============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 88 90 00 00 00 00 00 00 00 00 00 00 F8 92 00 00 C8 91 00 00 98 90 00 00 00 00 00 00 00 00 00 00 êÉ..........°Æ..╚æ..ÿÉ.......... 00000020 82 94 00 00 D8 91 00 00 70 91 00 00 00 00 00 00 00 00 00 00 8C 95 00 00 B0 92 00 00 90 90 00 00 éö..╪æ..pæ..........îò..░Æ..ÉÉ.. 00000040 00 00 00 00 00 00 00 00 A8 95 00 00 D0 91 00 00 78 90 00 00 00 00 00 00 00 00 00 00 F6 95 00 00 ........¿ò..╨æ..xÉ..........÷ò.. 00000060 B8 91 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E2 95 00 00 B2 95 00 00 ╕æ......................Γò..▓ò.. 00000080 CA 95 00 00 00 00 00 00 11 00 00 80 00 00 00 00 98 95 00 00 00 00 00 00 86 93 00 00 9A 93 00 00 ╩ò......◄..Ç....ÿò......åô..Üô.. 000000A0 B0 93 00 00 C8 93 00 00 DC 93 00 00 72 93 00 00 1C 94 00 00 52 93 00 00 14 94 00 00 62 93 00 00 ░ô..╚ô..▄ô..rô..∟ö..Rô..¶ö..bô.. 000000C0 2C 94 00 00 3E 94 00 00 4E 94 00 00 5E 94 00 00 6E 94 00 00 40 93 00 00 2A 93 00 00 14 93 00 00 ,ö..>ö..Nö..^ö..nö..@ô..*ô..¶ô.. 000000E0 06 93 00 00 F0 93 00 00 08 94 00 00 20 98 00 00 70 96 00 00 84 96 00 00 EE 97 00 00 E2 97 00 00 ♠ô..≡ô..◘ö.. ÿ..pû..äû..εù..Γù.. 00000100 00 98 00 00 C2 97 00 00 AE 97 00 00 D4 97 00 00 10 98 00 00 9E 97 00 00 90 97 00 00 80 97 00 00 .ÿ..┬ù..«ù..╘ù..►ÿ..₧ù..Éù..Çù.. 00000120 72 97 00 00 60 97 00 00 54 97 00 00 4A 97 00 00 04 96 00 00 18 96 00 00 2A 96 00 00 3C 96 00 00 rù..`ù..Tù..Jù..♦û..↑û..*û..<û.. 00000140 4A 96 00 00 56 96 00 00 62 96 00 00 3E 97 00 00 90 96 00 00 AC 96 00 00 C2 96 00 00 DC 96 00 00 Jû..Vû..bû..>ù..Éû..¼û..┬û..▄û.. 00000160 F4 96 00 00 0E 97 00 00 28 97 00 00 00 00 00 00 90 94 00 00 9E 94 00 00 B0 94 00 00 BE 94 00 00 ⌠û..♫ù..(ù......Éö..₧ö..░ö..╛ö.. 00000180 CA 94 00 00 DA 94 00 00 E8 94 00 00 4C 95 00 00 70 95 00 00 60 95 00 00 20 95 00 00 3C 95 00 00 ╩ö..┌ö..Φö..Lò..pò..`ò.. ò..<ò.. 000001A0 2E 95 00 00 F8 94 00 00 10 95 00 00 04 95 00 00 7C 95 00 00 00 00 00 00 E2 95 00 00 B2 95 00 00 .ò..°ö..►ò..♦ò..|ò......Γò..▓ò.. 000001C0 CA 95 00 00 00 00 00 00 11 00 00 80 00 00 00 00 98 95 00 00 00 00 00 00 86 93 00 00 9A 93 00 00 ╩ò......◄..Ç....ÿò......åô..Üô.. 000001E0 B0 93 00 00 C8 93 00 00 DC 93 00 00 72 93 00 00 1C 94 00 00 52 93 00 00 14 94 00 00 62 93 00 00 ░ô..╚ô..▄ô..rô..∟ö..Rô..¶ö..bô.. 00000200 2C 94 00 00 3E 94 00 00 4E 94 00 00 5E 94 00 00 6E 94 00 00 40 93 00 00 2A 93 00 00 14 93 00 00 ,ö..>ö..Nö..^ö..nö..@ô..*ô..¶ô.. 00000220 06 93 00 00 F0 93 00 00 08 94 00 00 20 98 00 00 70 96 00 00 84 96 00 00 EE 97 00 00 E2 97 00 00 ♠ô..≡ô..