B6 9' B6 9' ) B6 999 +
B6 9 9
9 X�+ L X�6 9 9
9 X�6 9 9
9: X�6 : D X�6 9 9
9 X�6 9 9
9 X�+ L : 4 6 9 9
96 9 99<6 9 9
96 9 99<6 9 9
96 9 99<6 9 9
96 9 99<6 9 9
96 9 99<6 9 9
96 9 99<6 9 9
96 9 99<6 9 9
96 9 99<6 9 9
96 9 99<8 X�+ L 6 9 998 X)�: ) X"�6 9' : B6 9' B6 9 9 9
+
B 6 9 9
9 X �+ L 6 9
D X^�+ L X[�6 9 998 X&�: ) X�6 9' B6 9' B6 9 9 9
+
B 6 9 9
9 X �+ L 6 :
D X1�+ L X.�6 9 998 X%�: ) X�6 9' : B6 9' B6 9 9 9
+
B 6 9 9
9 X �+ L L X�+ L X�+ L K unsigned __int64[1]char[?]BINARYREG_BINARYREG_QWORD_LITTLE_ENDIANREG_QWORDREG_MULTI_SZREG_DWORD_BIG_ENDIANREG_DWORD_LITTLE_ENDIANNUMBERREG_EXPAND_SZSTRINGRegistryValueTypeMappingREG_SZERROR_MORE_DATA
tonumberREG_DWORDRegistryValueTypeConstantsERROR_SUCCESSERROR_FILE_NOT_FOUNDWin32ErrorConstants
Win32 coreRegQueryValueExACunsigned long[1]newffistring type hKey�
� 9 B X�6 9 9' B, J 6 9' B6 9' B6 99 9
+ +
B6 999
X�6 9 9' B, J 6 9' : B6 99 9
+
B 6 999
X�6 9 9' B, J + : 6 999 X�6 999 X�6 999 X�6 9 B X5�6 999 X�6 999 X
�6 6 9'
B: B X�6 999 X�6 999 X
�6 6 9'
B: B X �6 999 X�+ X�+ J REG_BINARYunsigned __int64*REG_QWORD_LITTLE_ENDIANREG_QWORDunsigned long* cast
tonumberREG_DWORD_LITTLE_ENDIANREG_DWORDstringREG_MULTI_SZREG_EXPAND_SZREG_SZRegistryValueTypeConstants%Error retrieving the value data.unsigned char[?]2Error determining the size of the value data.ERROR_SUCCESSWin32ErrorConstants
Win32 hKeyRegQueryValueExACunsigned long[1]newffi(Error: Invalid registry key handle. infologger coreIsValidI
X�6 999 BK FindClose
kernel32
Win32 core2 = 6 99 3 BK gcffihandle_
- 9 6 999 B C �FindFirstFileA
kernel32
Win32 coreFindHandleP 6 9999 BL handleFindNextFileA
kernel32
Win32 core�t &