============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 50 50 00 00 88 50 00 00 74 50 00 00 62 50 00 00 DC 4F 00 00 42 50 00 00 2E 50 00 00 1A 50 00 00 PP..êP..tP..bP..▄O..BP...P..→P.. 00000020 00 50 00 00 F0 4F 00 00 00 00 00 00 48 4E 00 00 A6 4E 00 00 98 4E 00 00 72 4E 00 00 B8 4F 00 00 .P..≡O......HN..ªN..ÿN..rN..╕O.. 00000040 AC 4F 00 00 8E 4F 00 00 7C 4F 00 00 6C 4F 00 00 60 4F 00 00 52 4F 00 00 3C 4F 00 00 2E 4F 00 00 ¼O..ÄO..|O..lO..`O..RO..<O...O.. 00000060 16 4F 00 00 00 4F 00 00 E4 4E 00 00 D8 4E 00 00 C0 4E 00 00 B4 4E 00 00 DA 4D 00 00 82 4E 00 00 ▬O...O..ΣN..╪N..└N..┤N..┌M..éN.. 00000080 6C 4D 00 00 7A 4D 00 00 8C 4D 00 00 9A 4D 00 00 A6 4D 00 00 B8 4D 00 00 C8 4D 00 00 26 4E 00 00 lM..zM..îM..ÜM..ªM..╕M..╚M..&N.. 000000A0 EA 4D 00 00 F6 4D 00 00 0C 4E 00 00 1A 4E 00 00 34 4E 00 00 54 4E 00 00 60 4E 00 00 00 00 00 00 ΩM..÷M..♀N..→N..4N..TN..`N...... 000000C0 40 4C 00 00 BA 4C 00 00 9C 4C 00 00 A6 4C 00 00 C2 4C 00 00 4A 4C 00 00 54 4C 00 00 B0 4C 00 00 @L..║L..£L..ªL..┬L..JL..TL..░L.. 000000E0 92 4C 00 00 74 4C 00 00 6A 4C 00 00 88 4C 00 00 5E 4C 00 00 7E 4C 00 00 00 00 00 00 BE 50 00 00 ÆL..tL..jL..êL..^L..~L......╛P.. 00000100 A4 50 00 00 B0 50 00 00 CA 50 00 00 D6 50 00 00 00 00 00 00 32 51 00 00 18 51 00 00 5A 51 00 00 ñP..░P..╩P..╓P......2Q..↑Q..ZQ.. 00000120 44 51 00 00 02 51 00 00 F0 50 00 00 00 00 00 00 FE 4C 00 00 4C 4D 00 00 E2 4C 00 00 1A 4D 00 00 DQ..☻Q..≡P......■L..LM..ΓL..→M.. 00000140 32 4D 00 00 D8 4C 00 00 00 00 00 00 00 00 00 00 00 00 00 00 A8 8E 5D 32 00 00 00 00 04 00 00 00 2M..╪L..............¿Ä]2....♦... 00000160 10 01 00 00 00 00 00 00 00 64 00 00 00 00 00 00 A8 8E 5D 32 00 00 00 00 04 00 00 00 10 01 00 00 ►☺.......d......¿Ä]2....♦...►☺.. 00000180 00 00 00 00 68 BB 00 00 00 00 00 00 A8 8E 5D 32 00 00 00 00 03 00 00 00 D0 02 00 00 00 00 00 00 ....h╗......¿Ä]2....♥...╨☻...... 000001A0 78 BC 00 00 00 00 00 00 A8 8E 5D 32 00 00 00 00 06 00 00 00 00 00 00 00 00 00 00 00 48 BF 00 00 x╝......¿Ä]2....♠...........H┐.. 000001C0 00 00 00 00 A8 8E 5D 32 00 00 00 00 02 00 00 00 B8 5F 00 00 00 00 00 00 C0 F5 B6 FF 5C 00 41 00 ....¿Ä]2....☻...╕_......└⌡╢ \.A. 000001E0 72 00 63 00 4E 00 61 00 6D 00 65 00 5C 00 00 00 5C 00 5C 00 2E 00 5C 00 3F 00 3A 00 00 00 00 00 r.c.N.a.m.e.\...\.\...\.?.:..... 00000200 25 00 77 00 63 00 3A 00 5C 00 25 00 73 00 00 00 4E 00 54 00 44 00 45 00 54 00 45 00 43 00 54 00 %.w.c.:.\.