============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 3C 00 04 00 00 00 00 00 00 00 00 00 34 03 04 00 4C 00 04 00 5C 00 04 00 00 00 00 00 00 00 00 00 <.♦.........4♥♦.L.♦.\.♦......... 00000020 3F 03 04 00 C8 01 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4C 03 04 00 ?♥♦.╚☺♦.....................L♥♦. 00000040 5E 03 04 00 70 03 04 00 00 00 00 00 4C 03 04 00 5E 03 04 00 70 03 04 00 00 00 00 00 7E 03 04 00 ^♥♦.p♥♦.....L♥♦.^♥♦.p♥♦.....~♥♦. 00000060 8C 03 04 00 A2 03 04 00 B6 03 04 00 C6 03 04 00 D4 03 04 00 E4 03 04 00 F2 03 04 00 04 04 04 00 î♥♦.ó♥♦.╢♥♦.╞♥♦.╘♥♦.Σ♥♦.≥♥♦.♦♦♦. 00000080 14 04 04 00 22 04 04 00 34 04 04 00 42 04 04 00 50 04 04 00 68 04 04 00 82 04 04 00 9A 04 04 00 ¶♦♦."♦♦.4♦♦.B♦♦.P♦♦.h♦♦.é♦♦.Ü♦♦. 000000A0 A6 04 04 00 B8 04 04 00 C8 04 04 00 E2 04 04 00 F6 04 04 00 08 05 04 00 1A 05 04 00 32 05 04 00 ª♦♦.╕♦♦.╚♦♦.Γ♦♦.÷♦♦.◘♣♦.→♣♦.2♣♦. 000000C0 46 05 04 00 5C 05 04 00 70 05 04 00 86 05 04 00 9E 05 04 00 B4 05 04 00 C8 05 04 00 DE 05 04 00 F♣♦.\♣♦.p♣♦.å♣♦.₧♣♦.┤♣♦.╚♣♦.▐♣♦. 000000E0 FC 05 04 00 0A 06 04 00 18 06 04 00 2C 06 04 00 4A 06 04 00 5A 06 04 00 6A 06 04 00 80 06 04 00 ⁿ♣♦.◙♠♦.↑♠♦.,♠♦.J♠♦.Z♠♦.j♠♦.Ç♠♦. 00000100 9C 06 04 00 BC 06 04 00 CE 06 04 00 E0 06 04 00 F0 06 04 00 00 07 04 00 10 07 04 00 24 07 04 00 £♠♦.╝♠♦.╬♠♦.α♠♦.≡♠♦..•♦.►•♦.$•♦. 00000120 34 07 04 00 4E 07 04 00 5C 07 04 00 74 07 04 00 80 07 04 00 90 07 04 00 9E 07 04 00 B8 07 04 00 4•♦.N•♦.\•♦.t•♦.Ç•♦.É•♦.₧•♦.╕•♦. 00000140 C4 07 04 00 D6 07 04 00 E6 07 04 00 FA 07 04 00 06 08 04 00 1A 08 04 00 2A 08 04 00 3E 08 04 00 ─•♦.╓•♦.µ•♦.·•♦.♠◘♦.→◘♦.*◘♦.>◘♦. 00000160 4E 08 04 00 66 08 04 00 78 08 04 00 90 08 04 00 A0 08 04 00 AC 08 04 00 C2 08 04 00 D4 08 04 00 N◘♦.f◘♦.x◘♦.É◘♦.á◘♦.¼◘♦.┬◘♦.╘◘♦. 00000180 E2 08 04 00 F4 08 04 00 04 09 04 00 18 09 04 00 36 09 04 00 46 09 04 00 5E 09 04 00 6A 09 04 00 Γ◘♦.⌠◘♦.♦○♦.↑○♦.6○♦.F○♦.^○♦.j○♦. 000001A0 74 09 04 00 82 09 04 00 90 09 04 00 A0 09 04 00 AE 09 04 00 C2 09 04 00 DC 09 04 00 F2 09 04 00 t○♦.é○♦.É○♦.á○♦.«○♦.┬○♦.▄○♦.≥○♦. 000001C0 FE 09 04 00 00 00 00 00 7E 03 04 00 8C 03 04 00 A2 03 04 00 B6 03 04 00 C6 03 04 00 D4 03 04 00 ■○♦.....~♥♦.î♥♦.ó♥♦.╢♥♦.╞♥♦.╘♥♦. 000001E0 E4 03 04 00 F2 03 04 00 04 04 04 00 14 04 04 00 22 04 04 00 34 04 04 00 42 04 04 00 50 04 04 00 Σ♥♦.≥♥♦.♦♦♦.¶♦♦."♦♦.4♦♦.B♦♦.P♦♦. 00000200 68 04 04 00 82 04 04 00 9A 04 04 00 A6 04 04 00 B8 04 04 00 C8 04 04 00 E2 04 04 00 F6 04 04 00 h♦♦.é♦♦.Ü♦♦.ª♦♦.╕♦♦.╚♦♦.