home *** CD-ROM | disk | FTP | other *** search
Unknown | 2007-08-29 | 4.0 KB |
open in:
MacOS 8.1
|
Win98
|
DOS
view JSON data
|
view as text
This file was not able to be converted.
This format is not currently supported by dexvert.
Confidence | Program | Detection | Match Type | Support
|
---|
100%
| file
| data
| default
|
|
hex view+--------+-------------------------+-------------------------+--------+--------+
|00000000| 00 00 00 00 00 00 8b c1 | c7 00 f4 e2 01 00 83 3d |........|.......=|
|00000010| 20 06 02 00 00 75 05 a3 | 20 06 02 00 c3 cc cc cc | ....u..| .......|
|00000020| cc cc 8b 51 08 b8 e2 10 | 01 00 89 42 38 8b 51 08 |...Q....|...B8.Q.|
|00000030| 89 42 40 8b 51 08 83 61 | 18 f9 89 42 70 8b 51 08 |.B@.Q..a|...Bp.Q.|
|00000040| 89 42 78 8b 51 08 83 49 | 18 01 89 82 80 00 00 00 |.Bx.Q..I|........|
|00000050| 8b 41 08 c7 40 34 06 30 | 02 00 c3 cc cc cc cc cc |.A..@4.0|........|
|00000060| 8b ff 56 8b f1 e8 9c ff | ff ff c7 46 1c 04 e3 01 |..V.....|...F....|
|00000070| 00 8d 4e 28 c7 06 1c e3 | 01 00 c7 46 1c 10 e3 01 |..N(....|...F....|
|00000080| 00 e8 0e 22 ff ff 33 c0 | 8d 4e 70 88 46 68 89 46 |..."..3.|.Np.Fh.F|
|00000090| 64 66 89 46 60 66 89 46 | 62 e8 7e 5b ff ff 8d 4e |df.F`f.F|b.~[...N|
|000000a0| 78 e8 9e 66 ff ff 8d 8e | b0 00 00 00 e8 e3 e6 fe |x..f....|........|
|000000b0| ff 8d 8e 40 01 00 00 e8 | 2a f7 fe ff 8b c6 5e c3 |...@....|*.....^.|
|000000c0| 24 00 73 00 79 00 73 00 | 74 00 65 00 6d 00 73 00 |$.s.y.s.|t.e.m.s.|
|000000d0| 65 00 63 00 75 00 72 00 | 69 00 74 00 79 00 00 00 |e.c.u.r.|i.t.y...|
|000000e0| 24 00 73 00 79 00 73 00 | 74 00 65 00 6d 00 73 00 |$.s.y.s.|t.e.m.s.|
|000000f0| 65 00 63 00 75 00 72 00 | 69 00 74 00 79 00 00 00 |e.c.u.r.|i.t.y...|
|00000100| cc cc cc cc cc cc 6a 20 | 68 30 e3 01 00 e8 ae 74 |......j |h0.....t|
|00000110| ff ff 8b f1 89 75 e0 c6 | 46 5c 01 33 ff 89 be d0 |.....u..|F\.3....|
|00000120| 01 00 00 89 be d4 01 00 | 00 ff 15 18 e1 01 00 89 |........|........|
|00000130| 46 6c 89 7e 20 89 7e 24 | 8d 9e a8 00 00 00 89 3b |Fl.~ .~$|.......;|
|00000140| 89 be ac 00 00 00 89 7d | fc 6a 10 57 68 c0 40 02 |.......}|.j.Wh.@.|
|00000150| 00 68 00 80 00 00 68 e0 | 40 02 00 6a 38 e8 38 f2 |.h....h.|@..j8.8.|
|00000160| ff ff 83 c4 18 89 45 dc | 3b c7 74 0a 57 8b c8 e8 |......E.|;.t.W...|
|00000170| d6 02 00 00 eb 02 33 c0 | 89 46 20 3b c7 0f 85 9e |......3.|.F ;....|
|00000180| 00 00 00 c7 45 e4 9a 00 | 00 c0 57 ff 15 14 e0 01 |....E...|..W.....|
|00000190| 00 53 68 8c e2 01 00 57 | 57 68 9c e2 01 00 ff 15 |.Sh....W|Wh......|
|000001a0| 10 e0 01 00 89 45 e4 3b | c7 0f 85 12 01 00 00 39 |.....E.;|.......9|
