============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 7C C0 00 00 00 00 00 00 00 00 00 00 60 C4 00 00 C8 C1 00 00 88 C1 00 00 00 00 00 00 00 00 00 00 |└..........`─..╚┴..ê┴.......... 00000020 AA C4 00 00 D4 C2 00 00 50 C0 00 00 00 00 00 00 00 00 00 00 74 C5 00 00 9C C1 00 00 00 00 00 00 ¬─..╘┬..P└..........t┼..£┴...... 00000040 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 08 C5 00 00 F6 C4 00 00 E4 C4 00 00 D4 C4 00 00 ................◘┼..÷─..Σ─..╘─.. 00000060 C4 C4 00 00 B6 C4 00 00 1C C5 00 00 30 C5 00 00 48 C5 00 00 60 C5 00 00 00 00 00 00 AC C3 00 00 ──..╢─..∟┼..0┼..H┼..`┼......¼├.. 00000080 B8 C3 00 00 D6 C3 00 00 98 C3 00 00 7A C3 00 00 88 C3 00 00 20 C4 00 00 38 C4 00 00 4E C4 00 00 ╕├..╓├..ÿ├..z├..ê├.. ─..8─..N─.. 000000A0 6A C3 00 00 58 C3 00 00 4C C3 00 00 40 C3 00 00 32 C3 00 00 26 C3 00 00 0E C3 00 00 F2 C2 00 00 j├..X├..L├..@├..2├..&├..♫├..≥┬.. 000000C0 0C C4 00 00 EE C3 00 00 E2 C5 00 00 0C C7 00 00 18 C7 00 00 A2 C8 00 00 88 C8 00 00 B2 C8 00 00 ♀─..ε├..Γ┼..♀╟..↑╟..ó╚..ê╚..▓╚.. 000000E0 82 C5 00 00 94 C5 00 00 A4 C5 00 00 B0 C5 00 00 C8 C5 00 00 E8 C2 00 00 EE C5 00 00 FA C5 00 00 é┼..ö┼..ñ┼..░┼..╚┼..Φ┬..ε┼..·┼.. 00000100 06 C6 00 00 1A C6 00 00 2C C6 00 00 3A C6 00 00 48 C6 00 00 64 C6 00 00 7A C6 00 00 94 C6 00 00 ♠╞..→╞..,╞..:╞..H╞..d╞..z╞..ö╞.. 00000120 AA C6 00 00 C2 C6 00 00 DC C6 00 00 F6 C6 00 00 D2 C7 00 00 C2 C7 00 00 22 C7 00 00 2E C7 00 00 ¬╞..┬╞..▄╞..÷╞..╥╟..┬╟.."╟...╟.. 00000140 40 C7 00 00 4E C7 00 00 5E C7 00 00 6A C7 00 00 84 C7 00 00 A2 C7 00 00 B2 C7 00 00 64 C8 00 00 @╟..N╟..^╟..j╟..ä╟..ó╟..▓╟..d╚.. 00000160 76 C8 00 00 E4 C7 00 00 F4 C7 00 00 06 C8 00 00 18 C8 00 00 24 C8 00 00 36 C8 00 00 4A C8 00 00 v╚..Σ╟..⌠╟..♠╚..↑╚..$╚..6╚..J╚.. 00000180 58 C8 00 00 00 00 00 00 6E C4 00 00 7C C4 00 00 8C C4 00 00 9A C4 00 00 00 00 00 00 08 C5 00 00 X╚......n─..|─..î─..Ü─......◘┼.. 000001A0 F6 C4 00 00 E4 C4 00 00 D4 C4 00 00 C4 C4 00 00 B6 C4 00 00 1C C5 00 00 30 C5 00 00 48 C5 00 00 ÷─..Σ─..╘─..──..╢─..∟┼..0┼..H┼.. 000001C0 60 C5 00 00 00 00 00 00 AC C3 00 00 B8 C3 00 00 D6 C3 00 00 98 C3 00 00 7A C3 00 00 88 C3 00 00 `┼......¼├..╕├..╓├..ÿ├..z├..ê├.. 000001E0 20 C4 00 00 38 C4 00 00 4E C4 00 00 6A C3 00 00 58 C3 00 00 4C C3 00 00 40 C3 00 00 32 C3 00 00 ─..8─..N─..j├..X├..L├..@├..2├.. 00000200 26 C3 00 00 0E C3 00 00 F2 C2 00 00 0C C4 00 00 EE C3 00 00 E2 C5 00 00 0C C7 00 00 18 C7 00 00 &├..♫├..≥┬..♀─..ε├..Γ┼..♀╟..↑╟.. 00000220 A2 C8 00 00 88 C8 00 00 B2 C8 00 00 82 C5 00 00 94 C5 00 00 A4 C5 00 00 B0 C5 00 00 C8 C5 00 00 ó╚..ê╚..▓╚..é┼..ö┼..ñ┼..░┼..╚┼.. 