ofs | hex dump | ascii |
---|
0000 | 4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 | MZ......................@....... |
0020 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 00 | ................................ |
0040 | 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f | ........!..L.!This.program.canno |
0060 | 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00 | t.be.run.in.DOS.mode....$....... |
0080 | 50 45 00 00 4c 01 04 00 d3 19 24 3a 40 0a 00 00 1f 00 00 00 e0 00 06 01 0b 01 03 0a 60 06 00 00 | PE..L.....$:@...............`... |
00a0 | a0 01 00 00 00 00 00 00 2a 05 00 00 20 02 00 00 40 07 00 00 00 00 01 00 20 00 00 00 20 00 00 00 | ........*.......@............... |
00c0 | 04 00 00 00 04 00 00 00 04 00 00 00 00 00 00 00 20 0a 00 00 20 02 00 00 30 e7 00 00 01 00 00 00 | ........................0....... |
00e0 | 00 00 10 00 00 10 00 00 00 00 10 00 00 10 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
0100 | 60 08 00 00 28 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | `...(........................... |
0120 | a0 09 00 00 48 00 00 00 50 02 00 00 54 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....H...P...T................... |
0140 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 02 00 00 30 00 00 00 | ............................0... |
0160 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 | .........................text... |
0180 | 04 05 00 00 20 02 00 00 20 05 00 00 20 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 68 | ...............................h |
01a0 | 2e 64 61 74 61 00 00 00 04 01 00 00 40 07 00 00 20 01 00 00 40 07 00 00 00 00 00 00 00 00 00 00 | .data.......@.......@........... |
01c0 | 00 00 00 00 40 00 00 c8 49 4e 49 54 00 00 00 00 40 01 00 00 60 08 00 00 40 01 00 00 60 08 00 00 | ....@...INIT....@...`...@...`... |
01e0 | 00 00 00 00 00 00 00 00 00 00 00 00 20 00 00 e2 2e 72 65 6c 6f 63 00 00 68 00 00 00 a0 09 00 00 | .................reloc..h....... |
0200 | 80 00 00 00 a0 09 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 00 42 00 00 00 00 00 00 00 00 | ....................@..B........ |
0220 | 40 09 00 00 ce 08 00 00 e8 08 00 00 fe 08 00 00 10 09 00 00 28 09 00 00 b8 08 00 00 58 09 00 00 | @...................(.......X... |
0240 | 6a 09 00 00 74 09 00 00 86 09 00 00 00 00 00 00 00 00 00 00 d3 19 24 3a 00 00 00 00 01 00 00 00 | j...t.................$:........ |
0260 | 33 05 00 00 00 00 00 00 20 0a 00 00 00 00 00 00 d3 19 24 3a 00 00 00 00 04 00 00 00 10 01 00 00 | 3.................$:............ |
0280 | 00 00 00 00 54 0f 00 00 00 00 00 00 d3 19 24 3a 00 00 00 00 03 00 00 00 30 00 00 00 00 00 00 00 | ....T.........$:........0....... |
02a0 | 64 10 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff | d............................... |
