============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 00 61 00 00 00 00 00 00 00 00 00 00 DC 64 00 00 70 02 00 00 B0 60 00 00 00 00 00 00 00 00 00 00 .a..........▄d..p☻..░`.......... 00000020 4E 65 00 00 20 02 00 00 C4 60 00 00 00 00 00 00 00 00 00 00 8E 66 00 00 34 02 00 00 00 00 00 00 Ne.. ☻..─`..........Äf..4☻...... 00000040 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 3A 65 00 00 1E 65 00 00 0A 65 00 00 F6 64 00 00 ................:e..▲e..◙e..÷d.. 00000060 00 00 00 00 78 66 00 00 46 66 00 00 36 66 00 00 20 66 00 00 0E 66 00 00 F8 65 00 00 DE 65 00 00 ....xf..Ff..6f.. f..♫f..°e..▐e.. 00000080 CA 65 00 00 B4 65 00 00 A2 65 00 00 8A 65 00 00 70 65 00 00 56 65 00 00 62 66 00 00 00 00 00 00 ╩e..┤e..óe..èe..pe..Ve..bf...... 000000A0 58 63 00 00 64 63 00 00 48 63 00 00 34 63 00 00 7C 63 00 00 A6 63 00 00 C0 63 00 00 D0 63 00 00 Xc..dc..Hc..4c..|c..ªc..└c..╨c.. 000000C0 E6 63 00 00 90 63 00 00 FA 62 00 00 08 63 00 00 1E 63 00 00 58 64 00 00 74 64 00 00 8A 64 00 00 µc..Éc..·b..◘c..▲c..Xd..td..èd.. 000000E0 A0 64 00 00 B2 64 00 00 C4 64 00 00 EA 64 00 00 14 62 00 00 FC 61 00 00 EA 61 00 00 D8 61 00 00 ád..▓d..─d..Ωd..¶b..ⁿa..Ωa..╪a.. 00000100 C4 61 00 00 E0 62 00 00 D2 62 00 00 B6 62 00 00 9E 62 00 00 80 62 00 00 68 62 00 00 5E 62 00 00 ─a..αb..╥b..╢b..₧b..Çb..hb..^b.. 00000120 50 62 00 00 38 62 00 00 28 62 00 00 26 64 00 00 3E 64 00 00 F6 63 00 00 A4 61 00 00 0E 64 00 00 Pb..8b..(b..&d..>d..÷c..ña..♫d.. 00000140 00 00 00 00 19 02 52 74 6C 41 6E 73 69 53 74 72 69 6E 67 54 6F 55 6E 69 63 6F 64 65 53 74 72 69 ....↓☻RtlAnsiStringToUnicodeStri 00000160 6E 67 00 00 65 02 52 74 6C 49 6E 69 74 41 6E 73 69 53 74 72 69 6E 67 00 D5 00 49 6F 44 65 6C 65 ng..e☻RtlInitAnsiString.╒.IoDele 00000180 74 65 44 65 76 69 63 65 00 00 CE 00 49 6F 43 72 65 61 74 65 44 65 76 69 63 65 00 00 45 01 4B 65 teDevice..╬.IoCreateDevice..E☺Ke 000001A0 49 6E 69 74 69 61 6C 69 7A 65 53 70 69 6E 4C 6F 63 6B 00 00 3F 01 4B 65 49 6E 69 74 69 61 6C 69 InitializeSpinLock..?☺KeInitiali 000001C0 7A 65 45 76 65 6E 74 00 67 01 4B 65 52 65 73 65 74 45 76 65 6E 74 00 00 7A 01 4B 65 57 61 69 74 zeEvent.g☺KeResetEvent..z☺KeWait 000001E0 46 6F 72 53 69 6E 67 6C 65 4F 62 6A 65 63 74 00 6B 01 4B 65 53 65 74 45 76 65 6E 74 00 00 E5 02 ForSingleObject.k☺KeSetEvent..