============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 74 20 03 00 00 00 00 00 00 00 00 00 B6 24 03 00 40 21 03 00 14 21 03 00 00 00 00 00 00 00 00 00 t ♥.........╢$♥.@!♥.¶!♥......... 00000020 02 25 03 00 E0 21 03 00 64 20 03 00 00 00 00 00 00 00 00 00 40 25 03 00 30 21 03 00 28 21 03 00 ☻%♥.α!♥.d ♥.........@%♥.0!♥.(!♥. 00000040 00 00 00 00 00 00 00 00 5C 25 03 00 F4 21 03 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........\%♥.⌠!♥................. 00000060 00 00 00 00 1C 25 03 00 30 25 03 00 0E 25 03 00 00 00 00 00 54 22 03 00 6A 22 03 00 7C 22 03 00 ....∟%♥.0%♥.♫%♥.....T"♥.j"♥.|"♥. 00000080 8A 22 03 00 42 22 03 00 96 22 03 00 A4 22 03 00 B4 22 03 00 C2 22 03 00 CE 22 03 00 DC 22 03 00 è"♥.B"♥.û"♥.ñ"♥.┤"♥.┬"♥.╬"♥.▄"♥. 000000A0 F2 22 03 00 0E 23 03 00 26 23 03 00 3E 23 03 00 4A 23 03 00 66 23 03 00 7E 23 03 00 90 23 03 00 ≥"♥.♫#♥.&#♥.>#♥.J#♥.f#♥.~#♥.É#♥. 000000C0 A4 23 03 00 BA 23 03 00 CC 23 03 00 10 22 03 00 30 22 03 00 04 24 03 00 FC 21 03 00 22 24 03 00 ñ#♥.║#♥.╠#♥.►"♥.0"♥.♦$♥.ⁿ!♥."$♥. 000000E0 36 24 03 00 4A 24 03 00 60 24 03 00 70 24 03 00 7E 24 03 00 8A 24 03 00 96 24 03 00 A6 24 03 00 6$♥.J$♥.`$♥.p$♥.~$♥.è$♥.û$♥.ª$♥. 00000100 24 22 03 00 DE 23 03 00 F4 23 03 00 14 24 03 00 00 00 00 00 F6 24 03 00 EA 24 03 00 D4 24 03 00 $"♥.▐#♥.⌠#♥.¶$♥.....÷$♥.Ω$♥.╘$♥. 00000120 C4 24 03 00 00 00 00 00 4E 25 03 00 00 00 00 00 1C 25 03 00 30 25 03 00 0E 25 03 00 00 00 00 00 ─$♥.....N%♥.....∟%♥.0%♥.♫%♥..... 00000140 54 22 03 00 6A 22 03 00 7C 22 03 00 8A 22 03 00 42 22 03 00 96 22 03 00 A4 22 03 00 B4 22 03 00 T"♥.j"♥.|"♥.è"♥.B"♥.û"♥.ñ"♥.┤"♥. 00000160 C2 22 03 00 CE 22 03 00 DC 22 03 00 F2 22 03 00 0E 23 03 00 26 23 03 00 3E 23 03 00 4A 23 03 00 ┬"♥.╬"♥.▄"♥.≥"♥.♫#♥.&#♥.>#♥.J#♥. 00000180 66 23 03 00 7E 23 03 00 90 23 03 00 A4 23 03 00 BA 23 03 00 CC 23 03 00 10 22 03 00 30 22 03 00 f#♥.~#♥.É#♥.ñ#♥.║#♥.╠#♥.►"♥.0"♥. 000001A0 04 24 03 00 FC 21 03 00 22 24 03 00 36 24 03 00 4A 24 03 00 60 24 03 00 70 24 03 00 7E 24 03 00 ♦$♥.ⁿ!♥."$♥.6$♥.J$♥.`$♥.p$♥.~$♥. 000001C0 8A 24 03 00 96 24 03 00 A6 24 03 00 24 22 03 00 DE 23 03 00 F4 23 03 00 14 24 03 00 00 00 00 00 è$♥.û$♥.ª$♥.$"♥.▐#♥.⌠#♥.¶$♥..... 000001E0 F6 24 03 00 EA 24 03 00 D4 24 03 00 C4 24 03 00 00 00 00 00 4E 25 03 00 00 00 00 00 90 01 4B 33 ÷$♥.Ω$♥.╘$♥.─$♥.....N%♥.....É☺K3 00000200 32 54 68 6B 31 36 33 32 50 72 6F 6C 6F 67 00 00 8F 01 4B 33 32 54 68 6B 31 36 33 32 45 70 69 6C 2Thk1632Prolog..Å☺K32Thk1632Epil 00000220 6F 67 00 00 B1 01 4D 61 70 53 4C 46 69 78 00 00 68 02 55 6E 4D 61 70 53 4C 46 69 78 41 72 72 61 og..▒☺MapSLFix..h☻UnMapSLFixArra 00000240 79 00 5B 02 54 68 75 6E 6B 43 6F 6E 6E 65 63 74 33 32 00 00 63 01 47 6C 6F 62 61 6C 4D 65 6D 6F y.[☻ThunkConnect32..c☺GlobalMemo 00000260 72 79 53 74 61 74 75 73 00 00 5D 00 44 65 76 69 63 65 49 6F 43 6F 6E 74 72 6F 6C 00 3C 00 43 72 ryStatus..].DeviceIoControl.<.Cr 00000280 65 61 74 65 46 69 6C 65 41 00 AD 02 6C 73 74 72 63 6D 70 69 41 00 25 00 43 6C 6F 73 65 48 61 6E eateFileA.¡☻lstrcmpiA.%.CloseHan 000002A0 64 6C 65 00 4F 01 47 65 74 56 65 72 73 69 6F 6E 45 78 41 00 71 01 48 65 61 70 44 65 73 74 72 6F dle.O☺GetVersionExA.q☺HeapDestro 000002C0 79 00 72 01 48 65 61 70 46 72 65 65 00 00 70 01 48 65 61 70 43 72 65 61 74 65 00 00 7E 01 49 6E y.r☺HeapFree..p☺HeapCreate..