%.s...N.T.D.E.T.E.C.T. 00000220 2E 00 43 00 4F 00 4D 00 00 00 00 00 4E 00 54 00 4C 00 44 00 52 00 00 00 42 00 4F 00 4F 00 54 00 ..C.O.M.....N.T.L.D.R...B.O.O.T. 00000240 2E 00 49 00 4E 00 49 00 00 00 00 00 3F 00 3A 00 5C 00 00 00 5C 00 5C 00 2E 00 5C 00 3F 00 3A 00 ..I.N.I.....?.:.\...\.\...\.?.:. 00000260 00 00 00 00 5C 00 5C 00 2E 00 5C 00 50 00 68 00 79 00 73 00 69 00 63 00 61 00 6C 00 44 00 72 00 ....\.\...\.P.h.y.s.i.c.a.l.D.r. 00000280 69 00 76 00 65 00 25 00 75 00 00 00 5C 00 64 00 65 00 76 00 69 00 63 00 65 00 5C 00 68 00 61 00 i.v.e.%.u...\.d.e.v.i.c.e.\.h.a. 000002A0 72 00 64 00 64 00 69 00 73 00 6B 00 00 00 00 00 5C 00 70 00 61 00 72 00 74 00 69 00 74 00 69 00 r.d.d.i.s.k.....\.p.a.r.t.i.t.i. 000002C0 6F 00 6E 00 00 00 00 00 6D 00 75 00 6C 00 74 00 69 00 28 00 30 00 29 00 64 00 69 00 73 00 6B 00 o.n.....m.u.l.t.i.(.0.).d.i.s.k. 000002E0 28 00 30 00 29 00 72 00 64 00 69 00 73 00 6B 00 28 00 30 00 29 00 00 00 5C 53 79 73 74 65 6D 33 (.0.).r.d.i.s.k.(.0.)...\System3 00000300 32 5C 6E 77 73 65 76 65 6E 74 2E 64 6C 6C 00 00 5C 53 79 73 74 65 6D 33 32 5C 6E 77 73 6C 69 62 2\nwsevent.dll..\System32\nwslib 00000320 2E 64 6C 6C 00 00 00 00 5C 53 79 73 74 65 6D 33 32 5C 66 70 6E 77 6D 67 72 2E 63 70 6C 00 00 00 .dll....\System32\fpnwmgr.cpl... 00000340 5C 53 79 73 74 65 6D 33 32 5C 66 70 6E 77 63 6C 6E 74 2E 64 6C 6C 00 00 5C 53 79 73 74 65 6D 33 \System32\fpnwclnt.dll..\System3 00000360 32 5C 75 6D 65 78 74 2E 68 6C 70 00 5C 53 79 73 74 65 6D 33 32 5C 66 70 6E 77 2E 68 6C 70 00 00 2\umext.hlp.\System32\fpnw.hlp.. 00000380 5C 53 79 73 74 65 6D 33 32 5C 66 70 6E 77 70 65 72 66 2E 68 00 00 00 00 5C 53 79 73 74 65 6D 33 \System32\fpnwperf.h....\System3 000003A0 32 5C 66 70 6E 77 70 65 72 66 2E 69 6E 69 00 00 5C 53 79 73 74 65 6D 33 32 5C 6E 77 73 73 76 63 2\fpnwperf.ini..\System32\nwssvc 000003C0 2E 65 78 65 00 00 00 00 5C 53 79 73 74 65 6D 33 32 5C 6E 77 6D 6F 6E 2E 64 6C 6C 00 5C 53 79 73 .exe....\System32\nwmon.dll.\Sys 000003E0 74 65 6D 33 32 5C 66 70 6E 77 2E 64 6C 6C 00 00 5C 53 79 73 74 65 6D 33 32 5C 66 70 6E 77 63 66 tem32\fpnw.dll..\System32\fpnwcf 00000400 67 2E 64 6C 6C 00 00 00 5C 53 79 73 74 65 6D 33 32 5C 4C 4F 47 56 49 45 57 2E 48 4C 50 00 00 00 g.dll...\System32\LOGVIEW.HLP... 00000420 5C 53 79 73 74 65 6D 33 32 5C 4E 57 43 4F 4E 56 2E 48 4C 50 00 00 00 00 5C 53 79 73 74 65 6D 33 \System32\NWCONV.HLP....\System3 00000440 32 5C 4C 4F 47 56 49 45 57 2E 45 58 45 00 00 00 5C 53 79 73 74 65 6D 33 32 5C 4E 45 54 2E 48 4C 2\LOGVIEW.EXE...