============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 E2 67 00 00 F6 67 00 00 BE 67 00 00 CE 67 00 00 B2 67 00 00 4C 68 00 00 30 68 00 00 1C 68 00 00 Γg..÷g..╛g..╬g..▓g..Lh..0h..∟h.. 00000020 08 68 00 00 8E 67 00 00 A2 67 00 00 80 67 00 00 00 00 00 00 32 66 00 00 22 66 00 00 14 66 00 00 ◘h..Äg..óg..Çg......2f.."f..¶f.. 00000040 42 66 00 00 68 66 00 00 74 66 00 00 80 66 00 00 52 66 00 00 2E 6A 00 00 F6 65 00 00 06 66 00 00 Bf..hf..tf..Çf..Rf...j..÷e..♠f.. 00000060 D8 66 00 00 E6 66 00 00 F2 66 00 00 FE 66 00 00 0A 67 00 00 16 67 00 00 26 67 00 00 36 67 00 00 ╪f..µf..≥f..■f..◙g..▬g..&g..6g.. 00000080 4A 67 00 00 5E 67 00 00 EA 65 00 00 C4 66 00 00 A8 66 00 00 9A 66 00 00 B0 66 00 00 00 00 00 00 Jg..^g..Ωe..─f..¿f..Üf..░f...... 000000A0 58 65 00 00 6E 65 00 00 64 65 00 00 A2 69 00 00 B4 69 00 00 AC 69 00 00 8E 69 00 00 98 69 00 00 Xe..ne..de..ói..┤i..¼i..Äi..ÿi.. 000000C0 00 00 00 00 7E 68 00 00 44 6A 00 00 6A 68 00 00 00 00 00 00 03 00 00 80 00 00 00 00 00 69 00 00 ....~h..Dj..jh......♥..Ç.....i.. 000000E0 1C 69 00 00 2C 69 00 00 E6 68 00 00 AC 68 00 00 BE 68 00 00 D8 68 00 00 9C 68 00 00 00 00 00 00 ∟i..,i..µh..¼h..╛h..╪h..£h...... 00000100 4E 6A 00 00 60 6A 00 00 76 6A 00 00 00 00 00 00 AC 65 00 00 9C 65 00 00 BE 69 00 00 D4 69 00 00 Nj..`j..vj......¼e..£e..╛i..╘i.. 00000120 E4 69 00 00 EE 69 00 00 06 6A 00 00 14 6A 00 00 86 65 00 00 C8 65 00 00 00 00 00 00 52 69 00 00 Σi..εi..♠j..¶j..åe..╚e......Ri.. 00000140 6A 69 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1F E0 C9 32 00 00 00 00 04 00 00 00 ji..................▼α╔2....♦... 00000160 10 01 00 00 00 00 00 00 00 6E 00 00 00 00 00 00 1F E0 C9 32 00 00 00 00 04 00 00 00 10 01 00 00 ►☺.......n......▼α╔2....♦...►☺.. 00000180 00 00 00 00 D8 C7 00 00 00 00 00 00 1F E0 C9 32 00 00 00 00 03 00 00 00 B0 04 00 00 00 00 00 00 ....╪╟......▼α╔2....♥...░♦...... 000001A0 E8 C8 00 00 00 00 00 00 1F E0 C9 32 00 00 00 00 06 00 00 00 00 00 00 00 00 00 00 00 98 CD 00 00 Φ╚......▼α╔2....♠...........ÿ═.. 000001C0 00 00 00 00 1F E0 C9 32 00 00 00 00 02 00 00 00 08 4E 00 00 00 00 00 00 C0 F5 B6 FF 44 49 41 4C ....▼α╔2....☻...◘N......└⌡╢ DIAL 000001E0 49 4E 5F 47 41 54 45 57 41 59 20 20 00 00 00 00 2A 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 IN_GATEWAY ....