============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 28 D1 00 00 00 00 00 00 00 00 00 00 EE D8 00 00 90 D3 00 00 80 D2 00 00 00 00 00 00 00 00 00 00 (╤..........ε╪..É╙..Ç╥.......... 00000020 88 D9 00 00 E8 D4 00 00 20 D1 00 00 00 00 00 00 00 00 00 00 A8 D9 00 00 88 D3 00 00 C0 D2 00 00 ê┘..Φ╘.. ╤..........¿┘..ê╙..└╥.. 00000040 00 00 00 00 00 00 00 00 9A DB 00 00 28 D5 00 00 DC D0 00 00 00 00 00 00 00 00 00 00 BC DC 00 00 ........Ü█..(╒..▄╨..........╝▄.. 00000060 44 D3 00 00 34 D3 00 00 00 00 00 00 00 00 00 00 00 DD 00 00 9C D5 00 00 2C D3 00 00 00 00 00 00 D╙..4╙...........▌..£╒..,╙...... 00000080 00 00 00 00 18 DD 00 00 94 D5 00 00 70 D2 00 00 00 00 00 00 00 00 00 00 56 DD 00 00 D8 D4 00 00 ....↑▌..ö╒..p╥..........V▌..╪╘.. 000000A0 A8 D2 00 00 00 00 00 00 00 00 00 00 C2 DD 00 00 10 D5 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ¿╥..........┬▌..►╒.............. 000000C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 A8 DB 00 00 ............................¿█.. 000000E0 BA DB 00 00 CA DB 00 00 DA DB 00 00 40 DC 00 00 EA DB 00 00 FC DB 00 00 10 DC 00 00 1E DC 00 00 ║█..╩█..┌█..@▄..Ω█..ⁿ█..►▄..▲▄.. 00000100 30 DC 00 00 4A DC 00 00 56 DC 00 00 72 DC 00 00 88 DC 00 00 9C DC 00 00 AE DC 00 00 00 00 00 00 0▄..J▄..V▄..r▄..ê▄..£▄..«▄...... 00000120 94 D9 00 00 00 00 00 00 DC D6 00 00 EA D6 00 00 00 D7 00 00 16 D7 00 00 24 D7 00 00 3C D7 00 00 ö┘......▄╓..Ω╓...╫..▬╫..$╫..<╫.. 00000140 D0 D6 00 00 54 D7 00 00 70 D7 00 00 84 D7 00 00 90 D7 00 00 A4 D7 00 00 BA D7 00 00 CE D7 00 00 ╨╓..T╫..p╫..ä╫..É╫..ñ╫..║╫..╬╫.. 00000160 E2 D7 00 00 6A D8 00 00 DC D5 00 00 12 D8 00 00 24 D8 00 00 36 D8 00 00 46 D8 00 00 56 D8 00 00 Γ╫..j╪..▄╒..↕╪..$╪..6╪..F╪..V╪.. 00000180 B6 D6 00 00 7E D8 00 00 8E D8 00 00 9A D8 00 00 B4 D8 00 00 C2 D8 00 00 D2 D8 00 00 E0 D8 00 00 ╢╓..~╪..Ä╪..Ü╪..┤╪..┬╪..╥╪..α╪.. 000001A0 AA D6 00 00 9E D6 00 00 8C D6 00 00 80 D6 00 00 6A D6 00 00 52 D6 00 00 42 D6 00 00 34 D6 00 00 ¬╓..₧╓..î╓..Ç╓..j╓..R╓..B╓..4╓.. 000001C0 26 D6 00 00 1A D6 00 00 0A D6 00 00 F8 D5 00 00 EA D5 00 00 D0 D5 00 00 C4 D5 00 00 B8 D5 00 00 &╓..→╓..◙╓..°╒..Ω╒..╨╒..─╒..╕╒.. 000001E0 FE D7 00 00 F2 D7 00 00 76 DF 00 00 C4 DF 00 00 D4 DF 00 00 64 DF 00 00 52 DF 00 00 38 DF 00 00 ■╫..