\System32\NET.HL 00000460 50 00 00 00 5C 53 79 73 74 65 6D 33 32 5C 4E 45 54 31 2E 45 58 45 00 00 5C 53 79 73 74 65 6D 33 P...\System32\NET1.EXE..\System3 00000480 32 5C 4E 57 43 4F 4E 56 2E 45 58 45 00 00 00 00 5C 53 79 73 74 65 6D 33 32 5C 55 53 52 4D 47 52 2\NWCONV.EXE....\System32\USRMGR 000004A0 2E 45 58 45 00 00 00 00 5C 53 79 73 74 65 6D 33 32 5C 6E 65 74 6D 73 67 2E 64 6C 6C 00 00 00 00 .EXE....\System32\netmsg.dll.... 000004C0 5C 53 79 73 74 65 6D 33 32 5C 73 70 6F 6F 6C 5C 70 72 74 70 72 6F 63 73 5C 77 33 32 70 70 63 5C \System32\spool\prtprocs\w32ppc\ 000004E0 6E 77 70 72 69 6E 74 2E 64 6C 6C 00 5C 53 79 73 74 65 6D 33 32 5C 73 70 6F 6F 6C 5C 70 72 74 70 nwprint.dll.\System32\spool\prtp 00000500 72 6F 63 73 5C 77 33 32 61 6C 70 68 61 5C 6E 77 70 72 69 6E 74 2E 64 6C 6C 00 00 00 5C 53 79 73 rocs\w32alpha\nwprint.dll...\Sys 00000520 74 65 6D 33 32 5C 73 70 6F 6F 6C 5C 70 72 74 70 72 6F 63 73 5C 77 33 32 6D 69 70 73 5C 6E 77 70 tem32\spool\prtprocs\w32mips\nwp 00000540 72 69 6E 74 2E 64 6C 6C 00 00 00 00 5C 53 79 73 74 65 6D 33 32 5C 73 70 6F 6F 6C 5C 70 72 74 70 rint.dll....\System32\spool\prtp 00000560 72 6F 63 73 5C 77 33 32 78 38 36 5C 6E 77 70 72 69 6E 74 2E 64 6C 6C 00 5C 53 79 73 74 65 6D 33 rocs\w32x86\nwprint.dll.\System3 00000580 32 5C 64 72 69 76 65 72 73 5C 66 70 6E 77 73 72 76 2E 53 59 53 00 00 00 5C 53 79 73 74 65 6D 33 2\drivers\fpnwsrv.SYS...\System3 000005A0 32 5C 64 72 69 76 65 72 73 5C 4E 57 4C 4E 4B 49 50 58 2E 53 59 53 00 00 5C 70 75 62 6C 69 63 5C 2\drivers\NWLNKIPX.SYS..\public\ 000005C0 72 70 63 31 36 63 31 2E 72 70 63 00 5C 70 75 62 6C 69 63 5C 73 65 63 75 72 69 74 79 2E 72 70 63 rpc16c1.rpc.\public\security.rpc 000005E0 00 00 00 00 5C 70 75 62 6C 69 63 5C 72 70 63 31 36 63 36 2E 72 70 63 00 5C 70 75 62 6C 69 63 5C ....\public\rpc16c6.rpc.\public\ 00000600 73 65 74 70 61 73 73 2E 65 78 65 00 5C 70 75 62 6C 69 63 5C 63 68 67 70 61 73 73 2E 65 78 65 00 setpass.exe.\public\chgpass.exe. 00000620 5C 70 75 62 6C 69 63 5C 65 6E 64 63 61 70 2E 65 78 65 00 00 5C 70 75 62 6C 69 63 5C 63 61 70 74 \public\endcap.exe..\public\capt 00000640 75 72 65 2E 65 78 65 00 5C 70 75 62 6C 69 63 5C 61 74 74 61 63 68 2E 65 78 65 00 00 5C 70 75 62 ure.exe.\public\attach.exe..\pub 00000660 6C 69 63 5C 6C 6F 67 6F 75 74 2E 65 78 65 00 00 5C 70 75 62 6C 69 63 5C 6D 61 70 2E 65 78 65 00 lic\logout.exe..\public\map.exe. 00000680 5C 70 75 62 6C 69 63 5C 6C 6F 67 69 6E 2E 65 78 65 00 00 00 5C 70 75 62 6C 69 63 5C 73 6C 69 73 \public\login.exe...