============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 20 91 00 00 00 00 00 00 00 00 00 00 F4 91 00 00 D4 91 00 00 F4 90 00 00 00 00 00 00 00 00 00 00 æ..........⌠æ..╘æ..⌠É.......... 00000020 28 92 00 00 A8 91 00 00 BC 90 00 00 00 00 00 00 00 00 00 00 06 93 00 00 70 91 00 00 78 90 00 00 (Æ..¿æ..╝É..........♠ô..pæ..xÉ.. 00000040 00 00 00 00 00 00 00 00 38 94 00 00 2C 91 00 00 04 91 00 00 00 00 00 00 00 00 00 00 9A 94 00 00 ........8ö..,æ..♦æ..........Üö.. 00000060 B8 91 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 24 93 00 00 34 93 00 00 ╕æ......................$ô..4ô.. 00000080 C2 93 00 00 16 94 00 00 FE 93 00 00 EE 93 00 00 A0 93 00 00 8A 93 00 00 78 93 00 00 60 93 00 00 ┬ô..▬ö..■ô..εô..áô..èô..xô..`ô.. 000000A0 4A 93 00 00 D0 93 00 00 B2 93 00 00 26 94 00 00 DE 93 00 00 14 93 00 00 00 00 00 00 92 92 00 00 Jô..╨ô..▓ô..&ö..▐ô..¶ô......ÆÆ.. 000000C0 C6 92 00 00 B0 92 00 00 84 92 00 00 78 92 00 00 62 92 00 00 50 92 00 00 44 92 00 00 34 92 00 00 ╞Æ..░Æ..äÆ..xÆ..bÆ..PÆ..DÆ..4Æ.. 000000E0 CE 92 00 00 EA 92 00 00 A2 92 00 00 F8 92 00 00 00 00 00 00 0C 92 00 00 1A 92 00 00 FE 91 00 00 ╬Æ..ΩÆ..óÆ..°Æ......♀Æ..→Æ..■æ.. 00000100 00 00 00 00 80 94 00 00 8E 94 00 00 46 94 00 00 58 94 00 00 68 94 00 00 74 94 00 00 00 00 00 00 ....Çö..Äö..Fö..Xö..hö..tö...... 00000120 E0 91 00 00 EA 91 00 00 00 00 00 00 24 93 00 00 34 93 00 00 C2 93 00 00 16 94 00 00 FE 93 00 00 αæ..Ωæ......$ô..4ô..┬ô..▬ö..■ô.. 00000140 EE 93 00 00 A0 93 00 00 8A 93 00 00 78 93 00 00 60 93 00 00 4A 93 00 00 D0 93 00 00 B2 93 00 00 εô..áô..èô..xô..`ô..Jô..╨ô..▓ô.. 00000160 26 94 00 00 DE 93 00 00 14 93 00 00 00 00 00 00 92 92 00 00 C6 92 00 00 B0 92 00 00 84 92 00 00 &ö..▐ô..¶ô......ÆÆ..╞Æ..░Æ..äÆ.. 00000180 78 92 00 00 62 92 00 00 50 92 00 00 44 92 00 00 34 92 00 00 CE 92 00 00 EA 92 00 00 A2 92 00 00 xÆ..bÆ..PÆ..DÆ..4Æ..╬Æ..ΩÆ..óÆ.. 000001A0 F8 92 00 00 00 00 00 00 0C 92 00 00 1A 92 00 00 FE 91 00 00 00 00 00 00 80 94 00 00 8E 94 00 00 °Æ......♀Æ..→Æ..■æ......Çö..Äö.. 000001C0 46 94 00 00 58 94 00 00 68 94 00 00 74 94 00 00 00 00 00 00 E0 91 00 00 EA 91 00 00 00 00 00 00 Fö..Xö..hö..tö......αæ..Ωæ...... 000001E0 A5 03 77 63 73 63 61 74 00 00 A8 03 77 63 73 63 70 79 00 00 6E 74 64 6C 6C 2E 64 6C 6C 00 78 01 Ñ♥wcscat..¿♥wcscpy..ntdll.dll.x☺ 00000200 4C 6F 61 64 53 74 72 69 6E 67 57 00 8D 01 4D 65 73 73 61 67 65 42 6F 78 57 00 4C 02 77 76 73 70 LoadStringW.ì☺MessageBoxW.L☻wvsp 00000220 72 69 6E 74 66 57 00 00 55 53 45 52 33 32 2E 64 6C 6C 00 00 E1 00 47 65 74 4C 61 73 74 45 72 72 rintfW..USER32.dll..ß.GetLastErr 00000240 6F 72 00 00 F3 01 53 65 74 45 76 65 6E 74 00 00 47 00 44 65 76 69 63 65 49 6F 43 6F 6E 74 72 6F or..≤☺SetEvent..G.DeviceIoContro 00000260 6C 00 3E 02 57 61 69 74 46 6F 72 53 69 6E 67 6C 65 4F 62 6A 65 63 74 00 4F 02 57 72 69 74 65 46 l.>☻WaitForSingleObject.O☻WriteF 00000280 69 6C 65 00 16 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 2A 00 43 72 65 61 74 65 45 76 65 6E 74 57 ile.