============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 64 70 00 00 00 00 00 00 00 00 00 00 3A 72 00 00 28 71 00 00 F0 70 00 00 00 00 00 00 00 00 00 00 dp..........:r..(q..≡p.......... 00000020 E0 72 00 00 B4 71 00 00 50 70 00 00 00 00 00 00 00 00 00 00 2C 73 00 00 14 71 00 00 00 00 00 00 αr..┤q..Pp..........,s..¶q...... 00000040 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 EC 72 00 00 FA 72 00 00 1C 73 00 00 08 73 00 00 ................∞r..·r..∟s..◘s.. 00000060 00 00 00 00 E8 71 00 00 1C 72 00 00 0E 72 00 00 F8 71 00 00 2E 72 00 00 76 73 00 00 D2 73 00 00 ....Φq..∟r..♫r..°q...r..vs..╥s.. 00000080 C2 73 00 00 0A 75 00 00 FE 74 00 00 E8 74 00 00 CE 74 00 00 B4 74 00 00 9C 74 00 00 3A 73 00 00 ┬s..◙u..■t..Φt..╬t..┤t..£t..:s.. 000000A0 46 73 00 00 52 73 00 00 64 73 00 00 D8 71 00 00 8A 73 00 00 98 73 00 00 A6 73 00 00 B4 73 00 00 Fs..Rs..ds..╪q..ès..ÿs..ªs..┤s.. 000000C0 82 74 00 00 28 74 00 00 E0 73 00 00 F4 73 00 00 08 74 00 00 1A 74 00 00 38 74 00 00 4A 74 00 00 ét..(t..αs..⌠s..◘t..→t..8t..Jt.. 000000E0 60 74 00 00 6C 74 00 00 76 74 00 00 00 00 00 00 48 72 00 00 62 72 00 00 74 72 00 00 84 72 00 00 `t..lt..vt......Hr..br..tr..är.. 00000100 94 72 00 00 CA 72 00 00 B6 72 00 00 A4 72 00 00 00 00 00 00 EC 72 00 00 FA 72 00 00 1C 73 00 00 ör..╩r..╢r..ñr......∞r..·r..∟s.. 00000120 08 73 00 00 00 00 00 00 E8 71 00 00 1C 72 00 00 0E 72 00 00 F8 71 00 00 2E 72 00 00 76 73 00 00 ◘s......Φq..∟r..♫r..°q...r..vs.. 00000140 D2 73 00 00 C2 73 00 00 0A 75 00 00 FE 74 00 00 E8 74 00 00 CE 74 00 00 B4 74 00 00 9C 74 00 00 ╥s..┬s..◙u..■t..Φt..╬t..┤t..£t.. 00000160 3A 73 00 00 46 73 00 00 52 73 00 00 64 73 00 00 D8 71 00 00 8A 73 00 00 98 73 00 00 A6 73 00 00 :s..Fs..Rs..ds..╪q..ès..ÿs..ªs.. 00000180 B4 73 00 00 82 74 00 00 28 74 00 00 E0 73 00 00 F4 73 00 00 08 74 00 00 1A 74 00 00 38 74 00 00 ┤s..ét..(t..αs..⌠s..◘t..→t..8t.. 000001A0 4A 74 00 00 60 74 00 00 6C 74 00 00 76 74 00 00 00 00 00 00 48 72 00 00 62 72 00 00 74 72 00 00 Jt..`t..lt..vt......Hr..br..tr.. 000001C0 84 72 00 00 94 72 00 00 CA 72 00 00 B6 72 00 00 A4 72 00 00 00 00 00 00 A2 01 4D 61 70 56 69 65 är..ör..╩r..╢r..ñr......ó☺MapVie 000001E0 77 4F 66 46 69 6C 65 00 F3 00 47 65 74 4C 61 73 74 45 72 72 6F 72 00 00 32 00 43 72 65 61 74 65 wOfFile.≤.GetLastError..2.Create 00000200 46 69 6C 65 4D 61 70 70 69 6E 67 57 00 00 17 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 4E 02 55 6E FileMappingW..↨.CloseHandle.N☻Un 00000220 6D 61 70 56 69 65 77 4F 66 46 69 6C 65 00 94 02 6C 73 74 72 63 6D 70 69 57 00 4B 45 52 4E 45 4C mapViewOfFile.ö☻lstrcmpiW.KERNEL 00000240 33 32 2E 64 6C 6C 00 00 CA 01 52 65 67 69 73 74 65 72 57 69 6E 64 6F 77 4D 65 73 73 61 67 65 57 32.dll..╩☺RegisterWindowMessageW 00000260 00 00 11 00 43 61 6C 6C 4E 65 78 74 48 6F 6F 6B 45 78 00 00 ED 00 47 65 74 43 75 72 73 6F 72 50 ..◄.CallNextHookEx..φ.GetCursorP 00000280 6F 73 00 00 E2 00 47 65 74 43 6C 61 73 73 4E 61 6D 65 57 00 3D 01 47 65 74 57 69 6E 64 6F 77 52 os..Γ.GetClassNameW.