\public\slis 000006A0 74 2E 65 78 65 00 00 00 5C 4C 6F 67 69 6E 5C 72 70 63 31 36 63 31 2E 72 70 63 00 00 5C 4C 6F 67 t.exe...\Login\rpc16c1.rpc..\Log 000006C0 69 6E 5C 73 65 63 75 72 69 74 79 2E 72 70 63 00 5C 4C 6F 67 69 6E 5C 72 70 63 31 36 63 36 2E 72 in\security.rpc.\Login\rpc16c6.r 000006E0 70 63 00 00 5C 4C 6F 67 69 6E 5C 6C 6F 67 69 6E 2E 65 78 65 00 00 00 00 5C 4C 6F 67 69 6E 5C 73 pc..\Login\login.exe....\Login\s 00000700 6C 69 73 74 2E 65 78 65 00 00 00 00 4E 4F 00 00 59 45 53 00 25 64 00 00 74 65 6D 70 00 00 00 00 list.exe....NO..YES.%d..temp.... 00000720 4F 53 20 4C 6F 61 64 65 72 20 56 00 46 41 49 4C 55 52 45 00 53 55 43 43 45 53 53 00 4E 54 46 53 OS Loader V.FAILURE.SUCCESS.NTFS 00000740 00 00 00 00 3F 3A 5C 00 4E 54 4F 53 4B 52 4E 4C 4E 4F 54 46 4F 55 4E 44 00 00 00 00 6E 74 6F 73 ....?:\.NTOSKRNLNOTFOUND....ntos 00000760 6B 72 6E 6C 2E 65 78 65 00 00 00 00 68 61 6C 66 69 72 65 2E 64 6C 6C 2C 00 00 00 00 50 6F 77 65 krnl.exe....halfire.dll,....Powe 00000780 72 69 7A 65 64 20 4D 61 6E 75 66 61 63 74 75 72 69 6E 67 20 44 69 73 6B 65 74 74 65 00 00 00 00 rized Manufacturing Diskette.... 000007A0 68 61 6C 2E 64 6C 6C 00 00 00 00 00 53 45 54 55 50 4C 4F 47 4E 4F 54 50 52 45 53 45 4E 54 00 00 hal.dll.....SETUPLOGNOTPRESENT.. 000007C0 5C 72 65 70 61 69 72 5C 73 65 74 75 70 2E 6C 6F 67 00 00 00 25 78 00 00 5C 00 56 00 61 00 72 00 \repair\setup.log...%x..\.V.a.r. 000007E0 46 00 69 00 6C 00 65 00 49 00 6E 00 66 00 6F 00 5C 00 54 00 72 00 61 00 6E 00 73 00 6C 00 61 00 F.i.l.e.I.n.f.o.\.T.r.a.n.s.l.a. 00000800 74 00 69 00 6F 00 6E 00 00 00 00 00 5C 00 00 00 4E 00 54 00 44 00 4C 00 4C 00 2E 00 44 00 4C 00 t.i.o.n.....\...N.T.D.L.L...D.L. 00000820 4C 00 00 00 50 61 74 68 3D 00 00 00 53 79 73 00 53 79 73 74 65 6D 5C 43 75 72 72 65 6E 74 43 6F L...Path=...Sys.System\CurrentCo 00000840 6E 74 72 6F 6C 53 65 74 5C 53 65 72 76 69 63 65 73 5C 46 50 4E 57 5C 56 6F 6C 75 6D 65 73 00 00 ntrolSet\Services\FPNW\Volumes.. 00000860 3B 00 00 00 50 61 74 68 00 00 00 00 53 4F 46 54 57 41 52 45 5C 4D 69 63 72 6F 73 6F 66 74 5C 57 ;...Path....SOFTWARE\Microsoft\W 00000880 69 6E 64 6F 77 73 5C 43 75 72 72 65 6E 74 56 65 72 73 69 6F 6E 5C 41 70 70 20 50 61 74 68 73 5C indows\CurrentVersion\App Paths\ 000008A0 49 45 58 50 4C 4F 52 45 2E 45 58 45 00 00 00 00 31 32 38 00 73 73 6C 31 32 38 2E 64 6C 6C 00 00 IEXPLORE.EXE....128.ssl128.dll.. 000008C0 5C 53 74 72 69 6E 67 46 69 6C 65 49 6E 66 6F 5C 30 34 30 39 30 34 42 30 5C 4F 72 69 67 69 6E 61 \StringFileInfo\040904B0\Origina 000008E0 6C 46 69 6C 65 6E 61 6D 65 00 00 00 34 30 00 00 5C 53 74 72 69 6E 67 46 69 6C 65 49 6E 66 6F 5C lFilename...40..