σ☻ 00000200 5A 77 43 6C 6F 73 65 00 5C 02 52 74 6C 46 72 65 65 55 6E 69 63 6F 64 65 53 74 72 69 6E 67 00 00 ZwClose.\☻RtlFreeUnicodeString.. 00000220 ED 02 5A 77 43 72 65 61 74 65 53 79 6D 62 6F 6C 69 63 4C 69 6E 6B 4F 62 6A 65 63 74 00 00 FD 02 φ☻ZwCreateSymbolicLinkObject..²☻ 00000240 5A 77 4D 61 6B 65 54 65 6D 70 6F 72 61 72 79 4F 62 6A 65 63 74 00 07 03 5A 77 4F 70 65 6E 53 79 ZwMakeTemporaryObject.•♥ZwOpenSy 00000260 6D 62 6F 6C 69 63 4C 69 6E 6B 4F 62 6A 65 63 74 00 00 36 00 45 78 46 72 65 65 50 6F 6F 6C 00 00 mbolicLinkObject..6.ExFreePool.. 00000280 8C 02 52 74 6C 51 75 65 72 79 52 65 67 69 73 74 72 79 56 61 6C 75 65 73 00 00 02 03 5A 77 4F 70 î☻RtlQueryRegistryValues..☻♥ZwOp 000002A0 65 6E 46 69 6C 65 00 00 E2 00 49 6F 47 65 74 43 75 72 72 65 6E 74 50 72 6F 63 65 73 73 00 16 01 enFile..Γ.IoGetCurrentProcess.▬☺ 000002C0 49 6F 66 43 6F 6D 70 6C 65 74 65 52 65 71 75 65 73 74 00 00 A7 01 4D 6D 4D 61 70 4C 6F 63 6B 65 IofCompleteRequest..º☺MmMapLocke 000002E0 64 50 61 67 65 73 00 00 23 01 4B 65 43 61 6E 63 65 6C 54 69 6D 65 72 00 DF 00 49 6F 46 72 65 65 dPages..#☺KeCancelTimer.▀.IoFree 00000300 4D 64 6C 00 F2 02 5A 77 44 65 76 69 63 65 49 6F 43 6F 6E 74 72 6F 6C 46 69 6C 65 00 27 02 52 74 Mdl.≥☻ZwDeviceIoControlFile.'☻Rt 00000320 6C 43 6F 6D 70 61 72 65 4D 65 6D 6F 72 79 00 00 60 01 4B 65 52 65 6C 65 61 73 65 53 65 6D 61 70 lCompareMemory..`☺KeReleaseSemap 00000340 68 6F 72 65 00 00 5D 00 45 78 66 49 6E 74 65 72 6C 6F 63 6B 65 64 41 64 64 55 6C 6F 6E 67 00 00 hore..].ExfInterlockedAddUlong.. 00000360 BD 00 49 6F 41 6C 6C 6F 63 61 74 65 4D 64 6C 00 AC 01 4D 6D 50 72 6F 62 65 41 6E 64 4C 6F 63 6B ╜.IoAllocateMdl.¼☺MmProbeAndLock 00000380 50 61 67 65 73 00 B5 01 4D 6D 55 6E 6C 6F 63 6B 50 61 67 65 73 00 FD 01 50 73 43 72 65 61 74 65 Pages.╡☺MmUnlockPages.²☺PsCreate 000003A0 53 79 73 74 65 6D 54 68 72 65 61 64 00 00 44 01 4B 65 49 6E 69 74 69 61 6C 69 7A 65 53 65 6D 61 SystemThread..D☺KeInitializeSema 000003C0 70 68 6F 72 65 00 E7 01 4E 74 57 61 69 74 46 6F 72 53 69 6E 67 6C 65 4F 62 6A 65 63 74 00 0B 02 phore.τ☺NtWaitForSingleObject.♂☻ 000003E0 50 73 54 65 72 6D 69 6E 61 74 65 53 79 73 74 65 6D 54 68 72 65 61 64 00 78 01 4B 65 57 61 69 74 PsTerminateSystemThread.x☺KeWait 00000400 46 6F 72 4D 75 6C 74 69 70 6C 65 4F 62 6A 65 63 74 73 00 00 6E 01 4B 65 53 65 74 50 72 69 6F 72 ForMultipleObjects..n☺KeSetPrior 00000420 69 74 79 54 68 72 65 61 64 00 30 01 4B 65 47 65 74 43 75 72 72 65 6E 74 54 68 72 65 61 64 00 00 ityThread.0☺KeGetCurrentThread.. 