|000001b0| 3b 0f 84 0a 01 00 00 8d | 9e ac 00 00 00 53 68 7c |;.......|.....Sh||
|000001c0| e2 01 00 57 57 68 9c e2 | 01 00 ff 15 10 e0 01 00 |...WWh..|........|
|000001d0| 89 45 e4 3b c7 0f 85 e6 | 00 00 00 39 3b 0f 84 de |.E.;....|...9;...|
|000001e0| 00 00 00 8d 4e 78 e8 cf | 6a ff ff 8d 8e b0 00 00 |....Nx..|j.......|
|000001f0| 00 e8 ae ee fe ff 85 c0 | 74 1b 8d 8e 40 01 00 00 |........|t...@...|
|00000200| e8 23 06 ff ff 85 c0 74 | 0c 8d 4e 70 e8 ef 59 ff |.#.....t|..Np..Y.|
|00000210| ff 85 c0 75 2e c7 45 e4 | 01 00 00 c0 e9 a0 00 00 |...u..E.|........|
|00000220| 00 8b 48 28 89 4d e4 3b | cf 0f 8d 5b ff ff ff 8b |..H(.M.;|...[....|
|00000230| c8 89 4d d8 89 4d d4 8b | 01 6a 01 ff 50 04 89 7e |..M..M..|.j..P..~|
|00000240| 20 eb 7e 89 be d4 01 00 | 00 8d 5e 28 8b cb e8 ef | .~.....|..^(....|
|00000250| 07 ff ff 8b 03 8b cb ff | 50 1c 89 45 e4 3d 3a 00 |........|P..E.=:.|
|00000260| 00 c0 75 25 8b 46 08 89 | 45 d0 8d 8e d4 01 00 00 |..u%.F..|E.......|
|00000270| 51 56 68 56 15 01 00 50 | 68 f4 fb 01 00 6a 01 6a |QVhV...P|h....j.j|
|00000280| 02 ff 15 1c e1 01 00 eb | 14 3b c7 7c 34 8b 13 57 |........|.;.|4..W|
|00000290| 57 8d 86 d0 01 00 00 50 | 8b cb ff 52 08 89 45 e4 |W......P|...R..E.|
|000002a0| ff 76 08 e8 e8 3e ff ff | 8b c8 e8 23 3d ff ff 57 |.v...>..|...#=..W|
|000002b0| 57 57 8d 46 1c 50 68 5c | e2 01 00 ff 15 0c e0 01 |WW.F.Ph\|........|
|000002c0| 00 83 4d fc ff e8 10 00 | 00 00 8b 45 e4 e8 29 73 |..M.....|...E..)s|
|000002d0| ff ff c2 04 00 33 ff 8b | 75 e0 39 7d e4 74 07 8b |.....3..|u.9}.t..|
|000002e0| 06 8b ce ff 50 08 c3 cc | cc cc cc cc 68 44 64 6b |....P...|....hDdk|
|000002f0| 20 68 d8 01 00 00 6a 00 | ff 15 78 e1 01 00 85 c0 | h....j.|..x.....|
|00000300| 74 07 8b c8 e8 57 fd ff | ff 6a 00 68 28 06 02 00 |t....W..|.j.h(...|
|00000310| ff 15 30 e0 01 00 c3 cc | cc cc cc cc 8b ff 55 8b |..0.....|......U.|
|00000320| ec 51 53 e8 c4 ff ff ff | 8b 1d 20 06 02 00 85 db |.QS.....|.. .....|
|00000330| 89 5d fc 75 0a b8 9a 00 | 00 c0 e9 c2 00 00 00 8b |.].u....|........|
|00000340| 45 08 56 8b 75 0c 89 43 | 08 0f b7 06 57 d1 e8 8d |E.V.u..C|....W...|
|00000350| 44 00 02 6a 01 50 e8 15 | 28 ff ff 85 c0 59 59 74 |D..j.P..|(....YYt|
|00000360| 26 0f b7 0e 8b 76 04 8b | d1 c1 e9 02 8b f8 f3 a5 |&....v..|........|
|00000370| 8b ca 83 e1 03 f3 a4 8b | 4d 0c 0f b7 09 d1 e9 66 |........|M......f|
|00000380| 83 24 48 00 50 eb 02 6a | 00 8d 43 0c 50 ff 15 30 |.$H.P..j|..C.P..0|
|00000390| e0 01 00 a1 28 06 02 00 | 66 85 c0 76 46 0f b7 f0 |....(...|f..vF...|
|000003a0| 8b de d1 eb d1 e3 8d 43 | 02 6a 01 50 e8 bf 27 ff |.......C|.j.P..'.|
