============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 3C 50 01 00 00 00 00 00 00 00 00 00 C6 52 01 00 C0 50 01 00 9C 50 01 00 00 00 00 00 00 00 00 00 <P☺.........╞R☺.└P☺.£P☺......... 00000020 74 53 01 00 20 51 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 60 52 01 00 tS☺. Q☺.....................`R☺. 00000040 50 51 01 00 5E 51 01 00 70 51 01 00 7E 51 01 00 8E 51 01 00 A0 51 01 00 B4 51 01 00 C2 51 01 00 PQ☺.^Q☺.pQ☺.~Q☺.ÄQ☺.áQ☺.┤Q☺.┬Q☺. 00000060 D0 51 01 00 E8 51 01 00 FA 51 01 00 08 52 01 00 1E 52 01 00 2E 52 01 00 3C 52 01 00 4E 52 01 00 ╨Q☺.ΦQ☺.·Q☺.◘R☺.▲R☺..R☺.<R☺.NR☺. 00000080 44 51 01 00 6C 52 01 00 78 52 01 00 8A 52 01 00 A0 52 01 00 B6 52 01 00 00 00 00 00 2A 53 01 00 DQ☺.lR☺.xR☺.èR☺.áR☺.╢R☺.....*S☺. 000000A0 EA 52 01 00 FE 52 01 00 14 53 01 00 D4 52 01 00 3A 53 01 00 4E 53 01 00 64 53 01 00 00 00 00 00 ΩR☺.■R☺.¶S☺.╘R☺.:S☺.NS☺.dS☺..... 000000C0 60 52 01 00 50 51 01 00 5E 51 01 00 70 51 01 00 7E 51 01 00 8E 51 01 00 A0 51 01 00 B4 51 01 00 `R☺.PQ☺.^Q☺.pQ☺.~Q☺.ÄQ☺.áQ☺.┤Q☺. 000000E0 C2 51 01 00 D0 51 01 00 E8 51 01 00 FA 51 01 00 08 52 01 00 1E 52 01 00 2E 52 01 00 3C 52 01 00 ┬Q☺.╨Q☺.ΦQ☺.·Q☺.◘R☺.▲R☺..R☺.<R☺. 00000100 4E 52 01 00 44 51 01 00 6C 52 01 00 78 52 01 00 8A 52 01 00 A0 52 01 00 B6 52 01 00 00 00 00 00 NR☺.DQ☺.lR☺.xR☺.èR☺.áR☺.╢R☺..... 00000120 2A 53 01 00 EA 52 01 00 FE 52 01 00 14 53 01 00 D4 52 01 00 3A 53 01 00 4E 53 01 00 64 53 01 00 *S☺.ΩR☺.■R☺.¶S☺.╘R☺.:S☺.NS☺.dS☺. 00000140 00 00 00 00 82 01 4C 6F 63 61 6C 46 72 65 65 00 16 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 29 02 ....é☺LocalFree.▬.CloseHandle.)☻ 00000160 55 6E 6D 61 70 56 69 65 77 4F 66 46 69 6C 65 00 7E 01 4C 6F 63 61 6C 41 6C 6C 6F 63 00 00 8C 01 UnmapViewOfFile.~☺LocalAlloc..î☺ 00000180 4D 61 70 56 69 65 77 4F 66 46 69 6C 65 00 4C 00 44 75 70 6C 69 63 61 74 65 48 61 6E 64 6C 65 00 MapViewOfFile.L.DuplicateHandle. 000001A0 C4 00 47 65 74 43 75 72 72 65 6E 74 50 72 6F 63 65 73 73 00 9C 01 4F 70 65 6E 50 72 6F 63 65 73 ─.GetCurrentProcess.£☺OpenProces 000001C0 73 00 37 01 47 65 74 56 65 72 73 69 6F 6E 00 00 D0 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 s.7☺GetVersion..╨.GetEnvironment 000001E0 53 74 72 69 6E 67 73 00 9F 00 47 65 74 43 6F 6D 6D 61 6E 64 4C 69 6E 65 41 00 62 00 45 78 69 74 Strings.ƒ.GetCommandLineA.b.Exit 00000200 50 72 6F 63 65 73 73 00 E9 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 00 00 16 01 Process.Θ.GetModuleFileNameA..▬☺ 00000220 47 65 74 53 74 64 48 61 6E 64 6C 65 00 00 DC 00 47 65 74 46 69 6C 65 54 79 70 65 00 14 01 47 65 GetStdHandle..▄.GetFileType.¶☺Ge 00000240 74 53 74 61 72 74 75 70 49 6E 66 6F 41 00 05 01 47 65 74 50 72 6F 63 65 73 73 48 65 61 70 00 00 tStartupInfoA.♣☺GetProcessHeap.. 00000260 4F 02 57 72 69 74 65 46 69 6C 65 00 53 01 48 65 61 70 41 6C 6C 6F 63 00 1A 01 47 65 74 53 74 72 O☻WriteFile.S☺HeapAlloc.→☺GetStr 00000280 69 6E 67 54 79 70 65 57 00 00 93 01 4D 75 6C 74 69 42 79 74 65 54 6F 57 69 64 65 43 68 61 72 00 ingTypeW..ô☺MultiByteToWideChar. 000002A0 42 02 57 69 64 65 43 68 61 72 54 6F 4D 75 6C 74 69 42 79 74 65 00 76 01 4C 43 4D 61 70 53 74 72 B☻WideCharToMultiByte.v☺LCMapStr 000002C0 69 6E 67 57 00 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 2E 00 45 6E 67 55 6E 6C 6F 63 6B 44 ingW..KERNEL32.dll....EngUnlockD 000002E0 72 69 76 65 72 4F 62 6A 00 00 23 00 45 6E 67 4C 6F 63 6B 44 72 69 76 65 72 4F 62 6A 00 00 14 00 riverObj..#.EngLockDriverObj..¶. 00000300 45 6E 67 43 72 65 61 74 65 44 72 69 76 65 72 4F 62 6A 00 00 1C 00 45 6E 67 44 65 6C 65 74 65 44 EngCreateDriverObj..∟.EngDeleteD 00000320 72 69 76 65 72 4F 62 6A 00 00 4F 00 57 4E 44 4F 42 4A 5F 62 45 6E 75 6D 00 00 50 00 57 4E 44 4F riverObj..O.WNDOBJ_bEnum..P.WNDO 00000340 42 4A 5F 63 45 6E 75 6D 53 74 61 72 74 00 52 00 57 4E 44 4F 42 4A 5F 76 53 65 74 43 6F 6E 73 75 BJ_cEnumStart.R.WNDOBJ_vSetConsu 00000360 6D 65 72 00 19 00 45 6E 67 43 72 65 61 74 65 57 6E 64 00 00 57 49 4E 53 52 56 2E 64 6C 6C 00 00 mer.↓.EngCreateWnd..WINSRV.dll.. 00000380 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000003A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000003C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000003E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................