≥╫..v▀..─▀..╘▀..d▀..R▀..8▀.. 00000200 1E DF 00 00 B2 DF 00 00 06 DF 00 00 E0 DE 00 00 AC D5 00 00 A2 DF 00 00 B2 DE 00 00 A0 DE 00 00 ▲▀..▓▀..♠▀..α▐..¼╒..ó▀..▓▐..á▐.. 00000220 CA DE 00 00 82 DE 00 00 70 DE 00 00 90 DE 00 00 54 DE 00 00 46 DE 00 00 62 DE 00 00 2C DE 00 00 ╩▐..é▐..p▐..É▐..T▐..F▐..b▐..,▐.. 00000240 20 DE 00 00 36 DE 00 00 FC DD 00 00 EE DD 00 00 12 DE 00 00 CE DD 00 00 82 DF 00 00 8E DF 00 00 ▐..6▐..ⁿ▌..ε▌..↕▐..╬▌..é▀..Ä▀.. 00000260 E0 DD 00 00 D6 DE 00 00 EC DE 00 00 00 00 00 00 46 DD 00 00 32 DD 00 00 22 DD 00 00 00 00 00 00 α▌..╓▐..∞▐......F▌..2▌.."▌...... 00000280 38 D9 00 00 44 D9 00 00 18 D9 00 00 08 D9 00 00 64 D9 00 00 7A D9 00 00 2C D9 00 00 54 D9 00 00 8┘..D┘..↑┘..◘┘..d┘..z┘..,┘..T┘.. 000002A0 FC D8 00 00 00 00 00 00 80 DD 00 00 92 DD 00 00 A8 DD 00 00 5E DD 00 00 70 DD 00 00 00 00 00 00 ⁿ╪......Ç▌..Æ▌..¿▌..^▌..p▌...... 000002C0 B2 D9 00 00 E6 D9 00 00 C2 D9 00 00 D0 D9 00 00 5E DB 00 00 7C DB 00 00 24 DB 00 00 52 DB 00 00 ▓┘..µ┘..┬┘..╨┘..^█..|█..$█..R█.. 000002E0 3C DB 00 00 F4 DA 00 00 14 DB 00 00 02 DB 00 00 A4 DA 00 00 DC DA 00 00 C8 DA 00 00 94 DA 00 00 <█..⌠┌..¶█..☻█..ñ┌..▄┌..╚┌..ö┌.. 00000300 84 DA 00 00 52 DA 00 00 44 DA 00 00 30 DA 00 00 18 DA 00 00 08 DA 00 00 FA D9 00 00 68 DA 00 00 ä┌..R┌..D┌..0┌..↑┌..◘┌..·┘..h┌.. 00000320 76 DA 00 00 B6 DA 00 00 00 00 00 00 0A DD 00 00 00 00 00 00 EC DC 00 00 DA DC 00 00 CA DC 00 00 v┌..╢┌......◙▌......∞▄..┌▄..╩▄.. 00000340 00 00 00 00 A8 DB 00 00 BA DB 00 00 CA DB 00 00 DA DB 00 00 40 DC 00 00 EA DB 00 00 FC DB 00 00 ....¿█..║█..╩█..┌█..@▄..Ω█..ⁿ█.. 00000360 10 DC 00 00 1E DC 00 00 30 DC 00 00 4A DC 00 00 56 DC 00 00 72 DC 00 00 88 DC 00 00 9C DC 00 00 ►▄..▲▄..0▄..J▄..V▄..r▄..ê▄..£▄.. 00000380 AE DC 00 00 00 00 00 00 94 D9 00 00 00 00 00 00 DC D6 00 00 EA D6 00 00 00 D7 00 00 16 D7 00 00 «▄......ö┘......▄╓..Ω╓...╫..▬╫.. 000003A0 24 D7 00 00 3C D7 00 00 D0 D6 00 00 54 D7 00 00 70 D7 00 00 84 D7 00 00 90 D7 00 00 A4 D7 00 00 $╫..<╫..╨╓..T╫..p╫..ä╫..É╫..ñ╫.. 000003C0 BA D7 00 00 CE D7 00 00 E2 D7 00 00 6A D8 00 00 DC D5 00 00 12 D8 00 00 24 D8 00 00 36 D8 00 00 ║╫..╬╫..Γ╫..j╪..▄╒..↕╪..$╪..6╪.. 000003E0 46 D8 00 00 56 D8 00 00 B6 D6 00 00 7E D8 00 00 8E D8 00 00 9A D8 00 00 B4 D8 00 00 C2 D8 00 00 F╪..V╪..╢╓..