============================================================================================================================================== OFFSET 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F 10 11 12 13 14 15 16 17 18 19 1A 1B 1C 1D 1E 1F ---------------------------------------------------------------------------------------------------------------------------------------------- 00000000 00 00 00 00 00 00 00 00 00 00 00 00 40 81 00 00 78 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ............@ü..xÇ.............. 00000020 06 83 00 00 E8 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 83 00 00 F0 80 00 00 00 00 00 00 ♠â..ΦÇ.............. â..≡Ç...... 00000040 00 00 00 00 00 00 00 00 86 83 00 00 08 81 00 00 00 00 00 00 00 00 00 00 00 00 00 00 E4 83 00 00 ........åâ..◘ü..............Σâ.. 00000060 1C 81 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 4E 81 00 00 66 81 00 00 ∟ü......................Nü..fü.. 00000080 7E 81 00 00 96 81 00 00 B2 81 00 00 C0 81 00 00 D0 81 00 00 DC 81 00 00 EA 81 00 00 00 82 00 00 ~ü..ûü..▓ü..└ü..╨ü..▄ü..Ωü...é.. 000000A0 0E 82 00 00 1C 82 00 00 26 82 00 00 32 82 00 00 48 82 00 00 58 82 00 00 64 82 00 00 76 82 00 00 ♫é..∟é..&é..2é..Hé..Xé..dé..vé.. 000000C0 86 82 00 00 92 82 00 00 9E 82 00 00 B0 82 00 00 C0 82 00 00 CE 82 00 00 DC 82 00 00 EA 82 00 00 åé..Æé..₧é..░é..└é..╬é..▄é..Ωé.. 000000E0 F8 82 00 00 00 00 00 00 12 83 00 00 00 00 00 00 2E 83 00 00 44 83 00 00 52 83 00 00 62 83 00 00 °é......↕â.......â..Dâ..Râ..bâ.. 00000100 72 83 00 00 00 00 00 00 94 83 00 00 A4 83 00 00 BC 83 00 00 D2 83 00 00 00 00 00 00 F0 83 00 00 râ......öâ..ñâ..╝â..╥â......≡â.. 00000120 06 84 00 00 1A 84 00 00 2A 84 00 00 38 84 00 00 46 84 00 00 5C 84 00 00 6A 84 00 00 00 00 00 00 ♠ä..→ä..*ä..8ä..Fä..\ä..jä...... 00000140 6B 65 72 6E 65 6C 33 32 2E 64 6C 6C 00 00 00 00 44 65 6C 65 74 65 43 72 69 74 69 63 61 6C 53 65 kernel32.dll....DeleteCriticalSe 00000160 63 74 69 6F 6E 00 00 00 4C 65 61 76 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 00 00 ction...LeaveCriticalSection.... 00000180 45 6E 74 65 72 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 00 00 49 6E 69 74 69 61 6C 69 EnterCriticalSection....Initiali 000001A0 7A 65 43 72 69 74 69 63 61 6C 53 65 63 74 69 6F 6E 00 00 00 56 69 72 74 75 61 6C 46 72 65 65 00 zeCriticalSection...VirtualFree. 000001C0 00 00 56 69 72 74 75 61 6C 41 6C 6C 6F 63 00 00 00 00 4C 6F 63 61 6C 46 72 65 65 00 00 00 4C 6F ..VirtualAlloc....LocalFree...Lo 000001E0 63 61 6C 41 6C 6C 6F 63 00 00 00 00 57 69 64 65 43 68 61 72 54 6F 4D 75 6C 74 69 42 79 74 65 00 calAlloc....WideCharToMultiByte. 00000200 00 00 54 6C 73 53 65 74 56 61 6C 75 65 00 00 00 54 6C 73 47 65 74 56 61 6C 75 65 00 00 00 54 6C ..TlsSetValue...TlsGetValue...Tl 00000220 73 46 72 65 65 00 00 00 54 6C 73 41 6C 6C 6F 63 00 00 00 00 4D 75 6C 74 69 42 79 74 65 54 6F 57 sFree...TlsAlloc....MultiByteToW 00000240 69 64 65 43 68 61 72 00 00 00 47 65 74 4C 61 73 74 45 72 72 6F 72 00 00 00 00 57 72 69 74 65 46 ideChar...GetLastError....WriteF 00000260 69 6C 65 00 00 00 53 65 74 46 69 6C 65 50 6F 69 6E 74 65 72 00 00 00 00 53 65 74 45 6E 64 4F 66 ile...SetFilePointer....SetEndOf 00000280 46 69 6C 65 00 00 00 00 52 74 6C 55 6E 77 69 6E 64 00 00 00 52 65 61 64 46 69 6C 65 00 00 00 00 File....RtlUnwind...ReadFile.... 