============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 64 20 01 00 00 00 00 00 00 00 00 00 0C 22 01 00 38 21 01 00 F4 20 01 00 00 00 00 00 00 00 00 00 d ☺.........♀"☺.8!☺.⌠ ☺......... 00000020 19 22 01 00 C8 21 01 00 18 21 01 00 00 00 00 00 00 00 00 00 24 22 01 00 EC 21 01 00 30 21 01 00 ↓"☺.╚!☺.↑!☺.........$"☺.∞!☺.0!☺. 00000040 00 00 00 00 00 00 00 00 31 22 01 00 04 22 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........1"☺.♦"☺................. 00000060 00 00 00 00 3C 22 01 00 4C 22 01 00 5E 22 01 00 74 22 01 00 82 22 01 00 9E 22 01 00 AC 22 01 00 ....<"☺.L"☺.^"☺.t"☺.é"☺.₧"☺.¼"☺. 00000080 BA 22 01 00 D2 22 01 00 E2 22 01 00 EE 22 01 00 00 23 01 00 18 23 01 00 2E 23 01 00 3C 23 01 00 ║"☺.╥"☺.Γ"☺.ε"☺..#☺.↑#☺..#☺.<#☺. 000000A0 4C 23 01 00 5C 23 01 00 72 23 01 00 86 23 01 00 98 23 01 00 AE 23 01 00 BC 23 01 00 CE 23 01 00 L#☺.\#☺.r#☺.å#☺.ÿ#☺.«#☺.╝#☺.╬#☺. 000000C0 DC 23 01 00 F8 23 01 00 0C 24 01 00 20 24 01 00 38 24 01 00 46 24 01 00 52 24 01 00 64 24 01 00 ▄#☺.°#☺.♀$☺. $☺.8$☺.F$☺.R$☺.d$☺. 000000E0 70 24 01 00 88 24 01 00 9A 24 01 00 AC 24 01 00 00 00 00 00 BE 24 01 00 CA 24 01 00 D8 24 01 00 p$☺.ê$☺.Ü$☺.¼$☺.....╛$☺.╩$☺.╪$☺. 00000100 E8 24 01 00 FC 24 01 00 0C 25 01 00 20 25 01 00 32 25 01 00 00 00 00 00 40 25 01 00 52 25 01 00 Φ$☺.ⁿ$☺.♀%☺. %☺.2%☺.....@%☺.R%☺. 00000120 62 25 01 00 72 25 01 00 84 25 01 00 00 00 00 00 92 25 01 00 00 00 00 00 3C 22 01 00 4C 22 01 00 b%☺.r%☺.ä%☺.....Æ%☺.....<"☺.L"☺. 00000140 5E 22 01 00 74 22 01 00 82 22 01 00 9E 22 01 00 AC 22 01 00 BA 22 01 00 D2 22 01 00 E2 22 01 00 ^"☺.t"☺.é"☺.₧"☺.¼"☺.║"☺.╥"☺.Γ"☺. 00000160 EE 22 01 00 00 23 01 00 18 23 01 00 2E 23 01 00 3C 23 01 00 4C 23 01 00 5C 23 01 00 72 23 01 00 ε"☺..#☺.↑#☺..#☺.<#☺.L#☺.\#☺.r#☺. 00000180 86 23 01 00 98 23 01 00 AE 23 01 00 BC 23 01 00 CE 23 01 00 DC 23 01 00 F8 23 01 00 0C 24 01 00 å#☺.ÿ#☺.«#☺.╝#☺.╬#☺.▄#☺.°#☺.♀$☺. 000001A0 20 24 01 00 38 24 01 00 46 24 01 00 52 24 01 00 64 24 01 00 70 24 01 00 88 24 01 00 9A 24 01 00 $☺.8$☺.F$☺.R$☺.d$☺.p$☺.ê$☺.Ü$☺. 000001C0 AC 24 01 00 00 00 00 00 BE 24 01 00 CA 24 01 00 D8 24 01 00 E8 24 01 00 FC 24 01 00 0C 25 01 00 ¼$☺.....╛$☺.╩$☺.╪$☺.Φ$☺.ⁿ$☺.♀%☺. 000001E0 20 25 01 00 32 25 01 00 00 00 00 00 40 25 01 00 52 25 01 00 62 25 01 00 72 25 01 00 84 25 01 00 %☺.2%☺.....@%☺.R%☺.b%☺.r%☺.ä%☺. 00000200 00 00 00 00 92 25 01 00 00 00 00 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 55 53 45 52 33 32 2E ....Æ%☺.....KERNEL32.dll.USER32. 00000220 64 6C 6C 00 41 44 56 41 50 49 33 32 2E 64 6C 6C 00 44 44 52 41 57 2E 64 6C 6C 00 00 00 00 56 69 dll.ADVAPI32.dll.DDRAW.dll....Vi 00000240 72 74 75 61 6C 41 6C 6C 6F 63 00 00 00 00 55 6E 4D 61 70 53 4C 46 69 78 41 72 72 61 79 00 00 00 rtualAlloc....UnMapSLFixArray... 00000260 47 65 74 43 75 72 72 65 6E 74 54 68 72 65 61 64 49 64 00 00 00 00 56 69 72 74 75 61 6C 46 72 65 GetCurrentThreadId....VirtualFre 00000280 65 00 00 00 55 6E 68 61 6E 64 6C 65 64 45 78 63 65 70 74 69 6F 6E 46 69 6C 74 65 72 00 00 00 00 e...UnhandledExceptionFilter.... 000002A0 43 6C 6F 73 65 48 61 6E 64 6C 65 00 00 00 43 72 65 61 74 65 46 69 6C 65 41 00 00 00 45 6E 74 65 CloseHandle...CreateFileA...Ente 000002C0 72 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 00 00 47 65 74 53 74 64 48 61 6E 64 6C 65 rCriticalSection....GetStdHandle 000002E0 00 00 00 00 57 72 69 74 65 46 69 6C 65 00 00 00 47 65 74 43 6F 6D 6D 61 6E 64 4C 69 6E 65 41 00 ....WriteFile...GetCommandLineA. 