~╪..Ä╪..Ü╪..┤╪..┬╪.. 00000400 D2 D8 00 00 E0 D8 00 00 AA D6 00 00 9E D6 00 00 8C D6 00 00 80 D6 00 00 6A D6 00 00 52 D6 00 00 ╥╪..α╪..¬╓..₧╓..î╓..Ç╓..j╓..R╓.. 00000420 42 D6 00 00 34 D6 00 00 26 D6 00 00 1A D6 00 00 0A D6 00 00 F8 D5 00 00 EA D5 00 00 D0 D5 00 00 B╓..4╓..&╓..→╓..◙╓..°╒..Ω╒..╨╒.. 00000440 C4 D5 00 00 B8 D5 00 00 FE D7 00 00 F2 D7 00 00 76 DF 00 00 C4 DF 00 00 D4 DF 00 00 64 DF 00 00 ─╒..╕╒..■╫..≥╫..v▀..─▀..╘▀..d▀.. 00000460 52 DF 00 00 38 DF 00 00 1E DF 00 00 B2 DF 00 00 06 DF 00 00 E0 DE 00 00 AC D5 00 00 A2 DF 00 00 R▀..8▀..▲▀..▓▀..♠▀..α▐..¼╒..ó▀.. 00000480 B2 DE 00 00 A0 DE 00 00 CA DE 00 00 82 DE 00 00 70 DE 00 00 90 DE 00 00 54 DE 00 00 46 DE 00 00 ▓▐..á▐..╩▐..é▐..p▐..É▐..T▐..F▐.. 000004A0 62 DE 00 00 2C DE 00 00 20 DE 00 00 36 DE 00 00 FC DD 00 00 EE DD 00 00 12 DE 00 00 CE DD 00 00 b▐..,▐.. ▐..6▐..ⁿ▌..ε▌..↕▐..╬▌.. 000004C0 82 DF 00 00 8E DF 00 00 E0 DD 00 00 D6 DE 00 00 EC DE 00 00 00 00 00 00 46 DD 00 00 32 DD 00 00 é▀..Ä▀..α▌..╓▐..∞▐......F▌..2▌.. 000004E0 22 DD 00 00 00 00 00 00 38 D9 00 00 44 D9 00 00 18 D9 00 00 08 D9 00 00 64 D9 00 00 7A D9 00 00 "▌......8┘..D┘..↑┘..◘┘..d┘..z┘.. 00000500 2C D9 00 00 54 D9 00 00 FC D8 00 00 00 00 00 00 80 DD 00 00 92 DD 00 00 A8 DD 00 00 5E DD 00 00 ,┘..T┘..ⁿ╪......Ç▌..Æ▌..¿▌..^▌.. 00000520 70 DD 00 00 00 00 00 00 B2 D9 00 00 E6 D9 00 00 C2 D9 00 00 D0 D9 00 00 5E DB 00 00 7C DB 00 00 p▌......▓┘..µ┘..┬┘..╨┘..^█..|█.. 00000540 24 DB 00 00 52 DB 00 00 3C DB 00 00 F4 DA 00 00 14 DB 00 00 02 DB 00 00 A4 DA 00 00 DC DA 00 00 $█..R█..<█..⌠┌..¶█..☻█..ñ┌..▄┌.. 00000560 C8 DA 00 00 94 DA 00 00 84 DA 00 00 52 DA 00 00 44 DA 00 00 30 DA 00 00 18 DA 00 00 08 DA 00 00 ╚┌..ö┌..ä┌..R┌..D┌..0┌..↑┌..◘┌.. 00000580 FA D9 00 00 68 DA 00 00 76 DA 00 00 B6 DA 00 00 00 00 00 00 0A DD 00 00 00 00 00 00 EC DC 00 00 ·┘..h┌..v┌..╢┌......◙▌......∞▄.. 000005A0 DA DC 00 00 CA DC 00 00 00 00 00 00 75 02 6C 73 74 72 6C 65 6E 41 00 00 6F 02 6C 73 74 72 63 70 ┌▄..╩▄......u☻lstrlenA..o☻lstrcp 000005C0 79 41 00 00 66 02 6C 73 74 72 63 61 74 41 00 00 82 01 4C 6F 63 61 6C 46 72 65 65 00 7E 01 4C 6F yA..f☻lstrcatA..é☺LocalFree.~☺Lo 000005E0 63 61 6C 41 6C 6C 6F 63 00 00 8D 00 46 72 65 65 4C 69 62 72 61 72 79 00 03 01 47 65 74 50 72 6F calAlloc..