============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 90 10 01 00 00 00 00 00 00 00 00 00 88 16 01 00 C0 11 01 00 64 10 01 00 00 00 00 00 00 00 00 00 É►☺.........ê▬☺.└◄☺.d►☺......... 00000020 3C 17 01 00 94 11 01 00 7C 11 01 00 00 00 00 00 00 00 00 00 90 17 01 00 AC 12 01 00 00 00 00 00 <↨☺.ö◄☺.|◄☺.........É↨☺.¼↕☺..... 00000040 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000060 00 00 00 00 2A 17 01 00 18 17 01 00 06 17 01 00 F6 16 01 00 E6 16 01 00 D6 16 01 00 C6 16 01 00 ....*↨☺.↑↨☺.♠↨☺.÷▬☺.µ▬☺.╓▬☺.╞▬☺. 00000080 B8 16 01 00 A4 16 01 00 96 16 01 00 00 00 00 00 8C 13 01 00 A2 13 01 00 B4 13 01 00 C0 13 01 00 ╕▬☺.ñ▬☺.û▬☺.....î‼☺.ó‼☺.┤‼☺.└‼☺. 000000A0 7E 13 01 00 CA 13 01 00 D8 13 01 00 F4 13 01 00 0C 14 01 00 18 14 01 00 28 14 01 00 40 14 01 00 ~‼☺.╩‼☺.╪‼☺.⌠‼☺.♀¶☺.↑¶☺.(¶☺.@¶☺. 000000C0 4C 14 01 00 56 14 01 00 60 14 01 00 6A 14 01 00 76 14 01 00 82 14 01 00 92 14 01 00 AE 14 01 00 L¶☺.V¶☺.`¶☺.j¶☺.v¶☺.é¶☺.ƶ☺.«¶☺. 000000E0 BA 14 01 00 CA 14 01 00 DA 14 01 00 58 13 01 00 6E 13 01 00 16 15 01 00 22 15 01 00 C4 12 01 00 ║¶☺.╩¶☺.┌¶☺.X‼☺.n‼☺.▬§☺."§☺.─↕☺. 00000100 40 15 01 00 54 15 01 00 60 15 01 00 70 15 01 00 84 15 01 00 98 15 01 00 AE 15 01 00 B8 15 01 00 @§☺.T§☺.`§☺.p§☺.ä§☺.ÿ§☺.«§☺.╕§☺. 00000120 C6 15 01 00 D8 15 01 00 E8 15 01 00 F4 15 01 00 02 16 01 00 0A 16 01 00 20 16 01 00 2C 16 01 00 ╞§☺.╪§☺.Φ§☺.⌠§☺.☻▬☺.◙▬☺. ▬☺.,▬☺. 00000140 42 16 01 00 5A 16 01 00 72 16 01 00 40 13 01 00 28 13 01 00 1C 13 01 00 0E 13 01 00 00 13 01 00 B▬☺.Z▬☺.r▬☺.@‼☺.(‼☺.∟‼☺.♫‼☺..‼☺. 00000160 F0 12 01 00 E0 12 01 00 D2 12 01 00 06 15 01 00 EC 14 01 00 2E 15 01 00 00 00 00 00 58 17 01 00 ≡↕☺.α↕☺.╥↕☺.♠§☺.∞¶☺..§☺.....X↨☺. 00000180 64 17 01 00 72 17 01 00 80 17 01 00 4A 17 01 00 00 00 00 00 2A 17 01 00 18 17 01 00 06 17 01 00 d↨☺.r↨☺.Ç↨☺.J↨☺.....*↨☺.↑↨☺.♠↨☺. 000001A0 F6 16 01 00 E6 16 01 00 D6 16 01 00 C6 16 01 00 B8 16 01 00 A4 16 01 00 96 16 01 00 00 00 00 00 ÷▬☺.µ▬☺.╓▬☺.╞▬☺.╕▬☺.ñ▬☺.û▬☺..... 000001C0 8C 13 01 00 A2 13 01 00 B4 13 01 00 C0 13 01 00 7E 13 01 00 CA 13 01 00 D8 13 01 00 F4 13 01 00 î‼☺.ó‼☺.┤‼☺.└‼☺.~‼☺.╩‼☺.╪‼☺.⌠‼☺. 000001E0 0C 14 01 00 18 14 01 00 28 14 01 00 40 14 01 00 4C 14 01 00 56 14 01 00 60 14 01 00 6A 14 01 00 ♀¶☺.