|000003b0| ff 85 c0 59 59 74 29 8b | ce 8b 35 2c 06 02 00 8b |...YYt).|..5,....|
|000003c0| d1 c1 e9 02 8b f8 f3 a5 | 8b ca 83 e1 03 50 f3 a4 |........|.....P..|
|000003d0| 66 83 24 03 00 68 28 06 | 02 00 ff 15 30 e0 01 00 |f.$..h(.|....0...|
|000003e0| 8b 5d fc 8b cb e8 38 fc | ff ff ff 75 0c 8b 03 ff |.]....8.|...u....|
|000003f0| 50 04 8b 4b 08 83 79 04 | 00 5f 0f 95 c1 88 4b 14 |P..K..y.|._....K.|
|00000400| 5e 5b c9 c2 08 00 cc cc | cc cc cc cc 8b ff 55 8b |^[......|......U.|
|00000410| ec 56 57 e8 00 87 ff ff | be 00 00 00 c0 8b f8 23 |.VW.....|.......#|
|00000420| c6 3b c6 74 13 ff 75 0c | ff 75 08 e8 ec fe ff ff |.;.t..u.|.u......|
|00000430| 8b f8 23 c6 3b c6 75 05 | e8 2e 86 ff ff 8b c7 5f |..#.;.u.|......._|
|00000440| 5e 5d c2 08 00 cc cc cc | cc cc 8b ff 55 8b ec 56 |^]......|....U..V|
|00000450| 8b f1 e8 63 ec ff ff 8b | 45 08 83 66 34 00 89 46 |...c....|E..f4..F|
|00000460| 30 c7 06 40 e3 01 00 8b | c6 5e 5d c2 04 00 cc cc |0..@....|.^].....|
|00000470| cc cc cc 8b ff 55 8b ec | a1 5c 05 02 00 85 c0 b9 |.....U..|.\......|
|00000480| 40 bb 00 00 74 04 3b c1 | 75 23 8b 15 0c e1 01 00 |@...t.;.|u#......|
|00000490| b8 5c 05 02 00 c1 e8 08 | 33 02 25 ff ff 00 00 a3 |.\......|3.%.....|
|000004a0| 5c 05 02 00 75 07 8b c1 | a3 5c 05 02 00 f7 d0 a3 |\...u...|.\......|
|000004b0| 58 05 02 00 5d e9 52 ff | ff ff cc cc 4c 45 01 00 |X...].R.|....LE..|
|000004c0| 00 00 00 00 00 00 00 00 | 1e 4c 01 00 2c e0 00 00 |........|.L..,...|
|000004d0| 20 45 01 00 00 00 00 00 | 00 00 00 00 58 4c 01 00 | E......|....XL..|
|000004e0| 00 e0 00 00 2c 45 01 00 | 00 00 00 00 00 00 00 00 |....,E..|........|
|000004f0| a6 4c 01 00 0c e0 00 00 | 3c 45 01 00 00 00 00 00 |.L......|<E......|
|00000500| 00 00 00 00 f0 4c 01 00 | 1c e0 00 00 00 00 00 00 |.....L..|........|
|00000510| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000520| 2c 4c 01 00 42 4c 01 00 | 00 00 00 00 60 4c 01 00 |,L..BL..|....`L..|
|00000530| 7c 4c 01 00 94 4c 01 00 | 00 00 00 00 d6 4c 01 00 ||L...L..|.....L..|
|00000540| bc 4c 01 00 b0 4c 01 00 | 00 00 00 00 c0 47 01 00 |.L...L..|.....G..|
|00000550| ca 47 01 00 e2 47 01 00 | f8 47 01 00 04 48 01 00 |.G...G..|.G...H..|
|00000560| 14 48 01 00 34 48 01 00 | 4a 48 01 00 5a 48 01 00 |.H..4H..|JH..ZH..|
|00000570| 6a 48 01 00 7a 48 01 00 | 92 48 01 00 a4 48 01 00 |jH..zH..|.H...H..|
|00000580| b0 48 01 00 cc 48 01 00 | e4 48 01 00 fe 48 01 00 |.H...H..|.H...H..|
|00000590| 12 49 01 00 22 49 01 00 | 44 49 01 00 5e 49 01 00 |.I.."I..|DI..^I..|
|000005a0| 68 49 01 00 74 49 01 00 | 88 49 01 00 9c 49 01 00 |hI..tI..|.I...I..|
