============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 00 31 01 00 00 00 00 00 00 00 00 00 E6 31 01 00 C4 31 01 00 08 31 01 00 00 00 00 00 00 00 00 00 .1☺.........µ1☺.─1☺.◘1☺......... 00000020 1A 32 01 00 CC 31 01 00 50 30 01 00 00 00 00 00 00 00 00 00 0C 35 01 00 14 31 01 00 00 00 00 00 →2☺.╠1☺.P0☺.........♀5☺.¶1☺..... 00000040 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 6A 33 01 00 7A 33 01 00 5C 33 01 00 F8 34 01 00 ................j3☺.z3☺.\3☺.°4☺. 00000060 26 32 01 00 34 32 01 00 46 32 01 00 54 32 01 00 66 32 01 00 78 32 01 00 8C 32 01 00 9A 32 01 00 &2☺.42☺.F2☺.T2☺.f2☺.x2☺.î2☺.Ü2☺. 00000080 AC 32 01 00 C2 32 01 00 D4 32 01 00 EA 32 01 00 F8 32 01 00 0C 33 01 00 20 33 01 00 2E 33 01 00 ¼2☺.┬2☺.╘2☺.Ω2☺.°2☺.♀3☺. 3☺..3☺. 000000A0 3C 33 01 00 4A 33 01 00 DE 34 01 00 2A 34 01 00 EA 34 01 00 8C 33 01 00 A2 33 01 00 AE 33 01 00 <3☺.J3☺.▐4☺.*4☺.Ω4☺.î3☺.ó3☺.«3☺. 000000C0 B8 33 01 00 C4 33 01 00 DE 33 01 00 F6 33 01 00 10 34 01 00 70 34 01 00 36 34 01 00 42 34 01 00 ╕3☺.─3☺.▐3☺.÷3☺.►4☺.p4☺.64☺.B4☺. 000000E0 4E 34 01 00 5E 34 01 00 80 34 01 00 90 34 01 00 A2 34 01 00 B4 34 01 00 CE 34 01 00 00 00 00 00 N4☺.^4☺.Ç4☺.É4☺.ó4☺.┤4☺.╬4☺..... 00000100 D8 31 01 00 00 00 00 00 04 32 01 00 F2 31 01 00 00 00 00 00 6A 33 01 00 7A 33 01 00 5C 33 01 00 ╪1☺.....♦2☺.≥1☺.....j3☺.z3☺.\3☺. 00000120 F8 34 01 00 26 32 01 00 34 32 01 00 46 32 01 00 54 32 01 00 66 32 01 00 78 32 01 00 8C 32 01 00 °4☺.&2☺.42☺.F2☺.T2☺.f2☺.x2☺.î2☺. 00000140 9A 32 01 00 AC 32 01 00 C2 32 01 00 D4 32 01 00 EA 32 01 00 F8 32 01 00 0C 33 01 00 20 33 01 00 Ü2☺.¼2☺.┬2☺.╘2☺.Ω2☺.°2☺.♀3☺. 3☺. 00000160 2E 33 01 00 3C 33 01 00 4A 33 01 00 DE 34 01 00 2A 34 01 00 EA 34 01 00 8C 33 01 00 A2 33 01 00 .3☺.<3☺.J3☺.▐4☺.*4☺.Ω4☺.î3☺.ó3☺. 00000180 AE 33 01 00 B8 33 01 00 C4 33 01 00 DE 33 01 00 F6 33 01 00 10 34 01 00 70 34 01 00 36 34 01 00 «3☺.╕3☺.─3☺.▐3☺.÷3☺.►4☺.p4☺.64☺. 000001A0 42 34 01 00 4E 34 01 00 5E 34 01 00 80 34 01 00 90 34 01 00 A2 34 01 00 B4 34 01 00 CE 34 01 00 B4☺.N4☺.^4☺.Ç4☺.É4☺.ó4☺.┤4☺.╬4☺. 000001C0 00 00 00 00 D8 31 01 00 00 00 00 00 04 32 01 00 F2 31 01 00 00 00 00 00 95 01 4D 65 73 73 61 67 ....╪1☺.....♦2☺.≥1☺.....ò☺Messag 000001E0 65 42 6F 78 41 00 55 53 45 52 33 32 2E 64 6C 6C 00 00 0A 00 56 65 72 51 75 65 72 79 56 61 6C 75 eBoxA.USER32.dll..◙.VerQueryValu 00000200 65 41 00 00 00 00 47 65 74 46 69 6C 65 56 65 72 73 69 6F 6E 49 6E 66 6F 41 00 56 45 52 53 49 4F eA....GetFileVersionInfoA.VERSIO 00000220 4E 2E 64 6C 6C 00 17 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 4F 00 44 65 76 69 63 65 49 6F 43 6F N.dll.↨.CloseHandle.O.DeviceIoCo 00000240 6E 74 72 6F 6C 00 30 00 43 72 65 61 74 65 46 69 6C 65 41 00 A9 00 47 65 74 43 6F 6D 6D 61 6E 64 ntrol.0.CreateFileA.⌐.GetCommand 00000260 4C 69 6E 65 41 00 15 01 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 FD 00 47 65 74 4D 6F 64 LineA.§☺GetProcAddress..².GetMod 00000280 75 6C 65 48 61 6E 64 6C 65 41 00 00 4B 01 47 65 74 56 65 72 73 69 6F 6E 00 00 2A 01 47 65 74 53 uleHandleA..K☺GetVersion..