\StringFileInfo\ 00000900 25 30 34 78 25 30 34 78 5C 46 69 6C 65 44 65 73 63 72 69 70 74 69 6F 6E 00 00 00 00 5C 56 61 72 %04x%04x\FileDescription....\Var 00000920 46 69 6C 65 49 6E 66 6F 5C 54 72 61 6E 73 6C 61 74 69 6F 6E 00 00 00 00 44 6F 6D 65 73 74 69 63 FileInfo\Translation....Domestic 00000940 20 55 73 65 20 4F 6E 6C 79 00 00 00 55 53 2F 43 61 6E 61 64 61 20 4F 6E 6C 79 2C 20 4E 6F 74 20 Use Only...US/Canada Only, Not 00000960 66 6F 72 20 45 78 70 6F 72 74 00 00 46 69 6C 65 73 2E 57 69 6E 4E 74 00 5C 72 65 70 61 69 72 5C for Export..Files.WinNt.\repair\ 00000980 73 65 74 75 70 2E 63 73 64 00 00 00 30 00 00 00 22 00 00 00 5C 73 79 73 74 65 6D 33 32 5C 73 61 setup.csd...0..."...\system32\sa 000009A0 6D 73 72 76 2E 64 6C 6C 00 00 00 00 45 69 73 61 00 00 00 00 49 73 61 00 53 79 73 74 65 6D 5C 43 msrv.dll....Eisa....Isa.System\C 000009C0 75 72 72 65 6E 74 43 6F 6E 74 72 6F 6C 53 65 74 5C 43 6F 6E 74 72 6F 6C 5C 53 79 73 74 65 6D 52 urrentControlSet\Control\SystemR 000009E0 65 73 6F 75 72 63 65 73 5C 52 65 73 65 72 76 65 64 52 65 73 6F 75 72 63 65 73 00 00 4C 00 69 00 esources\ReservedResources..L.i. 00000A00 63 00 65 00 6E 00 73 00 65 00 64 00 50 00 72 00 6F 00 63 00 65 00 73 00 73 00 6F 00 72 00 73 00 c.e.n.s.e.d.P.r.o.c.e.s.s.o.r.s. 00000A20 00 00 00 00 43 4F 52 52 55 50 54 00 53 59 53 54 45 4D 5C 43 75 72 72 65 6E 74 43 6F 6E 74 72 6F ....CORRUPT.SYSTEM\CurrentContro 00000A40 6C 53 65 74 5C 43 6F 6E 74 72 6F 6C 5C 53 65 73 73 69 6F 6E 20 4D 61 6E 61 67 65 72 00 00 00 00 lSet\Control\Session Manager.... 00000A60 4F 4B 00 00 43 3A 00 B4 4B 00 00 00 00 00 00 00 00 00 00 CC 4C 00 00 C0 40 00 00 24 4C 00 00 00 OK..C:.┤K..........╠L..└@..$L... 00000A80 00 00 00 00 00 00 00 62 4D 00 00 30 41 00 00 20 4B 00 00 00 00 00 00 00 00 00 00 CE 4F 00 00 2C .......bM..0A.. K..........╬O.., 00000AA0 40 00 00 F4 4A 00 00 00 00 00 00 00 00 00 00 96 50 00 00 00 40 00 00 F0 4B 00 00 00 00 00 00 00 @..⌠J..........ûP...@..≡K....... 00000AC0 00 00 00 E4 50 00 00 FC 40 00 00 08 4C 00 00 00 00 00 00 00 00 00 00 74 51 00 00 14 41 00 00 00 ...ΣP..ⁿ@..◘L..........tQ..¶A... 00000AE0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 50 50 00 00 88 50 00 00 74 50 00 00 ....................PP..êP..tP.. 00000B00 62 50 00 00 DC 4F 00 00 42 50 00 00 2E 50 00 00 1A 50 00 00 00 50 00 00 F0 4F 00 00 00 00 00 00 bP..