|000005b0| aa 49 01 00 b4 49 01 00 | c2 49 01 00 d8 49 01 00 |.I...I..|.I...I..|
|000005c0| 9c 47 01 00 fc 49 01 00 | 10 4a 01 00 2c 4a 01 00 |.G...I..|.J..,J..|
|000005d0| 36 4a 01 00 40 4a 01 00 | 56 4a 01 00 70 4a 01 00 |6J..@J..|VJ..pJ..|
|000005e0| 88 4a 01 00 a4 4a 01 00 | c2 4a 01 00 cc 4a 01 00 |.J...J..|.J...J..|
|000005f0| d6 4a 01 00 ee 4a 01 00 | 0a 4b 01 00 26 4b 01 00 |.J...J..|.K..&K..|
|00000600| 40 4b 01 00 5c 4b 01 00 | 70 4b 01 00 7e 4b 01 00 |@K..\K..|pK..~K..|
|00000610| 90 4b 01 00 9e 4b 01 00 | ae 4b 01 00 c4 4b 01 00 |.K...K..|.K...K..|
|00000620| d6 4b 01 00 e2 4b 01 00 | f0 4b 01 00 00 4c 01 00 |.K...K..|.K...L..|
|00000630| 0e 4c 01 00 88 47 01 00 | 70 47 01 00 4e 47 01 00 |.L...G..|pG..NG..|
|00000640| 32 47 01 00 1a 47 01 00 | fe 46 01 00 ee 46 01 00 |2G...G..|.F...F..|
|00000650| e4 46 01 00 cc 46 01 00 | b8 46 01 00 ea 49 01 00 |.F...F..|.F...I..|
|00000660| fe 4c 01 00 1a 4d 01 00 | 2c 4d 01 00 44 4d 01 00 |.L...M..|,M..DM..|
|00000670| 5c 4d 01 00 7e 4d 01 00 | a2 4d 01 00 b4 4d 01 00 |\M..~M..|.M...M..|
|00000680| cc 4d 01 00 e0 4d 01 00 | f0 4d 01 00 fe 4d 01 00 |.M...M..|.M...M..|
|00000690| 0c 4e 01 00 26 4e 01 00 | a0 46 01 00 00 00 00 00 |.N..&N..|.F......|
|000006a0| 45 00 45 78 41 6c 6c 6f | 63 61 74 65 50 6f 6f 6c |E.ExAllo|catePool|
|000006b0| 57 69 74 68 54 61 67 00 | 57 00 45 78 46 72 65 65 |WithTag.|W.ExFree|
|000006c0| 50 6f 6f 6c 57 69 74 68 | 54 61 67 00 51 02 4b 65 |PoolWith|Tag.Q.Ke|
|000006d0| 49 6e 69 74 69 61 6c 69 | 7a 65 53 70 69 6e 4c 6f |Initiali|zeSpinLo|
|000006e0| 63 6b 00 00 5e 05 5a 77 | 43 6c 6f 73 65 00 7f 00 |ck..^.Zw|Close...|
|000006f0| 45 78 52 61 69 73 65 53 | 74 61 74 75 73 00 8f 02 |ExRaiseS|tatus...|
|00000700| 4b 65 53 65 72 76 69 63 | 65 44 65 73 63 72 69 70 |KeServic|eDescrip|
|00000710| 74 6f 72 54 61 62 6c 65 | 00 00 75 03 4f 62 66 44 |torTable|..u.ObfD|
|00000720| 65 72 65 66 65 72 65 6e | 63 65 4f 62 6a 65 63 74 |ereferen|ceObject|
|00000730| 00 00 94 01 49 6f 47 65 | 74 44 65 76 69 63 65 4f |....IoGe|tDeviceO|
|00000740| 62 6a 65 63 74 50 6f 69 | 6e 74 65 72 00 00 c6 01 |bjectPoi|nter....|
|00000750| 49 6f 52 65 67 69 73 74 | 65 72 50 6c 75 67 50 6c |IoRegist|erPlugPl|
|00000760| 61 79 4e 6f 74 69 66 69 | 63 61 74 69 6f 6e 00 00 |ayNotifi|cation..|
|00000770| 98 03 50 73 47 65 74 43 | 75 72 72 65 6e 74 50 72 |..PsGetC|urrentPr|
|00000780| 6f 63 65 73 73 49 64 00 | df 05 5f 65 78 63 65 70 |ocessId.|.._excep|
|00000790| 74 5f 68 61 6e 64 6c 65 | 72 33 00 00 ef 01 49 6f |t_handle|r3....Io|