◘ö.. ÿ..pû..äû..εù..Γù.. 00000240 00 98 00 00 C2 97 00 00 AE 97 00 00 D4 97 00 00 10 98 00 00 9E 97 00 00 90 97 00 00 80 97 00 00 .ÿ..┬ù..«ù..╘ù..►ÿ..₧ù..Éù..Çù.. 00000260 72 97 00 00 60 97 00 00 54 97 00 00 4A 97 00 00 04 96 00 00 18 96 00 00 2A 96 00 00 3C 96 00 00 rù..`ù..Tù..Jù..♦û..↑û..*û..<û.. 00000280 4A 96 00 00 56 96 00 00 62 96 00 00 3E 97 00 00 90 96 00 00 AC 96 00 00 C2 96 00 00 DC 96 00 00 Jû..Vû..bû..>ù..Éû..¼û..┬û..▄û.. 000002A0 F4 96 00 00 0E 97 00 00 28 97 00 00 00 00 00 00 90 94 00 00 9E 94 00 00 B0 94 00 00 BE 94 00 00 ⌠û..♫ù..(ù......Éö..₧ö..░ö..╛ö.. 000002C0 CA 94 00 00 DA 94 00 00 E8 94 00 00 4C 95 00 00 70 95 00 00 60 95 00 00 20 95 00 00 3C 95 00 00 ╩ö..┌ö..Φö..Lò..pò..`ò.. ò..<ò.. 000002E0 2E 95 00 00 F8 94 00 00 10 95 00 00 04 95 00 00 7C 95 00 00 00 00 00 00 43 4F 4D 43 54 4C 33 32 .ò..°ö..►ò..♦ò..|ò......COMCTL32 00000300 2E 64 6C 6C 00 00 16 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 D5 00 47 65 74 45 78 69 74 43 6F 64 .dll..▬.CloseHandle.╒.GetExitCod 00000320 65 50 72 6F 63 65 73 73 00 00 3E 02 57 61 69 74 46 6F 72 53 69 6E 67 6C 65 4F 62 6A 65 63 74 00 eProcess..>☻WaitForSingleObject. 00000340 37 00 43 72 65 61 74 65 50 72 6F 63 65 73 73 41 00 00 38 01 47 65 74 56 65 72 73 69 6F 6E 45 78 7.CreateProcessA..8☺GetVersionEx 00000360 41 00 E1 00 47 65 74 4C 61 73 74 45 72 72 6F 72 00 00 3A 00 43 72 65 61 74 65 53 65 6D 61 70 68 A.ß.GetLastError..:.CreateSemaph 00000380 6F 72 65 41 00 00 C1 01 52 65 6D 6F 76 65 44 69 72 65 63 74 6F 72 79 41 00 00 F6 01 53 65 74 46 oreA..┴☺RemoveDirectoryA..÷☺SetF 000003A0 69 6C 65 41 74 74 72 69 62 75 74 65 73 41 00 00 EB 01 53 65 74 43 75 72 72 65 6E 74 44 69 72 65 ileAttributesA..δ☺SetCurrentDire 000003C0 63 74 6F 72 79 41 00 00 CC 00 47 65 74 44 69 73 6B 46 72 65 65 53 70 61 63 65 41 00 25 00 43 72 ctoryA..╠.GetDiskFreeSpaceA.%.Cr 000003E0 65 61 74 65 44 69 72 65 63 74 6F 72 79 41 00 00 3C 01 47 65 74 57 69 6E 64 6F 77 73 44 69 72 65 eateDirectoryA..<☺GetWindowsDire 00000400 63 74 6F 72 79 41 00 00 97 01 4F 70 65 6E 46 69 6C 65 00 00 18 02 53 6C 65 65 70 00 8F 00 46 72 ctoryA..ù☺OpenFile..↑☻Sleep.Å.Fr 00000420 65 65 52 65 73 6F 75 72 63 65 00 00 17 02 53 69 7A 65 6F 66 52 65 73 6F 75 72 63 65 00 00 8B 01 eeResource..↨☻SizeofResource..ï☺ 00000440 4C 6F 63 6B 52 65 73 6F 75 72 63 65 00 00 7D 01 4C 6F 61 64 52 65 73 6F 75 72 63 65 00 00 7E 00 LockResource..}☺LoadResource..~. 00000460 46 69 6E 64 52 65 73 6F 75 72 63 65 41 00 C4 00 47 65 74 43 75 72 72 65 6E 74 50 72 6F 63 65 73 FindResourceA.