↑¶☺.(¶☺.@¶☺.L¶☺.V¶☺.`¶☺.j¶☺. 00000200 76 14 01 00 82 14 01 00 92 14 01 00 AE 14 01 00 BA 14 01 00 CA 14 01 00 DA 14 01 00 58 13 01 00 v¶☺.é¶☺.ƶ☺.«¶☺.║¶☺.╩¶☺.┌¶☺.X‼☺. 00000220 6E 13 01 00 16 15 01 00 22 15 01 00 C4 12 01 00 40 15 01 00 54 15 01 00 60 15 01 00 70 15 01 00 n‼☺.▬§☺."§☺.─↕☺.@§☺.T§☺.`§☺.p§☺. 00000240 84 15 01 00 98 15 01 00 AE 15 01 00 B8 15 01 00 C6 15 01 00 D8 15 01 00 E8 15 01 00 F4 15 01 00 ä§☺.ÿ§☺.«§☺.╕§☺.╞§☺.╪§☺.Φ§☺.⌠§☺. 00000260 02 16 01 00 0A 16 01 00 20 16 01 00 2C 16 01 00 42 16 01 00 5A 16 01 00 72 16 01 00 40 13 01 00 ☻▬☺.◙▬☺. ▬☺.,▬☺.B▬☺.Z▬☺.r▬☺.@‼☺. 00000280 28 13 01 00 1C 13 01 00 0E 13 01 00 00 13 01 00 F0 12 01 00 E0 12 01 00 D2 12 01 00 06 15 01 00 (‼☺.∟‼☺.♫‼☺..‼☺.≡↕☺.α↕☺.╥↕☺.♠§☺. 000002A0 EC 14 01 00 2E 15 01 00 00 00 00 00 58 17 01 00 64 17 01 00 72 17 01 00 80 17 01 00 4A 17 01 00 ∞¶☺..§☺.....X↨☺.d↨☺.r↨☺.Ç↨☺.J↨☺. 000002C0 00 00 00 00 71 02 54 6C 73 47 65 74 56 61 6C 75 65 00 26 00 43 6C 6F 73 65 48 61 6E 64 6C 65 00 ....q☻TlsGetValue.&.CloseHandle. 000002E0 51 00 43 72 65 61 74 65 54 68 72 65 61 64 00 00 3A 00 43 72 65 61 74 65 45 76 65 6E 74 41 00 00 Q.CreateThread..:.CreateEventA.. 00000300 63 01 47 6C 6F 62 61 6C 41 6C 6C 6F 63 00 6A 01 47 6C 6F 62 61 6C 46 72 65 65 00 00 3C 02 53 65 c☺GlobalAlloc.j☺GlobalFree..<☻Se 00000320 74 45 76 65 6E 74 00 00 65 00 45 6E 74 65 72 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 tEvent..e.EnterCriticalSection.. 00000340 A1 01 4C 65 61 76 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 8F 02 57 61 69 74 46 6F í☺LeaveCriticalSection..Å☻WaitFo 00000360 72 53 69 6E 67 6C 65 4F 62 6A 65 63 74 00 46 02 53 65 74 4C 61 73 74 45 72 72 6F 72 00 00 B5 00 rSingleObject.F☻SetLastError..╡. 00000380 46 72 65 65 4C 69 62 72 61 72 79 00 8A 01 49 6E 74 65 72 6C 6F 63 6B 65 64 45 78 63 68 61 6E 67 FreeLibrary.è☺InterlockedExchang 000003A0 65 00 23 01 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 6D 02 54 6C 73 41 6C 6C 6F 63 00 00 e.#☺GetProcAddress..m☻TlsAlloc.. 000003C0 6F 02 54 6C 73 46 72 65 65 00 72 02 54 6C 73 53 65 74 56 61 6C 75 65 00 87 01 49 6E 69 74 69 61 o☻TlsFree.r☻TlsSetValue.