|000007a0| 55 6e 72 65 67 69 73 74 | 65 72 50 6c 75 67 50 6c |Unregist|erPlugPl|
|000007b0| 61 79 4e 6f 74 69 66 69 | 63 61 74 69 6f 6e 00 00 |ayNotifi|cation..|
|000007c0| 20 06 77 63 73 6c 65 6e | 00 00 6c 04 52 74 6c 49 | .wcslen|..l.RtlI|
|000007d0| 6e 69 74 55 6e 69 63 6f | 64 65 53 74 72 69 6e 67 |nitUnico|deString|
|000007e0| 00 00 0b 02 49 6f 66 43 | 6f 6d 70 6c 65 74 65 52 |....IofC|ompleteR|
|000007f0| 65 71 75 65 73 74 00 00 | 89 01 49 6f 46 72 65 65 |equest..|..IoFree|
|00000800| 4d 64 6c 00 10 03 4d 6d | 55 6e 6c 6f 63 6b 50 61 |Mdl...Mm|UnlockPa|
|00000810| 67 65 73 00 f5 02 4d 6d | 4d 61 70 4c 6f 63 6b 65 |ges...Mm|MapLocke|
|00000820| 64 50 61 67 65 73 53 70 | 65 63 69 66 79 43 61 63 |dPagesSp|ecifyCac|
|00000830| 68 65 00 00 01 03 4d 6d | 50 72 6f 62 65 41 6e 64 |he....Mm|ProbeAnd|
|00000840| 4c 6f 63 6b 50 61 67 65 | 73 00 4a 01 49 6f 41 6c |LockPage|s.J.IoAl|
|00000850| 6c 6f 63 61 74 65 4d 64 | 6c 00 8a 03 50 72 6f 62 |locateMd|l...Prob|
|00000860| 65 46 6f 72 57 72 69 74 | 65 00 89 03 50 72 6f 62 |eForWrit|e...Prob|
|00000870| 65 46 6f 72 52 65 61 64 | 00 00 ae 02 4b 65 57 61 |eForRead|....KeWa|
|00000880| 69 74 46 6f 72 53 69 6e | 67 6c 65 4f 62 6a 65 63 |itForSin|gleObjec|
|00000890| 74 00 7e 02 4b 65 52 65 | 6c 65 61 73 65 4d 75 74 |t.~.KeRe|leaseMut|
|000008a0| 65 78 00 00 f0 05 5f 77 | 63 73 69 63 6d 70 00 00 |ex...._w|csicmp..|
|000008b0| 9f 05 5a 77 51 75 65 72 | 79 49 6e 66 6f 72 6d 61 |..ZwQuer|yInforma|
|000008c0| 74 69 6f 6e 50 72 6f 63 | 65 73 73 00 9c 03 50 73 |tionProc|ess...Ps|
|000008d0| 47 65 74 43 75 72 72 65 | 6e 74 54 68 72 65 61 64 |GetCurre|ntThread|
|000008e0| 49 64 00 00 94 00 45 78 | 53 79 73 74 65 6d 54 69 |Id....Ex|SystemTi|
|000008f0| 6d 65 54 6f 4c 6f 63 61 | 6c 54 69 6d 65 00 6b 02 |meToLoca|lTime.k.|
|00000900| 4b 65 51 75 65 72 79 53 | 79 73 74 65 6d 54 69 6d |KeQueryS|ystemTim|
|00000910| 65 00 89 05 5a 77 4f 70 | 65 6e 50 72 6f 63 65 73 |e...ZwOp|enProces|
|00000920| 73 00 fa 03 52 74 6c 41 | 70 70 65 6e 64 55 6e 69 |s...RtlA|ppendUni|
|00000930| 63 6f 64 65 53 74 72 69 | 6e 67 54 6f 53 74 72 69 |codeStri|ngToStri|
|00000940| 6e 67 00 00 0b 04 52 74 | 6c 43 6f 6d 70 61 72 65 |ng....Rt|lCompare|
|00000950| 55 6e 69 63 6f 64 65 53 | 74 72 69 6e 67 00 1c 06 |UnicodeS|tring...|
|00000960| 77 63 73 63 68 72 00 00 | f2 05 5f 77 63 73 6e 69 |wcschr..|.._wcsni|
|00000970| 63 6d 70 00 4a 02 4b 65 | 49 6e 69 74 69 61 6c 69 |cmp.J.Ke|Initiali|
|00000980| 7a 65 45 76 65 6e 74 00 | 6d 05 5a 77 44 65 6c 65 |zeEvent.|m.ZwDele|
|00000990| 74 65 56 61 6c 75 65 4b | 65 79 00 00 6c 05 5a 77 |teValueK|ey..l.Zw|
