============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 A8 40 01 00 00 00 00 00 00 00 00 00 FE 45 01 00 DC 41 01 00 90 41 01 00 00 00 00 00 00 00 00 00 ¿@☺.........■E☺.▄A☺.ÉA☺......... 00000020 18 46 01 00 C4 42 01 00 64 40 01 00 00 00 00 00 00 00 00 00 3A 47 01 00 98 41 01 00 88 41 01 00 ↑F☺.─B☺.d@☺.........:G☺.ÿA☺.êA☺. 00000040 00 00 00 00 00 00 00 00 56 47 01 00 BC 42 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........VG☺.╝B☺................. 00000060 00 00 00 00 18 47 01 00 06 47 01 00 F4 46 01 00 E2 46 01 00 D0 46 01 00 C0 46 01 00 B0 46 01 00 ....↑G☺.♠G☺.⌠F☺.ΓF☺.╨F☺.└F☺.░F☺. 00000080 9E 46 01 00 8C 46 01 00 7C 46 01 00 6C 46 01 00 58 46 01 00 44 46 01 00 34 46 01 00 24 46 01 00 ₧F☺.îF☺.|F☺.lF☺.XF☺.DF☺.4F☺.$F☺. 000000A0 26 47 01 00 00 00 00 00 1A 44 01 00 2A 44 01 00 3A 44 01 00 0A 44 01 00 4A 44 01 00 60 44 01 00 &G☺.....→D☺.*D☺.:D☺.◙D☺.JD☺.`D☺. 000000C0 76 44 01 00 8A 44 01 00 9E 44 01 00 B0 44 01 00 C2 44 01 00 DA 44 01 00 E8 43 01 00 F8 43 01 00 vD☺.èD☺.₧D☺.░D☺.┬D☺.┌D☺.ΦC☺.°C☺. 000000E0 0E 45 01 00 1A 45 01 00 28 45 01 00 36 45 01 00 44 45 01 00 CC 42 01 00 62 45 01 00 70 45 01 00 ♫E☺.→E☺.(E☺.6E☺.DE☺.╠B☺.bE☺.pE☺. 00000100 80 45 01 00 88 45 01 00 A4 45 01 00 BA 45 01 00 D6 45 01 00 EE 45 01 00 D8 43 01 00 C2 43 01 00 ÇE☺.êE☺.ñE☺.║E☺.╓E☺.εE☺.╪C☺.┬C☺. 00000120 AC 43 01 00 98 43 01 00 86 43 01 00 76 43 01 00 68 43 01 00 58 43 01 00 42 43 01 00 32 43 01 00 ¼C☺.ÿC☺.åC☺.vC☺.hC☺.XC☺.BC☺.2C☺. 00000140 1C 43 01 00 04 43 01 00 EC 42 01 00 DC 42 01 00 02 45 01 00 F2 44 01 00 56 45 01 00 94 47 01 00 ∟C☺.♦C☺.∞B☺.▄B☺.☻E☺.≥D☺.VE☺.öG☺. 00000160 84 47 01 00 00 48 01 00 62 47 01 00 6E 47 01 00 EC 47 01 00 CE 47 01 00 A6 47 01 00 B4 47 01 00 äG☺..H☺.bG☺.nG☺.∞G☺.╬G☺.ªG☺.┤G☺. 00000180 DC 47 01 00 00 00 00 00 48 47 01 00 00 00 00 00 0C 46 01 00 00 00 00 00 18 47 01 00 06 47 01 00 ▄G☺.....HG☺.....♀F☺.....↑G☺.♠G☺. 000001A0 F4 46 01 00 E2 46 01 00 D0 46 01 00 C0 46 01 00 B0 46 01 00 9E 46 01 00 8C 46 01 00 7C 46 01 00 ⌠F☺.ΓF☺.╨F☺.└F☺.░F☺.₧F☺.îF☺.|F☺. 000001C0 6C 46 01 00 58 46 01 00 44 46 01 00 34 46 01 00 24 46 01 00 26 47 01 00 00 00 00 00 1A 44 01 00 lF☺.XF☺.DF☺.4F☺.$F☺.&G☺.....→D☺. 000001E0 2A 44 01 00 3A 44 01 00 0A 44 01 00 4A 44 01 00 60 44 01 00 76 44 01 00 8A 44 01 00 9E 44 01 00 *D☺.:D☺.◙D☺.JD☺.`D☺.vD☺.èD☺.₧D☺. 00000200 B0 44 01 00 C2 44 01 00 DA 44 01 00 E8 43 01 00 F8 43 01 00 0E 45 01 00 1A 45 01 00 28 45 01 00 ░D☺.┬D☺.┌D☺.ΦC☺.°C☺.♫E☺.→E☺.(E☺. 00000220 36 45 01 00 44 45 01 00 CC 42 01 00 62 45 01 00 70 45 01 00 80 45 01 00 88 45 01 00 A4 45 01 00 6E☺.DE☺.