* 00000200 00 00 00 00 46 6F 72 63 65 45 6E 63 72 79 70 74 65 64 44 61 74 61 00 00 53 59 53 54 45 4D 5C 43 ....ForceEncryptedData..SYSTEM\C 00000220 75 72 72 65 6E 74 43 6F 6E 74 72 6F 6C 53 65 74 5C 53 65 72 76 69 63 65 73 5C 52 61 73 4D 61 6E urrentControlSet\Services\RasMan 00000240 5C 50 50 50 00 00 00 00 5C 00 5C 00 00 00 00 00 4D 49 43 52 4F 53 4F 46 54 5F 41 55 54 48 45 4E \PPP....\.\.....MICROSOFT_AUTHEN 00000260 54 49 43 41 54 49 4F 4E 5F 50 41 43 4B 41 47 45 5F 56 31 5F 30 00 00 00 52 45 4D 4F 54 45 5F 41 TICATION_PACKAGE_V1_0...REMOTE_A 00000280 43 43 45 53 53 00 00 00 4D 53 2E 52 41 53 20 20 00 00 00 00 00 00 00 00 00 00 00 00 5C 00 4C 00 CCESS...MS.RAS ............\.L. 000002A0 73 00 61 00 41 00 75 00 74 00 68 00 65 00 6E 00 74 00 69 00 63 00 61 00 74 00 69 00 6F 00 6E 00 s.a.A.u.t.h.e.n.t.i.c.a.t.i.o.n. 000002C0 50 00 6F 00 72 00 74 00 00 00 00 00 5C 00 53 00 45 00 43 00 55 00 52 00 49 00 54 00 59 00 5C 00 P.o.r.t.....\.S.E.C.U.R.I.T.Y.\. 000002E0 4C 00 53 00 41 00 5F 00 41 00 55 00 54 00 48 00 45 00 4E 00 54 00 49 00 43 00 41 00 54 00 49 00 L.S.A._.A.U.T.H.E.N.T.I.C.A.T.I. 00000300 4F 00 4E 00 5F 00 49 00 4E 00 49 00 54 00 49 00 41 00 4C 00 49 00 5A 00 45 00 44 00 00 00 00 00 O.N._.I.N.I.T.I.A.L.I.Z.E.D..... 00000320 5C 56 61 72 46 69 6C 65 49 6E 66 6F 5C 54 72 61 6E 73 6C 61 74 69 6F 6E 00 00 00 00 5C 55 53 45 \VarFileInfo\Translation....\USE 00000340 52 33 32 2E 44 4C 4C 00 B0 64 00 00 00 00 00 00 00 00 00 00 7A 65 00 00 A0 60 00 00 20 65 00 00 R32.DLL.░d..........ze..á`.. e.. 00000360 00 00 00 00 00 00 00 00 E0 65 00 00 10 61 00 00 44 64 00 00 00 00 00 00 00 00 00 00 72 67 00 00 ........αe..►a..Dd..........rg.. 00000380 34 60 00 00 10 64 00 00 00 00 00 00 00 00 00 00 5C 68 00 00 00 60 00 00 D4 64 00 00 00 00 00 00 4`..►d..........\h...`..╘d...... 000003A0 00 00 00 00 8E 68 00 00 C4 60 00 00 EC 64 00 00 00 00 00 00 00 00 00 00 3A 69 00 00 DC 60 00 00 ....Äh..─`..∞d..........:i..▄`.. 000003C0 E4 64 00 00 00 00 00 00 00 00 00 00 46 69 00 00 D4 60 00 00 4C 65 00 00 00 00 00 00 00 00 00 00 Σd..........Fi..╘`..Le.......... 000003E0 82 69 00 00 3C 61 00 00 10 65 00 00 00 00 00 00 00 00 00 00 90 6A 00 00 00 61 00 00 00 00 00 00 éi..<a..►e..........Éj...a...... 00000400 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E2 67 00 00 F6 67 00 00 BE 67 00 00 CE 67 00 00 ................Γg..÷g..╛g..╬g.. 00000420 B2 67 00 00 4C 68 00 00 30 68 00 00 1C 68 00 00 08 68 00 00 8E 67 00 00 A2 67 00 00 80 67 00 00 ▓g..Lh..0h..∟h..◘h..Äg..óg..Çg.. 00000440 00 00 00 00 32 66 00 00 22 66 00 00 14 66 00 00 42 66 00 00 68 66 00 00 74 66 00 00 80 66 00 00 ....2f.."f..¶f..Bf..hf..tf..