02c0 | ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff ff | ................................ |
02e0 | ff ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
0300 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ff ff ff ff ff ff ff 0f | ................................ |
0320 | ff ff ff ff ff 00 00 00 6a 01 ff 15 28 02 01 00 50 e8 e8 03 00 00 8b 4c 24 08 33 c0 33 d2 89 41 | ........j...(...P......L$.3.3..A |
0340 | 1c 89 41 18 ff 15 38 02 01 00 33 c0 c2 08 00 cc 5c 00 44 00 6f 00 73 00 44 00 65 00 76 00 69 00 | ..A...8...3.....\.D.o.s.D.e.v.i. |
0360 | 63 00 65 00 73 00 5c 00 55 00 73 00 65 00 72 00 50 00 6f 00 72 00 74 00 00 00 55 b9 0a 00 00 00 | c.e.s.\.U.s.e.r.P.o.r.t...U..... |
0380 | 8b ec 83 ec 3c 56 57 be 50 03 01 00 8d 7d c4 f3 a5 66 a5 fa 0f 01 45 f8 0f 00 4d fe 66 8b 45 fe | ....<VW.P....}...f....E...M.f.E. |
03a0 | 8b 0d 40 08 01 00 24 f8 81 e1 ff ff 00 00 0f bf d0 03 55 fa 8b 02 25 00 00 ff ff 0b c1 89 02 8d | ..@...$...........U...%......... |
03c0 | 42 04 8b 08 80 e5 f9 80 cd 09 89 08 0f 00 5d fe fb 8b 08 8b 02 c1 e8 10 8b f1 81 e6 ff 00 00 00 | B.............]................. |
03e0 | 81 e1 00 00 00 ff c1 e6 10 0b f0 0b f1 33 c9 0f b7 46 66 03 c6 81 c6 88 00 00 00 8a 91 40 07 01 | .............3...Ff..........@.. |
0400 | 00 88 14 08 8a 91 c0 07 01 00 88 14 0e 41 81 f9 80 00 00 00 72 e5 8d 45 c4 8d 4d f0 50 51 ff 15 | .............A......r..E..M.PQ.. |
0420 | 34 02 01 00 8d 4d f0 51 ff 15 30 02 01 00 8b 4d 08 ff 71 04 ff 15 2c 02 01 00 5f 5e 8b e5 5d c2 | 4....M.Q..0....M..q...,..._^..]. |
0440 | 04 00 5c 00 44 00 65 00 76 00 69 00 63 00 65 00 5c 00 55 00 73 00 65 00 72 00 50 00 6f 00 72 00 | ..\.D.e.v.i.c.e.\.U.s.e.r.P.o.r. |
0460 | 74 00 00 00 00 00 5c 00 44 00 6f 00 73 00 44 00 65 00 76 00 69 00 63 00 65 00 73 00 5c 00 55 00 | t.....\.D.o.s.D.e.v.i.c.e.s.\.U. |
0480 | 73 00 65 00 72 00 50 00 6f 00 72 00 74 00 00 00 00 00 41 00 6c 00 6c 00 50 00 72 00 6f 00 63 00 | s.e.r.P.o.r.t.....A.l.l.P.r.o.c. |
04a0 | 65 00 73 00 73 00 65 00 73 00 49 00 4f 00 50 00 4d 00 00 00 00 00 54 00 68 00 72 00 6f 00 75 00 | e.s.s.e.s.I.O.P.M.....T.h.r.o.u. |
04c0 | 67 00 68 00 43 00 72 00 65 00 61 00 74 00 65 00 46 00 69 00 6c 00 65 00 49 00 4f 00 50 00 4d 00 | g.h.C.r.e.a.t.e.F.i.l.e.I.O.P.M. |
04e0 | 00 00 5c 00 52 00 65 00 67 00 69 00 73 00 74 00 72 00 79 00 5c 00 4d 00 61 00 63 00 68 00 69 00 | ..\.R.e.g.i.s.t.r.y.\.M.a.c.h.i. |
0500 | 6e 00 65 00 5c 00 53 00 6f 00 66 00 74 00 77 00 61 00 72 00 65 00 5c 00 55 00 73 00 65 00 72 00 | n.e.\.S.o.f.t.w.a.r.e.\.U.s.e.r. |
0520 | 50 00 6f 00 72 00 74 00 00 00 55 8b ec 81 ec c8 01 00 00 b9 08 00 00 00 53 56 57 be 42 04 01 00 | P.o.r.t...U.............SVW.B... |
0540 | 8d 7d 84 f3 a5 66 a5 be 66 04 01 00 8d bd 58 ff ff ff b9 0a 00 00 00 68 92 04 01 00 f3 a5 66 a5 | .}...f..f.....X........h......f. |