Γ♦♦.÷♦♦. 00000220 08 05 04 00 1A 05 04 00 32 05 04 00 46 05 04 00 5C 05 04 00 70 05 04 00 86 05 04 00 9E 05 04 00 ◘♣♦.→♣♦.2♣♦.F♣♦.\♣♦.p♣♦.å♣♦.₧♣♦. 00000240 B4 05 04 00 C8 05 04 00 DE 05 04 00 FC 05 04 00 0A 06 04 00 18 06 04 00 2C 06 04 00 4A 06 04 00 ┤♣♦.╚♣♦.▐♣♦.ⁿ♣♦.◙♠♦.↑♠♦.,♠♦.J♠♦. 00000260 5A 06 04 00 6A 06 04 00 80 06 04 00 9C 06 04 00 BC 06 04 00 CE 06 04 00 E0 06 04 00 F0 06 04 00 Z♠♦.j♠♦.Ç♠♦.£♠♦.╝♠♦.╬♠♦.α♠♦.≡♠♦. 00000280 00 07 04 00 10 07 04 00 24 07 04 00 34 07 04 00 4E 07 04 00 5C 07 04 00 74 07 04 00 80 07 04 00 .•♦.►•♦.$•♦.4•♦.N•♦.\•♦.t•♦.Ç•♦. 000002A0 90 07 04 00 9E 07 04 00 B8 07 04 00 C4 07 04 00 D6 07 04 00 E6 07 04 00 FA 07 04 00 06 08 04 00 É•♦.₧•♦.╕•♦.─•♦.╓•♦.µ•♦.·•♦.♠◘♦. 000002C0 1A 08 04 00 2A 08 04 00 3E 08 04 00 4E 08 04 00 66 08 04 00 78 08 04 00 90 08 04 00 A0 08 04 00 →◘♦.*◘♦.>◘♦.N◘♦.f◘♦.x◘♦.É◘♦.á◘♦. 000002E0 AC 08 04 00 C2 08 04 00 D4 08 04 00 E2 08 04 00 F4 08 04 00 04 09 04 00 18 09 04 00 36 09 04 00 ¼◘♦.┬◘♦.╘◘♦.Γ◘♦.⌠◘♦.♦○♦.↑○♦.6○♦. 00000300 46 09 04 00 5E 09 04 00 6A 09 04 00 74 09 04 00 82 09 04 00 90 09 04 00 A0 09 04 00 AE 09 04 00 F○♦.^○♦.j○♦.t○♦.é○♦.É○♦.á○♦.«○♦. 00000320 C2 09 04 00 DC 09 04 00 F2 09 04 00 FE 09 04 00 00 00 00 00 55 53 45 52 33 32 2E 44 4C 4C 00 4B ┬○♦.▄○♦.≥○♦.■○♦.....USER32.DLL.K 00000340 45 52 4E 45 4C 33 32 2E 44 4C 4C 00 01 00 43 68 61 72 55 70 70 65 72 42 75 66 66 41 00 00 02 00 ERNEL32.DLL.☺.CharUpperBuffA..☻. 00000360 47 65 74 41 63 74 69 76 65 57 69 6E 64 6F 77 00 03 00 4D 65 73 73 61 67 65 42 6F 78 41 00 01 00 GetActiveWindow.♥.MessageBoxA.☺. 00000380 43 6C 6F 73 65 48 61 6E 64 6C 65 00 02 00 43 6F 6E 74 69 6E 75 65 44 65 62 75 67 45 76 65 6E 74 CloseHandle.☻.ContinueDebugEvent 000003A0 00 00 03 00 43 72 65 61 74 65 44 69 72 65 63 74 6F 72 79 41 00 00 04 00 43 72 65 61 74 65 45 76 ..♥.CreateDirectoryA..♦.CreateEv 000003C0 65 6E 74 41 00 00 05 00 43 72 65 61 74 65 46 69 6C 65 41 00 06 00 43 72 65 61 74 65 4D 75 74 65 entA..♣.CreateFileA.♠.CreateMute 000003E0 78 41 00 00 07 00 43 72 65 61 74 65 50 69 70 65 00 00 08 00 43 72 65 61 74 65 50 72 6F 63 65 73 xA..•.CreatePipe..◘.CreateProces 00000400 73 41 00 00 09 00 43 72 65 61 74 65 54 68 72 65 61 64 00 00 0A 00 44 65 6C 65 74 65 46 69 6C 65 sA..○.CreateThread..◙.DeleteFile 00000420 41 00 0B 00 44 75 70 6C 69 63 61 74 65 48 61 6E 64 6C 65 00 0C 00 45 78 69 74 50 72 6F 63 65 73 A.♂.DuplicateHandle.