============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 AA 99 00 00 96 99 00 00 88 99 00 00 00 00 00 00 50 98 00 00 8E 98 00 00 72 98 00 00 D0 97 00 00 ¬Ö..ûÖ..êÖ......Pÿ..Äÿ..rÿ..╨ù.. 00000020 0A 99 00 00 E0 97 00 00 A0 97 00 00 18 99 00 00 F2 98 00 00 DA 98 00 00 D2 98 00 00 B6 98 00 00 ◙Ö..αù..áù..↑Ö..≥ÿ..┌ÿ..╥ÿ..╢ÿ.. 00000040 9E 98 00 00 4C 99 00 00 3E 99 00 00 2A 99 00 00 FE 97 00 00 B8 97 00 00 0E 98 00 00 EE 97 00 00 ₧ÿ..LÖ..>Ö..*Ö..■ù..╕ù..♫ÿ..εù.. 00000060 40 98 00 00 24 98 00 00 62 98 00 00 00 00 00 00 56 96 00 00 4C 96 00 00 6A 96 00 00 60 96 00 00 @ÿ..$ÿ..bÿ......Vû..Lû..jû..`û.. 00000080 00 00 00 00 70 99 00 00 00 00 00 00 30 9A 00 00 0A 9A 00 00 FA 99 00 00 20 9A 00 00 C8 99 00 00 ....pÖ......0Ü..◙Ü..·Ö.. Ü..╚Ö.. 000000A0 E0 99 00 00 00 00 00 00 32 97 00 00 22 97 00 00 4A 97 00 00 62 97 00 00 EA 96 00 00 DC 96 00 00 αÖ......2ù.."ù..Jù..bù..Ωû..▄û.. 000000C0 CC 96 00 00 C2 96 00 00 76 97 00 00 84 97 00 00 10 97 00 00 B0 96 00 00 00 97 00 00 98 96 00 00 ╠û..┬û..vù..äù..►ù..░û...ù..ÿû.. 000000E0 8A 96 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 1C 76 1B 32 00 00 00 00 04 00 00 00 èû..................∟v←2....♦... 00000100 10 01 00 00 00 00 00 00 00 A8 00 00 00 00 00 00 1C 76 1B 32 00 00 00 00 04 00 00 00 10 01 00 00 ►☺.......¿......∟v←2....♦...►☺.. 00000120 00 00 00 00 40 31 01 00 00 00 00 00 1C 76 1B 32 00 00 00 00 03 00 00 00 C0 05 00 00 00 00 00 00 ....@1☺.....∟v←2....♥...└♣...... 00000140 50 32 01 00 00 00 00 00 1C 76 1B 32 00 00 00 00 06 00 00 00 00 00 00 00 00 00 00 00 10 38 01 00 P2☺.....∟v←2....♠...........►8☺. 00000160 00 00 00 00 1C 76 1B 32 00 00 00 00 02 00 00 00 3C 4A 00 00 00 00 00 00 C0 F5 B6 FF 00 00 00 00 ....∟v←2....☻...<J......└⌡╢ .... 00000180 4D 69 63 72 6F 73 6F 66 74 20 57 69 6E 53 6F 63 6B 20 32 2E 30 20 53 65 72 76 69 63 65 20 50 72 Microsoft WinSock 2.0 Service Pr 000001A0 6F 76 69 64 65 72 00 00 4D 00 61 00 70 00 70 00 69 00 6E 00 67 00 00 00 4D 00 61 00 70 00 70 00 ovider..M.a.p.p.i.n.g...M.a.p.p. 000001C0 69 00 6E 00 67 00 00 00 5C 00 50 00 61 00 72 00 61 00 6D 00 65 00 74 00 65 00 72 00 73 00 5C 00 i.n.g...\.P.a.r.a.m.e.t.e.r.s.\. 000001E0 57 00 69 00 6E 00 73 00 6F 00 63 00 6B 00 00 00 53 00 79 00 73 00 74 00 65 00 6D 00 5C 00 43 00 W.i.n.s.o.c.k...S.y.s.t.e.m.\.C. 00000200 75 00 72 00 72 00 65 00 6E 00 74 00 43 00 6F 00 6E 00 74 00 72 00 6F 00 6C 00 53 00 65 00 74 00 u.r.r.e.n.t.C.o.n.t.r.o.l.S.e.t. 00000220 5C 00 53 00 65 00 72 00 76 00 69 00 63 00 65 00 73 00 5C 00 00 00 00 00 57 53 48 49 6F 63 74 6C \.S.e.r.v.i.c.e.s.