0560 | be a8 02 01 00 8d 45 d0 8b fe 50 ff 15 34 02 01 00 68 b6 04 01 00 8d 45 c8 50 ff 15 34 02 01 00 | ......E...P..4...h.....E.P..4... |
0580 | 68 e2 04 01 00 8d 45 c0 50 ff 15 34 02 01 00 33 c0 8d 4d c0 89 45 ac 89 4d b0 8d 55 a8 89 45 b8 | h.....E.P..4...3..M..E..M..U..E. |
05a0 | 52 89 45 bc 6a 01 8d 45 f8 c7 45 a8 18 00 00 00 c7 45 b4 40 00 00 00 50 ff 15 48 02 01 00 85 c0 | R.E.j..E..E......E.@...P..H..... |
05c0 | 75 5b 8d 45 f4 8d 8d 38 fe ff ff 50 8d 55 c8 68 90 00 00 00 51 6a 02 52 ff 75 f8 ff 15 44 02 01 | u[.E...8...P.U.h....Qj.R.u...D.. |
05e0 | 00 85 c0 75 06 8d bd 44 fe ff ff 8d 45 f4 8d 8d c8 fe ff ff 50 8d 55 d0 68 90 00 00 00 51 6a 02 | ...u...D....E.......P.U.h....Qj. |
0600 | 52 ff 75 f8 ff 15 44 02 01 00 85 c0 75 06 8d b5 d4 fe ff ff ff 75 f8 ff 15 40 02 01 00 fa 0f 00 | R.u...D.....u........u...@...... |
0620 | 4d fe 0f 01 45 e8 66 8b 45 fe b9 ff ff 00 00 24 f8 0f bf d0 03 55 ea 8b 02 23 c1 a3 40 08 01 00 | M...E.f.E......$.....U...#..@... |
0640 | 8b 02 8d 98 82 00 00 00 25 00 00 ff ff 23 d9 0b d8 8d 42 04 89 1a 8b 08 80 e5 f9 80 cd 09 89 08 | ........%....#....B............. |
0660 | 0f 00 5d fe fb 8b 18 8b 02 c1 e8 10 8b cb 81 e1 ff 00 00 00 81 e3 00 00 00 ff c1 e1 10 33 d2 0b | ..]..........................3.. |
0680 | c8 0b cb 0f b7 41 66 03 c1 81 c1 88 00 00 00 8a 1c 10 88 9a 40 07 01 00 8a 1c 16 88 1c 10 8a 1c | .....Af.............@........... |
06a0 | 11 88 9a c0 07 01 00 8a 1c 17 20 1c 11 42 81 fa 80 00 00 00 72 d9 8d 45 84 8d 4d e0 50 51 ff 15 | .............B......r..E..M.PQ.. |
06c0 | 34 02 01 00 8d 8d 58 ff ff ff 8d 55 d8 51 33 ff 52 ff 15 34 02 01 00 8d 4d f0 8d 45 e0 51 8b 75 | 4.....X....U.Q3.R..4....M..E.Q.u |
06e0 | 08 57 57 6a 22 50 57 56 ff 15 3c 02 01 00 85 c0 7c 22 8d 45 e0 8d 4d d8 50 51 ff 15 20 02 01 00 | .WWj"PWV..<.....|".E..M.PQ...... |
0700 | 85 c0 7c 10 c7 46 38 28 03 01 00 c7 46 34 7a 03 01 00 33 c0 5f 5e 5b 8b e5 5d c2 08 00 cc ff 25 | ..|..F8(....F4z...3._^[..].....% |
0720 | 24 02 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | $............................... |
0740 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
0760 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
0780 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
07a0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
07c0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
07e0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
0800 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
0820 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
0840 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
0860 | 88 08 00 00 00 00 00 00 00 00 00 00 92 09 00 00 20 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