|000009a0| 44 65 6c 65 74 65 4b 65 | 79 00 02 06 6d 65 6d 6d |DeleteKe|y...memm|
|000009b0| 6f 76 65 00 93 02 4b 65 | 53 65 74 45 76 65 6e 74 |ove...Ke|SetEvent|
|000009c0| 00 00 4b 01 49 6f 41 6c | 6c 6f 63 61 74 65 57 6f |..K.IoAl|locateWo|
|000009d0| 72 6b 49 74 65 6d 00 00 | 8a 01 49 6f 46 72 65 65 |rkItem..|..IoFree|
|000009e0| 57 6f 72 6b 49 74 65 6d | 00 00 b8 01 49 6f 51 75 |WorkItem|....IoQu|
|000009f0| 65 75 65 57 6f 72 6b 49 | 74 65 6d 00 e9 02 4d 6d |eueWorkI|tem...Mm|
|00000a00| 49 73 41 64 64 72 65 73 | 73 56 61 6c 69 64 00 00 |IsAddres|sValid..|
|00000a10| a8 05 5a 77 51 75 65 72 | 79 53 79 73 74 65 6d 49 |..ZwQuer|ySystemI|
|00000a20| 6e 66 6f 72 6d 61 74 69 | 6f 6e 00 00 23 06 77 63 |nformati|on..#.wc|
|00000a30| 73 6e 63 70 79 00 22 06 | 77 63 73 6e 63 6d 70 00 |sncpy.".|wcsncmp.|
|00000a40| c6 05 5a 77 54 65 72 6d | 69 6e 61 74 65 50 72 6f |..ZwTerm|inatePro|
|00000a50| 63 65 73 73 00 00 a8 02 | 4b 65 55 6e 73 74 61 63 |cess....|KeUnstac|
|00000a60| 6b 44 65 74 61 63 68 50 | 72 6f 63 65 73 73 00 00 |kDetachP|rocess..|
|00000a70| a1 02 4b 65 53 74 61 63 | 6b 41 74 74 61 63 68 50 |..KeStac|kAttachP|
|00000a80| 72 6f 63 65 73 73 00 00 | 6d 03 4f 62 52 65 66 65 |rocess..|m.ObRefe|
|00000a90| 72 65 6e 63 65 4f 62 6a | 65 63 74 42 79 48 61 6e |renceObj|ectByHan|
|00000aa0| 64 6c 65 00 ca 03 50 73 | 4c 6f 6f 6b 75 70 50 72 |dle...Ps|LookupPr|
|00000ab0| 6f 63 65 73 73 42 79 50 | 72 6f 63 65 73 73 49 64 |ocessByP|rocessId|
|00000ac0| 00 00 0e 06 73 74 72 6e | 63 6d 70 00 14 06 74 6f |....strn|cmp...to|
|00000ad0| 6c 6f 77 65 72 00 84 05 | 5a 77 4f 70 65 6e 44 69 |lower...|ZwOpenDi|
|00000ae0| 72 65 63 74 6f 72 79 4f | 62 6a 65 63 74 00 8d 05 |rectoryO|bject...|
|00000af0| 5a 77 4f 70 65 6e 53 79 | 6d 62 6f 6c 69 63 4c 69 |ZwOpenSy|mbolicLi|
|00000b00| 6e 6b 4f 62 6a 65 63 74 | 00 00 a7 05 5a 77 51 75 |nkObject|....ZwQu|
|00000b10| 65 72 79 53 79 6d 62 6f | 6c 69 63 4c 69 6e 6b 4f |erySymbo|licLinkO|
|00000b20| 62 6a 65 63 74 00 99 05 | 5a 77 51 75 65 72 79 44 |bject...|ZwQueryD|
|00000b30| 69 72 65 63 74 6f 72 79 | 4f 62 6a 65 63 74 00 00 |irectory|Object..|
|00000b40| fb 03 52 74 6c 41 70 70 | 65 6e 64 55 6e 69 63 6f |..RtlApp|endUnico|
|00000b50| 64 65 54 6f 53 74 72 69 | 6e 67 00 00 6b 03 4f 62 |deToStri|ng..k.Ob|
|00000b60| 51 75 65 72 79 4e 61 6d | 65 53 74 72 69 6e 67 00 |QueryNam|eString.|
|00000b70| 77 05 5a 77 46 6c 75 73 | 68 4b 65 79 00 00 a9 05 |w.ZwFlus|hKey....|
|00000b80| 5a 77 51 75 65 72 79 56 | 61 6c 75 65 4b 65 79 00 |ZwQueryV|alueKey.|
|00000b90| a3 05 5a 77 51 75 65 72 | 79 4b 65 79 00 00 c3 05 |..ZwQuer|yKey....|