ì.FreeLibrary.♥☺GetPro 00000600 63 41 64 64 72 65 73 73 00 00 78 01 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 22 00 43 6F 70 79 cAddress..x☺LoadLibraryA..".Copy 00000620 46 69 6C 65 41 00 16 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 2B 00 43 72 65 61 74 65 46 69 6C 65 FileA.▬.CloseHandle.+.CreateFile 00000640 41 00 E1 00 47 65 74 4C 61 73 74 45 72 72 6F 72 00 00 3C 01 47 65 74 57 69 6E 64 6F 77 73 44 69 A.ß.GetLastError..<☺GetWindowsDi 00000660 72 65 63 74 6F 72 79 41 00 00 42 02 57 69 64 65 43 68 61 72 54 6F 4D 75 6C 74 69 42 79 74 65 00 rectoryA..B☻WideCharToMultiByte. 00000680 69 02 6C 73 74 72 63 6D 70 41 00 00 70 01 49 73 44 42 43 53 4C 65 61 64 42 79 74 65 00 00 4F 02 i☻lstrcmpA..p☺IsDBCSLeadByte..O☻ 000006A0 57 72 69 74 65 46 69 6C 65 00 B8 01 52 65 61 64 46 69 6C 65 00 00 D3 00 47 65 74 45 6E 76 69 72 WriteFile.╕☺ReadFile..╙.GetEnvir 000006C0 6F 6E 6D 65 6E 74 56 61 72 69 61 62 6C 65 41 00 8E 01 4D 6F 76 65 46 69 6C 65 41 00 8F 01 4D 6F onmentVariableA.Ä☺MoveFileA.Å☺Mo 000006E0 76 65 46 69 6C 65 45 78 41 00 93 01 4D 75 6C 74 69 42 79 74 65 54 6F 57 69 64 65 43 68 61 72 00 veFileExA.ô☺MultiByteToWideChar. 00000700 1D 01 47 65 74 53 79 73 74 65 6D 44 69 72 65 63 74 6F 72 79 41 00 45 00 44 65 6C 65 74 65 46 69 ↔☺GetSystemDirectoryA.E.DeleteFi 00000720 6C 65 41 00 77 01 4C 65 61 76 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 4F 00 45 6E leA.w☺LeaveCriticalSection..O.En 00000740 74 65 72 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 64 01 49 6E 69 74 69 61 6C 69 7A 65 terCriticalSection..d☺Initialize 00000760 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 C1 01 52 65 6D 6F 76 65 44 69 72 65 63 74 6F 72 CriticalSection.┴☺RemoveDirector 00000780 79 41 00 00 75 00 46 69 6E 64 43 6C 6F 73 65 00 25 00 43 72 65 61 74 65 44 69 72 65 63 74 6F 72 yA..u.FindClose.%.CreateDirector 000007A0 79 41 00 00 E9 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 00 00 C4 00 47 65 74 43 yA..Θ.GetModuleFileNameA..─.GetC 000007C0 75 72 72 65 6E 74 50 72 6F 63 65 73 73 00 C6 00 47 65 74 43 75 72 72 65 6E 74 54 68 72 65 61 64 urrentProcess.╞.GetCurrentThread 000007E0 00 00 38 01 47 65 74 56 65 72 73 69 6F 6E 45 78 41 00 6C 02 6C 73 74 72 63 6D 70 69 41 00 EB 00 ..8☺GetVersionExA.l☻lstrcmpiA.