\.....WSHIoctl 00000240 00 00 00 00 57 53 48 53 74 72 69 6E 67 54 6F 41 64 64 72 65 73 73 00 00 57 53 48 41 64 64 72 65 ....WSHStringToAddress..WSHAddre 00000260 73 73 54 6F 53 74 72 69 6E 67 00 00 57 53 48 47 65 74 42 72 6F 61 64 63 61 73 74 53 6F 63 6B 61 ssToString..WSHGetBroadcastSocka 00000280 64 64 72 00 57 53 48 47 65 74 57 69 6C 64 63 61 72 64 53 6F 63 6B 61 64 64 72 00 00 57 53 48 47 ddr.WSHGetWildcardSockaddr..WSHG 000002A0 65 74 53 6F 63 6B 61 64 64 72 54 79 70 65 00 00 57 53 48 53 65 74 53 6F 63 6B 65 74 49 6E 66 6F etSockaddrType..WSHSetSocketInfo 000002C0 72 6D 61 74 69 6F 6E 00 57 53 48 47 65 74 53 6F 63 6B 65 74 49 6E 66 6F 72 6D 61 74 69 6F 6E 00 rmation.WSHGetSocketInformation. 000002E0 57 53 48 4E 6F 74 69 66 79 00 00 00 57 53 48 4A 6F 69 6E 4C 65 61 66 00 57 53 48 4F 70 65 6E 53 WSHNotify...WSHJoinLeaf.WSHOpenS 00000300 6F 63 6B 65 74 32 00 00 57 53 48 4F 70 65 6E 53 6F 63 6B 65 74 00 00 00 48 00 65 00 6C 00 70 00 ocket2..WSHOpenSocket...H.e.l.p. 00000320 65 00 72 00 44 00 6C 00 6C 00 4E 00 61 00 6D 00 65 00 00 00 4D 00 61 00 78 00 53 00 6F 00 63 00 e.r.D.l.l.N.a.m.e...M.a.x.S.o.c. 00000340 6B 00 61 00 64 00 64 00 72 00 4C 00 65 00 6E 00 67 00 74 00 68 00 00 00 4D 00 69 00 6E 00 53 00 k.a.d.d.r.L.e.n.g.t.h...M.i.n.S. 00000360 6F 00 63 00 6B 00 61 00 64 00 64 00 72 00 4C 00 65 00 6E 00 67 00 74 00 68 00 00 00 00 00 00 00 o.c.k.a.d.d.r.L.e.n.g.t.h....... 00000380 FF FF FF FF 0C 3A 66 77 1C 3A 66 77 54 00 72 00 61 00 6E 00 73 00 70 00 6F 00 72 00 74 00 73 00 ♀:fw∟:fwT.r.a.n.s.p.o.r.t.s. 000003A0 00 00 00 00 54 00 72 00 61 00 6E 00 73 00 70 00 6F 00 72 00 74 00 73 00 00 00 00 00 53 00 59 00 ....T.r.a.n.s.p.o.r.t.s.....S.Y. 000003C0 53 00 54 00 45 00 4D 00 5C 00 43 00 75 00 72 00 72 00 65 00 6E 00 74 00 43 00 6F 00 6E 00 74 00 S.T.E.M.\.C.u.r.r.e.n.t.C.o.n.t. 000003E0 72 00 6F 00 6C 00 53 00 65 00 74 00 5C 00 53 00 65 00 72 00 76 00 69 00 63 00 65 00 73 00 5C 00 r.o.l.S.e.t.\.S.e.r.v.i.c.e.s.\. 00000400 57 00 69 00 6E 00 73 00 6F 00 63 00 6B 00 5C 00 50 00 61 00 72 00 61 00 6D 00 65 00 74 00 65 00 W.i.n.s.o.c.k.\.P.a.r.a.m.e.t.e. 00000420 72 00 73 00 00 00 00 00 FF FF FF FF 05 5F 66 77 15 5F 66 77 5C 00 44 00 65 00 76 00 69 00 63 00 r.s..... ♣_fw§_fw\.D.e.v.i.c. 00000440 65 00 5C 00 41 00 66 00 64 00 5C 00 45 00 6E 00 64 00 70 00 6F 00 69 00 6E 00 74 00 00 00 00 00 e.\.A.f.d.