============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 90 B0 00 00 00 00 00 00 00 00 00 00 1A B6 00 00 A4 B1 00 00 6C B1 00 00 00 00 00 00 00 00 00 00 É░..........→╢..ñ▒..l▒.......... 00000020 9A B6 00 00 80 B2 00 00 78 B0 00 00 00 00 00 00 00 00 00 00 F8 B6 00 00 8C B1 00 00 64 B1 00 00 Ü╢..Ç▓..x░..........°╢..î▒..d▒.. 00000040 00 00 00 00 00 00 00 00 06 B7 00 00 78 B2 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ........♠╖..x▓.................. 00000060 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 B4 B6 00 00 C6 B6 00 00 ........................┤╢..╞╢.. 00000080 A6 B6 00 00 E8 B6 00 00 DA B6 00 00 00 00 00 00 F6 B2 00 00 18 B3 00 00 30 B3 00 00 3C B3 00 00 ª╢..Φ╢..┌╢......÷▓..↑│..0│..<│.. 000000A0 48 B3 00 00 54 B3 00 00 66 B3 00 00 72 B3 00 00 80 B3 00 00 8E B3 00 00 9C B3 00 00 A8 B3 00 00 H│..T│..f│..r│..Ç│..Ä│..£│..¿│.. 000000C0 C0 B3 00 00 D4 B3 00 00 E6 B3 00 00 F8 B3 00 00 06 B4 00 00 14 B4 00 00 28 B4 00 00 3C B4 00 00 └│..╘│..µ│..°│..♠┤..¶┤..(┤..<┤.. 000000E0 58 B4 00 00 6E B4 00 00 E0 B2 00 00 08 B3 00 00 B8 B4 00 00 D0 B4 00 00 EA B4 00 00 00 B5 00 00 X┤..n┤..α▓..◘│..╕┤..╨┤..Ω┤...╡.. 00000100 A0 B2 00 00 16 B5 00 00 22 B5 00 00 34 B5 00 00 44 B5 00 00 52 B5 00 00 60 B5 00 00 6E B5 00 00 á▓..▬╡.."╡..4╡..D╡..R╡..`╡..n╡.. 00000120 7C B5 00 00 88 B5 00 00 9A B5 00 00 AC B5 00 00 B8 B5 00 00 C4 B5 00 00 D4 B5 00 00 E6 B5 00 00 |╡..ê╡..Ü╡..¼╡..╕╡..─╡..╘╡..µ╡.. 00000140 F6 B5 00 00 06 B6 00 00 AC B2 00 00 CA B2 00 00 BC B2 00 00 88 B4 00 00 9E B4 00 00 0C B5 00 00 ÷╡..♠╢..¼▓..╩▓..╝▓..ê┤..₧┤..♀╡.. 00000160 00 00 00 00 3B 00 00 80 00 00 00 00 62 B6 00 00 74 B6 00 00 88 B6 00 00 38 B6 00 00 28 B6 00 00 ....;..Ç....b╢..t╢..ê╢..8╢..(╢.. 00000180 54 B6 00 00 46 B6 00 00 00 00 00 00 B4 B6 00 00 C6 B6 00 00 A6 B6 00 00 E8 B6 00 00 DA B6 00 00 T╢..F╢......┤╢..╞╢..ª╢..Φ╢..┌╢.. 000001A0 00 00 00 00 F6 B2 00 00 18 B3 00 00 30 B3 00 00 3C B3 00 00 48 B3 00 00 54 B3 00 00 66 B3 00 00 ....÷▓..↑│..0│..<│..H│..T│..f│.. 000001C0 72 B3 00 00 80 B3 00 00 8E B3 00 00 9C B3 00 00 A8 B3 00 00 C0 B3 00 00 D4 B3 00 00 E6 B3 00 00 r│..Ç│..Ä│..£│..¿│..└│..╘│..µ│.. 000001E0 F8 B3 00 00 06 B4 00 00 14 B4 00 00 28 B4 00 00 3C B4 00 00 58 B4 00 00 6E B4 00 00 E0 B2 00 00 °│..♠┤..¶┤..(┤..<┤..X┤..n┤..α▓.. 00000200 08 B3 00 00 B8 B4 00 00 D0 B4 00 00 EA B4 00 00 00 B5 00 00 A0 B2 00 00 16 B5 00 00 22 B5 00 00 ◘│..╕┤..╨┤..Ω┤...╡..á▓..▬╡.."╡.. 00000220 34 B5 00 00 44 B5 00 00 52 B5 00 00 60 B5 00 00 6E B5 00 00 7C B5 00 00 88 B5 00 00 9A B5 00 00 4╡..D╡..R╡..`╡..n╡..|╡..ê╡..Ü╡.. 00000240 AC B5 00 00 B8 B5 00 00 C4 B5 00 00 D4 B5 00 00 E6 B5 00 00 F6 B5 00 00 06 B6 00 00 AC B2 00 00 ¼╡..╕╡..─╡..╘╡..µ╡..÷╡..♠╢..¼▓.. 00000260 CA B2 00 00 BC B2 00 00 88 B4 00 00 9E B4 00 00 0C B5 00 00 00 00 00 00 3B 00 00 80 00 00 00 00 ╩▓..╝▓..ê┤..₧┤..♀╡......;..