0880 | 00 00 00 00 00 00 00 00 40 09 00 00 ce 08 00 00 e8 08 00 00 fe 08 00 00 10 09 00 00 28 09 00 00 | ........@...................(... |
08a0 | b8 08 00 00 58 09 00 00 6a 09 00 00 74 09 00 00 86 09 00 00 00 00 00 00 45 01 49 6f 66 43 6f 6d | ....X...j...t...........E.IofCom |
08c0 | 70 6c 65 74 65 52 65 71 75 65 73 74 00 00 4a 01 4b 65 33 38 36 49 6f 53 65 74 41 63 63 65 73 73 | pleteRequest..J.Ke386IoSetAccess |
08e0 | 50 72 6f 63 65 73 73 00 0c 01 49 6f 47 65 74 43 75 72 72 65 6e 74 50 72 6f 63 65 73 73 00 fb 00 | Process...IoGetCurrentProcess... |
0900 | 49 6f 44 65 6c 65 74 65 44 65 76 69 63 65 00 00 fc 00 49 6f 44 65 6c 65 74 65 53 79 6d 62 6f 6c | IoDeleteDevice....IoDeleteSymbol |
0920 | 69 63 4c 69 6e 6b 00 00 d0 02 52 74 6c 49 6e 69 74 55 6e 69 63 6f 64 65 53 74 72 69 6e 67 00 00 | icLink....RtlInitUnicodeString.. |
0940 | f7 00 49 6f 43 72 65 61 74 65 53 79 6d 62 6f 6c 69 63 4c 69 6e 6b 00 00 f3 00 49 6f 43 72 65 61 | ..IoCreateSymbolicLink....IoCrea |
0960 | 74 65 44 65 76 69 63 65 00 00 5b 03 5a 77 43 6c 6f 73 65 00 8c 03 5a 77 51 75 65 72 79 56 61 6c | teDevice..[.ZwClose...ZwQueryVal |
0980 | 75 65 4b 65 79 00 79 03 5a 77 4f 70 65 6e 4b 65 79 00 6e 74 6f 73 6b 72 6e 6c 2e 65 78 65 00 00 | ueKey.y.ZwOpenKey.ntoskrnl.exe.. |
09a0 | 00 00 00 00 48 00 00 00 2c 33 46 33 88 33 a2 33 fd 33 06 34 20 34 2a 34 36 34 3c 35 48 35 58 35 | ....H...,3F3.3.3.3.4.4*464<5H5X5 |
09c0 | 61 35 6d 35 72 35 7c 35 81 35 8b 35 ba 35 dd 35 06 36 19 36 3c 36 94 36 a3 36 c0 36 d3 36 ea 36 | a5m5r5|5.5.5.5.5.6.6<6.6.6.6.6.6 |
09e0 | fc 36 07 37 0e 37 20 37 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | .6.7.7.7........................ |
0a00 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
0a20 | 1f 00 00 00 20 00 00 00 00 00 00 00 20 00 00 00 20 02 00 00 80 08 00 00 40 07 00 00 c0 03 00 00 | ........................@....... |
0a40 | 24 53 47 33 30 38 38 00 50 03 00 00 01 00 00 00 03 00 24 53 47 33 31 33 33 00 e2 04 00 00 01 00 | $SG3088.P.........$SG3133....... |
0a60 | 00 00 03 00 24 53 47 33 31 33 32 00 b6 04 00 00 01 00 00 00 03 00 24 53 47 33 31 33 31 00 92 04 | ....$SG3132...........$SG3131... |
0a80 | 00 00 01 00 00 00 03 00 24 53 47 33 31 30 39 00 66 04 00 00 01 00 00 00 03 00 24 53 47 33 31 30 | ........$SG3109.f.........$SG310 |
0aa0 | 37 00 42 04 00 00 01 00 00 00 03 00 2e 69 64 61 74 61 24 36 92 09 00 00 03 00 00 00 03 00 68 65 | 7.B..........idata$6..........he |
0ac0 | 61 64 65 72 00 00 00 00 00 00 fe ff 00 00 02 00 00 00 00 00 37 01 00 00 20 02 00 00 01 00 00 00 | ader................7........... |
0ae0 | 02 00 00 00 00 00 e0 01 00 00 24 02 00 00 01 00 00 00 02 00 00 00 00 00 c6 00 00 00 28 02 00 00 | ..........$.................(... |
0b00 | 01 00 00 00 02 00 00 00 00 00 e3 00 00 00 2c 02 00 00 01 00 00 00 02 00 00 00 00 00 fb 00 00 00 | ..............,................. |