─.GetCurrentProces 00000480 73 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 88 01 4D 65 73 73 61 67 65 42 6F 78 41 00 8A 00 s.KERNEL32.dll..ê☺MessageBoxA.è. 000004A0 44 69 61 6C 6F 67 42 6F 78 50 61 72 61 6D 41 00 77 01 4C 6F 61 64 53 74 72 69 6E 67 41 00 AD 00 DialogBoxParamA.w☺LoadStringA.¡. 000004C0 45 6E 64 44 69 61 6C 6F 67 00 37 02 55 70 64 61 74 65 57 69 6E 64 6F 77 00 00 16 02 53 68 6F 77 EndDialog.7☻UpdateWindow..▬☻Show 000004E0 57 69 6E 64 6F 77 00 00 D3 01 53 65 74 43 6C 61 73 73 4C 6F 6E 67 41 00 6B 01 4C 6F 61 64 49 63 Window..╙☺SetClassLongA.k☺LoadIc 00000500 6F 6E 41 00 E1 01 53 65 74 46 6F 63 75 73 00 00 AB 00 45 6E 61 62 6C 65 57 69 6E 64 6F 77 00 00 onA.ß☺SetFocus..½.EnableWindow.. 00000520 EB 00 47 65 74 44 6C 67 49 74 65 6D 00 00 90 01 4D 6F 76 65 57 69 6E 64 6F 77 00 00 33 01 47 65 δ.GetDlgItem..É☺MoveWindow..3☺Ge 00000540 74 57 69 6E 64 6F 77 52 65 63 74 00 E8 00 47 65 74 44 65 73 6B 74 6F 70 57 69 6E 64 6F 77 00 00 tWindowRect.Φ.GetDesktopWindow.. 00000560 C6 01 53 65 6E 64 4D 65 73 73 61 67 65 41 00 00 49 02 77 73 70 72 69 6E 74 66 41 00 C4 00 45 78 ╞☺SendMessageA..I☻wsprintfA.─.Ex 00000580 69 74 57 69 6E 64 6F 77 73 45 78 00 55 53 45 52 33 32 2E 64 6C 6C 00 00 46 00 44 65 6C 65 74 65 itWindowsEx.USER32.dll..F.Delete 000005A0 4F 62 6A 65 63 74 00 00 47 44 49 33 32 2E 64 6C 6C 00 0A 00 41 64 6A 75 73 74 54 6F 6B 65 6E 50 Object..GDI32.dll.◙.AdjustTokenP 000005C0 72 69 76 69 6C 65 67 65 73 00 71 00 4C 6F 6F 6B 75 70 50 72 69 76 69 6C 65 67 65 56 61 6C 75 65 rivileges.q.LookupPrivilegeValue 000005E0 41 00 B0 00 4F 70 65 6E 50 72 6F 63 65 73 73 54 6F 6B 65 6E 00 00 41 44 56 41 50 49 33 32 2E 64 A.░.OpenProcessToken..ADVAPI32.d 00000600 6C 6C 00 00 EB 00 47 65 74 4D 6F 64 75 6C 65 48 61 6E 64 6C 65 41 00 00 14 01 47 65 74 53 74 61 ll..δ.GetModuleHandleA..¶☺GetSta 00000620 72 74 75 70 49 6E 66 6F 41 00 9F 00 47 65 74 43 6F 6D 6D 61 6E 64 4C 69 6E 65 41 00 37 01 47 65 rtupInfoA.ƒ.GetCommandLineA.7☺Ge 00000640 74 56 65 72 73 69 6F 6E 00 00 59 01 48 65 61 70 46 72 65 65 00 00 4F 02 57 72 69 74 65 46 69 6C tVersion..Y☺HeapFree..O☻WriteFil 00000660 65 00 62 00 45 78 69 74 50 72 6F 63 65 73 73 00 1D 02 54 65 72 6D 69 6E 61 74 65 50 72 6F 63 65 e.b.ExitProcess.↔☻TerminateProce 00000680 73 73 00 00 C7 01 52 74 6C 55 6E 77 69 6E 64 00 26 02 55 6E 68 61 6E 64 6C 65 64 45 78 63 65 70 ss..╟☺RtlUnwind.&☻UnhandledExcep 000006A0 74 69 6F 6E 46 69 6C 74 65 72 00 00 E9 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 tionFilter..