\.E.n.d.p.o.i.n.t..... 00000460 41 66 64 4F 70 65 6E 50 61 63 6B 65 74 58 58 00 FF FF FF FF C7 62 66 77 D7 62 66 77 00 00 00 00 AfdOpenPacketXX. ╟bfw╫bfw.... 00000480 FF FF FF FF 99 78 66 77 A9 78 66 77 4D 00 69 00 63 00 72 00 6F 00 73 00 6F 00 66 00 74 00 20 00 Öxfw⌐xfwM.i.c.r.o.s.o.f.t. . 000004A0 57 00 69 00 6E 00 64 00 6F 00 77 00 73 00 20 00 53 00 6F 00 63 00 6B 00 65 00 74 00 73 00 20 00 W.i.n.d.o.w.s. .S.o.c.k.e.t.s. . 000004C0 56 00 65 00 72 00 73 00 69 00 6F 00 6E 00 20 00 32 00 2E 00 00 00 D4 95 00 00 00 00 00 00 00 00 V.e.r.s.i.o.n. .2.....╘ò........ 000004E0 00 00 7E 96 00 00 70 90 00 00 0C 96 00 00 00 00 00 00 00 00 00 00 96 97 00 00 A8 90 00 00 74 95 ..~û..pÉ..♀û..........ûù..¿É..tò 00000500 00 00 00 00 00 00 00 00 00 00 62 99 00 00 10 90 00 00 E8 95 00 00 00 00 00 00 00 00 00 00 7C 99 ..........bÖ..►É..Φò..........|Ö 00000520 00 00 84 90 00 00 64 95 00 00 00 00 00 00 00 00 00 00 BA 99 00 00 00 90 00 00 F0 95 00 00 00 00 ..äÉ..dò..........║Ö...É..≡ò.... 00000540 00 00 00 00 00 00 44 9A 00 00 8C 90 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ......DÜ..îÉ.................... 00000560 00 00 00 00 AA 99 00 00 96 99 00 00 88 99 00 00 00 00 00 00 50 98 00 00 8E 98 00 00 72 98 00 00 ....¬Ö..ûÖ..êÖ......Pÿ..Äÿ..rÿ.. 00000580 D0 97 00 00 0A 99 00 00 E0 97 00 00 A0 97 00 00 18 99 00 00 F2 98 00 00 DA 98 00 00 D2 98 00 00 ╨ù..◙Ö..αù..áù..↑Ö..≥ÿ..┌ÿ..╥ÿ.. 000005A0 B6 98 00 00 9E 98 00 00 4C 99 00 00 3E 99 00 00 2A 99 00 00 FE 97 00 00 B8 97 00 00 0E 98 00 00 ╢ÿ..₧ÿ..LÖ..>Ö..*Ö..■ù..╕ù..♫ÿ.. 000005C0 EE 97 00 00 40 98 00 00 24 98 00 00 62 98 00 00 00 00 00 00 56 96 00 00 4C 96 00 00 6A 96 00 00 εù..@ÿ..$ÿ..bÿ......Vû..Lû..jû.. 000005E0 60 96 00 00 00 00 00 00 70 99 00 00 00 00 00 00 30 9A 00 00 0A 9A 00 00 FA 99 00 00 20 9A 00 00 `û......pÖ......0Ü..◙Ü..·Ö.. Ü.. 00000600 C8 99 00 00 E0 99 00 00 00 00 00 00 32 97 00 00 22 97 00 00 4A 97 00 00 62 97 00 00 EA 96 00 00 ╚Ö..αÖ......2ù.."ù..Jù..bù..Ωû.. 00000620 DC 96 00 00 CC 96 00 00 C2 96 00 00 76 97 00 00 84 97 00 00 10 97 00 00 B0 96 00 00 00 97 00 00 ▄û..╠û..┬û..vù..äù..►ù..░û...ù.. 00000640 98 96 00 00 8A 96 00 00 00 00 00 00 E1 02 77 63 73 6C 65 6E 00 00 DA 02 77 63 73 63 61 74 00 00 ÿû..èû......ß☻wcslen..┌☻wcscat.. 00000660 DE 02 77 63 73 63 70 79 00 00 C6 00 5F 65 78 63 65 70 74 5F 68 61 6E 64 6C 65 72 33 00 00 4D 53 ▐☻wcscpy..╞._except_handler3..MS 00000680 56 43 52 54 2E 64 6C 6C 00 00 95 01 52 74 6C 46 72 65 65 48 65 61 70 00 60 00 4E 74 44 65 76 69 VCRT.dll..ò☺RtlFreeHeap.