=☺GetWindowR 000002A0 65 63 74 00 3B 01 47 65 74 57 69 6E 64 6F 77 4C 6F 6E 67 57 00 00 25 02 53 65 74 57 69 6E 64 6F ect.;☺GetWindowLongW..%☻SetWindo 000002C0 77 73 48 6F 6F 6B 45 78 57 00 46 02 55 6E 68 6F 6F 6B 57 69 6E 64 6F 77 73 48 6F 6F 6B 45 78 00 wsHookExW.F☻UnhookWindowsHookEx. 000002E0 55 53 45 52 33 32 2E 64 6C 6C 00 00 17 01 52 65 67 43 6C 6F 73 65 4B 65 79 00 30 01 52 65 67 4F USER32.dll..↨☺RegCloseKey.0☺RegO 00000300 70 65 6E 4B 65 79 57 00 37 01 52 65 67 51 75 65 72 79 56 61 6C 75 65 45 78 57 00 00 2F 01 52 65 penKeyW.7☺RegQueryValueExW../☺Re 00000320 67 4F 70 65 6E 4B 65 79 45 78 57 00 41 44 56 41 50 49 33 32 2E 64 6C 6C 00 00 6D 01 48 65 61 70 gOpenKeyExW.ADVAPI32.dll..m☺Heap 00000340 46 72 65 65 00 00 67 01 48 65 61 70 41 6C 6C 6F 63 00 A9 00 47 65 74 43 6F 6D 6D 61 6E 64 4C 69 Free..g☺HeapAlloc.⌐.GetCommandLi 00000360 6E 65 41 00 15 01 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 FD 00 47 65 74 4D 6F 64 75 6C neA.§☺GetProcAddress..².GetModul 00000380 65 48 61 6E 64 6C 65 41 00 00 4B 01 47 65 74 56 65 72 73 69 6F 6E 00 00 6B 01 48 65 61 70 44 65 eHandleA..K☺GetVersion..k☺HeapDe 000003A0 73 74 72 6F 79 00 69 01 48 65 61 70 43 72 65 61 74 65 00 00 59 02 56 69 72 74 75 61 6C 46 72 65 stroy.i☺HeapCreate..Y☻VirtualFre 000003C0 65 00 56 02 56 69 72 74 75 61 6C 41 6C 6C 6F 63 00 00 6A 00 45 78 69 74 50 72 6F 63 65 73 73 00 e.V☻VirtualAlloc..j.ExitProcess. 000003E0 41 02 54 65 72 6D 69 6E 61 74 65 50 72 6F 63 65 73 73 00 00 D2 00 47 65 74 43 75 72 72 65 6E 74 A☻TerminateProcess..╥.GetCurrent 00000400 50 72 6F 63 65 73 73 00 16 02 53 65 74 48 61 6E 64 6C 65 43 6F 75 6E 74 00 00 EE 00 47 65 74 46 Process.▬☻SetHandleCount..ε.GetF 00000420 69 6C 65 54 79 70 65 00 29 01 47 65 74 53 74 64 48 61 6E 64 6C 65 00 00 27 01 47 65 74 53 74 61 ileType.)☺GetStdHandle..'☺GetSta 00000440 72 74 75 70 49 6E 66 6F 41 00 FB 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 00 00 rtupInfoA.√.GetModuleFileNameA.. 00000460 A2 00 47 65 74 43 50 49 6E 66 6F 00 9C 00 47 65 74 41 43 50 00 00 08 01 47 65 74 4F 45 4D 43 50 ó.GetCPInfo.£.GetACP..◘☺GetOEMCP 00000480 00 00 95 00 46 72 65 65 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 41 00 E0 00 47 65 ..ò.FreeEnvironmentStringsA.α.Ge 000004A0 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 00 96 00 46 72 65 65 45 6E 76 69 72 6F tEnvironmentStrings.û.FreeEnviro 000004C0 6E 6D 65 6E 74 53 74 72 69 6E 67 73 57 00 E2 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 nmentStringsW.Γ.GetEnvironmentSt 000004E0 72 69 6E 67 73 57 00 00 69 02 57 69 64 65 43 68 61 72 54 6F 4D 75 6C 74 69 42 79 74 65 00 76 02 ringsW..i☻WideCharToMultiByte.v☻ 00000500 57 72 69 74 65 46 69 6C 65 00 8E 01 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 00 00 00 00 00 00 WriteFile.Ä☺LoadLibraryA........ 00000520 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000540 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000560 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000580 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................