Çf.. 00000460 52 66 00 00 2E 6A 00 00 F6 65 00 00 06 66 00 00 D8 66 00 00 E6 66 00 00 F2 66 00 00 FE 66 00 00 Rf...j..÷e..♠f..╪f..µf..≥f..■f.. 00000480 0A 67 00 00 16 67 00 00 26 67 00 00 36 67 00 00 4A 67 00 00 5E 67 00 00 EA 65 00 00 C4 66 00 00 ◙g..▬g..&g..6g..Jg..^g..Ωe..─f.. 000004A0 A8 66 00 00 9A 66 00 00 B0 66 00 00 00 00 00 00 58 65 00 00 6E 65 00 00 64 65 00 00 A2 69 00 00 ¿f..Üf..░f......Xe..ne..de..ói.. 000004C0 B4 69 00 00 AC 69 00 00 8E 69 00 00 98 69 00 00 00 00 00 00 7E 68 00 00 44 6A 00 00 6A 68 00 00 ┤i..¼i..Äi..ÿi......~h..Dj..jh.. 000004E0 00 00 00 00 03 00 00 80 00 00 00 00 00 69 00 00 1C 69 00 00 2C 69 00 00 E6 68 00 00 AC 68 00 00 ....♥..Ç.....i..∟i..,i..µh..¼h.. 00000500 BE 68 00 00 D8 68 00 00 9C 68 00 00 00 00 00 00 4E 6A 00 00 60 6A 00 00 76 6A 00 00 00 00 00 00 ╛h..╪h..£h......Nj..`j..vj...... 00000520 AC 65 00 00 9C 65 00 00 BE 69 00 00 D4 69 00 00 E4 69 00 00 EE 69 00 00 06 6A 00 00 14 6A 00 00 ¼e..£e..╛i..╘i..Σi..εi..♠j..¶j.. 00000540 86 65 00 00 C8 65 00 00 00 00 00 00 52 69 00 00 6A 69 00 00 00 00 00 00 EC 02 77 63 73 74 6F 6D åe..╚e......Ri..ji......∞☻wcstom 00000560 62 73 00 00 93 02 6D 65 6D 6D 6F 76 65 00 8E 02 6D 62 73 74 6F 77 63 73 00 00 4D 53 56 43 52 54 bs..ô☻memmove.Ä☻mbstowcs..MSVCRT 00000580 2E 64 6C 6C 00 00 A8 01 52 74 6C 47 65 74 4E 74 50 72 6F 64 75 63 74 54 79 70 65 00 B7 01 52 74 .dll..¿☺RtlGetNtProductType.╖☺Rt 000005A0 6C 49 6E 69 74 53 74 72 69 6E 67 00 39 00 4E 74 41 6C 6C 6F 63 61 74 65 4C 6F 63 61 6C 6C 79 55 lInitString.9.NtAllocateLocallyU 000005C0 6E 69 71 75 65 49 64 00 B8 01 52 74 6C 49 6E 69 74 55 6E 69 63 6F 64 65 53 74 72 69 6E 67 00 00 niqueId.╕☺RtlInitUnicodeString.. 000005E0 6E 74 64 6C 6C 2E 64 6C 6C 00 15 02 53 65 74 45 76 65 6E 74 00 00 38 00 43 72 65 61 74 65 4D 75 ntdll.dll.§☻SetEvent..8.CreateMu 00000600 74 65 78 41 00 00 55 01 47 6C 6F 62 61 6C 41 6C 6C 6F 63 00 18 00 43 6C 6F 73 65 48 61 6E 64 6C texA..U☺GlobalAlloc.↑.CloseHandl 00000620 65 00 43 00 43 72 65 61 74 65 54 68 72 65 61 64 00 00 2E 00 43 72 65 61 74 65 45 76 65 6E 74 41 e.C.CreateThread....CreateEventA 00000640 00 00 DE 01 52 65 6C 65 61 73 65 4D 75 74 65 78 00 00 6B 02 57 61 69 74 46 6F 72 53 69 6E 67 6C ..▐☺ReleaseMutex..k☻WaitForSingl 00000660 65 4F 62 6A 65 63 74 00 A4 02 6C 73 74 72 6C 65 6E 57 00 00 9D 02 6C 73 74 72 63 70 79 41 00 00 eObject.ñ☻lstrlenW..¥☻lstrcpyA.. 