`.NtDevi 000006A0 63 65 49 6F 43 6F 6E 74 72 6F 6C 46 69 6C 65 00 1A 01 52 74 6C 41 6C 6C 6F 63 61 74 65 48 65 61 ceIoControlFile.→☺RtlAllocateHea 000006C0 70 00 40 00 4E 74 43 6C 6F 73 65 00 47 00 4E 74 43 72 65 61 74 65 45 76 65 6E 74 00 D3 00 4E 74 p.@.NtClose.G.NtCreateEvent.╙.Nt 000006E0 53 65 74 45 76 65 6E 74 00 00 A6 01 52 74 6C 47 65 74 4E 74 50 72 6F 64 75 63 74 54 79 70 65 00 SetEvent..ª☺RtlGetNtProductType. 00000700 4A 01 52 74 6C 43 72 65 61 74 65 48 65 61 70 00 67 01 52 74 6C 44 65 73 74 72 6F 79 48 65 61 70 J☺RtlCreateHeap.g☺RtlDestroyHeap 00000720 00 00 49 00 4E 74 43 72 65 61 74 65 46 69 6C 65 00 00 B6 01 52 74 6C 49 6E 69 74 55 6E 69 63 6F ..I.NtCreateFile..╢☺RtlInitUnico 00000740 64 65 53 74 72 69 6E 67 00 00 FD 00 4E 74 57 61 69 74 46 6F 72 53 69 6E 67 6C 65 4F 62 6A 65 63 deString..².NtWaitForSingleObjec 00000760 74 00 B2 00 4E 74 51 75 65 72 79 53 79 73 74 65 6D 54 69 6D 65 00 F4 00 4E 74 54 65 73 74 41 6C t.▓.NtQuerySystemTime.⌠.NtTestAl 00000780 65 72 74 00 3D 00 4E 74 43 61 6E 63 65 6C 49 6F 46 69 6C 65 00 00 6E 74 64 6C 6C 2E 64 6C 6C 00 ert.=.NtCancelIoFile..ntdll.dll. 000007A0 8F 01 4C 65 61 76 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 58 00 45 6E 74 65 72 43 Å☺LeaveCriticalSection..X.EnterC 000007C0 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 1E 02 53 65 74 4C 61 73 74 45 72 72 6F 72 00 00 riticalSection..▲☻SetLastError.. 000007E0 98 00 46 72 65 65 4C 69 62 72 61 72 79 00 43 00 43 72 65 61 74 65 54 68 72 65 61 64 00 00 90 01 ÿ.FreeLibrary.C.CreateThread..É☺ 00000800 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 FC 00 47 65 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D LoadLibraryA..ⁿ.GetModuleFileNam 00000820 65 41 00 00 99 00 46 72 65 65 4C 69 62 72 61 72 79 41 6E 64 45 78 69 74 54 68 72 65 61 64 00 00 eA..Ö.FreeLibraryAndExitThread.. 00000840 F4 00 47 65 74 4C 61 73 74 45 72 72 6F 72 00 00 16 01 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 ⌠.GetLastError..▬☺GetProcAddress 00000860 00 00 93 01 4C 6F 61 64 4C 69 62 72 61 72 79 57 00 00 6F 00 45 78 70 61 6E 64 45 6E 76 69 72 6F ..ô☺LoadLibraryW..o.ExpandEnviro 00000880 6E 6D 65 6E 74 53 74 72 69 6E 67 73 57 00 33 01 47 65 74 53 79 73 74 65 6D 49 6E 66 6F 00 4C 00 nmentStringsW.3☺GetSystemInfo.L. 000008A0 44 65 6C 65 74 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 79 01 49 6E 69 74 69 61 6C 69 DeleteCriticalSection.y☺Initiali 000008C0 7A 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 3F 02 53 6C 65 65 70 00 7E 01 49 6E 74 65 zeCriticalSection.?