♀.ExitProces 00000440 73 00 0D 00 45 78 69 74 54 68 72 65 61 64 00 00 0E 00 46 69 6C 65 54 69 6D 65 54 6F 44 6F 73 44 s.♪.ExitThread..♫.FileTimeToDosD 00000460 61 74 65 54 69 6D 65 00 0F 00 46 69 6C 65 54 69 6D 65 54 6F 4C 6F 63 61 6C 46 69 6C 65 54 69 6D ateTime.☼.FileTimeToLocalFileTim 00000480 65 00 10 00 46 69 6C 65 54 69 6D 65 54 6F 53 79 73 74 65 6D 54 69 6D 65 00 00 11 00 46 69 6E 64 e.►.FileTimeToSystemTime..◄.Find 000004A0 43 6C 6F 73 65 00 12 00 46 69 6E 64 46 69 72 73 74 46 69 6C 65 41 00 00 13 00 46 69 6E 64 4E 65 Close.↕.FindFirstFileA..‼.FindNe 000004C0 78 74 46 69 6C 65 41 00 14 00 46 6C 75 73 68 43 6F 6E 73 6F 6C 65 49 6E 70 75 74 42 75 66 66 65 xtFileA.¶.FlushConsoleInputBuffe 000004E0 72 00 15 00 46 6C 75 73 68 46 69 6C 65 42 75 66 66 65 72 73 00 00 16 00 47 65 74 43 6F 6D 6D 61 r.§.FlushFileBuffers..▬.GetComma 00000500 6E 64 4C 69 6E 65 41 00 17 00 47 65 74 43 6F 6E 73 6F 6C 65 4D 6F 64 65 00 00 18 00 47 65 74 43 ndLineA.↨.GetConsoleMode..↑.GetC 00000520 75 72 72 65 6E 74 44 69 72 65 63 74 6F 72 79 41 00 00 19 00 47 65 74 43 75 72 72 65 6E 74 50 72 urrentDirectoryA..↓.GetCurrentPr 00000540 6F 63 65 73 73 00 1A 00 47 65 74 43 75 72 72 65 6E 74 50 72 6F 63 65 73 73 49 64 00 1B 00 47 65 ocess.→.GetCurrentProcessId.←.Ge 00000560 74 43 75 72 72 65 6E 74 54 68 72 65 61 64 00 00 1C 00 47 65 74 43 75 72 72 65 6E 74 54 68 72 65 tCurrentThread..∟.GetCurrentThre 00000580 61 64 49 64 00 00 1D 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 00 1E 00 adId..↔.GetEnvironmentStrings.▲. 000005A0 47 65 74 45 78 69 74 43 6F 64 65 50 72 6F 63 65 73 73 00 00 1F 00 47 65 74 45 78 69 74 43 6F 64 GetExitCodeProcess..▼.GetExitCod 000005C0 65 54 68 72 65 61 64 00 20 00 47 65 74 46 69 6C 65 41 74 74 72 69 62 75 74 65 73 41 00 00 21 00 eThread. .GetFileAttributesA..!. 000005E0 47 65 74 46 69 6C 65 49 6E 66 6F 72 6D 61 74 69 6F 6E 42 79 48 61 6E 64 6C 65 00 00 22 00 47 65 GetFileInformationByHandle..".Ge 00000600 74 46 69 6C 65 53 69 7A 65 00 23 00 47 65 74 46 69 6C 65 54 79 70 65 00 24 00 47 65 74 46 75 6C tFileSize.#.GetFileType.$.GetFul 00000620 6C 50 61 74 68 4E 61 6D 65 41 00 00 25 00 47 65 74 4C 61 72 67 65 73 74 43 6F 6E 73 6F 6C 65 57 lPathNameA..%.GetLargestConsoleW 00000640 69 6E 64 6F 77 53 69 7A 65 00 26 00 47 65 74 4C 61 73 74 45 72 72 6F 72 00 00 27 00 47 65 74 4C indowSize.&.GetLastError..'.GetL 00000660 6F 63 61 6C 54 69 6D 65 00 00 28 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 00 00 ocalTime..