δ. 00000800 47 65 74 4D 6F 64 75 6C 65 48 61 6E 64 6C 65 41 00 00 37 00 43 72 65 61 74 65 50 72 6F 63 65 73 GetModuleHandleA..7.CreateProces 00000820 73 41 00 00 79 00 46 69 6E 64 46 69 72 73 74 46 69 6C 65 41 00 00 7C 00 46 69 6E 64 4E 65 78 74 sA..y.FindFirstFileA..|.FindNext 00000840 46 69 6C 65 41 00 C4 01 52 65 73 75 6D 65 54 68 72 65 61 64 00 00 03 02 53 65 74 50 72 69 6F 72 FileA.─☺ResumeThread..♥☻SetPrior 00000860 69 74 79 43 6C 61 73 73 00 00 0F 02 53 65 74 54 68 72 65 61 64 50 72 69 6F 72 69 74 79 00 29 01 ityClass..☼☻SetThreadPriority.)☺ 00000880 47 65 74 54 65 6D 70 50 61 74 68 41 00 00 97 01 4F 70 65 6E 46 69 6C 65 00 00 6E 00 46 69 6C 65 GetTempPathA..ù☺OpenFile..n.File 000008A0 54 69 6D 65 54 6F 4C 6F 63 61 6C 46 69 6C 65 54 69 6D 65 00 47 01 47 6C 6F 62 61 6C 46 72 65 65 TimeToLocalFileTime.G☺GlobalFree 000008C0 00 00 51 01 47 6C 6F 62 61 6C 55 6E 6C 6F 63 6B 00 00 4B 01 47 6C 6F 62 61 6C 4C 6F 63 6B 00 00 ..Q☺GlobalUnlock..K☺GlobalLock.. 000008E0 40 01 47 6C 6F 62 61 6C 41 6C 6C 6F 63 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 49 02 77 73 @☺GlobalAlloc.KERNEL32.dll..I☻ws 00000900 70 72 69 6E 74 66 41 00 A1 01 50 65 65 6B 4D 65 73 73 61 67 65 41 00 00 8C 00 44 69 73 70 61 74 printfA.í☺PeekMessageA..î.Dispat 00000920 63 68 4D 65 73 73 61 67 65 41 00 00 1E 00 43 68 61 72 4E 65 78 74 41 00 21 00 43 68 61 72 50 72 chMessageA..▲.CharNextA.!.CharPr 00000940 65 76 41 00 4F 01 49 73 43 68 61 72 4C 6F 77 65 72 41 00 00 4B 01 49 73 43 68 61 72 41 6C 70 68 evA.O☺IsCharLowerA..K☺IsCharAlph 00000960 61 41 00 00 4C 01 49 73 43 68 61 72 41 6C 70 68 61 4E 75 6D 65 72 69 63 41 00 88 01 4D 65 73 73 aA..L☺IsCharAlphaNumericA.ê☺Mess 00000980 61 67 65 42 6F 78 41 00 55 53 45 52 33 32 2E 64 6C 6C 00 00 02 00 41 64 64 46 6F 6E 74 52 65 73 ageBoxA.USER32.dll..☻.AddFontRes 000009A0 6F 75 72 63 65 41 00 00 47 44 49 33 32 2E 64 6C 6C 00 49 00 45 6E 75 6D 50 72 69 6E 74 65 72 73 ourceA..GDI32.dll.I.EnumPrinters 000009C0 41 00 56 00 47 65 74 50 72 69 6E 74 65 72 41 00 47 00 45 6E 75 6D 50 72 69 6E 74 65 72 44 72 69 A.V.GetPrinterA.G.EnumPrinterDri 000009E0 76 65 72 73 41 00 59 00 47 65 74 50 72 69 6E 74 65 72 44 72 69 76 65 72 41 00 41 00 45 6E 75 6D versA.Y.GetPrinterDriverA.A.Enum 00000A00 50 6F 72 74 73 41 00 00 3F 00 45 6E 75 6D 4D 6F 6E 69 74 6F 72 73 41 00 45 00 45 6E 75 6D 50 72 PortsA..?.EnumMonitorsA.E.EnumPr 00000A20 69 6E 74 50 72 6F 63 65 73 73 6F 72 73 41 00 00 13 00 41 64 64 50 72 69 6E 74 65 72 44 72 69 76 intProcessorsA..