============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 3C B0 00 00 00 00 00 00 00 00 00 00 CC B1 00 00 04 B1 00 00 F8 B0 00 00 00 00 00 00 00 00 00 00 <░..........╠▒..♦▒..°░.......... 00000020 D9 B1 00 00 C0 B1 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E4 B1 00 00 ┘▒..└▒......................Σ▒.. 00000040 F8 B1 00 00 0A B2 00 00 18 B2 00 00 26 B2 00 00 38 B2 00 00 4E B2 00 00 66 B2 00 00 7E B2 00 00 °▒..◙▓..↑▓..&▓..8▓..N▓..f▓..~▓.. 00000060 8C B2 00 00 9C B2 00 00 AC B2 00 00 C2 B2 00 00 D6 B2 00 00 E8 B2 00 00 FA B2 00 00 0A B3 00 00 î▓..£▓..¼▓..┬▓..╓▓..Φ▓..·▓..◙│.. 00000080 1A B3 00 00 30 B3 00 00 3E B3 00 00 5A B3 00 00 6E B3 00 00 82 B3 00 00 9A B3 00 00 A8 B3 00 00 →│..0│..>│..Z│..n│..é│..Ü│..¿│.. 000000A0 B4 B3 00 00 C6 B3 00 00 D2 B3 00 00 DC B3 00 00 F4 B3 00 00 06 B4 00 00 18 B4 00 00 2A B4 00 00 ┤│..╞│..╥│..▄│..⌠│..♠┤..↑┤..*┤.. 000000C0 3C B4 00 00 58 B4 00 00 68 B4 00 00 76 B4 00 00 82 B4 00 00 90 B4 00 00 A6 B4 00 00 B2 B4 00 00 <┤..X┤..h┤..v┤..é┤..É┤..ª┤..▓┤.. 000000E0 BE B4 00 00 CA B4 00 00 DE B4 00 00 F0 B4 00 00 FC B4 00 00 00 00 00 00 12 B5 00 00 20 B5 00 00 ╛┤..╩┤..▐┤..≡┤..ⁿ┤......↕╡.. ╡.. 00000100 00 00 00 00 E4 B1 00 00 F8 B1 00 00 0A B2 00 00 18 B2 00 00 26 B2 00 00 38 B2 00 00 4E B2 00 00 ....Σ▒..°▒..◙▓..↑▓..&▓..8▓..N▓.. 00000120 66 B2 00 00 7E B2 00 00 8C B2 00 00 9C B2 00 00 AC B2 00 00 C2 B2 00 00 D6 B2 00 00 E8 B2 00 00 f▓..~▓..î▓..£▓..¼▓..┬▓..╓▓..Φ▓.. 00000140 FA B2 00 00 0A B3 00 00 1A B3 00 00 30 B3 00 00 3E B3 00 00 5A B3 00 00 6E B3 00 00 82 B3 00 00 ·▓..◙│..→│..0│..>│..Z│..n│..é│.. 00000160 9A B3 00 00 A8 B3 00 00 B4 B3 00 00 C6 B3 00 00 D2 B3 00 00 DC B3 00 00 F4 B3 00 00 06 B4 00 00 Ü│..¿│..┤│..╞│..╥│..▄│..⌠│..♠┤.. 00000180 18 B4 00 00 2A B4 00 00 3C B4 00 00 58 B4 00 00 68 B4 00 00 76 B4 00 00 82 B4 00 00 90 B4 00 00 ↑┤..*┤..<┤..X┤..h┤..v┤..é┤..É┤.. 000001A0 A6 B4 00 00 B2 B4 00 00 BE B4 00 00 CA B4 00 00 DE B4 00 00 F0 B4 00 00 FC B4 00 00 00 00 00 00 ª┤..▓┤..╛┤..╩┤..▐┤..≡┤..ⁿ┤...... 000001C0 12 B5 00 00 20 B5 00 00 00 00 00 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 55 53 45 52 33 32 2E ↕╡.. ╡......KERNEL32.dll.USER32. 000001E0 64 6C 6C 00 FE 01 53 55 6E 4D 61 70 4C 53 5F 49 50 5F 45 42 50 5F 38 00 00 00 44 65 76 69 63 65 dll.■☺SUnMapLS_IP_EBP_8...Device 00000200 49 6F 43 6F 6E 74 72 6F 6C 00 00 00 43 72 65 61 74 65 46 69 6C 65 41 00 00 00 43 6C 6F 73 65 48 IoControl...CreateFileA...CloseH 00000220 61 6E 64 6C 65 00 00 00 47 65 74 43 6F 6D 6D 61 6E 64 4C 69 6E 65 41 00 00 00 47 65 74 43 75 72 andle...GetCommandLineA...GetCur 00000240 72 65 6E 74 54 68 72 65 61 64 49 64 00 00 00 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 rentThreadId....GetEnvironmentSt 00000260 72 69 6E 67 73 00 00 00 45 6E 74 65 72 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 00 00 rings...EnterCriticalSection.... 