Θ.GetModuleFileNameA 000006C0 00 00 8B 00 46 72 65 65 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 41 00 D0 00 47 65 ..ï.FreeEnvironmentStringsA.╨.Ge 000006E0 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 00 8C 00 46 72 65 65 45 6E 76 69 72 6F tEnvironmentStrings.î.FreeEnviro 00000700 6E 6D 65 6E 74 53 74 72 69 6E 67 73 57 00 D2 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 nmentStringsW.╥.GetEnvironmentSt 00000720 72 69 6E 67 73 57 00 00 42 02 57 69 64 65 43 68 61 72 54 6F 4D 75 6C 74 69 42 79 74 65 00 98 00 ringsW..B☻WideCharToMultiByte.ÿ. 00000740 47 65 74 43 50 49 6E 66 6F 00 92 00 47 65 74 41 43 50 00 00 F6 00 47 65 74 4F 45 4D 43 50 00 00 GetCPInfo.Æ.GetACP..÷.GetOEMCP.. 00000760 FA 01 53 65 74 48 61 6E 64 6C 65 43 6F 75 6E 74 00 00 DC 00 47 65 74 46 69 6C 65 54 79 70 65 00 ·☺SetHandleCount..▄.GetFileType. 00000780 16 01 47 65 74 53 74 64 48 61 6E 64 6C 65 00 00 55 01 48 65 61 70 43 72 65 61 74 65 00 00 06 02 ▬☺GetStdHandle..U☺HeapCreate..♠☻ 000007A0 53 65 74 53 74 64 48 61 6E 64 6C 65 00 00 83 00 46 6C 75 73 68 46 69 6C 65 42 75 66 66 65 72 73 SetStdHandle..â.FlushFileBuffers 000007C0 00 00 F8 01 53 65 74 46 69 6C 65 50 6F 69 6E 74 65 72 00 00 2B 00 43 72 65 61 74 65 46 69 6C 65 ..°☺SetFilePointer..+.CreateFile 000007E0 41 00 53 01 48 65 61 70 41 6C 6C 6F 63 00 03 01 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 A.S☺HeapAlloc.♥☺GetProcAddress.. 00000800 78 01 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 EF 01 53 65 74 45 6E 64 4F 66 46 69 6C 65 00 00 x☺LoadLibraryA..∩☺SetEndOfFile.. 00000820 B8 01 52 65 61 64 46 69 6C 65 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ╕☺ReadFile...................... 00000840 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000860 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000880 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000008A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000008C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000008E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000900 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000920 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000940 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000960 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000980 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000009A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000009C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000009E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................