☻Sleep.~☺Inte 000008E0 72 6C 6F 63 6B 65 64 49 6E 63 72 65 6D 65 6E 74 00 00 7B 01 49 6E 74 65 72 6C 6F 63 6B 65 64 44 rlockedIncrement..{☺InterlockedD 00000900 65 63 72 65 6D 65 6E 74 00 00 18 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 55 00 44 75 70 6C 69 63 ecrement..↑.CloseHandle.U.Duplic 00000920 61 74 65 48 61 6E 64 6C 65 00 D3 00 47 65 74 43 75 72 72 65 6E 74 50 72 6F 63 65 73 73 00 B4 01 ateHandle.╙.GetCurrentProcess.┤☺ 00000940 4F 70 65 6E 50 72 6F 63 65 73 73 00 0A 01 47 65 74 4F 76 65 72 6C 61 70 70 65 64 52 65 73 75 6C OpenProcess.◙☺GetOverlappedResul 00000960 74 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 67 01 49 73 57 69 6E 64 6F 77 00 00 55 53 45 52 t.KERNEL32.dll..g☺IsWindow..USER 00000980 33 32 2E 64 6C 6C 00 00 17 01 52 65 67 43 6C 6F 73 65 4B 65 79 00 37 01 52 65 67 51 75 65 72 79 32.dll..↨☺RegCloseKey.7☺RegQuery 000009A0 56 61 6C 75 65 45 78 57 00 00 2F 01 52 65 67 4F 70 65 6E 4B 65 79 45 78 57 00 41 44 56 41 50 49 ValueExW../☺RegOpenKeyExW.ADVAPI 000009C0 33 32 2E 64 6C 6C 00 00 02 00 57 61 68 43 72 65 61 74 65 43 6F 6E 74 65 78 74 54 61 62 6C 65 00 32.dll..☻.WahCreateContextTable. 000009E0 03 00 57 61 68 44 65 73 74 72 6F 79 43 6F 6E 74 65 78 74 54 61 62 6C 65 00 00 0A 00 57 61 68 53 ♥.WahDestroyContextTable..◙.WahS 00000A00 65 74 43 6F 6E 74 65 78 74 00 09 00 57 61 68 52 65 6D 6F 76 65 43 6F 6E 74 65 78 74 45 78 00 00 etContext.○.WahRemoveContextEx.. 00000A20 04 00 57 61 68 47 65 74 43 6F 6E 74 65 78 74 00 08 00 57 61 68 52 65 6D 6F 76 65 43 6F 6E 74 65 ♦.WahGetContext.◘.WahRemoveConte 00000A40 78 74 00 00 57 53 32 48 45 4C 50 2E 64 6C 6C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 xt..WS2HELP.dll................. 00000A60 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000A80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000AA0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000AC0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000AE0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B20 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B60 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000B80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000BA0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000BC0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000BE0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................