‼.AddPrinterDriv 00000A40 65 72 41 00 6E 00 53 65 74 50 72 69 6E 74 65 72 41 00 36 00 44 6F 63 75 6D 65 6E 74 50 72 6F 70 erA.n.SetPrinterA.6.DocumentProp 00000A60 65 72 74 69 65 73 41 00 10 00 41 64 64 50 72 69 6E 74 65 72 41 00 06 00 41 64 64 4D 6F 6E 69 74 ertiesA.►.AddPrinterA.♠.AddMonit 00000A80 6F 72 41 00 19 00 43 6C 6F 73 65 50 72 69 6E 74 65 72 00 00 5F 00 4F 70 65 6E 50 72 69 6E 74 65 orA.↓.ClosePrinter.._.OpenPrinte 00000AA0 72 41 00 00 57 00 47 65 74 50 72 69 6E 74 65 72 44 61 74 61 41 00 6F 00 53 65 74 50 72 69 6E 74 rA..W.GetPrinterDataA.o.SetPrint 00000AC0 65 72 44 61 74 61 41 00 64 00 50 72 69 6E 74 65 72 50 72 6F 70 65 72 74 69 65 73 00 26 00 44 65 erDataA.d.PrinterProperties.&.De 00000AE0 6C 65 74 65 50 72 69 6E 74 50 72 6F 63 65 73 73 6F 72 41 00 24 00 44 65 6C 65 74 65 50 6F 72 74 letePrintProcessorA.$.DeletePort 00000B00 41 00 22 00 44 65 6C 65 74 65 4D 6F 6E 69 74 6F 72 41 00 00 2A 00 44 65 6C 65 74 65 50 72 69 6E A.".DeleteMonitorA..*.DeletePrin 00000B20 74 65 72 00 2D 00 44 65 6C 65 74 65 50 72 69 6E 74 65 72 44 72 69 76 65 72 41 00 00 0C 00 41 64 ter.-.DeletePrinterDriverA..♀.Ad 00000B40 64 50 72 69 6E 74 50 72 6F 63 65 73 73 6F 72 41 00 00 08 00 41 64 64 50 6F 72 74 41 00 00 54 00 dPrintProcessorA..◘.AddPortA..T. 00000B60 47 65 74 50 72 69 6E 74 50 72 6F 63 65 73 73 6F 72 44 69 72 65 63 74 6F 72 79 41 00 5A 00 47 65 GetPrintProcessorDirectoryA.Z.Ge 00000B80 74 50 72 69 6E 74 65 72 44 72 69 76 65 72 44 69 72 65 63 74 6F 72 79 41 00 00 57 49 4E 53 50 4F tPrinterDriverDirectoryA..WINSPO 00000BA0 4F 4C 2E 44 52 56 00 00 EC 00 52 65 67 53 65 74 56 61 6C 75 65 45 78 41 00 00 C9 00 52 65 67 44 OL.DRV..∞.RegSetValueExA..╔.RegD 00000BC0 65 6C 65 74 65 4B 65 79 41 00 CE 00 52 65 67 45 6E 75 6D 4B 65 79 45 78 41 00 D1 00 52 65 67 45 eleteKeyA.╬.RegEnumKeyExA.╤.RegE 00000BE0 6E 75 6D 56 61 6C 75 65 41 00 CB 00 52 65 67 44 65 6C 65 74 65 56 61 6C 75 65 41 00 E1 00 52 65 numValueA.