(.GetModuleFileNameA.. 00000680 29 00 47 65 74 4E 61 6D 65 64 50 69 70 65 48 61 6E 64 6C 65 53 74 61 74 65 41 00 00 2A 00 47 65 ).GetNamedPipeHandleStateA..*.Ge 000006A0 74 4E 75 6D 62 65 72 4F 66 43 6F 6E 73 6F 6C 65 49 6E 70 75 74 45 76 65 6E 74 73 00 2B 00 47 65 tNumberOfConsoleInputEvents.+.Ge 000006C0 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 2C 00 47 65 74 50 72 6F 63 65 73 73 48 65 61 70 00 00 tProcAddress..,.GetProcessHeap.. 000006E0 2D 00 47 65 74 53 74 64 48 61 6E 64 6C 65 00 00 2E 00 47 65 74 53 79 73 74 65 6D 49 6E 66 6F 00 -.GetStdHandle....GetSystemInfo. 00000700 2F 00 47 65 74 53 79 73 74 65 6D 54 69 6D 65 00 30 00 47 65 74 54 68 72 65 61 64 43 6F 6E 74 65 /.GetSystemTime.0.GetThreadConte 00000720 78 74 00 00 31 00 47 65 74 54 69 63 6B 43 6F 75 6E 74 00 00 32 00 47 65 74 54 69 6D 65 5A 6F 6E xt..1.GetTickCount..2.GetTimeZon 00000740 65 49 6E 66 6F 72 6D 61 74 69 6F 6E 00 00 33 00 47 65 74 56 65 72 73 69 6F 6E 00 00 34 00 47 65 eInformation..3.GetVersion..4.Ge 00000760 74 56 6F 6C 75 6D 65 49 6E 66 6F 72 6D 61 74 69 6F 6E 41 00 35 00 48 65 61 70 41 6C 6C 6F 63 00 tVolumeInformationA.5.HeapAlloc. 00000780 36 00 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 37 00 4C 6F 63 61 6C 41 6C 6C 6F 63 00 00 38 00 6.LoadLibraryA..7.LocalAlloc..8. 000007A0 4C 6F 63 61 6C 46 69 6C 65 54 69 6D 65 54 6F 46 69 6C 65 54 69 6D 65 00 39 00 4D 6F 76 65 46 69 LocalFileTimeToFileTime.9.MoveFi 000007C0 6C 65 41 00 3A 00 52 61 69 73 65 45 78 63 65 70 74 69 6F 6E 00 00 3B 00 52 65 61 64 43 6F 6E 73 leA.:.RaiseException..;.ReadCons 000007E0 6F 6C 65 41 00 00 3C 00 52 65 61 64 43 6F 6E 73 6F 6C 65 49 6E 70 75 74 41 00 3D 00 52 65 61 64 oleA..<.ReadConsoleInputA.=.Read 00000800 46 69 6C 65 00 00 3E 00 52 65 61 64 50 72 6F 63 65 73 73 4D 65 6D 6F 72 79 00 3F 00 52 65 6C 65 File..>.ReadProcessMemory.?.Rele 00000820 61 73 65 4D 75 74 65 78 00 00 40 00 52 65 6D 6F 76 65 44 69 72 65 63 74 6F 72 79 41 00 00 41 00 aseMutex..@.RemoveDirectoryA..A. 00000840 52 65 73 75 6D 65 54 68 72 65 61 64 00 00 42 00 53 65 74 43 6F 6E 73 6F 6C 65 43 74 72 6C 48 61 ResumeThread..B.SetConsoleCtrlHa 00000860 6E 64 6C 65 72 00 43 00 53 65 74 43 6F 6E 73 6F 6C 65 4D 6F 64 65 00 00 44 00 53 65 74 43 75 72 ndler.C.SetConsoleMode..D.SetCur 00000880 72 65 6E 74 44 69 72 65 63 74 6F 72 79 41 00 00 45 00 53 65 74 45 6E 64 4F 66 46 69 6C 65 00 00 rentDirectoryA..E.SetEndOfFile.. 