╠B☺.bE☺.pE☺.ÇE☺.êE☺.ñE☺. 00000240 BA 45 01 00 D6 45 01 00 EE 45 01 00 D8 43 01 00 C2 43 01 00 AC 43 01 00 98 43 01 00 86 43 01 00 ║E☺.╓E☺.εE☺.╪C☺.┬C☺.¼C☺.ÿC☺.åC☺. 00000260 76 43 01 00 68 43 01 00 58 43 01 00 42 43 01 00 32 43 01 00 1C 43 01 00 04 43 01 00 EC 42 01 00 vC☺.hC☺.XC☺.BC☺.2C☺.∟C☺.♦C☺.∞B☺. 00000280 DC 42 01 00 02 45 01 00 F2 44 01 00 56 45 01 00 94 47 01 00 84 47 01 00 00 48 01 00 62 47 01 00 ▄B☺.☻E☺.≥D☺.VE☺.öG☺.äG☺..H☺.bG☺. 000002A0 6E 47 01 00 EC 47 01 00 CE 47 01 00 A6 47 01 00 B4 47 01 00 DC 47 01 00 00 00 00 00 48 47 01 00 nG☺.∞G☺.╬G☺.ªG☺.┤G☺.▄G☺.....HG☺. 000002C0 00 00 00 00 0C 46 01 00 00 00 00 00 46 01 47 65 74 54 69 63 6B 43 6F 75 6E 74 00 00 86 01 49 73 ....♀F☺.....F☺GetTickCount..å☺Is 000002E0 42 61 64 57 72 69 74 65 50 74 72 00 91 01 4C 65 61 76 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 BadWritePtr.æ☺LeaveCriticalSecti 00000300 6F 6E 00 00 64 00 45 6E 74 65 72 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 7C 02 57 61 on..d.EnterCriticalSection..|☻Wa 00000320 69 74 46 6F 72 53 69 6E 67 6C 65 4F 62 6A 65 63 74 00 80 01 49 73 42 61 64 43 6F 64 65 50 74 72 itForSingleObject.Ç☺IsBadCodePtr 00000340 00 00 FD 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 00 00 4D 01 47 65 74 56 65 72 ..².GetModuleFileNameA..M☺GetVer 00000360 73 69 6F 6E 45 78 41 00 25 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 F5 00 47 65 74 4C 61 73 74 45 sionExA.%.CloseHandle.⌡.GetLastE 00000380 72 72 6F 72 00 00 61 00 44 75 70 6C 69 63 61 74 65 48 61 6E 64 6C 65 00 D3 00 47 65 74 43 75 72 rror..a.DuplicateHandle.╙.GetCur 000003A0 72 65 6E 74 50 72 6F 63 65 73 73 00 80 02 57 69 64 65 43 68 61 72 54 6F 4D 75 6C 74 69 42 79 74 rentProcess.Ç☻WideCharToMultiByt 000003C0 65 00 B9 01 4D 75 6C 74 69 42 79 74 65 54 6F 57 69 64 65 43 68 61 72 00 95 01 4C 6F 61 64 4C 69 e.╣☺MultiByteToWideChar.ò☺LoadLi 000003E0 62 72 61 72 79 57 00 00 92 01 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 15 01 47 65 74 50 72 6F braryW..Æ☺LoadLibraryA..§☺GetPro 00000400 63 41 64 64 72 65 73 73 00 00 3A 00 43 72 65 61 74 65 45 76 65 6E 74 57 00 00 39 00 43 72 65 61 cAddress..:.CreateEventW..9.Crea 00000420 74 65 45 76 65 6E 74 41 00 00 45 00 43 72 65 61 74 65 4D 75 74 65 78 57 00 00 44 00 43 72 65 61 teEventA..E.CreateMutexW..D.Crea 00000440 74 65 4D 75 74 65 78 41 00 00 3E 00 43 72 65 61 74 65 46 69 6C 65 4D 61 70 70 69 6E 67 57 00 00 teMutexA..>.CreateFileMappingW.. 00000460 3D 00 43 72 65 61 74 65 46 69 6C 65 4D 61 70 70 69 6E 67 41 00 00 BF 01 4F 70 65 6E 46 69 6C 65 =.CreateFileMappingA..