▄O..BP...P..→P...P..≡O...... 00000B20 48 4E 00 00 A6 4E 00 00 98 4E 00 00 72 4E 00 00 B8 4F 00 00 AC 4F 00 00 8E 4F 00 00 7C 4F 00 00 HN..ªN..ÿN..rN..╕O..¼O..ÄO..|O.. 00000B40 6C 4F 00 00 60 4F 00 00 52 4F 00 00 3C 4F 00 00 2E 4F 00 00 16 4F 00 00 00 4F 00 00 E4 4E 00 00 lO..`O..RO..<O...O..▬O...O..ΣN.. 00000B60 D8 4E 00 00 C0 4E 00 00 B4 4E 00 00 DA 4D 00 00 82 4E 00 00 6C 4D 00 00 7A 4D 00 00 8C 4D 00 00 ╪N..└N..┤N..┌M..éN..lM..zM..îM.. 00000B80 9A 4D 00 00 A6 4D 00 00 B8 4D 00 00 C8 4D 00 00 26 4E 00 00 EA 4D 00 00 F6 4D 00 00 0C 4E 00 00 ÜM..ªM..╕M..╚M..&N..ΩM..÷M..♀N.. 00000BA0 1A 4E 00 00 34 4E 00 00 54 4E 00 00 60 4E 00 00 00 00 00 00 40 4C 00 00 BA 4C 00 00 9C 4C 00 00 →N..4N..TN..`N......@L..║L..£L.. 00000BC0 A6 4C 00 00 C2 4C 00 00 4A 4C 00 00 54 4C 00 00 B0 4C 00 00 92 4C 00 00 74 4C 00 00 6A 4C 00 00 ªL..┬L..JL..TL..░L..ÆL..tL..jL.. 00000BE0 88 4C 00 00 5E 4C 00 00 7E 4C 00 00 00 00 00 00 BE 50 00 00 A4 50 00 00 B0 50 00 00 CA 50 00 00 êL..^L..~L......╛P..ñP..░P..╩P.. 00000C00 D6 50 00 00 00 00 00 00 32 51 00 00 18 51 00 00 5A 51 00 00 44 51 00 00 02 51 00 00 F0 50 00 00 ╓P......2Q..↑Q..ZQ..DQ..☻Q..≡P.. 00000C20 00 00 00 00 FE 4C 00 00 4C 4D 00 00 E2 4C 00 00 1A 4D 00 00 32 4D 00 00 D8 4C 00 00 00 00 00 00 ....■L..LM..ΓL..→M..2M..╪L...... 00000C40 DA 02 77 63 73 63 61 74 00 00 DE 02 77 63 73 63 70 79 00 00 E1 02 77 63 73 6C 65 6E 00 00 E9 01 ┌☻wcscat..▐☻wcscpy..ß☻wcslen..Θ☺ 00000C60 5F 77 63 73 6E 69 63 6D 70 00 ED 02 77 63 73 74 6F 75 6C 00 E3 02 77 63 73 6E 63 6D 70 00 E8 02 _wcsnicmp.φ☻wcstoul.π☻wcsncmp.Φ☻ 00000C80 77 63 73 73 74 72 00 00 BE 02 73 74 72 72 63 68 72 00 B2 02 73 74 72 63 68 72 00 00 BB 02 73 74 wcsstr..╛☻strrchr.▓☻strchr..╗☻st 00000CA0 72 6E 63 6D 70 00 C0 02 73 74 72 73 74 72 00 00 AD 02 73 70 72 69 6E 74 66 00 59 02 66 72 65 65 rncmp.└☻strstr..¡☻sprintf.Y☻free 00000CC0 00 00 8C 02 6D 61 6C 6C 6F 63 00 00 4D 53 56 43 52 54 2E 64 6C 6C 00 00 40 00 4E 74 43 6C 6F 73 ..î☻malloc..MSVCRT.dll..@.NtClos 00000CE0 65 00 AF 00 4E 74 51 75 65 72 79 53 79 6D 62 6F 6C 69 63 4C 69 6E 6B 4F 62 6A 65 63 74 00 8D 00 e.».NtQuerySymbolicLinkObject.ì. 00000D00 4E 74 4F 70 65 6E 53 79 6D 62 6F 6C 69 63 4C 69 6E 6B 4F 62 6A 65 63 74 00 00 B6 01 52 74 6C 49 NtOpenSymbolicLinkObject..╢☺RtlI 00000D20 6E 69 74 55 6E 69 63 6F 64 65 53 74 72 69 6E 67 00 00 36 00 4E 74 41 64 6A 75 73 74 50 72 69 76 nitUnicodeString..6.NtAdjustPriv 00000D40 69 6C 65 67 65 73 54 6F 6B 65 6E 00 8A 00 4E 74 4F 70 65 6E 50 72 6F 63 65 73 73 54 6F 6B 65 6E ilegesToken.