ç☺Initia 000003E0 6C 69 7A 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 5A 00 44 65 6C 65 74 65 43 72 69 74 lizeCriticalSection.Z.DeleteCrit 00000400 69 63 61 6C 53 65 63 74 69 6F 6E 00 C7 02 6C 73 74 72 6C 65 6E 41 00 00 05 02 52 74 6C 4D 6F 76 icalSection.╟☻lstrlenA..♣☻RtlMov 00000420 65 4D 65 6D 6F 72 79 00 5F 01 47 65 74 57 69 6E 64 6F 77 73 44 69 72 65 63 74 6F 72 79 41 00 00 eMemory._☺GetWindowsDirectoryA.. 00000440 CD 01 4F 70 65 6E 46 69 6C 65 00 00 B0 02 5F 6C 63 6C 6F 73 65 00 B4 02 5F 6C 72 65 61 64 00 00 ═☺OpenFile..░☻_lclose.┤☻_lread.. 00000460 B2 02 5F 6C 6C 73 65 65 6B 00 BE 02 6C 73 74 72 63 6D 70 69 41 00 C1 02 6C 73 74 72 63 70 79 41 ▓☻_llseek.╛☻lstrcmpiA.┴☻lstrcpyA 00000480 00 00 A2 01 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 00 7E 00 45 78 70 61 6E 64 45 6E 76 69 72 6F ..ó☺LoadLibraryA..~.ExpandEnviro 000004A0 6E 6D 65 6E 74 53 74 72 69 6E 67 73 41 00 B8 02 6C 73 74 72 63 61 74 41 00 00 01 01 47 65 74 4C nmentStringsA.╕☻lstrcatA..☺☺GetL 000004C0 61 73 74 45 72 72 6F 72 00 00 91 01 49 73 42 61 64 52 65 61 64 50 74 72 00 00 69 02 54 65 72 6D astError..æ☺IsBadReadPtr..i☻Term 000004E0 69 6E 61 74 65 54 68 72 65 61 64 00 8D 02 57 61 69 74 46 6F 72 4D 75 6C 74 69 70 6C 65 4F 62 6A inateThread.ì☻WaitForMultipleObj 00000500 65 63 74 73 00 00 03 02 52 65 73 75 6D 65 54 68 72 65 61 64 00 00 BB 02 6C 73 74 72 63 6D 70 41 ects..♥☻ResumeThread..╗☻lstrcmpA 00000520 00 00 C4 02 6C 73 74 72 63 70 79 6E 41 00 AF 00 46 6F 72 6D 61 74 4D 65 73 73 61 67 65 41 00 00 ..─☻lstrcpynA.».FormatMessageA.. 00000540 0D 01 47 65 74 4D 6F 64 75 6C 65 48 61 6E 64 6C 65 41 00 00 9E 02 57 72 69 74 65 46 69 6C 65 00 ♪☺GetModuleHandleA..₧☻WriteFile. 00000560 3A 01 47 65 74 53 74 64 48 61 6E 64 6C 65 00 00 CD 00 47 65 74 43 6F 6D 70 75 74 65 72 4E 61 6D :☺GetStdHandle..═.GetComputerNam 00000580 65 41 00 00 FC 00 47 65 74 48 61 6E 64 6C 65 43 6F 6E 74 65 78 74 00 00 4F 00 43 72 65 61 74 65 eA..ⁿ.GetHandleContext..O.Create 000005A0 53 6F 63 6B 65 74 48 61 6E 64 6C 65 00 00 63 02 53 6C 65 65 70 45 78 00 3D 00 43 72 65 61 74 65 SocketHandle..c☻SleepEx.=.Create 000005C0 46 69 6C 65 41 00 5E 00 44 65 76 69 63 65 49 6F 43 6F 6E 74 72 6F 6C 00 54 01 47 65 74 54 69 63 FileA.