┐☺OpenFile 00000480 4D 61 70 70 69 6E 67 57 00 00 BE 01 4F 70 65 6E 46 69 6C 65 4D 61 70 70 69 6E 67 41 00 00 4A 00 MappingW..╛☺OpenFileMappingA..J. 000004A0 43 72 65 61 74 65 50 72 6F 63 65 73 73 57 00 00 49 00 43 72 65 61 74 65 50 72 6F 63 65 73 73 41 CreateProcessW..I.CreateProcessA 000004C0 00 00 D2 00 47 65 74 43 75 72 72 65 6E 74 44 69 72 65 63 74 6F 72 79 57 00 00 D1 00 47 65 74 43 ..╥.GetCurrentDirectoryW..╤.GetC 000004E0 75 72 72 65 6E 74 44 69 72 65 63 74 6F 72 79 41 00 00 83 01 49 73 42 61 64 52 65 61 64 50 74 72 urrentDirectoryA..â☺IsBadReadPtr 00000500 00 00 6C 01 48 65 61 70 41 6C 6C 6F 63 00 70 01 48 65 61 70 46 72 65 65 00 00 72 01 48 65 61 70 ..l☺HeapAlloc.p☺HeapFree..r☺Heap 00000520 52 65 41 6C 6C 6F 63 00 6E 01 48 65 61 70 43 72 65 61 74 65 00 00 6F 01 48 65 61 70 44 65 73 74 ReAlloc.n☺HeapCreate..o☺HeapDest 00000540 72 6F 79 00 56 02 54 65 72 6D 69 6E 61 74 65 54 68 72 65 61 64 00 2A 02 53 65 74 45 76 65 6E 74 roy.V☻TerminateThread.*☻SetEvent 00000560 00 00 F0 01 52 65 73 65 74 45 76 65 6E 74 00 00 50 00 43 72 65 61 74 65 54 68 72 65 61 64 00 00 ..≡☺ResetEvent..P.CreateThread.. 00000580 4F 02 53 6C 65 65 70 00 79 01 49 6E 69 74 69 61 6C 69 7A 65 43 72 69 74 69 63 61 6C 53 65 63 74 O☻Sleep.y☺InitializeCriticalSect 000005A0 69 6F 6E 00 7C 01 49 6E 74 65 72 6C 6F 63 6B 65 64 45 78 63 68 61 6E 67 65 00 5E 00 44 69 73 61 ion.|☺InterlockedExchange.^.Disa 000005C0 62 6C 65 54 68 72 65 61 64 4C 69 62 72 61 72 79 43 61 6C 6C 73 00 59 00 44 65 6C 65 74 65 43 72 bleThreadLibraryCalls.Y.DeleteCr 000005E0 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 F3 01 52 74 6C 4D 6F 76 65 4D 65 6D 6F 72 79 00 4B 45 iticalSection.≤☺RtlMoveMemory.KE 00000600 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 53 02 77 73 70 72 69 6E 74 66 41 00 55 53 45 52 33 32 2E 64 RNEL32.dll..S☻wsprintfA.USER32.d 00000620 6C 6C 00 00 AE 00 52 65 67 4F 70 65 6E 4B 65 79 45 78 57 00 AD 00 52 65 67 4F 70 65 6E 4B 65 79 ll..«.RegOpenKeyExW.¡.RegOpenKey 00000640 45 78 41 00 B6 00 52 65 67 51 75 65 72 79 56 61 6C 75 65 45 78 57 00 00 B5 00 52 65 67 51 75 65 ExA.╢.RegQueryValueExW..╡.RegQue 00000660 72 79 56 61 6C 75 65 45 78 41 00 00 A3 00 52 65 67 45 6E 75 6D 4B 65 79 45 78 57 00 A2 00 52 65 ryValueExA..ú.RegEnumKeyExW.ó.Re 00000680 67 45 6E 75 6D 4B 65 79 45 78 41 00 C2 00 52 65 67 53 65 74 56 61 6C 75 65 45 78 57 00 00 C1 00 gEnumKeyExA.┬.RegSetValueExW..┴. 000006A0 52 65 67 53 65 74 56 61 6C 75 65 45 78 41 00 00 A6 00 52 65 67 45 6E 75 6D 56 61 6C 75 65 57 00 RegSetValueExA..