00000680 69 02 57 61 69 74 46 6F 72 4D 75 6C 74 69 70 6C 65 4F 62 6A 65 63 74 73 00 00 6C 00 45 78 69 74 i☻WaitForMultipleObjects..l.Exit 000006A0 54 68 72 65 61 64 00 00 40 02 53 6C 65 65 70 00 0B 01 47 65 74 50 72 69 6F 72 69 74 79 43 6C 61 Thread..@☻Sleep.♂☺GetPriorityCla 000006C0 73 73 00 00 D3 00 47 65 74 43 75 72 72 65 6E 74 50 72 6F 63 65 73 73 00 5C 01 47 6C 6F 62 61 6C ss..╙.GetCurrentProcess.\☺Global 000006E0 46 72 65 65 00 00 9B 02 6C 73 74 72 63 6D 70 69 57 00 9E 02 6C 73 74 72 63 70 79 57 00 00 95 02 Free..¢☻lstrcmpiW.₧☻lstrcpyW..ò☻ 00000700 6C 73 74 72 63 61 74 57 00 00 A3 02 6C 73 74 72 6C 65 6E 41 00 00 45 01 47 65 74 54 69 63 6B 43 lstrcatW..ú☻lstrlenA..E☺GetTickC 00000720 6F 75 6E 74 00 00 39 00 43 72 65 61 74 65 4D 75 74 65 78 57 00 00 34 02 53 65 74 54 68 72 65 61 ount..9.CreateMutexW..4☻SetThrea 00000740 64 50 72 69 6F 72 69 74 79 00 D5 00 47 65 74 43 75 72 72 65 6E 74 54 68 72 65 61 64 00 00 41 01 dPriority.╒.GetCurrentThread..A☺ 00000760 47 65 74 54 68 72 65 61 64 50 72 69 6F 72 69 74 79 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 GetThreadPriority.KERNEL32.dll.. 00000780 17 01 52 65 67 43 6C 6F 73 65 4B 65 79 00 36 01 52 65 67 51 75 65 72 79 56 61 6C 75 65 45 78 41 ↨☺RegCloseKey.6☺RegQueryValueExA 000007A0 00 00 2E 01 52 65 67 4F 70 65 6E 4B 65 79 45 78 41 00 C6 00 4C 73 61 43 6C 6F 73 65 00 00 D2 00 ...☺RegOpenKeyExA.╞.LsaClose..╥. 000007C0 4C 73 61 46 72 65 65 4D 65 6D 6F 72 79 00 73 01 53 79 73 74 65 6D 46 75 6E 63 74 69 6F 6E 30 30 LsaFreeMemory.s☺SystemFunction00 000007E0 39 00 72 01 53 79 73 74 65 6D 46 75 6E 63 74 69 6F 6E 30 30 38 00 D8 00 4C 73 61 4C 6F 6F 6B 75 9.r☺SystemFunction008.╪.LsaLooku 00000800 70 4E 61 6D 65 73 00 00 7D 01 53 79 73 74 65 6D 46 75 6E 63 74 69 6F 6E 30 31 39 00 7B 01 53 79 pNames..}☺SystemFunction019.{☺Sy 00000820 73 74 65 6D 46 75 6E 63 74 69 6F 6E 30 31 37 00 E3 00 4C 73 61 51 75 65 72 79 49 6E 66 6F 72 6D stemFunction017.π.LsaQueryInform 00000840 61 74 69 6F 6E 50 6F 6C 69 63 79 00 DF 00 4C 73 61 4F 70 65 6E 50 6F 6C 69 63 79 00 41 44 56 41 ationPolicy.▀.LsaOpenPolicy.ADVA 00000860 50 49 33 32 2E 64 6C 6C 00 00 31 00 4E 65 74 41 70 69 42 75 66 66 65 72 46 72 65 65 00 00 4C 00 PI32.dll..1.NetApiBufferFree..L. 00000880 4E 65 74 47 65 74 44 43 4E 61 6D 65 00 00 4E 45 54 41 50 49 33 32 2E 64 6C 6C 00 00 12 00 53 61 NetGetDCName..NETAPI32.dll..↕.Sa 000008A0 6D 46 72 65 65 4D 65 6D 6F 72 79 00 05 00 53 61 6D 43 6C 6F 73 65 48 61 6E 64 6C 65 00 00 32 00 mFreeMemory.♣.SamCloseHandle..2. 