============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 3C 60 00 00 00 00 00 00 00 00 00 00 9A 61 00 00 BC 60 00 00 50 60 00 00 00 00 00 00 00 00 00 00 <`..........Üa..╝`..P`.......... 00000020 66 63 00 00 D0 60 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 56 61 00 00 fc..╨`......................Va.. 00000040 6E 61 00 00 86 61 00 00 3C 61 00 00 00 00 00 00 B6 61 00 00 C6 61 00 00 A8 61 00 00 DA 61 00 00 na..åa..<a......╢a..╞a..¿a..┌a.. 00000060 E8 61 00 00 00 62 00 00 12 62 00 00 24 62 00 00 38 62 00 00 4A 62 00 00 58 62 00 00 64 62 00 00 Φa...b..↕b..$b..8b..Jb..Xb..db.. 00000080 80 62 00 00 96 62 00 00 A6 62 00 00 B4 62 00 00 C6 62 00 00 D8 62 00 00 E4 62 00 00 F4 62 00 00 Çb..ûb..ªb..┤b..╞b..╪b..Σb..⌠b.. 000000A0 00 63 00 00 0C 63 00 00 22 63 00 00 30 63 00 00 44 63 00 00 56 63 00 00 00 00 00 00 56 61 00 00 .c..♀c.."c..0c..Dc..Vc......Va.. 000000C0 6E 61 00 00 86 61 00 00 3C 61 00 00 00 00 00 00 B6 61 00 00 C6 61 00 00 A8 61 00 00 DA 61 00 00 na..åa..<a......╢a..╞a..¿a..┌a.. 000000E0 E8 61 00 00 00 62 00 00 12 62 00 00 24 62 00 00 38 62 00 00 4A 62 00 00 58 62 00 00 64 62 00 00 Φa...b..↕b..$b..8b..Jb..Xb..db.. 00000100 80 62 00 00 96 62 00 00 A6 62 00 00 B4 62 00 00 C6 62 00 00 D8 62 00 00 E4 62 00 00 F4 62 00 00 Çb..ûb..ªb..┤b..╞b..╪b..Σb..⌠b.. 00000120 00 63 00 00 0C 63 00 00 22 63 00 00 30 63 00 00 44 63 00 00 56 63 00 00 00 00 00 00 5D 00 49 6E .c..♀c.."c..0c..Dc..Vc......].In 00000140 69 74 69 61 74 65 53 79 73 74 65 6D 53 68 75 74 64 6F 77 6E 41 00 0A 00 41 64 6A 75 73 74 54 6F itiateSystemShutdownA.◙.AdjustTo 00000160 6B 65 6E 50 72 69 76 69 6C 65 67 65 73 00 6C 00 4C 6F 6F 6B 75 70 50 72 69 76 69 6C 65 67 65 56 kenPrivileges.l.LookupPrivilegeV 00000180 61 6C 75 65 41 00 A1 00 4F 70 65 6E 50 72 6F 63 65 73 73 54 6F 6B 65 6E 00 00 41 44 56 41 50 49 alueA.í.OpenProcessToken..ADVAPI 000001A0 33 32 2E 64 6C 6C 00 00 17 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 E3 00 47 65 74 4C 61 73 74 45 32.dll..↨.CloseHandle.π.GetLastE 000001C0 72 72 6F 72 00 00 C6 00 47 65 74 43 75 72 72 65 6E 74 50 72 6F 63 65 73 73 00 32 01 47 65 74 56 rror..╞.GetCurrentProcess.2☺GetV 000001E0 65 72 73 69 6F 6E 00 00 D2 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 00 ersion..╥.GetEnvironmentStrings. 00000200 A1 00 47 65 74 43 6F 6D 6D 61 6E 64 4C 69 6E 65 41 00 D5 01 53 65 74 43 6F 6E 73 6F 6C 65 4D 6F í.GetCommandLineA.╒☺SetConsoleMo 00000220 64 65 00 00 A4 01 52 65 61 64 43 6F 6E 73 6F 6C 65 49 6E 70 75 74 41 00 BC 00 47 65 74 43 6F 6E de..ñ☺ReadConsoleInputA.╝.GetCon 00000240 73 6F 6C 65 4D 6F 64 65 00 00 64 00 45 78 69 74 50 72 6F 63 65 73 73 00 BB 01 52 74 6C 55 6E 77 soleMode..d.ExitProcess.╗☺RtlUnw 00000260 69 6E 64 00 19 02 55 6E 68 61 6E 64 6C 65 64 45 78 63 65 70 74 69 6F 6E 46 69 6C 74 65 72 00 00 ind.↓☻UnhandledExceptionFilter.. 00000280 EB 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 00 00 13 01 47 65 74 53 74 64 48 61 δ.GetModuleFileNameA..‼☺GetStdHa 000002A0 6E 64 6C 65 00 00 DE 00 47 65 74 46 69 6C 65 54 79 70 65 00 11 01 47 65 74 53 74 61 72 74 75 70 ndle..▐.GetFileType.◄☺GetStartup 000002C0 49 6E 66 6F 41 00 03 01 47 65 74 50 72 6F 63 65 73 73 48 65 61 70 00 00 42 02 57 72 69 74 65 46 InfoA.♥☺GetProcessHeap..B☻WriteF 000002E0 69 6C 65 00 37 02 57 72 69 74 65 43 6F 6E 73 6F 6C 65 41 00 4E 01 48 65 61 70 41 6C 6C 6F 63 00 ile.7☻WriteConsoleA.N☺HeapAlloc. 00000300 52 01 48 65 61 70 46 72 65 65 00 00 35 02 57 69 64 65 43 68 61 72 54 6F 4D 75 6C 74 69 42 79 74 R☺HeapFree..5☻WideCharToMultiByt 00000320 65 00 2D 00 43 72 65 61 74 65 46 69 6C 65 41 00 85 00 46 6C 75 73 68 46 69 6C 65 42 75 66 66 65 e.-.CreateFileA.à.FlushFileBuffe 00000340 72 73 00 00 EC 01 53 65 74 46 69 6C 65 50 6F 69 6E 74 65 72 00 00 FA 01 53 65 74 53 74 64 48 61 rs..∞☺SetFilePointer..·☺SetStdHa 00000360 6E 64 6C 65 00 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ndle..KERNEL32.dll.............. 00000380 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000003A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000003C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000003E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................