============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 1A 21 00 00 02 21 00 00 32 21 00 00 00 00 00 00 A0 20 00 00 C2 20 00 00 B4 20 00 00 00 00 00 00 →!..☻!..2!......á ..┬ ..┤ ...... 00000020 E6 20 00 00 00 00 00 00 88 20 00 00 00 00 00 00 00 00 00 00 D8 20 00 00 10 20 00 00 98 20 00 00 µ ......ê ..........╪ ..► ..ÿ .. 00000040 00 00 00 00 00 00 00 00 F6 20 00 00 20 20 00 00 78 20 00 00 00 00 00 00 00 00 00 00 46 21 00 00 ........÷ .. ..x ..........F!.. 00000060 00 20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1A 21 00 00 02 21 00 00 . ......................→!..☻!.. 00000080 32 21 00 00 00 00 00 00 A0 20 00 00 C2 20 00 00 B4 20 00 00 00 00 00 00 E6 20 00 00 00 00 00 00 2!......á ..┬ ..┤ ......µ ...... 000000A0 D3 00 47 65 74 43 75 72 72 65 6E 74 50 72 6F 63 65 73 73 00 A7 01 4D 6F 76 65 46 69 6C 65 45 78 ╙.GetCurrentProcess.º☺MoveFileEx 000000C0 41 00 FC 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 00 00 4B 45 52 4E 45 4C 33 32 A.ⁿ.GetModuleFileNameA..KERNEL32 000000E0 2E 64 6C 6C 00 00 CB 00 45 78 69 74 57 69 6E 64 6F 77 73 45 78 00 55 53 45 52 33 32 2E 64 6C 6C .dll..╦.ExitWindowsEx.USER32.dll 00000100 00 00 0A 00 41 64 6A 75 73 74 54 6F 6B 65 6E 50 72 69 76 69 6C 65 67 65 73 00 BF 00 4C 6F 6F 6B ..◙.AdjustTokenPrivileges.┐.Look 00000120 75 70 50 72 69 76 69 6C 65 67 65 56 61 6C 75 65 41 00 04 01 4F 70 65 6E 50 72 6F 63 65 73 73 54 upPrivilegeValueA.♦☺OpenProcessT 00000140 6F 6B 65 6E 00 00 41 44 56 41 50 49 33 32 2E 64 6C 6C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 oken..ADVAPI32.dll.............. 00000160 00 00 00 00 D6 1A C9 34 00 00 00 00 88 21 00 00 01 00 00 00 00 00 00 00 00 00 00 00 88 21 00 00 ....╓→╔4....ê!..☺...........ê!.. 00000180 88 21 00 00 88 21 00 00 52 45 42 4F 4F 54 4E 54 2E 45 58 45 00 00 00 00 00 00 00 00 00 00 00 00 ê!..ê!..REBOOTNT.EXE............ 000001A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000001C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000001E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................