Ç.... 00000280 62 B6 00 00 74 B6 00 00 88 B6 00 00 38 B6 00 00 28 B6 00 00 54 B6 00 00 46 B6 00 00 00 00 00 00 b╢..t╢..ê╢..8╢..(╢..T╢..F╢...... 000002A0 C0 02 6C 73 74 72 63 6D 70 69 41 00 01 01 47 65 74 4C 61 73 74 45 72 72 6F 72 00 00 26 00 43 6C └☻lstrcmpiA.☺☺GetLastError..&.Cl 000002C0 6F 73 65 48 61 6E 64 6C 65 00 F0 00 47 65 74 45 78 69 74 43 6F 64 65 50 72 6F 63 65 73 73 00 00 oseHandle.≡.GetExitCodeProcess.. 000002E0 91 02 57 61 69 74 46 6F 72 53 69 6E 67 6C 65 4F 62 6A 65 63 74 00 4A 00 43 72 65 61 74 65 50 72 æ☻WaitForSingleObject.J.CreatePr 00000300 6F 63 65 73 73 41 00 00 5B 01 47 65 74 56 65 72 73 69 6F 6E 45 78 41 00 D8 00 47 65 74 43 75 72 ocessA..[☺GetVersionExA.╪.GetCur 00000320 72 65 6E 74 44 69 72 65 63 74 6F 72 79 41 00 00 C9 02 6C 73 74 72 6C 65 6E 41 00 00 AD 01 4C 6F rentDirectoryA..╔☻lstrlenA..¡☺Lo 00000340 63 61 6C 46 72 65 65 00 A0 02 57 72 69 74 65 46 69 6C 65 00 43 02 53 65 74 46 69 6C 65 50 6F 69 calFree.á☻WriteFile.C☻SetFilePoi 00000360 6E 74 65 72 00 00 F7 01 52 65 61 64 46 69 6C 65 00 00 A9 01 4C 6F 63 61 6C 41 6C 6C 6F 63 00 00 nter..≈☺ReadFile..⌐☺LocalAlloc.. 00000380 F7 00 47 65 74 46 69 6C 65 53 69 7A 65 00 3D 00 43 72 65 61 74 65 46 69 6C 65 41 00 BA 02 6C 73 ≈.GetFileSize.=.CreateFileA.║☻ls 000003A0 74 72 63 61 74 41 00 00 5F 01 47 65 74 57 69 6E 64 6F 77 73 44 69 72 65 63 74 6F 72 79 41 00 00 trcatA.._☺GetWindowsDirectoryA.. 000003C0 0D 01 47 65 74 4D 6F 64 75 6C 65 48 61 6E 64 6C 65 41 00 00 38 01 47 65 74 53 74 61 72 74 75 70 ♪☺GetModuleHandleA..8☺GetStartup 000003E0 49 6E 66 6F 41 00 C9 00 47 65 74 43 6F 6D 6D 61 6E 64 4C 69 6E 65 41 00 5A 01 47 65 74 56 65 72 InfoA.╔.GetCommandLineA.Z☺GetVer 00000400 73 69 6F 6E 00 00 7C 00 45 78 69 74 50 72 6F 63 65 73 73 00 6A 02 54 65 72 6D 69 6E 61 74 65 50 sion..|.ExitProcess.j☻TerminateP 00000420 72 6F 63 65 73 73 00 00 DA 00 47 65 74 43 75 72 72 65 6E 74 50 72 6F 63 65 73 73 00 7C 02 55 6E rocess..┌.GetCurrentProcess.|☻Un 00000440 68 61 6E 64 6C 65 64 45 78 63 65 70 74 69 6F 6E 46 69 6C 74 65 72 00 00 0B 01 47 65 74 4D 6F 64 handledExceptionFilter..♂☺GetMod 00000460 75 6C 65 46 69 6C 65 4E 61 6D 65 41 00 00 B2 00 46 72 65 65 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 uleFileNameA..▓.FreeEnvironmentS 00000480 74 72 69 6E 67 73 41 00 CA 01 4D 75 6C 74 69 42 79 74 65 54 6F 57 69 64 65 43 68 61 72 00 B3 00 tringsA.╩☺MultiByteToWideChar.│. 000004A0 46 72 65 65 45 6E 76 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 57 00 EA 00 47 65 74 45 6E 76 FreeEnvironmentStringsW.Ω.GetEnv 000004C0 69 72 6F 6E 6D 65 6E 74 53 74 72 69 6E 67 73 00 EC 00 47 65 74 45 6E 76 69 72 6F 6E 6D 65 6E 74 ironmentStrings.∞.GetEnvironment 000004E0 53 74 72 69 6E 67 73 57 00 00 95 02 57 69 64 65 43 68 61 72 54 6F 4D 75 6C 74 69 42 79 74 65 00 StringsW..ò☻WideCharToMultiByte. 