╦.RegDeleteValueA.ß.Re 00000C00 67 51 75 65 72 79 56 61 6C 75 65 45 78 41 00 00 C2 00 52 65 67 43 6C 6F 73 65 4B 65 79 00 C6 00 gQueryValueExA..┬.RegCloseKey.╞. 00000C20 52 65 67 43 72 65 61 74 65 4B 65 79 45 78 41 00 D9 00 52 65 67 4F 70 65 6E 4B 65 79 45 78 41 00 RegCreateKeyExA.┘.RegOpenKeyExA. 00000C40 3D 00 46 72 65 65 53 69 64 00 3B 00 45 71 75 61 6C 53 69 64 00 00 0B 00 41 6C 6C 6F 63 61 74 65 =.FreeSid.;.EqualSid..♂.Allocate 00000C60 41 6E 64 49 6E 69 74 69 61 6C 69 7A 65 53 69 64 00 00 55 00 47 65 74 54 6F 6B 65 6E 49 6E 66 6F AndInitializeSid..U.GetTokenInfo 00000C80 72 6D 61 74 69 6F 6E 00 B0 00 4F 70 65 6E 50 72 6F 63 65 73 73 54 6F 6B 65 6E 00 00 B5 00 4F 70 rmation.░.OpenProcessToken..╡.Op 00000CA0 65 6E 54 68 72 65 61 64 54 6F 6B 65 6E 00 D8 00 52 65 67 4F 70 65 6E 4B 65 79 41 00 41 44 56 41 enThreadToken.╪.RegOpenKeyA.ADVA 00000CC0 50 49 33 32 2E 64 6C 6C 00 00 19 00 43 6F 49 6E 69 74 69 61 6C 69 7A 65 00 00 2E 00 43 6F 55 6E PI32.dll..↓.CoInitialize....CoUn 00000CE0 69 6E 69 74 69 61 6C 69 7A 65 00 00 06 00 43 6F 43 72 65 61 74 65 49 6E 73 74 61 6E 63 65 00 00 initialize..♠.CoCreateInstance.. 00000D00 6F 6C 65 33 32 2E 64 6C 6C 00 0E 00 57 4F 57 48 61 6E 64 6C 65 33 32 00 57 4F 57 33 32 2E 64 6C ole32.dll.♫.WOWHandle32.WOW32.dl 00000D20 6C 00 0E 00 57 4E 65 74 43 6C 6F 73 65 45 6E 75 6D 00 19 00 57 4E 65 74 45 6E 75 6D 52 65 73 6F l.♫.WNetCloseEnum.↓.WNetEnumReso 00000D40 75 72 63 65 41 00 39 00 57 4E 65 74 4F 70 65 6E 45 6E 75 6D 41 00 4D 50 52 2E 64 6C 6C 00 06 00 urceA.9.WNetOpenEnumA.MPR.dll.♠. 00000D60 56 65 72 49 6E 73 74 61 6C 6C 46 69 6C 65 41 00 04 00 56 65 72 46 69 6E 64 46 69 6C 65 41 00 00 VerInstallFileA.♦.VerFindFileA.. 00000D80 0A 00 56 65 72 51 75 65 72 79 56 61 6C 75 65 41 00 00 00 00 47 65 74 46 69 6C 65 56 65 72 73 69 ◙.VerQueryValueA....GetFileVersi 00000DA0 6F 6E 49 6E 66 6F 41 00 01 00 47 65 74 46 69 6C 65 56 65 72 73 69 6F 6E 49 6E 66 6F 53 69 7A 65 onInfoA.☺.GetFileVersionInfoSize 00000DC0 41 00 56 45 52 53 49 4F 4E 2E 64 6C 6C 00 9F 00 47 65 74 43 6F 6D 6D 61 6E 64 4C 69 6E 65 41 00 A.VERSION.dll.ƒ.GetCommandLineA. 00000DE0 37 01 47 65 74 56 65 72 73 69 6F 6E 00 00 62 00 45 78 69 74 50 72 6F 63 65 73 73 00 C7 00 47 65 7☺GetVersion..b.ExitProcess.