============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 60 80 00 00 00 00 00 00 00 00 00 00 D8 81 00 00 04 81 00 00 C4 80 00 00 00 00 00 00 00 00 00 00 `Ç..........╪ü..♦ü..─Ç.......... 00000020 BE 82 00 00 68 81 00 00 50 80 00 00 00 00 00 00 00 00 00 00 04 83 00 00 F4 80 00 00 00 00 00 00 ╛é..hü..PÇ..........♦â..⌠Ç...... 00000040 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E0 82 00 00 F2 82 00 00 CA 82 00 00 00 00 00 00 ................αé..≥é..╩é...... 00000060 CC 81 00 00 B6 81 00 00 12 83 00 00 4A 83 00 00 56 83 00 00 3C 84 00 00 2C 84 00 00 50 84 00 00 ╠ü..╢ü..↕â..Jâ..Vâ..<ä..,ä..Pä.. 00000080 04 84 00 00 F8 83 00 00 16 84 00 00 DA 83 00 00 C8 83 00 00 E8 83 00 00 AA 83 00 00 98 81 00 00 ♦ä..°â..▬ä..┌â..╚â..Φâ..¬â..ÿü.. 000000A0 A8 81 00 00 2A 83 00 00 3C 83 00 00 9E 83 00 00 BA 83 00 00 72 83 00 00 88 83 00 00 92 83 00 00 ¿ü..*â..<â..₧â..║â..râ..êâ..Æâ.. 000000C0 00 00 00 00 08 82 00 00 E6 81 00 00 FC 81 00 00 92 82 00 00 AC 82 00 00 58 82 00 00 84 82 00 00 ....◘é..µü..ⁿü..Æé..¼é..Xé..äé.. 000000E0 6E 82 00 00 1E 82 00 00 40 82 00 00 30 82 00 00 00 00 00 00 E0 82 00 00 F2 82 00 00 CA 82 00 00 né..▲é..@é..0é......αé..≥é..╩é.. 00000100 00 00 00 00 CC 81 00 00 B6 81 00 00 12 83 00 00 4A 83 00 00 56 83 00 00 3C 84 00 00 2C 84 00 00 ....╠ü..╢ü..↕â..Jâ..Vâ..<ä..,ä.. 00000120 50 84 00 00 04 84 00 00 F8 83 00 00 16 84 00 00 DA 83 00 00 C8 83 00 00 E8 83 00 00 AA 83 00 00 Pä..♦ä..°â..▬ä..┌â..╚â..Φâ..¬â.. 00000140 98 81 00 00 A8 81 00 00 2A 83 00 00 3C 83 00 00 9E 83 00 00 BA 83 00 00 72 83 00 00 88 83 00 00 ÿü..¿ü..*â..<â..₧â..║â..râ..êâ.. 00000160 92 83 00 00 00 00 00 00 08 82 00 00 E6 81 00 00 FC 81 00 00 92 82 00 00 AC 82 00 00 58 82 00 00 Æâ......◘é..µü..ⁿü..Æé..¼é..Xé.. 00000180 84 82 00 00 6E 82 00 00 1E 82 00 00 40 82 00 00 30 82 00 00 00 00 00 00 E1 00 47 65 74 4C 61 73 äé..né..▲é..@é..0é......ß.GetLas 000001A0 74 45 72 72 6F 72 00 00 37 01 47 65 74 56 65 72 73 69 6F 6E 00 00 A0 01 4F 75 74 70 75 74 44 65 tError..7☺GetVersion..á☺OutputDe 000001C0 62 75 67 53 74 72 69 6E 67 41 00 00 75 02 6C 73 74 72 6C 65 6E 41 00 00 4B 45 52 4E 45 4C 33 32 bugStringA..u☻lstrlenA..KERNEL32 000001E0 2E 64 6C 6C 00 00 E2 01 53 65 74 46 6F 72 65 67 72 6F 75 6E 64 57 69 6E 64 6F 77 00 49 02 77 73 .dll..Γ☺SetForegroundWindow.I☻ws 00000200 70 72 69 6E 74 66 41 00 F1 00 47 65 74 46 6F 72 65 67 72 6F 75 6E 64 57 69 6E 64 6F 77 00 76 00 printfA.±.GetForegroundWindow.v. 00000220 44 64 65 55 6E 69 6E 69 74 69 61 6C 69 7A 65 00 60 00 44 64 65 44 69 73 63 6F 6E 6E 65 63 74 00 DdeUninitialize.`.DdeDisconnect. 00000240 59 00 44 64 65 43 6C 69 65 6E 74 54 72 61 6E 73 61 63 74 69 6F 6E 00 00 5D 00 44 64 65 43 72 65 Y.DdeClientTransaction..].DdeCre 00000260 61 74 65 44 61 74 61 48 61 6E 64 6C 65 00 64 00 44 64 65 46 72 65 65 53 74 72 69 6E 67 48 61 6E ateDataHandle.d.DdeFreeStringHan 00000280 64 6C 65 00 5B 00 44 64 65 43 6F 6E 6E 65 63 74 00 00 5E 00 44 64 65 43 72 65 61 74 65 53 74 72 dle.