~☺In 000002E0 74 65 72 6C 6F 63 6B 65 64 45 78 63 68 61 6E 67 65 00 5E 00 44 69 73 61 62 6C 65 54 68 72 65 61 terlockedExchange.^.DisableThrea 00000300 64 4C 69 62 72 61 72 79 43 61 6C 6C 73 00 93 01 4C 65 61 76 65 43 72 69 74 69 63 61 6C 53 65 63 dLibraryCalls.ô☺LeaveCriticalSec 00000320 74 69 6F 6E 00 00 64 00 45 6E 74 65 72 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 6E 01 tion..d.EnterCriticalSection..n☺ 00000340 48 65 61 70 41 6C 6C 6F 63 00 7B 01 49 6E 69 74 69 61 6C 69 7A 65 43 72 69 74 69 63 61 6C 53 65 HeapAlloc.{☺InitializeCriticalSe 00000360 63 74 69 6F 6E 00 59 00 44 65 6C 65 74 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 17 01 ction.Y.DeleteCriticalSection.↨☺ 00000380 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 01 01 47 65 74 4D 6F 64 75 6C 65 48 61 6E 64 6C GetProcAddress..☺☺GetModuleHandl 000003A0 65 41 00 00 82 02 57 69 64 65 43 68 61 72 54 6F 4D 75 6C 74 69 42 79 74 65 00 2F 01 47 65 74 53 eA..é☻WideCharToMultiByte./☺GetS 000003C0 74 72 69 6E 67 54 79 70 65 41 00 00 32 01 47 65 74 53 74 72 69 6E 67 54 79 70 65 57 00 00 BB 01 tringTypeA..2☺GetStringTypeW..╗☺ 000003E0 4D 75 6C 74 69 42 79 74 65 54 6F 57 69 64 65 43 68 61 72 00 91 01 4C 43 4D 61 70 53 74 72 69 6E MultiByteToWideChar.æ☺LCMapStrin 00000400 67 41 00 00 92 01 4C 43 4D 61 70 53 74 72 69 6E 67 57 00 00 77 00 45 78 69 74 50 72 6F 63 65 73 gA..Æ☺LCMapStringW..w.ExitProces 00000420 73 00 57 02 54 65 72 6D 69 6E 61 74 65 50 72 6F 63 65 73 73 00 00 D3 00 47 65 74 43 75 72 72 65 s.W☻TerminateProcess..╙.GetCurre 00000440 6E 74 50 72 6F 63 65 73 73 00 FF 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 00 00 ntProcess. .GetModuleFileNameA.. 00000460 2E 01 47 65 74 53 74 64 48 61 6E 64 6C 65 00 00 73 02 56 69 72 74 75 61 6C 46 72 65 65 00 F6 01 .☺GetStdHandle..s☻VirtualFree.÷☺ 00000480 52 74 6C 55 6E 77 69 6E 64 00 8D 02 57 72 69 74 65 46 69 6C 65 00 72 02 56 69 72 74 75 61 6C 41 RtlUnwind.ì☻WriteFile.r☻VirtualA 000004A0 6C 6C 6F 63 00 00 94 01 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 4B 45 52 4E 45 4C 33 32 2E 64 lloc..ö☺LoadLibraryA..KERNEL32.d 000004C0 6C 6C 00 00 D8 00 47 65 74 43 6C 61 73 73 4E 61 6D 65 41 00 F1 00 47 65 74 46 6F 72 65 67 72 6F ll..╪.GetClassNameA.±.GetForegro 000004E0 75 6E 64 57 69 6E 64 6F 77 00 08 02 53 65 74 54 69 6D 65 72 00 00 6C 01 4B 69 6C 6C 54 69 6D 65 undWindow.◘☻SetTimer..l☺KillTime 00000500 72 00 55 53 45 52 33 32 2E 64 6C 6C 00 00 96 00 52 65 67 43 6C 6F 73 65 4B 65 79 00 B5 00 52 65 r.USER32.dll..û.RegCloseKey.╡.Re 00000520 67 51 75 65 72 79 56 61 6C 75 65 45 78 41 00 00 AD 00 52 65 67 4F 70 65 6E 4B 65 79 45 78 41 00 gQueryValueExA..¡.RegOpenKeyExA. 00000540 41 44 56 41 50 49 33 32 2E 64 6C 6C 00 00 89 00 74 69 6D 65 47 65 74 54 69 6D 65 00 57 49 4E 4D ADVAPI32.dll..ë.timeGetTime.WINM 00000560 4D 2E 64 6C 6C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 M.dll........................... 00000580 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................