╟.Ge 00000E00 74 43 75 72 72 65 6E 74 54 68 72 65 61 64 49 64 00 00 22 02 54 6C 73 53 65 74 56 61 6C 75 65 00 tCurrentThreadId.."☻TlsSetValue. 00000E20 1F 02 54 6C 73 41 6C 6C 6F 63 00 00 20 02 54 6C 73 46 72 65 65 00 FD 01 53 65 74 4C 61 73 74 45 ▼☻TlsAlloc.. ☻TlsFree.²☺SetLastE 00000E40 72 72 6F 72 00 00 21 02 54 6C 73 47 65 74 56 61 6C 75 65 00 55 01 48 65 61 70 43 72 65 61 74 65 rror..!☻TlsGetValue.U☺HeapCreate 00000E60 00 00 57 01 48 65 61 70 44 65 73 74 72 6F 79 00 FA 01 53 65 74 48 61 6E 64 6C 65 43 6F 75 6E 74 ..W☺HeapDestroy.·☺SetHandleCount 00000E80 00 00 DC 00 47 65 74 46 69 6C 65 54 79 70 65 00 16 01 47 65 74 53 74 64 48 61 6E 64 6C 65 00 00 ..▄.GetFileType.▬☺GetStdHandle.. 00000EA0 14 01 47 65 74 53 74 61 72 74 75 70 49 6E 66 6F 41 00 44 00 44 65 6C 65 74 65 43 72 69 74 69 63 ¶☺GetStartupInfoA.D.DeleteCritic 00000EC0 61 6C 53 65 63 74 69 6F 6E 00 98 00 47 65 74 43 50 49 6E 66 6F 00 92 00 47 65 74 41 43 50 00 00 alSection.ÿ.GetCPInfo.Æ.GetACP.. 00000EE0 F6 00 47 65 74 4F 45 4D 43 50 00 00 8B 00 46 72 65 65 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 ÷.GetOEMCP..ï.FreeEnvironmentStr 00000F00 69 6E 67 73 41 00 D0 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 00 8C 00 ingsA.╨.GetEnvironmentStrings.î. 00000F20 46 72 65 65 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 57 00 D2 00 47 65 74 45 6E 76 FreeEnvironmentStringsW.╥.GetEnv 00000F40 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 57 00 00 17 01 47 65 74 53 74 72 69 6E 67 54 79 70 ironmentStringsW..↨☺GetStringTyp 00000F60 65 41 00 00 1A 01 47 65 74 53 74 72 69 6E 67 54 79 70 65 57 00 00 53 01 48 65 61 70 41 6C 6C 6F eA..→☺GetStringTypeW..S☺HeapAllo 00000F80 63 00 59 01 48 65 61 70 46 72 65 65 00 00 83 00 46 6C 75 73 68 46 69 6C 65 42 75 66 66 65 72 73 c.Y☺HeapFree..â.FlushFileBuffers 00000FA0 00 00 06 02 53 65 74 53 74 64 48 61 6E 64 6C 65 00 00 F8 01 53 65 74 46 69 6C 65 50 6F 69 6E 74 ..♠☻SetStdHandle..°☺SetFilePoint 00000FC0 65 72 00 00 75 01 4C 43 4D 61 70 53 74 72 69 6E 67 41 00 00 76 01 4C 43 4D 61 70 53 74 72 69 6E er..u☺LCMapStringA..v☺LCMapStrin 00000FE0 67 57 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 gW..............................