▬.CloseHandle.*.CreateEventW 000002A0 00 00 2E 00 43 72 65 61 74 65 46 69 6C 65 57 00 A1 01 4F 75 74 70 75 74 44 65 62 75 67 53 74 72 ....CreateFileW.í☺OutputDebugStr 000002C0 69 6E 67 57 00 00 18 02 53 6C 65 65 70 00 00 01 47 65 74 50 72 69 76 61 74 65 50 72 6F 66 69 6C ingW..↑☻Sleep..☺GetPrivateProfil 000002E0 65 53 74 72 69 6E 67 57 00 00 4B 01 47 6C 6F 62 61 6C 4C 6F 63 6B 00 00 40 01 47 6C 6F 62 61 6C eStringW..K☺GlobalLock..@☺Global 00000300 41 6C 6C 6F 63 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 DA 00 52 65 67 4F 70 65 6E 4B 65 79 Alloc.KERNEL32.dll..┌.RegOpenKey 00000320 45 78 57 00 B4 00 4F 70 65 6E 53 65 72 76 69 63 65 57 00 00 16 00 43 6C 6F 73 65 53 65 72 76 69 ExW.┤.OpenServiceW..▬.CloseServi 00000340 63 65 48 61 6E 64 6C 65 00 00 BE 00 51 75 65 72 79 53 65 72 76 69 63 65 53 74 61 74 75 73 00 00 ceHandle..╛.QueryServiceStatus.. 00000360 2C 01 55 6E 6C 6F 63 6B 53 65 72 76 69 63 65 44 61 74 61 62 61 73 65 00 1D 00 43 72 65 61 74 65 ,☺UnlockServiceDatabase.↔.Create 00000380 53 65 72 76 69 63 65 57 00 00 66 00 4C 6F 63 6B 53 65 72 76 69 63 65 44 61 74 61 62 61 73 65 00 ServiceW..f.LockServiceDatabase. 000003A0 B2 00 4F 70 65 6E 53 43 4D 61 6E 61 67 65 72 57 00 00 1F 00 44 65 6C 65 74 65 53 65 72 76 69 63 ▓.OpenSCManagerW..▼.DeleteServic 000003C0 65 00 C2 00 52 65 67 43 6C 6F 73 65 4B 65 79 00 D3 00 52 65 67 46 6C 75 73 68 4B 65 79 00 CA 00 e.┬.RegCloseKey.╙.RegFlushKey.╩. 000003E0 52 65 67 44 65 6C 65 74 65 4B 65 79 57 00 C8 00 52 65 67 43 72 65 61 74 65 4B 65 79 57 00 12 00 RegDeleteKeyW.╚.RegCreateKeyW.↕. 00000400 43 68 61 6E 67 65 53 65 72 76 69 63 65 43 6F 6E 66 69 67 57 00 00 09 01 53 74 61 72 74 53 65 72 ChangeServiceConfigW..○☺StartSer 00000420 76 69 63 65 57 00 17 00 43 6F 6E 74 72 6F 6C 53 65 72 76 69 63 65 00 00 41 44 56 41 50 49 33 32 viceW.↨.ControlService..ADVAPI32 00000440 2E 64 6C 6C 00 00 02 00 44 72 69 76 65 72 43 61 6C 6C 62 61 63 6B 00 00 01 00 44 65 66 44 72 69 .dll..☻.DriverCallback..☺.DefDri 00000460 76 65 72 50 72 6F 63 00 77 00 6D 6D 69 6F 43 6C 6F 73 65 00 80 00 6D 6D 69 6F 52 65 61 64 00 00 verProc.w.mmioClose.Ç.mmioRead.. 00000480 79 00 6D 6D 69 6F 44 65 73 63 65 6E 64 00 7F 00 6D 6D 69 6F 4F 70 65 6E 57 00 57 49 4E 4D 4D 2E y.mmioDescend.⌂.mmioOpenW.WINMM. 000004A0 64 6C 6C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 dll............................. 000004C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000004E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000500 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000520 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000540 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000560 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000580 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................