^.DeviceIoControl.T☺GetTic 000005E0 6B 43 6F 75 6E 74 00 00 AC 01 4C 6F 63 61 6C 46 72 65 65 00 A8 01 4C 6F 63 61 6C 41 6C 6C 6F 63 kCount..¼☺LocalFree.¿☺LocalAlloc 00000600 00 00 62 02 53 6C 65 65 70 00 93 02 57 69 64 65 43 68 61 72 54 6F 4D 75 6C 74 69 42 79 74 65 00 ..b☻Sleep.ô☻WideCharToMultiByte. 00000620 C8 02 6C 73 74 72 6C 65 6E 57 00 00 C9 01 4D 75 6C 74 69 42 79 74 65 54 6F 57 69 64 65 43 68 61 ╚☻lstrlenW..╔☺MultiByteToWideCha 00000640 72 00 89 01 49 6E 74 65 72 6C 6F 63 6B 65 64 44 65 63 72 65 6D 65 6E 74 00 00 8C 01 49 6E 74 65 r.ë☺InterlockedDecrement..î☺Inte 00000660 72 6C 6F 63 6B 65 64 49 6E 63 72 65 6D 65 6E 74 00 00 41 01 47 65 74 53 79 73 74 65 6D 44 69 72 rlockedIncrement..A☺GetSystemDir 00000680 65 63 74 6F 72 79 41 00 4B 45 52 4E 45 4C 33 32 2E 64 6C 6C 00 00 7E 00 52 65 67 43 6C 6F 73 65 ectoryA.KERNEL32.dll..~.RegClose 000006A0 4B 65 79 00 9D 00 52 65 67 51 75 65 72 79 56 61 6C 75 65 45 78 41 00 00 94 00 52 65 67 4F 70 65 Key.¥.RegQueryValueExA..ö.RegOpe 000006C0 6E 4B 65 79 41 00 95 00 52 65 67 4F 70 65 6E 4B 65 79 45 78 41 00 8A 00 52 65 67 45 6E 75 6D 4B nKeyA.ò.RegOpenKeyExA.è.RegEnumK 000006E0 65 79 45 78 41 00 8D 00 52 65 67 45 6E 75 6D 56 61 6C 75 65 41 00 85 00 52 65 67 44 65 6C 65 74 eyExA.ì.RegEnumValueA.à.RegDelet 00000700 65 4B 65 79 41 00 A9 00 52 65 67 53 65 74 56 61 6C 75 65 45 78 41 00 00 82 00 52 65 67 43 72 65 eKeyA.⌐.RegSetValueExA..é.RegCre 00000720 61 74 65 4B 65 79 45 78 41 00 AA 00 52 65 67 53 65 74 56 61 6C 75 65 45 78 57 00 00 41 44 56 41 ateKeyExA.¬.RegSetValueExW..ADVA 00000740 50 49 33 32 2E 64 6C 6C 00 00 20 00 43 68 61 72 4C 6F 77 65 72 41 00 00 6C 02 77 73 70 72 69 6E PI32.dll.. .CharLowerA..l☻wsprin 00000760 74 66 41 00 6E 02 77 76 73 70 72 69 6E 74 66 41 00 00 30 00 43 68 61 72 55 70 70 65 72 41 00 00 tfA.n☻wvsprintfA..0.CharUpperA.. 00000780 C2 01 50 6F 73 74 4D 65 73 73 61 67 65 41 00 00 55 53 45 52 33 32 2E 64 6C 6C 00 00 00 00 00 00 ┬☺PostMessageA..USER32.dll...... 000007A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000007C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000007E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................