0b20 | 30 02 00 00 01 00 00 00 02 00 00 00 00 00 19 01 00 00 34 02 00 00 01 00 00 00 02 00 00 00 00 00 | 0.................4............. |
0b40 | 8f 00 00 00 38 02 00 00 01 00 00 00 02 00 00 00 00 00 55 01 00 00 3c 02 00 00 01 00 00 00 02 00 | ....8.............U...<......... |
0b60 | 00 00 00 00 6e 01 00 00 40 02 00 00 01 00 00 00 02 00 00 00 00 00 7f 01 00 00 44 02 00 00 01 00 | ....n...@.................D..... |
0b80 | 00 00 02 00 00 00 00 00 99 01 00 00 48 02 00 00 01 00 00 00 02 00 00 00 00 00 cb 02 00 00 4c 02 | ............H.................L. |
0ba0 | 00 00 01 00 00 00 02 00 00 00 00 00 3b 00 00 00 a8 02 00 00 01 00 00 00 02 00 00 00 00 00 13 00 | ............;................... |
0bc0 | 00 00 28 03 00 00 01 00 20 00 02 00 00 00 00 00 29 00 00 00 7a 03 00 00 01 00 20 00 02 00 00 00 | ..(.............)...z........... |
0be0 | 00 00 04 00 00 00 2a 05 00 00 01 00 20 00 02 00 00 00 00 00 ab 00 00 00 1e 07 00 00 01 00 20 00 | ......*......................... |
0c00 | 02 00 00 00 00 00 76 00 00 00 40 07 00 00 02 00 00 00 02 00 00 00 00 00 53 00 00 00 c0 07 00 00 | ......v...@.............S....... |
0c20 | 02 00 00 00 02 00 00 00 00 00 47 00 00 00 40 08 00 00 02 00 00 00 02 00 00 00 00 00 c3 01 00 00 | ..........G...@................. |
0c40 | 60 08 00 00 03 00 00 00 02 00 00 00 00 00 b2 02 00 00 74 08 00 00 03 00 00 00 02 00 65 6e 64 00 | `.................t.........end. |
0c60 | 00 00 00 00 20 0a 00 00 fe ff 00 00 02 00 e5 02 00 00 5f 44 72 69 76 65 72 45 6e 74 72 79 40 38 | .................._DriverEntry@8 |
0c80 | 00 5f 43 72 65 61 74 65 46 69 6c 65 44 69 73 70 61 74 63 68 40 38 00 5f 55 73 65 72 50 6f 72 74 | ._CreateFileDispatch@8._UserPort |
0ca0 | 55 6e 6c 6f 61 64 40 34 00 5f 44 65 66 61 75 6c 74 4d 61 70 00 5f 4f 72 67 47 44 54 53 69 7a 65 | Unload@4._DefaultMap._OrgGDTSize |
0cc0 | 00 5f 4f 72 69 67 69 6e 61 6c 54 68 72 6f 75 67 68 43 72 65 61 74 65 46 69 6c 65 49 4f 50 4d 43 | ._OriginalThroughCreateFileIOPMC |
0ce0 | 6f 70 79 00 5f 4f 72 69 67 69 6e 61 6c 41 6c 6c 50 72 6f 63 49 4f 50 4d 43 6f 70 79 00 5f 5f 69 | opy._OriginalAllProcIOPMCopy.__i |
0d00 | 6d 70 5f 40 49 6f 66 43 6f 6d 70 6c 65 74 65 52 65 71 75 65 73 74 40 38 00 5f 4b 65 33 38 36 49 | mp_@IofCompleteRequest@8._Ke386I |
0d20 | 6f 53 65 74 41 63 63 65 73 73 50 72 6f 63 65 73 73 40 38 00 5f 5f 69 6d 70 5f 5f 49 6f 47 65 74 | oSetAccessProcess@8.__imp__IoGet |
0d40 | 43 75 72 72 65 6e 74 50 72 6f 63 65 73 73 40 30 00 5f 5f 69 6d 70 5f 5f 49 6f 44 65 6c 65 74 65 | CurrentProcess@0.__imp__IoDelete |
0d60 | 44 65 76 69 63 65 40 34 00 5f 5f 69 6d 70 5f 5f 49 6f 44 65 6c 65 74 65 53 79 6d 62 6f 6c 69 63 | Device@4.__imp__IoDeleteSymbolic |
0d80 | 4c 69 6e 6b 40 34 00 5f 5f 69 6d 70 5f 5f 52 74 6c 49 6e 69 74 55 6e 69 63 6f 64 65 53 74 72 69 | Link@4.__imp__RtlInitUnicodeStri |