00000300 00 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 00 00 00 47 65 74 46 69 6C ..GetEnvironmentStrings...GetFil 00000320 65 41 74 74 72 69 62 75 74 65 73 41 00 00 00 00 47 65 74 46 69 6C 65 54 79 70 65 00 00 00 47 65 eAttributesA....GetFileType...Ge 00000340 74 4C 61 73 74 45 72 72 6F 72 00 00 00 00 47 65 74 4C 6F 63 61 6C 54 69 6D 65 00 00 00 00 47 65 tLastError....GetLocalTime....Ge 00000360 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 00 00 00 00 47 65 74 4D 6F 64 75 6C 65 48 61 6E tModuleFileNameA....GetModuleHan 00000380 64 6C 65 41 00 00 00 00 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 00 00 47 6C 6F 62 61 6C dleA....GetProcAddress....Global 000003A0 4D 65 6D 6F 72 79 53 74 61 74 75 73 00 00 00 00 45 78 69 74 50 72 6F 63 65 73 73 00 00 00 47 65 MemoryStatus....ExitProcess...Ge 000003C0 74 53 74 61 72 74 75 70 49 6E 66 6F 41 00 00 00 47 65 74 56 65 72 73 69 6F 6E 00 00 00 00 49 6E tStartupInfoA...GetVersion....In 000003E0 69 74 69 61 6C 69 7A 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 00 4B 33 32 54 68 6B itializeCriticalSection...K32Thk 00000400 31 36 33 32 45 70 69 6C 6F 67 00 00 00 00 4B 33 32 54 68 6B 31 36 33 32 50 72 6F 6C 6F 67 00 00 1632Epilog....K32Thk1632Prolog.. 00000420 00 00 4C 65 61 76 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 00 00 4D 61 70 48 49 6E ..LeaveCriticalSection....MapHIn 00000440 73 74 53 4C 00 00 00 00 4D 61 70 53 4C 46 69 78 00 00 00 00 52 61 69 73 65 45 78 63 65 70 74 69 stSL....MapSLFix....RaiseExcepti 00000460 6F 6E 00 00 00 00 52 74 6C 55 6E 77 69 6E 64 00 00 00 53 65 74 43 6F 6E 73 6F 6C 65 43 74 72 6C on....RtlUnwind...SetConsoleCtrl 00000480 48 61 6E 64 6C 65 72 00 00 00 53 65 74 46 69 6C 65 50 6F 69 6E 74 65 72 00 00 00 00 53 65 74 48 Handler...SetFilePointer....SetH 000004A0 61 6E 64 6C 65 43 6F 75 6E 74 00 00 00 00 54 68 75 6E 6B 43 6F 6E 6E 65 63 74 33 32 00 00 00 00 andleCount....ThunkConnect32.... 000004C0 77 73 70 72 69 6E 74 66 41 00 00 00 4D 65 73 73 61 67 65 42 6F 78 41 00 00 00 47 65 74 57 69 6E wsprintfA...MessageBoxA...GetWin 000004E0 64 6F 77 52 65 63 74 00 00 00 47 65 74 44 65 73 6B 74 6F 70 57 69 6E 64 6F 77 00 00 00 00 47 65 dowRect...GetDesktopWindow....Ge 00000500 74 43 6C 69 65 6E 74 52 65 63 74 00 00 00 45 6E 75 6D 54 68 72 65 61 64 57 69 6E 64 6F 77 73 00 tClientRect...EnumThreadWindows. 00000520 00 00 43 6C 69 65 6E 74 54 6F 53 63 72 65 65 6E 00 00 00 00 4C 6F 61 64 49 6D 61 67 65 41 00 00 ..ClientToScreen....LoadImageA.. 00000540 00 00 52 65 67 53 65 74 56 61 6C 75 65 45 78 41 00 00 00 00 52 65 67 43 72 65 61 74 65 4B 65 79 ..RegSetValueExA....RegCreateKey 00000560 41 00 00 00 52 65 67 53 65 74 56 61 6C 75 65 41 00 00 00 00 52 65 67 51 75 65 72 79 56 61 6C 75 A...RegSetValueA....RegQueryValu 00000580 65 41 00 00 00 00 52 65 67 43 6C 6F 73 65 4B 65 79 00 00 00 44 69 72 65 63 74 44 72 61 77 43 72 eA....RegCloseKey...DirectDrawCr 000005A0 65 61 74 65 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 eate............................ 000005C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................