è.NtOpenProcessToken 00000D60 00 00 6E 74 64 6C 6C 2E 64 6C 6C 00 18 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 50 00 44 65 76 69 ..ntdll.dll.↑.CloseHandle.P.Devi 00000D80 63 65 49 6F 43 6F 6E 74 72 6F 6C 00 34 00 43 72 65 61 74 65 46 69 6C 65 57 00 7E 00 46 69 6E 64 ceIoControl.4.CreateFileW.~.Find 00000DA0 43 6C 6F 73 65 00 85 00 46 69 6E 64 46 69 72 73 74 46 69 6C 65 57 00 00 E0 00 47 65 74 44 72 69 Close.à.FindFirstFileW..α.GetDri 00000DC0 76 65 54 79 70 65 57 00 C4 01 51 75 65 72 79 44 6F 73 44 65 76 69 63 65 57 00 F4 00 47 65 74 4C veTypeW.─☺QueryDosDeviceW.⌠.GetL 00000DE0 61 73 74 45 72 72 6F 72 00 00 A2 02 6C 73 74 72 6C 65 6E 57 00 00 17 02 53 65 74 46 69 6C 65 41 astError..ó☻lstrlenW..↨☻SetFileA 00000E00 74 74 72 69 62 75 74 65 73 41 00 00 4C 01 47 65 74 56 65 72 73 69 6F 6E 00 00 A6 01 4D 6F 76 65 ttributesA..L☺GetVersion..ª☺Move 00000E20 46 69 6C 65 41 00 4E 00 44 65 6C 65 74 65 46 69 6C 65 41 00 3B 01 47 65 74 54 65 6D 70 46 69 6C FileA.N.DeleteFileA.;☺GetTempFil 00000E40 65 4E 61 6D 65 41 00 00 9B 02 6C 73 74 72 63 70 79 41 00 00 AF 01 4F 70 65 6E 46 69 6C 65 00 00 eNameA..¢☻lstrcpyA..»☺OpenFile.. 00000E60 53 02 55 6E 6D 61 70 56 69 65 77 4F 66 46 69 6C 65 00 A4 01 4D 61 70 56 69 65 77 4F 66 46 69 6C S☻UnmapViewOfFile.ñ☺MapViewOfFil 00000E80 65 00 32 00 43 72 65 61 74 65 46 69 6C 65 4D 61 70 70 69 6E 67 41 00 00 ED 00 47 65 74 46 69 6C e.2.CreateFileMappingA..φ.GetFil 00000EA0 65 53 69 7A 65 00 A7 01 4D 6F 76 65 46 69 6C 65 45 78 41 00 98 02 6C 73 74 72 63 6D 70 69 41 00 eSize.º☺MoveFileExA.ÿ☻lstrcmpiA. 00000EC0 4F 01 47 65 74 56 6F 6C 75 6D 65 49 6E 66 6F 72 6D 61 74 69 6F 6E 41 00 A1 02 6C 73 74 72 6C 65 O☺GetVolumeInformationA.í☻lstrle 00000EE0 6E 41 00 00 12 01 47 65 74 50 72 69 76 61 74 65 50 72 6F 66 69 6C 65 53 74 72 69 6E 67 41 00 00 nA..↕☺GetPrivateProfileStringA.. 00000F00 E8 00 47 65 74 46 69 6C 65 41 74 74 72 69 62 75 74 65 73 41 00 00 51 01 47 65 74 57 69 6E 64 6F Φ.GetFileAttributesA..Q☺GetWindo 00000F20 77 73 44 69 72 65 63 74 6F 72 79 41 00 00 31 00 43 72 65 61 74 65 46 69 6C 65 41 00 32 01 47 65 wsDirectoryA..1.CreateFileA.2☺Ge 00000F40 74 53 79 73 74 65 6D 44 69 72 65 63 74 6F 72 79 57 00 96 01 4C 6F 63 61 6C 41 6C 6C 6F 63 00 00 tSystemDirectoryW.û☺LocalAlloc.. 00000F60 9A 01 4C 6F 63 61 6C 46 72 65 65 00 9D 01 4C 6F 63 61 6C 52 65 41 6C 6C 6F 63 00 00 82 00 46 69 Ü☺LocalFree.¥☺LocalReAlloc..