0da0 | 6e 67 40 38 00 5f 5f 69 6d 70 5f 5f 49 6f 43 72 65 61 74 65 53 79 6d 62 6f 6c 69 63 4c 69 6e 6b | ng@8.__imp__IoCreateSymbolicLink |
0dc0 | 40 38 00 5f 5f 69 6d 70 5f 5f 49 6f 43 72 65 61 74 65 44 65 76 69 63 65 40 32 38 00 5f 5f 69 6d | @8.__imp__IoCreateDevice@28.__im |
0de0 | 70 5f 5f 5a 77 43 6c 6f 73 65 40 34 00 5f 5f 69 6d 70 5f 5f 5a 77 51 75 65 72 79 56 61 6c 75 65 | p__ZwClose@4.__imp__ZwQueryValue |
0e00 | 4b 65 79 40 32 34 00 5f 5f 69 6d 70 5f 5f 5a 77 4f 70 65 6e 4b 65 79 40 31 32 00 40 49 6f 66 43 | Key@24.__imp__ZwOpenKey@12.@IofC |
0e20 | 6f 6d 70 6c 65 74 65 52 65 71 75 65 73 74 40 38 00 5f 5f 49 4d 50 4f 52 54 5f 44 45 53 43 52 49 | ompleteRequest@8.__IMPORT_DESCRI |
0e40 | 50 54 4f 52 5f 6e 74 6f 73 6b 72 6e 6c 00 5f 5f 69 6d 70 5f 5f 4b 65 33 38 36 49 6f 53 65 74 41 | PTOR_ntoskrnl.__imp__Ke386IoSetA |
0e60 | 63 63 65 73 73 50 72 6f 63 65 73 73 40 38 00 5f 49 6f 47 65 74 43 75 72 72 65 6e 74 50 72 6f 63 | ccessProcess@8._IoGetCurrentProc |
0e80 | 65 73 73 40 30 00 5f 49 6f 44 65 6c 65 74 65 44 65 76 69 63 65 40 34 00 5f 49 6f 44 65 6c 65 74 | ess@0._IoDeleteDevice@4._IoDelet |
0ea0 | 65 53 79 6d 62 6f 6c 69 63 4c 69 6e 6b 40 34 00 5f 52 74 6c 49 6e 69 74 55 6e 69 63 6f 64 65 53 | eSymbolicLink@4._RtlInitUnicodeS |
0ec0 | 74 72 69 6e 67 40 38 00 5f 49 6f 43 72 65 61 74 65 53 79 6d 62 6f 6c 69 63 4c 69 6e 6b 40 38 00 | tring@8._IoCreateSymbolicLink@8. |
0ee0 | 5f 49 6f 43 72 65 61 74 65 44 65 76 69 63 65 40 32 38 00 5f 5a 77 43 6c 6f 73 65 40 34 00 5f 5a | _IoCreateDevice@28._ZwClose@4._Z |
0f00 | 77 51 75 65 72 79 56 61 6c 75 65 4b 65 79 40 32 34 00 5f 5a 77 4f 70 65 6e 4b 65 79 40 31 32 00 | wQueryValueKey@24._ZwOpenKey@12. |
0f20 | 5f 5f 4e 55 4c 4c 5f 49 4d 50 4f 52 54 5f 44 45 53 43 52 49 50 54 4f 52 00 7f 6e 74 6f 73 6b 72 | __NULL_IMPORT_DESCRIPTOR..ntoskr |
0f40 | 6e 6c 5f 4e 55 4c 4c 5f 54 48 55 4e 4b 5f 44 41 54 41 00 00 01 00 00 00 10 01 00 00 00 2d 54 00 | nl_NULL_THUNK_DATA...........-T. |
0f60 | 2e 5c 69 33 38 36 5c 66 72 65 65 5c 55 73 65 72 50 6f 72 74 2e 73 79 73 00 00 00 00 00 00 00 00 | .\i386\free\UserPort.sys........ |
0f80 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
0fa0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
0fc0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
0fe0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
1000 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
1020 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
1040 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
1060 | 00 00 00 00 28 03 00 00 27 00 00 00 00 00 00 00 02 00 00 00 7a 03 00 00 c8 00 00 00 10 00 00 00 | ....(...'...........z........... |
1080 | 01 00 0d d2 2a 05 00 00 f3 01 00 00 73 00 00 00 02 00 11 d3 00 00 00 00 00 00 00 00 00 00 00 00 | ....*.......s................... |