============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 3C 90 00 00 00 00 00 00 00 00 00 00 74 91 00 00 D0 90 00 00 44 90 00 00 00 00 00 00 00 00 00 00 <É..........tæ..╨É..DÉ.......... 00000020 CA 93 00 00 D8 90 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 64 91 00 00 ╩ô..╪É......................dæ.. 00000040 00 00 00 00 94 91 00 00 82 91 00 00 A2 91 00 00 B0 91 00 00 C4 91 00 00 D8 91 00 00 E4 91 00 00 ....öæ..éæ..óæ..░æ..─æ..╪æ..Σæ.. 00000060 00 92 00 00 16 92 00 00 30 92 00 00 48 92 00 00 62 92 00 00 7C 92 00 00 92 92 00 00 9E 92 00 00 .Æ..▬Æ..0Æ..HÆ..bÆ..|Æ..ÆÆ..₧Æ.. 00000080 A8 92 00 00 B4 92 00 00 C6 92 00 00 D4 92 00 00 E4 92 00 00 F6 92 00 00 04 93 00 00 12 93 00 00 ¿Æ..┤Æ..╞Æ..╘Æ..ΣÆ..÷Æ..♦ô..↕ô.. 000000A0 20 93 00 00 2C 93 00 00 38 93 00 00 44 93 00 00 54 93 00 00 66 93 00 00 76 93 00 00 86 93 00 00 ô..,ô..8ô..Dô..Tô..fô..vô..åô.. 000000C0 9A 93 00 00 AC 93 00 00 BC 93 00 00 00 00 00 00 64 91 00 00 00 00 00 00 94 91 00 00 82 91 00 00 Üô..¼ô..╝ô......dæ......öæ..éæ.. 000000E0 A2 91 00 00 B0 91 00 00 C4 91 00 00 D8 91 00 00 E4 91 00 00 00 92 00 00 16 92 00 00 30 92 00 00 óæ..░æ..─æ..╪æ..Σæ...Æ..▬Æ..0Æ.. 00000100 48 92 00 00 62 92 00 00 7C 92 00 00 92 92 00 00 9E 92 00 00 A8 92 00 00 B4 92 00 00 C6 92 00 00 HÆ..bÆ..|Æ..ÆÆ..₧Æ..¿Æ..┤Æ..╞Æ.. 00000120 D4 92 00 00 E4 92 00 00 F6 92 00 00 04 93 00 00 12 93 00 00 20 93 00 00 2C 93 00 00 38 93 00 00 ╘Æ..ΣÆ..÷Æ..♦ô..↕ô.. ô..,ô..8ô.. 00000140 44 93 00 00 54 93 00 00 66 93 00 00 76 93 00 00 86 93 00 00 9A 93 00 00 AC 93 00 00 BC 93 00 00 Dô..Tô..fô..vô..åô..Üô..¼ô..╝ô.. 00000160 00 00 00 00 1E 01 52 65 67 44 65 6C 65 74 65 4B 65 79 41 00 41 44 56 41 50 49 33 32 2E 64 6C 6C ....▲☺RegDeleteKeyA.ADVAPI32.dll 00000180 00 00 A9 00 47 65 74 43 6F 6D 6D 61 6E 64 4C 69 6E 65 41 00 4B 01 47 65 74 56 65 72 73 69 6F 6E ..⌐.GetCommandLineA.K☺GetVersion 000001A0 00 00 6A 00 45 78 69 74 50 72 6F 63 65 73 73 00 41 02 54 65 72 6D 69 6E 61 74 65 50 72 6F 63 65 ..j.ExitProcess.A☻TerminateProce 000001C0 73 73 00 00 D2 00 47 65 74 43 75 72 72 65 6E 74 50 72 6F 63 65 73 73 00 E1 01 52 74 6C 55 6E 77 ss..╥.GetCurrentProcess.ß☺RtlUnw 000001E0 69 6E 64 00 4B 02 55 6E 68 61 6E 64 6C 65 64 45 78 63 65 70 74 69 6F 6E 46 69 6C 74 65 72 00 00 ind.K☻UnhandledExceptionFilter.. 00000200 FB 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 00 00 95 00 46 72 65 65 45 6E 76 69 √.GetModuleFileNameA..ò.FreeEnvi 00000220 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 41 00 E0 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 ronmentStringsA.α.GetEnvironment 00000240 53 74 72 69 6E 67 73 00 96 00 46 72 65 65 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 Strings.û.FreeEnvironmentStrings 00000260 57 00 E2 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 57 00 00 69 02 57 69 W.Γ.GetEnvironmentStringsW..i☻Wi 00000280 64 65 43 68 61 72 54 6F 4D 75 6C 74 69 42 79 74 65 00 A2 00 47 65 74 43 50 49 6E 66 6F 00 9C 00 deCharToMultiByte.ó.GetCPInfo.£. 000002A0 47 65 74 41 43 50 00 00 08 01 47 65 74 4F 45 4D 43 50 00 00 16 02 53 65 74 48 61 6E 64 6C 65 43 GetACP..◘☺GetOEMCP..▬☻SetHandleC 000002C0 6F 75 6E 74 00 00 EE 00 47 65 74 46 69 6C 65 54 79 70 65 00 29 01 47 65 74 53 74 64 48 61 6E 64 ount..ε.GetFileType.)☺GetStdHand 000002E0 6C 65 00 00 27 01 47 65 74 53 74 61 72 74 75 70 49 6E 66 6F 41 00 6B 01 48 65 61 70 44 65 73 74 le..'☺GetStartupInfoA.k☺HeapDest 00000300 72 6F 79 00 69 01 48 65 61 70 43 72 65 61 74 65 00 00 59 02 56 69 72 74 75 61 6C 46 72 65 65 00 roy.i☺HeapCreate..Y☻VirtualFree. 00000320 76 02 57 72 69 74 65 46 69 6C 65 00 67 01 48 65 61 70 41 6C 6C 6F 63 00 6D 01 48 65 61 70 46 72 v☻WriteFile.g☺HeapAlloc.m☺HeapFr 00000340 65 65 00 00 56 02 56 69 72 74 75 61 6C 41 6C 6C 6F 63 00 00 15 01 47 65 74 50 72 6F 63 41 64 64 ee..V☻VirtualAlloc..§☺GetProcAdd 00000360 72 65 73 73 00 00 8E 01 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 F3 00 47 65 74 4C 61 73 74 45 ress..Ä☺LoadLibraryA..≤.GetLastE 00000380 72 72 6F 72 00 00 8D 00 46 6C 75 73 68 46 69 6C 65 42 75 66 66 65 72 73 00 00 14 02 53 65 74 46 rror..ì.FlushFileBuffers..¶☻SetF 000003A0 69 6C 65 50 6F 69 6E 74 65 72 00 00 24 02 53 65 74 53 74 64 48 61 6E 64 6C 65 00 00 17 00 43 6C ilePointer..$☻SetStdHandle..↨.Cl 000003C0 6F 73 65 48 61 6E 64 6C 65 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 00 00 00 00 00 00 00 00 oseHandle.KERNEL32.dll.......... 000003E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................