============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 00 00 00 00 00 00 00 00 00 00 00 00 A8 71 00 00 B4 70 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ............¿q..┤p.............. 00000020 B6 73 00 00 34 71 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E2 73 00 00 40 71 00 00 00 00 00 00 ╢s..4q..............Γs..@q...... 00000040 00 00 00 00 00 00 00 00 22 74 00 00 50 71 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 74 00 00 ........"t..Pq..............@t.. 00000060 58 71 00 00 00 00 00 00 00 00 00 00 00 00 00 00 A2 74 00 00 70 71 00 00 00 00 00 00 00 00 00 00 Xq..............ót..pq.......... 00000080 00 00 00 00 DE 74 00 00 80 71 00 00 00 00 00 00 00 00 00 00 00 00 00 00 6E 75 00 00 A0 71 00 00 ....▐t..Çq..............nu..áq.. 000000A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 B6 71 00 00 CE 71 00 00 E6 71 00 00 ....................╢q..╬q..µq.. 000000C0 FE 71 00 00 1A 72 00 00 28 72 00 00 38 72 00 00 44 72 00 00 52 72 00 00 62 72 00 00 6E 72 00 00 ■q..→r..(r..8r..Dr..Rr..br..nr.. 000000E0 7A 72 00 00 8C 72 00 00 9E 72 00 00 B0 72 00 00 C6 72 00 00 D8 72 00 00 E8 72 00 00 FA 72 00 00 zr..îr..₧r..░r..╞r..╪r..Φr..·r.. 00000100 08 73 00 00 16 73 00 00 22 73 00 00 34 73 00 00 44 73 00 00 50 73 00 00 5C 73 00 00 6E 73 00 00 ◘s..▬s.."s..4s..Ds..Ps..\s..ns.. 00000120 7E 73 00 00 8C 73 00 00 9A 73 00 00 A8 73 00 00 00 00 00 00 C2 73 00 00 D4 73 00 00 00 00 00 00 ~s..îs..Üs..¿s......┬s..╘s...... 00000140 F0 73 00 00 04 74 00 00 14 74 00 00 00 00 00 00 30 74 00 00 00 00 00 00 4E 74 00 00 5C 74 00 00 ≡s..♦t..¶t......0t......Nt..\t.. 00000160 6A 74 00 00 78 74 00 00 8C 74 00 00 00 00 00 00 B0 74 00 00 C0 74 00 00 D0 74 00 00 00 00 00 00 jt..xt..ît......░t..└t..╨t...... 00000180 EC 74 00 00 00 75 00 00 0E 75 00 00 26 75 00 00 36 75 00 00 4A 75 00 00 60 75 00 00 00 00 00 00 ∞t...u..♫u..&u..6u..Ju..`u...... 000001A0 7A 75 00 00 00 00 00 00 6B 65 72 6E 65 6C 33 32 2E 64 6C 6C 00 00 00 00 44 65 6C 65 74 65 43 72 zu......kernel32.dll....DeleteCr 000001C0 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 00 4C 65 61 76 65 43 72 69 74 69 63 61 6C 53 65 63 iticalSection...LeaveCriticalSec 000001E0 74 69 6F 6E 00 00 00 00 45 6E 74 65 72 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 00 00 tion....EnterCriticalSection.... 00000200 49 6E 69 74 69 61 6C 69 7A 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 00 56 69 72 74 InitializeCriticalSection...Virt 00000220 75 61 6C 46 72 65 65 00 00 00 56 69 72 74 75 61 6C 41 6C 6C 6F 63 00 00 00 00 4C 6F 63 61 6C 46 ualFree...VirtualAlloc....LocalF 00000240 72 65 65 00 00 00 4C 6F 63 61 6C 41 6C 6C 6F 63 00 00 00 00 56 69 72 74 75 61 6C 51 75 65 72 79 ree...LocalAlloc....VirtualQuery 00000260 00 00 00 00 6C 73 74 72 6C 65 6E 41 00 00 00 00 6C 73 74 72 63 70 79 41 00 00 00 00 4C 6F 61 64 ....lstrlenA....lstrcpyA....Load 00000280 4C 69 62 72 61 72 79 45 78 41 00 00 00 00 47 65 74 54 68 72 65 61 64 4C 6F 63 61 6C 65 00 00 00 LibraryExA....GetThreadLocale... 