é.Fi 00000F80 6E 64 46 69 72 73 74 46 69 6C 65 41 00 00 7F 02 57 72 69 74 65 50 72 69 76 61 74 65 50 72 6F 66 ndFirstFileA..⌂☻WritePrivateProf 00000FA0 69 6C 65 53 74 72 69 6E 67 41 00 00 25 00 43 6F 70 79 46 69 6C 65 41 00 6E 02 57 69 64 65 43 68 ileStringA..%.CopyFileA.n☻WideCh 00000FC0 61 72 54 6F 4D 75 6C 74 69 42 79 74 65 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 36 01 52 65 arToMultiByte.KERNEL32.dll..6☺Re 00000FE0 67 51 75 65 72 79 56 61 6C 75 65 45 78 41 00 00 2E 01 52 65 67 4F 70 65 6E 4B 65 79 45 78 41 00 gQueryValueExA...☺RegOpenKeyExA. 00001000 AC 00 49 6E 69 74 69 61 74 65 53 79 73 74 65 6D 53 68 75 74 64 6F 77 6E 41 00 56 01 53 65 74 46 ¼.InitiateSystemShutdownA.V☺SetF 00001020 69 6C 65 53 65 63 75 72 69 74 79 41 00 00 7E 00 47 65 74 46 69 6C 65 53 65 63 75 72 69 74 79 41 ileSecurityA..~.GetFileSecurityA 00001040 00 00 17 01 52 65 67 43 6C 6F 73 65 4B 65 79 00 20 01 52 65 67 44 65 6C 65 74 65 56 61 6C 75 65 ..↨☺RegCloseKey. ☺RegDeleteValue 00001060 41 00 41 01 52 65 67 53 65 74 56 61 6C 75 65 45 78 41 00 00 37 01 52 65 67 51 75 65 72 79 56 61 A.A☺RegSetValueExA..7☺RegQueryVa 00001080 6C 75 65 45 78 57 00 00 2D 01 52 65 67 4F 70 65 6E 4B 65 79 41 00 41 44 56 41 50 49 33 32 2E 64 lueExW..-☺RegOpenKeyA.ADVAPI32.d 000010A0 6C 6C 00 00 65 02 77 73 70 72 69 6E 74 66 57 00 20 00 43 68 61 72 4C 6F 77 65 72 57 00 00 64 02 ll..e☻wsprintfW. .CharLowerW..d☻ 000010C0 77 73 70 72 69 6E 74 66 41 00 21 00 43 68 61 72 4E 65 78 74 41 00 83 01 4C 6F 61 64 53 74 72 69 wsprintfA.!.CharNextA.â☺LoadStri 000010E0 6E 67 41 00 55 53 45 52 33 32 2E 64 6C 6C 00 00 0D 00 56 65 72 51 75 65 72 79 56 61 6C 75 65 57 ngA.USER32.dll..♪.VerQueryValueW 00001100 00 00 03 00 47 65 74 46 69 6C 65 56 65 72 73 69 6F 6E 49 6E 66 6F 57 00 02 00 47 65 74 46 69 6C ..♥.GetFileVersionInfoW.☻.GetFil 00001120 65 56 65 72 73 69 6F 6E 49 6E 66 6F 53 69 7A 65 57 00 0A 00 56 65 72 51 75 65 72 79 56 61 6C 75 eVersionInfoSizeW.◙.VerQueryValu 00001140 65 41 00 00 00 00 47 65 74 46 69 6C 65 56 65 72 73 69 6F 6E 49 6E 66 6F 41 00 01 00 47 65 74 46 eA....GetFileVersionInfoA.☺.GetF 00001160 69 6C 65 56 65 72 73 69 6F 6E 49 6E 66 6F 53 69 7A 65 41 00 56 45 52 53 49 4F 4E 2E 64 6C 6C 00 ileVersionInfoSizeA.VERSION.dll. 00001180 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000011A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000011C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000011E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................