*☺GetS 000002A0 74 72 69 6E 67 54 79 70 65 41 00 00 69 02 57 69 64 65 43 68 61 72 54 6F 4D 75 6C 74 69 42 79 74 tringTypeA..i☻WideCharToMultiByt 000002C0 65 00 2D 01 47 65 74 53 74 72 69 6E 67 54 79 70 65 57 00 00 A9 01 4D 75 6C 74 69 42 79 74 65 54 e.-☺GetStringTypeW..⌐☺MultiByteT 000002E0 6F 57 69 64 65 43 68 61 72 00 6A 00 45 78 69 74 50 72 6F 63 65 73 73 00 41 02 54 65 72 6D 69 6E oWideChar.j.ExitProcess.A☻Termin 00000300 61 74 65 50 72 6F 63 65 73 73 00 00 D2 00 47 65 74 43 75 72 72 65 6E 74 50 72 6F 63 65 73 73 00 ateProcess..╥.GetCurrentProcess. 00000320 6B 01 48 65 61 70 44 65 73 74 72 6F 79 00 69 01 48 65 61 70 43 72 65 61 74 65 00 00 59 02 56 69 k☺HeapDestroy.i☺HeapCreate..Y☻Vi 00000340 72 74 75 61 6C 46 72 65 65 00 16 02 53 65 74 48 61 6E 64 6C 65 43 6F 75 6E 74 00 00 EE 00 47 65 rtualFree.▬☻SetHandleCount..ε.Ge 00000360 74 46 69 6C 65 54 79 70 65 00 29 01 47 65 74 53 74 64 48 61 6E 64 6C 65 00 00 27 01 47 65 74 53 tFileType.)☺GetStdHandle..'☺GetS 00000380 74 61 72 74 75 70 49 6E 66 6F 41 00 FB 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 tartupInfoA.√.GetModuleFileNameA 000003A0 00 00 A2 00 47 65 74 43 50 49 6E 66 6F 00 9C 00 47 65 74 41 43 50 00 00 08 01 47 65 74 4F 45 4D ..ó.GetCPInfo.£.GetACP..◘☺GetOEM 000003C0 43 50 00 00 95 00 46 72 65 65 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 41 00 E0 00 CP..ò.FreeEnvironmentStringsA.α. 000003E0 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 00 96 00 46 72 65 65 45 6E 76 69 GetEnvironmentStrings.û.FreeEnvi 00000400 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 57 00 E2 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 ronmentStringsW.Γ.GetEnvironment 00000420 53 74 72 69 6E 67 73 57 00 00 76 02 57 72 69 74 65 46 69 6C 65 00 6D 01 48 65 61 70 46 72 65 65 StringsW..v☻WriteFile.m☺HeapFree 00000440 00 00 67 01 48 65 61 70 41 6C 6C 6F 63 00 F3 00 47 65 74 4C 61 73 74 45 72 72 6F 72 00 00 14 02 ..g☺HeapAlloc.≤.GetLastError..¶☻ 00000460 53 65 74 46 69 6C 65 50 6F 69 6E 74 65 72 00 00 56 02 56 69 72 74 75 61 6C 41 6C 6C 6F 63 00 00 SetFilePointer..V☻VirtualAlloc.. 00000480 8E 01 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 1D 00 43 6F 6D 70 61 72 65 53 74 72 69 6E 67 41 Ä☺LoadLibraryA..↔.CompareStringA 000004A0 00 00 1E 00 43 6F 6D 70 61 72 65 53 74 72 69 6E 67 57 00 00 0C 02 53 65 74 45 6E 76 69 72 6F 6E ..▲.CompareStringW..♀☻SetEnviron 000004C0 6D 65 6E 74 56 61 72 69 61 62 6C 65 41 00 24 02 53 65 74 53 74 64 48 61 6E 64 6C 65 00 00 D2 01 mentVariableA.$☻SetStdHandle..╥☺ 000004E0 52 65 61 64 46 69 6C 65 00 00 70 01 48 65 61 70 52 65 41 6C 6C 6F 63 00 8D 00 46 6C 75 73 68 46 ReadFile..p☺HeapReAlloc.ì.FlushF 00000500 69 6C 65 42 75 66 66 65 72 73 00 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 00 00 00 00 00 00 ileBuffers..KERNEL32.dll........ 00000520 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000540 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000560 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000580 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................