000002A0 47 65 74 53 74 61 72 74 75 70 49 6E 66 6F 41 00 00 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E GetStartupInfoA...GetModuleFileN 000002C0 61 6D 65 41 00 00 00 00 47 65 74 4C 6F 63 61 6C 65 49 6E 66 6F 41 00 00 00 00 47 65 74 4C 61 73 ameA....GetLocaleInfoA....GetLas 000002E0 74 45 72 72 6F 72 00 00 00 00 47 65 74 43 6F 6D 6D 61 6E 64 4C 69 6E 65 41 00 00 00 46 72 65 65 tError....GetCommandLineA...Free 00000300 4C 69 62 72 61 72 79 00 00 00 45 78 69 74 50 72 6F 63 65 73 73 00 00 00 57 72 69 74 65 46 69 6C Library...ExitProcess...WriteFil 00000320 65 00 00 00 53 65 74 46 69 6C 65 50 6F 69 6E 74 65 72 00 00 00 00 53 65 74 45 6E 64 4F 66 46 69 e...SetFilePointer....SetEndOfFi 00000340 6C 65 00 00 00 00 52 74 6C 55 6E 77 69 6E 64 00 00 00 52 65 61 64 46 69 6C 65 00 00 00 00 52 61 le....RtlUnwind...ReadFile....Ra 00000360 69 73 65 45 78 63 65 70 74 69 6F 6E 00 00 00 00 47 65 74 53 74 64 48 61 6E 64 6C 65 00 00 00 00 iseException....GetStdHandle.... 00000380 47 65 74 46 69 6C 65 53 69 7A 65 00 00 00 47 65 74 46 69 6C 65 54 79 70 65 00 00 00 43 72 65 61 GetFileSize...GetFileType...Crea 000003A0 74 65 46 69 6C 65 41 00 00 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 75 73 65 72 33 32 2E 64 6C 6C teFileA...CloseHandle.user32.dll 000003C0 00 00 00 00 47 65 74 4B 65 79 62 6F 61 72 64 54 79 70 65 00 00 00 4D 65 73 73 61 67 65 42 6F 78 ....GetKeyboardType...MessageBox 000003E0 41 00 61 64 76 61 70 69 33 32 2E 64 6C 6C 00 00 00 00 52 65 67 51 75 65 72 79 56 61 6C 75 65 45 A.advapi32.dll....RegQueryValueE 00000400 78 41 00 00 00 00 52 65 67 4F 70 65 6E 4B 65 79 45 78 41 00 00 00 52 65 67 43 6C 6F 73 65 4B 65 xA....RegOpenKeyExA...RegCloseKe 00000420 79 00 6F 6C 65 61 75 74 33 32 2E 64 6C 6C 00 00 00 00 56 61 72 69 61 6E 74 43 6C 65 61 72 00 00 y.oleaut32.dll....VariantClear.. 00000440 6B 65 72 6E 65 6C 33 32 2E 64 6C 6C 00 00 00 00 54 6C 73 53 65 74 56 61 6C 75 65 00 00 00 54 6C kernel32.dll....TlsSetValue...Tl 00000460 73 47 65 74 56 61 6C 75 65 00 00 00 4C 6F 63 61 6C 41 6C 6C 6F 63 00 00 00 00 47 65 74 4D 6F 64 sGetValue...LocalAlloc....GetMod 00000480 75 6C 65 48 61 6E 64 6C 65 41 00 00 00 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 uleHandleA....GetModuleFileNameA 000004A0 00 00 61 64 76 61 70 69 33 32 2E 64 6C 6C 00 00 00 00 52 65 67 4F 70 65 6E 4B 65 79 45 78 41 00 ..advapi32.dll....RegOpenKeyExA. 000004C0 00 00 52 65 67 44 65 6C 65 74 65 4B 65 79 41 00 00 00 52 65 67 43 6C 6F 73 65 4B 65 79 00 6B 65 ..RegDeleteKeyA...RegCloseKey.ke 000004E0 72 6E 65 6C 33 32 2E 64 6C 6C 00 00 00 00 52 65 6D 6F 76 65 44 69 72 65 63 74 6F 72 79 41 00 00 rnel32.dll....RemoveDirectoryA.. 00000500 00 00 4D 6F 76 65 46 69 6C 65 45 78 41 00 00 00 47 65 74 57 69 6E 64 6F 77 73 44 69 72 65 63 74 ..MoveFileExA...GetWindowsDirect 00000520 6F 72 79 41 00 00 00 00 47 65 74 56 65 72 73 69 6F 6E 45 78 41 00 00 00 47 65 74 53 68 6F 72 74 oryA....GetVersionExA...GetShort 00000540 50 61 74 68 4E 61 6D 65 41 00 00 00 47 65 74 46 69 6C 65 41 74 74 72 69 62 75 74 65 73 41 00 00 PathNameA...GetFileAttributesA.. 00000560 00 00 44 65 6C 65 74 65 46 69 6C 65 41 00 75 73 65 72 33 32 2E 64 6C 6C 00 00 00 00 4D 65 73 73 ..DeleteFileA.user32.dll....Mess 00000580 61 67 65 42 6F 78 41 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ageBoxA......................... 000005A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................