00000240 E8 C2 00 00 EE C5 00 00 FA C5 00 00 06 C6 00 00 1A C6 00 00 2C C6 00 00 3A C6 00 00 48 C6 00 00 Φ┬..ε┼..·┼..♠╞..→╞..,╞..:╞..H╞.. 00000260 64 C6 00 00 7A C6 00 00 94 C6 00 00 AA C6 00 00 C2 C6 00 00 DC C6 00 00 F6 C6 00 00 D2 C7 00 00 d╞..z╞..ö╞..¬╞..┬╞..▄╞..÷╞..╥╟.. 00000280 C2 C7 00 00 22 C7 00 00 2E C7 00 00 40 C7 00 00 4E C7 00 00 5E C7 00 00 6A C7 00 00 84 C7 00 00 ┬╟.."╟...╟..@╟..N╟..^╟..j╟..ä╟.. 000002A0 A2 C7 00 00 B2 C7 00 00 64 C8 00 00 76 C8 00 00 E4 C7 00 00 F4 C7 00 00 06 C8 00 00 18 C8 00 00 ó╟..▓╟..d╚..v╚..Σ╟..⌠╟..♠╚..↑╚.. 000002C0 24 C8 00 00 36 C8 00 00 4A C8 00 00 58 C8 00 00 00 00 00 00 6E C4 00 00 7C C4 00 00 8C C4 00 00 $╚..6╚..J╚..X╚......n─..|─..î─.. 000002E0 9A C4 00 00 00 00 00 00 43 02 57 69 6E 45 78 65 63 00 FF 00 47 65 74 50 72 69 76 61 74 65 50 72 Ü─......C☻WinExec. .GetPrivatePr 00000300 6F 66 69 6C 65 53 74 72 69 6E 67 41 00 00 EB 01 53 65 74 43 75 72 72 65 6E 74 44 69 72 65 63 74 ofileStringA..δ☺SetCurrentDirect 00000320 6F 72 79 41 00 00 75 02 6C 73 74 72 6C 65 6E 41 00 00 62 00 45 78 69 74 50 72 6F 63 65 73 73 00 oryA..u☻lstrlenA..b.ExitProcess. 00000340 6C 02 6C 73 74 72 63 6D 70 69 41 00 6F 02 6C 73 74 72 63 70 79 41 00 00 9F 00 47 65 74 43 6F 6D l☻lstrcmpiA.o☻lstrcpyA..ƒ.GetCom 00000360 6D 61 6E 64 4C 69 6E 65 41 00 38 01 47 65 74 56 65 72 73 69 6F 6E 45 78 41 00 45 00 44 65 6C 65 mandLineA.8☺GetVersionExA.E.Dele 00000380 74 65 46 69 6C 65 41 00 E1 00 47 65 74 4C 61 73 74 45 72 72 6F 72 00 00 C4 00 47 65 74 43 75 72 teFileA.ß.GetLastError..─.GetCur 000003A0 72 65 6E 74 50 72 6F 63 65 73 73 00 66 02 6C 73 74 72 63 61 74 41 00 00 51 02 57 72 69 74 65 50 rentProcess.f☻lstrcatA..Q☻WriteP 000003C0 72 69 76 61 74 65 50 72 6F 66 69 6C 65 53 65 63 74 69 6F 6E 41 00 3C 01 47 65 74 57 69 6E 64 6F rivateProfileSectionA.<☺GetWindo 000003E0 77 73 44 69 72 65 63 74 6F 72 79 41 00 00 53 02 57 72 69 74 65 50 72 69 76 61 74 65 50 72 6F 66 wsDirectoryA..S☻WritePrivateProf 00000400 69 6C 65 53 74 72 69 6E 67 41 00 00 C1 01 52 65 6D 6F 76 65 44 69 72 65 63 74 6F 72 79 41 00 00 ileStringA..┴☺RemoveDirectoryA.. 00000420 C2 00 47 65 74 43 75 72 72 65 6E 74 44 69 72 65 63 74 6F 72 79 41 00 00 3E 02 57 61 69 74 46 6F ┬.GetCurrentDirectoryA..>☻WaitFo 00000440 72 53 69 6E 67 6C 65 4F 62 6A 65 63 74 00 37 00 43 72 65 61 74 65 50 72 6F 63 65 73 73 41 00 00 rSingleObject.7.CreateProcessA.. 00000460 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 88 01 4D 65 73 73 61 67 65 42 6F 78 41 00 C4 00 45 78 KERNEL32.dll..ê☺MessageBoxA.─.Ex 00000480 69 74 57 69 6E 64 6F 77 73 45 78 00 C6 00 46 69 6E 64 57 69 6E 64 6F 77 41 00 C6 01 53 65 6E 64 itWindowsEx.╞.FindWindowA.