ª.RegEnumValueW. 000006C0 A5 00 52 65 67 45 6E 75 6D 56 61 6C 75 65 41 00 A0 00 52 65 67 44 65 6C 65 74 65 56 61 6C 75 65 Ñ.RegEnumValueA.á.RegDeleteValue 000006E0 57 00 9F 00 52 65 67 44 65 6C 65 74 65 56 61 6C 75 65 41 00 9B 00 52 65 67 43 72 65 61 74 65 4B W.ƒ.RegDeleteValueA.¢.RegCreateK 00000700 65 79 45 78 57 00 9A 00 52 65 67 43 72 65 61 74 65 4B 65 79 45 78 41 00 96 00 52 65 67 43 6C 6F eyExW.Ü.RegCreateKeyExA.û.RegClo 00000720 73 65 4B 65 79 00 B1 00 52 65 67 51 75 65 72 79 49 6E 66 6F 4B 65 79 57 00 00 41 44 56 41 50 49 seKey.▒.RegQueryInfoKeyW..ADVAPI 00000740 33 32 2E 64 6C 6C 00 00 52 01 55 75 69 64 43 72 65 61 74 65 00 00 52 50 43 52 54 34 2E 64 6C 6C 32.dll..R☺UuidCreate..RPCRT4.dll 00000760 00 00 F4 01 52 74 6C 55 6E 77 69 6E 64 00 D4 00 47 65 74 43 75 72 72 65 6E 74 50 72 6F 63 65 73 ..⌠☺RtlUnwind.╘.GetCurrentProces 00000780 73 49 64 00 B0 01 4D 61 70 56 69 65 77 4F 66 46 69 6C 65 00 6B 02 55 6E 6D 61 70 56 69 65 77 4F sId.░☺MapViewOfFile.k☻UnmapViewO 000007A0 66 46 69 6C 65 00 78 00 45 78 69 74 54 68 72 65 61 64 00 00 7A 02 57 61 69 74 46 6F 72 4D 75 6C fFile.x.ExitThread..z☻WaitForMul 000007C0 74 69 70 6C 65 4F 62 6A 65 63 74 73 00 00 C2 01 4F 70 65 6E 50 72 6F 63 65 73 73 00 EC 01 52 65 tipleObjects..┬☺OpenProcess.∞☺Re 000007E0 6C 65 61 73 65 4D 75 74 65 78 00 00 55 02 54 65 72 6D 69 6E 61 74 65 50 72 6F 63 65 73 73 00 00 leaseMutex..U☻TerminateProcess.. 00000800 F1 01 52 65 73 75 6D 65 54 68 72 65 61 64 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ±☺ResumeThread.................. 00000820 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000840 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000860 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000880 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000008A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000008C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000008E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000900 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000920 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000940 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000960 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000980 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000009A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000009C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000009E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................