00000500 C0 00 47 65 74 43 50 49 6E 66 6F 00 BA 00 47 65 74 41 43 50 00 00 16 01 47 65 74 4F 45 4D 43 50 └.GetCPInfo.║.GetACP..▬☺GetOEMCP 00000520 00 00 46 02 53 65 74 48 61 6E 64 6C 65 43 6F 75 6E 74 00 00 3A 01 47 65 74 53 74 64 48 61 6E 64 ..F☻SetHandleCount..:☺GetStdHand 00000540 6C 65 00 00 F9 00 47 65 74 46 69 6C 65 54 79 70 65 00 7D 01 48 65 61 70 44 65 73 74 72 6F 79 00 le..∙.GetFileType.}☺HeapDestroy. 00000560 7C 01 48 65 61 70 43 72 65 61 74 65 00 00 86 02 56 69 72 74 75 61 6C 46 72 65 65 00 08 02 52 74 |☺HeapCreate..å☻VirtualFree.◘☻Rt 00000580 6C 55 6E 77 69 6E 64 00 3B 01 47 65 74 53 74 72 69 6E 67 54 79 70 65 41 00 00 3E 01 47 65 74 53 lUnwind.;☺GetStringTypeA..>☺GetS 000005A0 74 72 69 6E 67 54 79 70 65 57 00 00 7E 01 48 65 61 70 46 72 65 65 00 00 7A 01 48 65 61 70 41 6C tringTypeW..~☺HeapFree..z☺HeapAl 000005C0 6C 6F 63 00 85 02 56 69 72 74 75 61 6C 41 6C 6C 6F 63 00 00 23 01 47 65 74 50 72 6F 63 41 64 64 loc.à☻VirtualAlloc..#☺GetProcAdd 000005E0 72 65 73 73 00 00 A3 01 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 51 02 53 65 74 53 74 64 48 61 ress..ú☺LoadLibraryA..Q☻SetStdHa 00000600 6E 64 6C 65 00 00 AA 00 46 6C 75 73 68 46 69 6C 65 42 75 66 66 65 72 73 00 00 4B 45 52 4E 45 4C ndle..¬.FlushFileBuffers..KERNEL 00000620 33 32 2E 64 6C 6C 00 00 8C 00 44 65 73 74 72 6F 79 57 69 6E 64 6F 77 00 A2 01 4D 65 73 73 61 67 32.dll..î.DestroyWindow.ó☺Messag 00000640 65 42 6F 78 41 00 D1 00 46 69 6E 64 57 69 6E 64 6F 77 41 00 94 01 4C 6F 61 64 53 74 72 69 6E 67 eBoxA.╤.FindWindowA.ö☺LoadString 00000660 41 00 59 00 43 72 65 61 74 65 57 69 6E 64 6F 77 45 78 41 00 CE 01 52 65 67 69 73 74 65 72 43 6C A.Y.CreateWindowExA.╬☺RegisterCl 00000680 61 73 73 45 78 41 00 00 83 00 44 65 66 57 69 6E 64 6F 77 50 72 6F 63 41 00 00 55 53 45 52 33 32 assExA..â.DefWindowProcA..USER32 000006A0 2E 64 6C 6C 00 00 7E 00 52 65 67 43 6C 6F 73 65 4B 65 79 00 A9 00 52 65 67 53 65 74 56 61 6C 75 .dll..~.RegCloseKey.⌐.RegSetValu 000006C0 65 45 78 41 00 00 9D 00 52 65 67 51 75 65 72 79 56 61 6C 75 65 45 78 41 00 00 89 00 52 65 67 45 eExA..¥.RegQueryValueExA..ë.RegE 000006E0 6E 75 6D 4B 65 79 41 00 95 00 52 65 67 4F 70 65 6E 4B 65 79 45 78 41 00 41 44 56 41 50 49 33 32 numKeyA.ò.RegOpenKeyExA.ADVAPI32 00000700 2E 64 6C 6C 00 00 53 48 45 4C 4C 33 32 2E 64 6C 6C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 .dll..SHELL32.dll............... 00000720 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000740 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000760 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000780 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000007A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000007C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000007E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................