000002A0 52 61 69 73 65 45 78 63 65 70 74 69 6F 6E 00 00 00 00 47 65 74 53 74 64 48 61 6E 64 6C 65 00 00 RaiseException....GetStdHandle.. 000002C0 00 00 47 65 74 46 69 6C 65 53 69 7A 65 00 00 00 47 65 74 46 69 6C 65 54 79 70 65 00 00 00 45 78 ..GetFileSize...GetFileType...Ex 000002E0 69 74 50 72 6F 63 65 73 73 00 00 00 43 72 65 61 74 65 46 69 6C 65 41 00 00 00 43 6C 6F 73 65 48 itProcess...CreateFileA...CloseH 00000300 61 6E 64 6C 65 00 75 73 65 72 33 32 2E 64 6C 6C 00 00 00 00 4D 65 73 73 61 67 65 42 6F 78 41 00 andle.user32.dll....MessageBoxA. 00000320 6F 6C 65 61 75 74 33 32 2E 64 6C 6C 00 00 00 00 56 61 72 69 61 6E 74 43 68 61 6E 67 65 54 79 70 oleaut32.dll....VariantChangeTyp 00000340 65 45 78 00 00 00 56 61 72 69 61 6E 74 43 6F 70 79 00 00 00 56 61 72 69 61 6E 74 43 6C 65 61 72 eEx...VariantCopy...VariantClear 00000360 00 00 00 00 53 79 73 53 74 72 69 6E 67 4C 65 6E 00 00 00 00 53 79 73 41 6C 6C 6F 63 53 74 72 69 ....SysStringLen....SysAllocStri 00000380 6E 67 4C 65 6E 00 6B 65 72 6E 65 6C 33 32 2E 64 6C 6C 00 00 00 00 47 65 74 56 65 72 73 69 6F 6E ngLen.kernel32.dll....GetVersion 000003A0 45 78 41 00 00 00 47 65 74 53 79 73 74 65 6D 44 65 66 61 75 6C 74 4C 43 49 44 00 00 00 00 47 65 ExA...GetSystemDefaultLCID....Ge 000003C0 74 4D 6F 64 75 6C 65 46 69 6C 65 4E 61 6D 65 41 00 00 00 00 47 65 74 4C 6F 63 61 6C 65 49 6E 66 tModuleFileNameA....GetLocaleInf 000003E0 6F 41 00 00 75 73 65 72 33 32 2E 64 6C 6C 00 00 00 00 55 6E 68 6F 6F 6B 57 69 6E 64 6F 77 73 48 oA..user32.dll....UnhookWindowsH 00000400 6F 6F 6B 45 78 00 00 00 53 65 74 57 69 6E 64 6F 77 73 48 6F 6F 6B 45 78 41 00 00 00 50 6F 73 74 ookEx...SetWindowsHookExA...Post 00000420 4D 65 73 73 61 67 65 41 00 00 00 00 4D 65 73 73 61 67 65 42 6F 78 41 00 00 00 4C 6F 61 64 53 74 MessageA....MessageBoxA...LoadSt 00000440 72 69 6E 67 41 00 00 00 47 65 74 46 6F 72 65 67 72 6F 75 6E 64 57 69 6E 64 6F 77 00 00 00 46 69 ringA...GetForegroundWindow...Fi 00000460 6E 64 57 69 6E 64 6F 77 41 00 00 00 43 61 6C 6C 4E 65 78 74 48 6F 6F 6B 45 78 00 00 00 00 00 00 ndWindowA...CallNextHookEx...... 00000480 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000004A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000004C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000004E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000500 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000520 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000540 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000560 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 00000580 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005A0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005C0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................ 000005E0 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................................