|00000ba0| 5a 77 53 65 74 56 61 6c | 75 65 4b 65 79 00 75 05 |ZwSetVal|ueKey.u.|
|00000bb0| 5a 77 45 6e 75 6d 65 72 | 61 74 65 56 61 6c 75 65 |ZwEnumer|ateValue|
|00000bc0| 4b 65 79 00 74 05 5a 77 | 45 6e 75 6d 65 72 61 74 |Key.t.Zw|Enumerat|
|00000bd0| 65 4b 65 79 00 00 88 05 | 5a 77 4f 70 65 6e 4b 65 |eKey....|ZwOpenKe|
|00000be0| 79 00 65 05 5a 77 43 72 | 65 61 74 65 4b 65 79 00 |y.e.ZwCr|eateKey.|
|00000bf0| c1 03 50 73 47 65 74 56 | 65 72 73 69 6f 6e 00 00 |..PsGetV|ersion..|
|00000c00| a5 02 4b 65 54 69 63 6b | 43 6f 75 6e 74 00 26 02 |..KeTick|Count.&.|
|00000c10| 4b 65 42 75 67 43 68 65 | 63 6b 45 78 00 00 6e 74 |KeBugChe|ckEx..nt|
|00000c20| 6f 73 6b 72 6e 6c 2e 65 | 78 65 00 00 00 00 45 78 |oskrnl.e|xe....Ex|
|00000c30| 41 63 71 75 69 72 65 46 | 61 73 74 4d 75 74 65 78 |AcquireF|astMutex|
|00000c40| 00 00 01 00 45 78 52 65 | 6c 65 61 73 65 46 61 73 |....ExRe|leaseFas|
|00000c50| 74 4d 75 74 65 78 00 00 | 48 41 4c 2e 64 6c 6c 00 |tMutex..|HAL.dll.|
|00000c60| 05 00 5f 43 6f 52 65 67 | 69 73 74 65 72 43 6c 61 |.._CoReg|isterCla|
|00000c70| 73 73 4f 62 6a 65 63 74 | 40 32 30 00 02 00 5f 43 |ssObject|@20..._C|
|00000c80| 6f 43 72 65 61 74 65 49 | 6e 73 74 61 6e 63 65 40 |oCreateI|nstance@|
|00000c90| 32 30 00 00 04 00 5f 43 | 6f 49 6e 69 74 69 61 6c |20...._C|oInitial|
|00000ca0| 69 7a 65 40 34 00 4b 43 | 4f 4d 2e 53 59 53 00 00 |ize@4.KC|OM.SYS..|
|00000cb0| 02 00 53 63 61 6e 45 76 | 65 6e 74 00 01 00 49 73 |..ScanEv|ent...Is|
|00000cc0| 52 65 67 69 73 74 72 79 | 50 6f 72 74 43 6f 6e 6e |Registry|PortConn|
|00000cd0| 65 63 74 65 64 00 00 00 | 49 73 50 72 6f 63 65 73 |ected...|IsProces|
|00000ce0| 73 50 6f 72 74 43 6f 6e | 6e 65 63 74 65 64 00 00 |sPortCon|nected..|
|00000cf0| 69 6b 66 69 6c 65 73 65 | 63 2e 53 59 53 00 f5 03 |ikfilese|c.SYS...|
|00000d00| 52 74 6c 41 6e 73 69 43 | 68 61 72 54 6f 55 6e 69 |RtlAnsiC|harToUni|
|00000d10| 63 6f 64 65 43 68 61 72 | 00 00 76 01 49 6f 44 65 |codeChar|..v.IoDe|
|00000d20| 6c 65 74 65 44 65 76 69 | 63 65 00 00 6c 01 49 6f |leteDevi|ce..l.Io|
|00000d30| 43 72 65 61 74 65 53 79 | 6d 62 6f 6c 69 63 4c 69 |CreateSy|mbolicLi|
|00000d40| 6e 6b 00 00 78 01 49 6f | 44 65 6c 65 74 65 53 79 |nk..x.Io|DeleteSy|
|00000d50| 6d 62 6f 6c 69 63 4c 69 | 6e 6b 00 00 c7 01 49 6f |mbolicLi|nk....Io|
|00000d60| 52 65 67 69 73 74 65 72 | 53 68 75 74 64 6f 77 6e |Register|Shutdown|
|00000d70| 4e 6f 74 69 66 69 63 61 | 74 69 6f 6e 00 00 f0 01 |Notifica|tion....|
|00000d80| 49 6f 55 6e 72 65 67 69 | 73 74 65 72 53 68 75 74 |IoUnregi|sterShut|
|00000d90| 64 6f 77 6e 4e 6f 74 69 | 66 69 63 61 74 69 6f 6e |downNoti|fication|