00000280 45 78 69 74 50 72 6F 63 65 73 73 00 00 00 47 65 74 4C 61 73 74 45 72 72 6F 72 00 00 00 00 47 65 ExitProcess...GetLastError....Ge 000002A0 74 4C 6F 63 61 6C 54 69 6D 65 00 00 00 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 tLocalTime....GetModuleFileNameA 000002C0 00 00 00 00 47 65 74 4D 6F 64 75 6C 65 48 61 6E 64 6C 65 41 00 00 00 00 47 65 74 50 72 6F 63 41 ....GetModuleHandleA....GetProcA 000002E0 64 64 72 65 73 73 00 00 00 00 47 65 74 53 74 61 72 74 75 70 49 6E 66 6F 41 00 00 00 47 65 74 53 ddress....GetStartupInfoA...GetS 00000300 74 64 48 61 6E 64 6C 65 00 00 00 00 47 65 74 54 69 63 6B 43 6F 75 6E 74 00 00 00 00 47 65 74 46 tdHandle....GetTickCount....GetF 00000320 69 6C 65 41 74 74 72 69 62 75 74 65 73 41 00 00 00 00 47 65 74 46 69 6C 65 54 79 70 65 00 00 00 ileAttributesA....GetFileType... 00000340 49 6E 69 74 69 61 6C 69 7A 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 00 4B 33 32 54 InitializeCriticalSection...K32T 00000360 68 6B 31 36 33 32 45 70 69 6C 6F 67 00 00 00 00 4B 33 32 54 68 6B 31 36 33 32 50 72 6F 6C 6F 67 hk1632Epilog....K32Thk1632Prolog 00000380 00 00 00 00 4C 65 61 76 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 00 00 4D 61 70 48 ....LeaveCriticalSection....MapH 000003A0 49 6E 73 74 4C 53 00 00 00 00 4D 61 70 53 4C 46 69 78 00 00 00 00 52 61 69 73 65 45 78 63 65 70 InstLS....MapSLFix....RaiseExcep 000003C0 74 69 6F 6E 00 00 00 00 52 74 6C 55 6E 77 69 6E 64 00 00 00 53 4D 61 70 4C 53 00 00 00 00 53 65 tion....RtlUnwind...SMapLS....Se 000003E0 74 43 6F 6E 73 6F 6C 65 43 74 72 6C 48 61 6E 64 6C 65 72 00 00 00 53 65 74 46 69 6C 65 50 6F 69 tConsoleCtrlHandler...SetFilePoi 00000400 6E 74 65 72 00 00 00 00 53 65 74 48 61 6E 64 6C 65 43 6F 75 6E 74 00 00 00 00 54 68 75 6E 6B 43 nter....SetHandleCount....ThunkC 00000420 6F 6E 6E 65 63 74 33 32 00 00 00 00 55 6E 4D 61 70 53 4C 46 69 78 41 72 72 61 79 00 00 00 55 6E onnect32....UnMapSLFixArray...Un 00000440 68 61 6E 64 6C 65 64 45 78 63 65 70 74 69 6F 6E 46 69 6C 74 65 72 00 00 00 00 56 69 72 74 75 61 handledExceptionFilter....Virtua 00000460 6C 41 6C 6C 6F 63 00 00 00 00 56 69 72 74 75 61 6C 46 72 65 65 00 00 00 57 72 69 74 65 46 69 6C lAlloc....VirtualFree...WriteFil 00000480 65 00 00 00 47 65 74 56 65 72 73 69 6F 6E 00 00 00 00 47 6C 6F 62 61 6C 4D 65 6D 6F 72 79 53 74 e...GetVersion....GlobalMemorySt 000004A0 61 74 75 73 00 00 7D 00 46 54 5F 45 78 69 74 34 00 00 83 00 46 54 5F 45 78 69 74 38 00 00 85 00 atus..}.FT_Exit4..â.FT_Exit8..à. 000004C0 46 54 5F 54 68 75 6E 6B 00 00 ED 01 53 4D 61 70 4C 53 5F 49 50 5F 45 42 50 5F 31 36 00 00 F4 01 FT_Thunk..φ☺SMapLS_IP_EBP_16..⌠☺ 000004E0 53 4D 61 70 4C 53 5F 49 50 5F 45 42 50 5F 38 00 F5 01 53 55 6E 4D 61 70 4C 53 00 00 F7 01 53 55 SMapLS_IP_EBP_8.⌡☺SUnMapLS..≈☺SU 00000500 6E 4D 61 70 4C 53 5F 49 50 5F 45 42 50 5F 31 36 00 00 00 00 4D 65 73 73 61 67 65 42 6F 78 41 00 nMapLS_IP_EBP_16....MessageBoxA. 00000520 00 00 45 6E 75 6D 54 68 72 65 61 64 57 69 6E 64 6F 77 73 00 00 00 00 00 00 00 00 00 00 00 00 00 ..EnumThreadWindows............. 00000540 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000560 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000580 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................