============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 68 70 00 00 00 00 00 00 00 00 00 00 2C 72 00 00 50 71 00 00 14 71 00 00 00 00 00 00 00 00 00 00 hp..........,r..Pq..¶q.......... 00000020 D2 72 00 00 FC 71 00 00 50 70 00 00 00 00 00 00 00 00 00 00 2C 73 00 00 38 71 00 00 00 00 00 00 ╥r..ⁿq..Pp..........,s..8q...... 00000040 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 EC 72 00 00 18 73 00 00 08 73 00 00 FA 72 00 00 ................∞r..↑s..◘s..·r.. 00000060 DE 72 00 00 00 00 00 00 1A 74 00 00 42 74 00 00 FA 75 00 00 EA 75 00 00 DC 75 00 00 C8 75 00 00 ▐r......→t..Bt..·u..Ωu..▄u..╚u.. 00000080 B8 75 00 00 3A 73 00 00 46 73 00 00 52 73 00 00 64 73 00 00 76 73 00 00 8A 73 00 00 98 73 00 00 ╕u..:s..Fs..Rs..ds..vs..ès..ÿs.. 000000A0 A6 73 00 00 B4 73 00 00 C2 73 00 00 D6 73 00 00 EA 73 00 00 00 74 00 00 0E 74 00 00 20 72 00 00 ªs..┤s..┬s..╓s..Ωs...t..♫t.. r.. 000000C0 24 74 00 00 34 74 00 00 A0 75 00 00 D8 74 00 00 52 74 00 00 64 74 00 00 72 74 00 00 82 74 00 00 $t..4t..áu..╪t..Rt..dt..rt..ét.. 000000E0 94 74 00 00 AC 74 00 00 C2 74 00 00 CE 74 00 00 30 75 00 00 E4 74 00 00 FE 74 00 00 16 75 00 00 öt..¼t..┬t..╬t..0u..Σt..■t..▬u.. 00000100 4A 75 00 00 60 75 00 00 6C 75 00 00 88 75 00 00 00 00 00 00 3A 72 00 00 54 72 00 00 66 72 00 00 Ju..`u..lu..êu......:r..Tr..fr.. 00000120 76 72 00 00 86 72 00 00 96 72 00 00 BC 72 00 00 A8 72 00 00 00 00 00 00 EC 72 00 00 18 73 00 00 vr..år..ûr..╝r..¿r......∞r..↑s.. 00000140 08 73 00 00 FA 72 00 00 DE 72 00 00 00 00 00 00 1A 74 00 00 42 74 00 00 FA 75 00 00 EA 75 00 00 ◘s..·r..▐r......→t..Bt..·u..Ωu.. 00000160 DC 75 00 00 C8 75 00 00 B8 75 00 00 3A 73 00 00 46 73 00 00 52 73 00 00 64 73 00 00 76 73 00 00 ▄u..╚u..╕u..:s..Fs..Rs..ds..vs.. 00000180 8A 73 00 00 98 73 00 00 A6 73 00 00 B4 73 00 00 C2 73 00 00 D6 73 00 00 EA 73 00 00 00 74 00 00 ès..ÿs..ªs..┤s..┬s..╓s..Ωs...t.. 000001A0 0E 74 00 00 20 72 00 00 24 74 00 00 34 74 00 00 A0 75 00 00 D8 74 00 00 52 74 00 00 64 74 00 00 ♫t.. r..$t..4t..áu..╪t..Rt..dt.. 000001C0 72 74 00 00 82 74 00 00 94 74 00 00 AC 74 00 00 C2 74 00 00 CE 74 00 00 30 75 00 00 E4 74 00 00 rt..ét..öt..¼t..┬t..╬t..0u..Σt.. 000001E0 FE 74 00 00 16 75 00 00 4A 75 00 00 60 75 00 00 6C 75 00 00 88 75 00 00 00 00 00 00 3A 72 00 00 ■t..▬u..Ju..`u..lu..êu......:r.. 00000200 54 72 00 00 66 72 00 00 76 72 00 00 86 72 00 00 96 72 00 00 BC 72 00 00 A8 72 00 00 00 00 00 00 Tr..fr..vr..år..ûr..╝r..¿r...... 00000220 6D 02 6C 73 74 72 63 6D 70 69 57 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 B7 01 52 65 67 69 m☻lstrcmpiW.KERNEL32.dll..╖☺Regi 00000240 73 74 65 72 57 69 6E 64 6F 77 4D 65 73 73 61 67 65 57 00 00 10 00 43 61 6C 6C 4E 65 78 74 48 6F sterWindowMessageW..►.CallNextHo 00000260 6F 6B 45 78 00 00 E5 00 47 65 74 43 75 72 73 6F 72 50 6F 73 00 00 DA 00 47 65 74 43 6C 61 73 73 okEx..σ.GetCursorPos..┌.GetClass 00000280 4E 61 6D 65 57 00 33 01 47 65 74 57 69 6E 64 6F 77 52 65 63 74 00 31 01 47 65 74 57 69 6E 64 6F NameW.3☺GetWindowRect.1☺GetWindo 000002A0 77 4C 6F 6E 67 57 00 00 0F 02 53 65 74 57 69 6E 64 6F 77 73 48 6F 6F 6B 45 78 57 00 2E 02 55 6E wLongW..☼☻SetWindowsHookExW..☻Un 000002C0 68 6F 6F 6B 57 69 6E 64 6F 77 73 48 6F 6F 6B 45 78 00 55 53 45 52 33 32 2E 64 6C 6C 00 00 DB 00 hookWindowsHookEx.USER32.dll..█. 000002E0 52 65 67 4F 70 65 6E 4B 65 79 57 00 C2 00 52 65 67 43 6C 6F 73 65 4B 65 79 00 D0 00 52 65 67 45 RegOpenKeyW.┬.RegCloseKey.╨.RegE 00000300 6E 75 6D 4B 65 79 57 00 DA 00 52 65 67 4F 70 65 6E 4B 65 79 45 78 57 00 E2 00 52 65 67 51 75 65 numKeyW.┌.RegOpenKeyExW.Γ.RegQue 00000320 72 79 56 61 6C 75 65 45 78 57 00 00 41 44 56 41 50 49 33 32 2E 64 6C 6C 00 00 59 01 48 65 61 70 ryValueExW..ADVAPI32.dll..Y☺Heap 00000340 46 72 65 65 00 00 53 01 48 65 61 70 41 6C 6C 6F 63 00 9F 00 47 65 74 43 6F 6D 6D 61 6E 64 4C 69 Free..S☺HeapAlloc.ƒ.GetCommandLi 00000360 6E 65 41 00 03 01 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 EB 00 47 65 74 4D 6F 64 75 6C neA.