000008C0 53 61 6D 69 43 68 61 6E 67 65 50 61 73 73 77 6F 72 64 55 73 65 72 00 00 1E 00 53 61 6D 4F 70 65 SamiChangePasswordUser..▲.SamOpe 000008E0 6E 55 73 65 72 00 1A 00 53 61 6D 4C 6F 6F 6B 75 70 4E 61 6D 65 73 49 6E 44 6F 6D 61 69 6E 00 00 nUser.→.SamLookupNamesInDomain.. 00000900 21 00 53 61 6D 51 75 65 72 79 49 6E 66 6F 72 6D 61 74 69 6F 6E 44 6F 6D 61 69 6E 00 1C 00 53 61 !.SamQueryInformationDomain.∟.Sa 00000920 6D 4F 70 65 6E 44 6F 6D 61 69 6E 00 06 00 53 61 6D 43 6F 6E 6E 65 63 74 00 00 53 41 4D 4C 49 42 mOpenDomain.♠.SamConnect..SAMLIB 00000940 2E 64 6C 6C 00 00 52 41 53 53 41 50 49 2E 64 6C 6C 00 09 00 52 61 73 43 6F 6D 70 72 65 73 73 69 .dll..RASSAPI.dll.○.RasCompressi 00000960 6F 6E 53 65 74 49 6E 66 6F 00 08 00 52 61 73 43 6F 6D 70 72 65 73 73 69 6F 6E 47 65 74 49 6E 66 onSetInfo.◘.RasCompressionGetInf 00000980 6F 00 72 61 73 6D 61 6E 2E 64 6C 6C 00 00 BC 02 73 74 72 6E 63 70 79 00 92 02 6D 65 6D 63 70 79 o.rasman.dll..╝☻strncpy.Æ☻memcpy 000009A0 00 00 94 02 6D 65 6D 73 65 74 00 00 59 02 66 72 65 65 00 00 8C 02 6D 61 6C 6C 6F 63 00 00 9A 02 ..ö☻memset..Y☻free..î☻malloc..Ü☻ 000009C0 5A 77 46 72 65 65 56 69 72 74 75 61 6C 4D 65 6D 6F 72 79 00 71 02 5A 77 43 6F 6E 6E 65 63 74 50 ZwFreeVirtualMemory.q☻ZwConnectP 000009E0 6F 72 74 00 6E 02 5A 77 43 6C 6F 73 65 00 2B 03 5A 77 57 61 69 74 46 6F 72 53 69 6E 67 6C 65 4F ort.n☻ZwClose.+♥ZwWaitForSingleO 00000A00 62 6A 65 63 74 00 AF 02 5A 77 4F 70 65 6E 45 76 65 6E 74 00 F6 02 5A 77 52 65 71 75 65 73 74 57 bject.»☻ZwOpenEvent.÷☻ZwRequestW 00000A20 61 69 74 52 65 70 6C 79 50 6F 72 74 00 00 31 01 47 65 74 53 79 73 74 65 6D 44 69 72 65 63 74 6F aitReplyPort..1☺GetSystemDirecto 00000A40 72 79 41 00 CD 00 4E 65 74 62 69 6F 73 00 0A 00 56 65 72 51 75 65 72 79 56 61 6C 75 65 41 00 00 ryA.═.Netbios.◙.VerQueryValueA.. 00000A60 00 00 47 65 74 46 69 6C 65 56 65 72 73 69 6F 6E 49 6E 66 6F 41 00 01 00 47 65 74 46 69 6C 65 56 ..GetFileVersionInfoA.☺.GetFileV 00000A80 65 72 73 69 6F 6E 49 6E 66 6F 53 69 7A 65 41 00 56 45 52 53 49 4F 4E 2E 64 6C 6C 00 00 00 00 00 ersionInfoSizeA.VERSION.dll..... 00000AA0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000AC0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000AE0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B60 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000BA0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000BC0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000BE0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................