╞☺Send 000004A0 4D 65 73 73 61 67 65 41 00 00 55 53 45 52 33 32 2E 64 6C 6C 00 00 C2 00 52 65 67 43 6C 6F 73 65 MessageA..USER32.dll..┬.RegClose 000004C0 4B 65 79 00 D9 00 52 65 67 4F 70 65 6E 4B 65 79 45 78 41 00 C9 00 52 65 67 44 65 6C 65 74 65 4B Key.┘.RegOpenKeyExA.╔.RegDeleteK 000004E0 65 79 41 00 C6 00 52 65 67 43 72 65 61 74 65 4B 65 79 45 78 41 00 EC 00 52 65 67 53 65 74 56 61 eyA.╞.RegCreateKeyExA.∞.RegSetVa 00000500 6C 75 65 45 78 41 00 00 E1 00 52 65 67 51 75 65 72 79 56 61 6C 75 65 45 78 41 00 00 DC 00 52 65 lueExA..ß.RegQueryValueExA..▄.Re 00000520 67 51 75 65 72 79 49 6E 66 6F 4B 65 79 41 00 00 0A 00 41 64 6A 75 73 74 54 6F 6B 65 6E 50 72 69 gQueryInfoKeyA..◙.AdjustTokenPri 00000540 76 69 6C 65 67 65 73 00 71 00 4C 6F 6F 6B 75 70 50 72 69 76 69 6C 65 67 65 56 61 6C 75 65 41 00 vileges.q.LookupPrivilegeValueA. 00000560 B0 00 4F 70 65 6E 50 72 6F 63 65 73 73 54 6F 6B 65 6E 00 00 41 44 56 41 50 49 33 32 2E 64 6C 6C ░.OpenProcessToken..ADVAPI32.dll 00000580 00 00 79 00 46 69 6E 64 46 69 72 73 74 46 69 6C 65 41 00 00 7C 00 46 69 6E 64 4E 65 78 74 46 69 ..y.FindFirstFileA..|.FindNextFi 000005A0 6C 65 41 00 75 00 46 69 6E 64 43 6C 6F 73 65 00 6F 00 46 69 6C 65 54 69 6D 65 54 6F 53 79 73 74 leA.u.FindClose.o.FileTimeToSyst 000005C0 65 6D 54 69 6D 65 00 00 6E 00 46 69 6C 65 54 69 6D 65 54 6F 4C 6F 63 61 6C 46 69 6C 65 54 69 6D emTime..n.FileTimeToLocalFileTim 000005E0 65 00 59 01 48 65 61 70 46 72 65 65 00 00 53 01 48 65 61 70 41 6C 6C 6F 63 00 C7 01 52 74 6C 55 e.Y☺HeapFree..S☺HeapAlloc.╟☺RtlU 00000600 6E 77 69 6E 64 00 EB 00 47 65 74 4D 6F 64 75 6C 65 48 61 6E 64 6C 65 41 00 00 14 01 47 65 74 53 nwind.δ.GetModuleHandleA..¶☺GetS 00000620 74 61 72 74 75 70 49 6E 66 6F 41 00 37 01 47 65 74 56 65 72 73 69 6F 6E 00 00 55 01 48 65 61 70 tartupInfoA.7☺GetVersion..U☺Heap 00000640 43 72 65 61 74 65 00 00 26 02 55 6E 68 61 6E 64 6C 65 64 45 78 63 65 70 74 69 6F 6E 46 69 6C 74 Create..&☻UnhandledExceptionFilt 00000660 65 72 00 00 E9 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 00 00 8B 00 46 72 65 65 er..Θ.GetModuleFileNameA..ï.Free 00000680 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 41 00 93 01 4D 75 6C 74 69 42 79 74 65 54 EnvironmentStringsA.ô☺MultiByteT 000006A0 6F 57 69 64 65 43 68 61 72 00 D0 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 oWideChar.╨.GetEnvironmentString 000006C0 73 00 8C 00 46 72 65 65 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 57 00 D2 00 47 65 s.î.FreeEnvironmentStringsW.╥.Ge 000006E0 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 57 00 00 42 02 57 69 64 65 43 68 61 72 tEnvironmentStringsW..B☻WideChar 00000700 54 6F 4D 75 6C 74 69 42 79 74 65 00 98 00 47 65 74 43 50 49 6E 66 6F 00 92 00 47 65 74 41 43 50 ToMultiByte.