[.DdeConnect..^.DdeCreateStr 000002A0 69 6E 67 48 61 6E 64 6C 65 41 00 00 69 00 44 64 65 49 6E 69 74 69 61 6C 69 7A 65 41 00 00 55 53 ingHandleA..i.DdeInitializeA..US 000002C0 45 52 33 32 2E 64 6C 6C 00 00 16 00 43 6C 6F 73 65 53 65 72 76 69 63 65 48 61 6E 64 6C 65 00 00 ER32.dll..▬.CloseServiceHandle.. 000002E0 B1 00 4F 70 65 6E 53 43 4D 61 6E 61 67 65 72 41 00 00 1C 00 43 72 65 61 74 65 53 65 72 76 69 63 ▒.OpenSCManagerA..∟.CreateServic 00000300 65 41 00 00 41 44 56 41 50 49 33 32 2E 64 6C 6C 00 00 D0 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 eA..ADVAPI32.dll..╨.GetEnvironme 00000320 6E 74 53 74 72 69 6E 67 73 00 9F 00 47 65 74 43 6F 6D 6D 61 6E 64 4C 69 6E 65 41 00 62 00 45 78 ntStrings.ƒ.GetCommandLineA.b.Ex 00000340 69 74 50 72 6F 63 65 73 73 00 C7 01 52 74 6C 55 6E 77 69 6E 64 00 26 02 55 6E 68 61 6E 64 6C 65 itProcess.╟☺RtlUnwind.&☻Unhandle 00000360 64 45 78 63 65 70 74 69 6F 6E 46 69 6C 74 65 72 00 00 E9 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C dExceptionFilter..Θ.GetModuleFil 00000380 65 4E 61 6D 65 41 00 00 92 00 47 65 74 41 43 50 00 00 F6 00 47 65 74 4F 45 4D 43 50 00 00 98 00 eNameA..Æ.GetACP..÷.GetOEMCP..ÿ. 000003A0 47 65 74 43 50 49 6E 66 6F 00 16 01 47 65 74 53 74 64 48 61 6E 64 6C 65 00 00 DC 00 47 65 74 46 GetCPInfo.▬☺GetStdHandle..▄.GetF 000003C0 69 6C 65 54 79 70 65 00 14 01 47 65 74 53 74 61 72 74 75 70 49 6E 66 6F 41 00 33 02 56 69 72 74 ileType.¶☺GetStartupInfoA.3☻Virt 000003E0 75 61 6C 46 72 65 65 00 31 02 56 69 72 74 75 61 6C 41 6C 6C 6F 63 00 00 4F 02 57 72 69 74 65 46 ualFree.1☻VirtualAlloc..O☻WriteF 00000400 69 6C 65 00 F8 01 53 65 74 46 69 6C 65 50 6F 69 6E 74 65 72 00 00 42 02 57 69 64 65 43 68 61 72 ile.°☺SetFilePointer..B☻WideChar 00000420 54 6F 4D 75 6C 74 69 42 79 74 65 00 06 02 53 65 74 53 74 64 48 61 6E 64 6C 65 00 00 83 00 46 6C ToMultiByte.♠☻SetStdHandle..â.Fl 00000440 75 73 68 46 69 6C 65 42 75 66 66 65 72 73 00 00 16 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 00 00 ushFileBuffers..▬.CloseHandle... 00000460 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000480 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000004A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000004C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000004E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000500 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000520 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000540 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000560 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000580 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................