============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 6C 20 01 00 00 00 00 00 00 00 00 00 74 24 01 00 34 21 01 00 08 21 01 00 00 00 00 00 00 00 00 00 l ☺.........t$☺.4!☺.◘!☺......... 00000020 AA 24 01 00 D0 21 01 00 50 20 01 00 00 00 00 00 00 00 00 00 1E 25 01 00 18 21 01 00 00 00 00 00 ¬$☺.╨!☺.P ☺.........▲%☺.↑!☺..... 00000040 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 D8 24 01 00 C8 24 01 00 B6 24 01 00 E6 24 01 00 ................╪$☺.╚$☺.╢$☺.µ$☺. 00000060 F8 24 01 00 0C 25 01 00 00 00 00 00 82 22 01 00 98 22 01 00 72 22 01 00 AE 22 01 00 C0 22 01 00 °$☺.♀%☺.....é"☺.ÿ"☺.r"☺.«"☺.└"☺. 00000080 D4 22 01 00 EA 22 01 00 FE 22 01 00 12 23 01 00 1E 23 01 00 36 23 01 00 48 23 01 00 56 23 01 00 ╘"☺.Ω"☺.■"☺.↕#☺.▲#☺.6#☺.H#☺.V#☺. 000000A0 64 23 01 00 74 23 01 00 54 22 01 00 64 22 01 00 9A 23 01 00 E0 21 01 00 B2 23 01 00 BC 23 01 00 d#☺.t#☺.T"☺.d"☺.Ü#☺.α!☺.▓#☺.╝#☺. 000000C0 C8 23 01 00 D4 23 01 00 E4 23 01 00 F2 23 01 00 04 24 01 00 16 24 01 00 2C 24 01 00 42 24 01 00 ╚#☺.╘#☺.Σ#☺.≥#☺.♦$☺.▬$☺.,$☺.B$☺. 000000E0 52 24 01 00 66 24 01 00 44 22 01 00 2C 22 01 00 10 22 01 00 F8 21 01 00 8E 23 01 00 80 23 01 00 R$☺.f$☺.D"☺.,"☺.►"☺.°!☺.Ä#☺.Ç#☺. 00000100 A4 23 01 00 00 00 00 00 9E 24 01 00 90 24 01 00 82 24 01 00 00 00 00 00 D8 24 01 00 C8 24 01 00 ñ#☺.....₧$☺.É$☺.é$☺.....╪$☺.╚$☺. 00000120 B6 24 01 00 E6 24 01 00 F8 24 01 00 0C 25 01 00 00 00 00 00 82 22 01 00 98 22 01 00 72 22 01 00 ╢$☺.µ$☺.°$☺.♀%☺.....é"☺.ÿ"☺.r"☺. 00000140 AE 22 01 00 C0 22 01 00 D4 22 01 00 EA 22 01 00 FE 22 01 00 12 23 01 00 1E 23 01 00 36 23 01 00 «"☺.└"☺.╘"☺.Ω"☺.■"☺.↕#☺.▲#☺.6#☺. 00000160 48 23 01 00 56 23 01 00 64 23 01 00 74 23 01 00 54 22 01 00 64 22 01 00 9A 23 01 00 E0 21 01 00 H#☺.V#☺.d#☺.t#☺.T"☺.d"☺.Ü#☺.α!☺. 00000180 B2 23 01 00 BC 23 01 00 C8 23 01 00 D4 23 01 00 E4 23 01 00 F2 23 01 00 04 24 01 00 16 24 01 00 ▓#☺.╝#☺.╚#☺.╘#☺.Σ#☺.≥#☺.♦$☺.▬$☺. 000001A0 2C 24 01 00 42 24 01 00 52 24 01 00 66 24 01 00 44 22 01 00 2C 22 01 00 10 22 01 00 F8 21 01 00 ,$☺.B$☺.R$☺.f$☺.D"☺.,"☺.►"☺.°!☺. 000001C0 8E 23 01 00 80 23 01 00 A4 23 01 00 00 00 00 00 9E 24 01 00 90 24 01 00 82 24 01 00 00 00 00 00 Ä#☺.Ç#☺.ñ#☺.....₧$☺.É$☺.é$☺..... 000001E0 77 01 4C 65 61 76 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 4F 00 45 6E 74 65 72 43 w☺LeaveCriticalSection..O.EnterC 00000200 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 64 01 49 6E 69 74 69 61 6C 69 7A 65 43 72 69 74 riticalSection..d☺InitializeCrit 00000220 69 63 61 6C 53 65 63 74 69 6F 6E 00 44 00 44 65 6C 65 74 65 43 72 69 74 69 63 61 6C 53 65 63 74 icalSection.D.DeleteCriticalSect 00000240 69 6F 6E 00 37 02 56 69 72 74 75 61 6C 51 75 65 72 79 00 00 31 02 56 69 72 74 75 61 6C 41 6C 6C ion.7☻VirtualQuery..1☻VirtualAll 00000260 6F 63 00 00 33 02 56 69 72 74 75 61 6C 46 72 65 65 00 69 01 49 73 42 61 64 43 6F 64 65 50 74 72 oc..3☻VirtualFree.i☺IsBadCodePtr 00000280 00 00 C7 00 47 65 74 43 75 72 72 65 6E 74 54 68 72 65 61 64 49 64 00 00 E9 00 47 65 74 4D 6F 64 ..╟.GetCurrentThreadId..