|00000da0| 00 00 63 01 49 6f 43 72 | 65 61 74 65 44 65 76 69 |..c.IoCr|eateDevi|
|00000db0| 63 65 00 00 15 04 52 74 | 6c 43 6f 70 79 55 6e 69 |ce....Rt|lCopyUni|
|00000dc0| 63 6f 64 65 53 74 72 69 | 6e 67 00 00 4e 02 4b 65 |codeStri|ng..N.Ke|
|00000dd0| 49 6e 69 74 69 61 6c 69 | 7a 65 4d 75 74 65 78 00 |Initiali|zeMutex.|
|00000de0| 63 05 5a 77 43 72 65 61 | 74 65 46 69 6c 65 00 00 |c.ZwCrea|teFile..|
|00000df0| ab 05 5a 77 52 65 61 64 | 46 69 6c 65 00 00 cd 05 |..ZwRead|File....|
|00000e00| 5a 77 57 72 69 74 65 46 | 69 6c 65 00 9d 05 5a 77 |ZwWriteF|ile...Zw|
|00000e10| 51 75 65 72 79 49 6e 66 | 6f 72 6d 61 74 69 6f 6e |QueryInf|ormation|
|00000e20| 46 69 6c 65 00 00 ba 05 | 5a 77 53 65 74 49 6e 66 |File....|ZwSetInf|
|00000e30| 6f 72 6d 61 74 69 6f 6e | 46 69 6c 65 00 00 00 00 |ormation|File....|
|00000e40| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000e50| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000e60| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000e70| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000e80| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000e90| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000ea0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000eb0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000ec0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000ed0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000ee0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000ef0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000f00| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000f10| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000f20| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000f30| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000f40| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000f50| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000f60| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000f70| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000f80| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000f90| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000fa0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000fb0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000fc0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000fd0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000fe0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
|00000ff0| 00 00 00 00 00 00 00 00 | 00 00 00 00 00 00 00 00 |........|........|
+--------+-------------------------+-------------------------+--------+--------+