ÿ.GetCPInfo.Æ.GetACP 00000720 00 00 F6 00 47 65 74 4F 45 4D 43 50 00 00 FA 01 53 65 74 48 61 6E 64 6C 65 43 6F 75 6E 74 00 00 ..÷.GetOEMCP..·☺SetHandleCount.. 00000740 DC 00 47 65 74 46 69 6C 65 54 79 70 65 00 16 01 47 65 74 53 74 64 48 61 6E 64 6C 65 00 00 4F 02 ▄.GetFileType.▬☺GetStdHandle..O☻ 00000760 57 72 69 74 65 46 69 6C 65 00 33 01 47 65 74 54 69 6D 65 5A 6F 6E 65 49 6E 66 6F 72 6D 61 74 69 WriteFile.3☺GetTimeZoneInformati 00000780 6F 6E 00 00 11 02 53 65 74 55 6E 68 61 6E 64 6C 65 64 45 78 63 65 70 74 69 6F 6E 46 69 6C 74 65 on..◄☻SetUnhandledExceptionFilte 000007A0 72 00 6C 01 49 73 42 61 64 52 65 61 64 50 74 72 00 00 6F 01 49 73 42 61 64 57 72 69 74 65 50 74 r.l☺IsBadReadPtr..o☺IsBadWritePt 000007C0 72 00 69 01 49 73 42 61 64 43 6F 64 65 50 74 72 00 00 03 01 47 65 74 50 72 6F 63 41 64 64 72 65 r.i☺IsBadCodePtr..♥☺GetProcAddre 000007E0 73 73 00 00 78 01 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 17 01 47 65 74 53 74 72 69 6E 67 54 ss..x☺LoadLibraryA..↨☺GetStringT 00000800 79 70 65 41 00 00 1A 01 47 65 74 53 74 72 69 6E 67 54 79 70 65 57 00 00 B8 01 52 65 61 64 46 69 ypeA..→☺GetStringTypeW..╕☺ReadFi 00000820 6C 65 00 00 F8 01 53 65 74 46 69 6C 65 50 6F 69 6E 74 65 72 00 00 83 00 46 6C 75 73 68 46 69 6C le..°☺SetFilePointer..â.FlushFil 00000840 65 42 75 66 66 65 72 73 00 00 5C 01 48 65 61 70 52 65 41 6C 6C 6F 63 00 5D 01 48 65 61 70 53 69 eBuffers..\☺HeapReAlloc.]☺HeapSi 00000860 7A 65 00 00 1C 00 43 6F 6D 70 61 72 65 53 74 72 69 6E 67 41 00 00 1D 00 43 6F 6D 70 61 72 65 53 ze..∟.CompareStringA..↔.CompareS 00000880 74 72 69 6E 67 57 00 00 F0 01 53 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 56 61 72 69 61 62 6C 65 tringW..≡☺SetEnvironmentVariable 000008A0 41 00 06 02 53 65 74 53 74 64 48 61 6E 64 6C 65 00 00 16 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 A.♠☻SetStdHandle..▬.CloseHandle. 000008C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000008E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000900 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000920 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000940 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000960 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000980 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000009A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000009C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000009E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................