000008A0 46 00 53 65 74 45 76 65 6E 74 00 00 47 00 53 65 74 46 69 6C 65 41 74 74 72 69 62 75 74 65 73 41 F.SetEvent..G.SetFileAttributesA 000008C0 00 00 48 00 53 65 74 46 69 6C 65 50 6F 69 6E 74 65 72 00 00 49 00 53 65 74 46 69 6C 65 54 69 6D ..H.SetFilePointer..I.SetFileTim 000008E0 65 00 4A 00 53 65 74 48 61 6E 64 6C 65 43 6F 75 6E 74 00 00 4B 00 53 65 74 53 74 64 48 61 6E 64 e.J.SetHandleCount..K.SetStdHand 00000900 6C 65 00 00 4C 00 53 65 74 54 68 72 65 61 64 43 6F 6E 74 65 78 74 00 00 4D 00 53 65 74 55 6E 68 le..L.SetThreadContext..M.SetUnh 00000920 61 6E 64 6C 65 64 45 78 63 65 70 74 69 6F 6E 46 69 6C 74 65 72 00 4E 00 53 75 73 70 65 6E 64 54 andledExceptionFilter.N.SuspendT 00000940 68 72 65 61 64 00 4F 00 53 79 73 74 65 6D 54 69 6D 65 54 6F 46 69 6C 65 54 69 6D 65 00 00 50 00 hread.O.SystemTimeToFileTime..P. 00000960 54 6C 73 41 6C 6C 6F 63 00 00 51 00 54 6C 73 46 72 65 65 00 52 00 54 6C 73 47 65 74 56 61 6C 75 TlsAlloc..Q.TlsFree.R.TlsGetValu 00000980 65 00 53 00 54 6C 73 53 65 74 56 61 6C 75 65 00 54 00 56 69 72 74 75 61 6C 41 6C 6C 6F 63 00 00 e.S.TlsSetValue.T.VirtualAlloc.. 000009A0 55 00 56 69 72 74 75 61 6C 46 72 65 65 00 56 00 57 61 69 74 46 6F 72 44 65 62 75 67 45 76 65 6E U.VirtualFree.V.WaitForDebugEven 000009C0 74 00 57 00 57 61 69 74 46 6F 72 4D 75 6C 74 69 70 6C 65 4F 62 6A 65 63 74 73 00 00 58 00 57 61 t.W.WaitForMultipleObjects..X.Wa 000009E0 69 74 46 6F 72 53 69 6E 67 6C 65 4F 62 6A 65 63 74 00 59 00 57 72 69 74 65 46 69 6C 65 00 5A 00 itForSingleObject.Y.WriteFile.Z. 00000A00 57 72 69 74 65 50 72 6F 63 65 73 73 4D 65 6D 6F 72 79 00 00 00 00 00 00 00 00 00 00 00 00 00 00 WriteProcessMemory.............. 00000A20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000A40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000A60 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000A80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000AA0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000AC0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000AE0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B60 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000BA0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000BC0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000BE0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................