============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 3C C0 04 00 00 00 00 00 00 00 00 00 DA C2 04 00 B0 C0 04 00 A8 C0 04 00 00 00 00 00 00 00 00 00 <└♦.........┌┬♦.░└♦.¿└♦......... 00000020 F6 C2 04 00 1C C1 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 30 C1 04 00 ÷┬♦.∟┴♦.....................0┴♦. 00000040 4A C1 04 00 5E C1 04 00 72 C1 04 00 86 C1 04 00 8E C1 04 00 96 C1 04 00 A4 C1 04 00 BA C1 04 00 J┴♦.^┴♦.r┴♦.å┴♦.Ä┴♦.û┴♦.ñ┴♦.║┴♦. 00000060 C8 C1 04 00 E4 C1 04 00 F2 C1 04 00 02 C2 04 00 10 C2 04 00 22 C2 04 00 34 C2 04 00 44 C2 04 00 ╚┴♦.Σ┴♦.≥┴♦.☻┬♦.►┬♦."┬♦.4┬♦.D┬♦. 00000080 56 C2 04 00 24 C1 04 00 64 C2 04 00 7A C2 04 00 8E C2 04 00 A4 C2 04 00 B0 C2 04 00 BE C2 04 00 V┬♦.$┴♦.d┬♦.z┬♦.Ä┬♦.ñ┬♦.░┬♦.╛┬♦. 000000A0 CE C2 04 00 00 00 00 00 E8 C2 04 00 00 00 00 00 30 C1 04 00 4A C1 04 00 5E C1 04 00 72 C1 04 00 ╬┬♦.....Φ┬♦.....0┴♦.J┴♦.^┴♦.r┴♦. 000000C0 86 C1 04 00 8E C1 04 00 96 C1 04 00 A4 C1 04 00 BA C1 04 00 C8 C1 04 00 E4 C1 04 00 F2 C1 04 00 å┴♦.Ä┴♦.û┴♦.ñ┴♦.║┴♦.╚┴♦.Σ┴♦.≥┴♦. 000000E0 02 C2 04 00 10 C2 04 00 22 C2 04 00 34 C2 04 00 44 C2 04 00 56 C2 04 00 24 C1 04 00 64 C2 04 00 ☻┬♦.►┬♦."┬♦.4┬♦.D┬♦.V┬♦.$┴♦.d┬♦. 00000100 7A C2 04 00 8E C2 04 00 A4 C2 04 00 B0 C2 04 00 BE C2 04 00 CE C2 04 00 00 00 00 00 E8 C2 04 00 z┬♦.Ä┬♦.ñ┬♦.░┬♦.╛┬♦.╬┬♦.....Φ┬♦. 00000120 00 00 00 00 6C 01 48 65 61 70 41 6C 6C 6F 63 00 D9 01 51 75 65 72 79 50 65 72 66 6F 72 6D 61 6E ....l☺HeapAlloc.┘☺QueryPerforman 00000140 63 65 43 6F 75 6E 74 65 72 00 3A 02 53 65 74 50 72 69 6F 72 69 74 79 43 6C 61 73 73 00 00 0A 01 ceCounter.:☻SetPriorityClass..◙☺ 00000160 47 65 74 50 72 69 6F 72 69 74 79 43 6C 61 73 73 00 00 D3 00 47 65 74 43 75 72 72 65 6E 74 50 72 GetPriorityClass..╙.GetCurrentPr 00000180 6F 63 65 73 73 00 AD 01 4D 61 70 4C 53 00 AE 01 4D 61 70 53 4C 00 6F 01 48 65 61 70 44 65 73 74 ocess.¡☺MapLS.«☺MapSL.o☺HeapDest 000001A0 72 6F 79 00 7C 01 49 6E 74 65 72 6C 6F 63 6B 65 64 45 78 63 68 61 6E 67 65 00 6E 01 48 65 61 70 roy.|☺InterlockedExchange.n☺Heap 000001C0 43 72 65 61 74 65 00 00 5E 00 44 69 73 61 62 6C 65 54 68 72 65 61 64 4C 69 62 72 61 72 79 43 61 Create..^.DisableThreadLibraryCa 000001E0 6C 6C 73 00 72 01 48 65 61 70 52 65 41 6C 6C 6F 63 00 F5 00 47 65 74 4C 61 73 74 45 72 72 6F 72 lls.r☺HeapReAlloc.⌡.GetLastError 00000200 00 00 3C 00 43 72 65 61 74 65 46 69 6C 65 41 00 5D 00 44 65 76 69 63 65 49 6F 43 6F 6E 74 72 6F ..<.CreateFileA.].DeviceIoContro 00000220 6C 00 15 01 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 92 01 4C 6F 61 64 4C 69 62 72 61 72 l.§☺GetProcAddress..Æ☺LoadLibrar 00000240 79 41 00 00 DC 01 52 61 69 73 65 45 78 63 65 70 74 69 6F 6E 00 00 77 00 45 78 69 74 50 72 6F 63 yA..▄☺RaiseException..w.ExitProc 00000260 65 73 73 00 80 02 57 69 64 65 43 68 61 72 54 6F 4D 75 6C 74 69 42 79 74 65 00 FF 00 47 65 74 4D ess.Ç☻WideCharToMultiByte. .GetM 00000280 6F 64 75 6C 65 48 61 6E 64 6C 65 41 00 00 B9 01 4D 75 6C 74 69 42 79 74 65 54 6F 57 69 64 65 43 oduleHandleA..╣☺MultiByteToWideC 000002A0 68 61 72 00 F4 01 52 74 6C 55 6E 77 69 6E 64 00 71 02 56 69 72 74 75 61 6C 46 72 65 65 00 70 02 har.⌠☺RtlUnwind.q☻VirtualFree.p☻ 000002C0 56 69 72 74 75 61 6C 41 6C 6C 6F 63 00 00 8B 02 57 72 69 74 65 46 69 6C 65 00 4B 45 52 4E 45 4C VirtualAlloc..ï☻WriteFile.KERNEL 000002E0 33 32 2E 64 6C 6C 00 00 88 01 4D 65 73 73 61 67 65 42 6F 78 41 00 55 53 45 52 33 32 2E 64 6C 6C 32.dll..ê☺MessageBoxA.USER32.dll 00000300 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000320 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000340 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000360 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000380 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000003A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000003C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000003E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................