♥☺GetProcAddress..δ.GetModul 00000380 65 48 61 6E 64 6C 65 41 00 00 37 01 47 65 74 56 65 72 73 69 6F 6E 00 00 55 01 48 65 61 70 43 72 eHandleA..7☺GetVersion..U☺HeapCr 000003A0 65 61 74 65 00 00 57 01 48 65 61 70 44 65 73 74 72 6F 79 00 62 00 45 78 69 74 50 72 6F 63 65 73 eate..W☺HeapDestroy.b.ExitProces 000003C0 73 00 1D 02 54 65 72 6D 69 6E 61 74 65 50 72 6F 63 65 73 73 00 00 C4 00 47 65 74 43 75 72 72 65 s.↔☻TerminateProcess..─.GetCurre 000003E0 6E 74 50 72 6F 63 65 73 73 00 C7 00 47 65 74 43 75 72 72 65 6E 74 54 68 72 65 61 64 49 64 00 00 ntProcess.╟.GetCurrentThreadId.. 00000400 22 02 54 6C 73 53 65 74 56 61 6C 75 65 00 1F 02 54 6C 73 41 6C 6C 6F 63 00 00 20 02 54 6C 73 46 "☻TlsSetValue.▼☻TlsAlloc.. ☻TlsF 00000420 72 65 65 00 FD 01 53 65 74 4C 61 73 74 45 72 72 6F 72 00 00 21 02 54 6C 73 47 65 74 56 61 6C 75 ree.²☺SetLastError..!☻TlsGetValu 00000440 65 00 E1 00 47 65 74 4C 61 73 74 45 72 72 6F 72 00 00 FA 01 53 65 74 48 61 6E 64 6C 65 43 6F 75 e.ß.GetLastError..·☺SetHandleCou 00000460 6E 74 00 00 DC 00 47 65 74 46 69 6C 65 54 79 70 65 00 16 01 47 65 74 53 74 64 48 61 6E 64 6C 65 nt..▄.GetFileType.▬☺GetStdHandle 00000480 00 00 14 01 47 65 74 53 74 61 72 74 75 70 49 6E 66 6F 41 00 44 00 44 65 6C 65 74 65 43 72 69 74 ..¶☺GetStartupInfoA.D.DeleteCrit 000004A0 69 63 61 6C 53 65 63 74 69 6F 6E 00 E9 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 icalSection.Θ.GetModuleFileNameA 000004C0 00 00 98 00 47 65 74 43 50 49 6E 66 6F 00 92 00 47 65 74 41 43 50 00 00 F6 00 47 65 74 4F 45 4D ..ÿ.GetCPInfo.Æ.GetACP..÷.GetOEM 000004E0 43 50 00 00 8B 00 46 72 65 65 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 41 00 D0 00 CP..ï.FreeEnvironmentStringsA.╨. 00000500 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 00 8C 00 46 72 65 65 45 6E 76 69 GetEnvironmentStrings.î.FreeEnvi 00000520 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 57 00 D2 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 ronmentStringsW.╥.GetEnvironment 00000540 53 74 72 69 6E 67 73 57 00 00 42 02 57 69 64 65 43 68 61 72 54 6F 4D 75 6C 74 69 42 79 74 65 00 StringsW..B☻WideCharToMultiByte. 00000560 4F 02 57 72 69 74 65 46 69 6C 65 00 64 01 49 6E 69 74 69 61 6C 69 7A 65 43 72 69 74 69 63 61 6C O☻WriteFile.d☺InitializeCritical 00000580 53 65 63 74 69 6F 6E 00 4F 00 45 6E 74 65 72 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 Section.O.EnterCriticalSection.. 000005A0 77 01 4C 65 61 76 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 78 01 4C 6F 61 64 4C 69 w☺LeaveCriticalSection..x☺LoadLi 000005C0 62 72 61 72 79 41 00 00 83 00 46 6C 75 73 68 46 69 6C 65 42 75 66 66 65 72 73 00 00 16 00 43 6C braryA..â.FlushFileBuffers..▬.Cl 000005E0 6F 73 65 48 61 6E 64 6C 65 00 06 02 53 65 74 53 74 64 48 61 6E 64 6C 65 00 00 F8 01 53 65 74 46 oseHandle.♠☻SetStdHandle..°☺SetF 00000600 69 6C 65 50 6F 69 6E 74 65 72 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ilePointer...................... 00000620 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000640 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000660 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000680 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000006A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000006C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000006E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000700 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000720 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000740 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000760 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000780 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000007A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000007C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000007E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................