00000440 29 01 4B 65 44 65 74 61 63 68 50 72 6F 63 65 73 73 00 20 01 4B 65 41 74 74 61 63 68 50 72 6F 63 )☺KeDetachProcess. ☺KeAttachProc 00000460 65 73 73 00 5B 01 4B 65 52 65 61 64 53 74 61 74 65 53 65 6D 61 70 68 6F 72 65 00 00 6E 74 6F 73 ess.[☺KeReadStateSemaphore..ntos 00000480 6B 72 6E 6C 2E 65 78 65 00 00 AA 02 52 74 6C 55 6E 77 69 6E 64 00 49 00 4B 66 52 65 6C 65 61 73 krnl.exe..¬☻RtlUnwind.I.KfReleas 000004A0 65 53 70 69 6E 4C 6F 63 6B 00 46 00 4B 66 41 63 71 75 69 72 65 53 70 69 6E 4C 6F 63 6B 00 42 00 eSpinLock.F.KfAcquireSpinLock.B. 000004C0 4B 65 51 75 65 72 79 50 65 72 66 6F 72 6D 61 6E 63 65 43 6F 75 6E 74 65 72 00 40 00 4B 65 47 65 KeQueryPerformanceCounter.@.KeGe 000004E0 74 43 75 72 72 65 6E 74 49 72 71 6C 00 00 48 41 4C 2E 64 6C 6C 00 25 00 4E 64 69 73 41 6C 6C 6F tCurrentIrql..HAL.dll.%.NdisAllo 00000500 63 61 74 65 42 75 66 66 65 72 50 6F 6F 6C 00 00 29 00 4E 64 69 73 41 6C 6C 6F 63 61 74 65 50 61 cateBufferPool..).NdisAllocatePa 00000520 63 6B 65 74 50 6F 6F 6C 00 00 8C 00 4E 64 69 73 52 65 67 69 73 74 65 72 50 72 6F 74 6F 63 6F 6C cketPool..î.NdisRegisterProtocol 00000540 00 00 7A 00 4E 64 69 73 4F 70 65 6E 41 64 61 70 74 65 72 00 40 00 4E 64 69 73 46 72 65 65 42 75 ..z.NdisOpenAdapter.@.NdisFreeBu 00000560 66 66 65 72 50 6F 6F 6C 00 00 2C 00 4E 64 69 73 43 6C 6F 73 65 41 64 61 70 74 65 72 00 00 3A 00 fferPool..,.NdisCloseAdapter..:. 00000580 4E 64 69 73 44 65 72 65 67 69 73 74 65 72 50 72 6F 74 6F 63 6F 6C 00 00 27 00 4E 64 69 73 41 6C NdisDeregisterProtocol..'.NdisAl 000005A0 6C 6F 63 61 74 65 4D 65 6D 6F 72 79 00 00 42 00 4E 64 69 73 46 72 65 65 4D 65 6D 6F 72 79 00 00 locateMemory..B.NdisFreeMemory.. 000005C0 53 00 4E 64 69 73 49 6E 69 74 69 61 6C 69 7A 65 54 69 6D 65 72 00 90 00 4E 64 69 73 53 65 74 54 S.NdisInitializeTimer.É.NdisSetT 000005E0 69 6D 65 72 00 00 95 00 4E 64 69 73 55 6E 63 68 61 69 6E 42 75 66 66 65 72 41 74 46 72 6F 6E 74 imer..ò.NdisUnchainBufferAtFront 00000600 00 00 24 00 4E 64 69 73 41 6C 6C 6F 63 61 74 65 42 75 66 66 65 72 00 00 28 00 4E 64 69 73 41 6C ..$.NdisAllocateBuffer..(.NdisAl 00000620 6C 6F 63 61 74 65 50 61 63 6B 65 74 00 00 4E 44 49 53 2E 53 59 53 00 00 00 00 00 00 00 00 00 00 locatePacket..NDIS.SYS..........