Θ.GetMod 000002A0 75 6C 65 46 69 6C 65 4E 61 6D 65 41 00 00 03 01 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 uleFileNameA..♥☺GetProcAddress.. 000002C0 EB 00 47 65 74 4D 6F 64 75 6C 65 48 61 6E 64 6C 65 41 00 00 57 02 57 72 69 74 65 50 72 6F 63 65 δ.GetModuleHandleA..W☻WriteProce 000002E0 73 73 4D 65 6D 6F 72 79 00 00 C4 00 47 65 74 43 75 72 72 65 6E 74 50 72 6F 63 65 73 73 00 BA 01 ssMemory..─.GetCurrentProcess.║☺ 00000300 52 65 61 64 50 72 6F 63 65 73 73 4D 65 6D 6F 72 79 00 C7 01 52 74 6C 55 6E 77 69 6E 64 00 D0 00 ReadProcessMemory.╟☺RtlUnwind.╨. 00000320 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 00 9F 00 47 65 74 43 6F 6D 6D 61 GetEnvironmentStrings.ƒ.GetComma 00000340 6E 64 4C 69 6E 65 41 00 37 01 47 65 74 56 65 72 73 69 6F 6E 00 00 62 00 45 78 69 74 50 72 6F 63 ndLineA.7☺GetVersion..b.ExitProc 00000360 65 73 73 00 E1 00 47 65 74 4C 61 73 74 45 72 72 6F 72 00 00 4F 02 57 72 69 74 65 46 69 6C 65 00 ess.ß.GetLastError..O☻WriteFile. 00000380 22 02 54 6C 73 53 65 74 56 61 6C 75 65 00 1F 02 54 6C 73 41 6C 6C 6F 63 00 00 20 02 54 6C 73 46 "☻TlsSetValue.▼☻TlsAlloc.. ☻TlsF 000003A0 72 65 65 00 21 02 54 6C 73 47 65 74 56 61 6C 75 65 00 92 00 47 65 74 41 43 50 00 00 F6 00 47 65 ree.!☻TlsGetValue.Æ.GetACP..÷.Ge 000003C0 74 4F 45 4D 43 50 00 00 98 00 47 65 74 43 50 49 6E 66 6F 00 16 01 47 65 74 53 74 64 48 61 6E 64 tOEMCP..ÿ.GetCPInfo.▬☺GetStdHand 000003E0 6C 65 00 00 DC 00 47 65 74 46 69 6C 65 54 79 70 65 00 14 01 47 65 74 53 74 61 72 74 75 70 49 6E le..▄.GetFileType.¶☺GetStartupIn 00000400 66 6F 41 00 F8 01 53 65 74 46 69 6C 65 50 6F 69 6E 74 65 72 00 00 42 02 57 69 64 65 43 68 61 72 foA.°☺SetFilePointer..B☻WideChar 00000420 54 6F 4D 75 6C 74 69 42 79 74 65 00 93 01 4D 75 6C 74 69 42 79 74 65 54 6F 57 69 64 65 43 68 61 ToMultiByte.ô☺MultiByteToWideCha 00000440 72 00 06 02 53 65 74 53 74 64 48 61 6E 64 6C 65 00 00 83 00 46 6C 75 73 68 46 69 6C 65 42 75 66 r.♠☻SetStdHandle..â.FlushFileBuf 00000460 66 65 72 73 00 00 16 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C fers..▬.CloseHandle.KERNEL32.dll 00000480 00 00 88 01 4D 65 73 73 61 67 65 42 6F 78 41 00 87 01 4D 65 73 73 61 67 65 42 65 65 70 00 5C 01 ..ê☺MessageBoxA.ç☺MessageBeep.\☺ 000004A0 49 73 57 69 6E 64 6F 77 00 00 55 53 45 52 33 32 2E 64 6C 6C 00 00 C6 00 52 65 67 43 72 65 61 74 IsWindow..USER32.dll..╞.RegCreat 000004C0 65 4B 65 79 45 78 41 00 D9 00 52 65 67 4F 70 65 6E 4B 65 79 45 78 41 00 C2 00 52 65 67 43 6C 6F eKeyExA.┘.RegOpenKeyExA.┬.RegClo 000004E0 73 65 4B 65 79 00 EC 00 52 65 67 53 65 74 56 61 6C 75 65 45 78 41 00 00 E1 00 52 65 67 51 75 65 seKey.∞.RegSetValueExA..ß.RegQue 00000500 72 79 56 61 6C 75 65 45 78 41 00 00 CB 00 52 65 67 44 65 6C 65 74 65 56 61 6C 75 65 41 00 41 44 ryValueExA..╦.RegDeleteValueA.AD 00000520 56 41 50 49 33 32 2E 64 6C 6C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 VAPI32.dll...................... 00000540 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000560 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000580 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................