ofs | hex dump | ascii |
---|
0000 | 21 3c 61 72 63 68 3e 0a 2f 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 31 35 31 36 31 36 31 30 | !<arch>./...............15161610 |
0020 | 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 30 20 20 20 20 20 20 20 32 38 39 36 20 20 20 20 | 48..0.....0.....0.......2896.... |
0040 | 20 20 60 0a 00 00 00 5a 00 00 0b 94 00 00 0e 3e 00 00 11 5a 00 00 11 5a 00 00 14 3c 00 00 14 3c | ..`....Z.......>...Z...Z...<...< |
0060 | 00 00 17 12 00 00 17 12 00 00 1a 16 00 00 1a 16 00 00 1c de 00 00 1c de 00 00 1f ca 00 00 1f ca | ................................ |
0080 | 00 00 22 96 00 00 22 96 00 00 25 60 00 00 25 60 00 00 28 3e 00 00 28 3e 00 00 2b 38 00 00 2b 38 | .."..."...%`..%`..(>..(>..+8..+8 |
00a0 | 00 00 2e 24 00 00 2e 24 00 00 30 f6 00 00 30 f6 00 00 33 ee 00 00 33 ee 00 00 36 d6 00 00 36 d6 | ...$...$..0...0...3...3...6...6. |
00c0 | 00 00 39 c4 00 00 39 c4 00 00 3c ae 00 00 3c ae 00 00 3f 9a 00 00 3f 9a 00 00 42 84 00 00 42 84 | ..9...9...<...<...?...?...B...B. |
00e0 | 00 00 45 4c 00 00 45 4c 00 00 48 60 00 00 48 60 00 00 4b 4c 00 00 4b 4c 00 00 4e 5c 00 00 4e 5c | ..EL..EL..H`..H`..KL..KL..N\..N\ |
0100 | 00 00 51 7a 00 00 51 7a 00 00 54 8e 00 00 54 8e 00 00 57 9c 00 00 57 9c 00 00 5a 94 00 00 5a 94 | ..Qz..Qz..T...T...W...W...Z...Z. |
0120 | 00 00 5d a4 00 00 5d a4 00 00 60 8e 00 00 60 8e 00 00 63 6e 00 00 63 6e 00 00 66 7e 00 00 66 7e | ..]...]...`...`...cn..cn..f~..f~ |
0140 | 00 00 69 6c 00 00 69 6c 00 00 6c 68 00 00 6c 68 00 00 6f 40 00 00 6f 40 00 00 72 2e 00 00 72 2e | ..il..il..lh..lh..o@..o@..r...r. |
0160 | 00 00 75 32 00 00 75 32 00 00 78 12 00 00 78 12 00 00 7b 16 00 00 7b 16 00 00 7d f8 00 00 7d f8 | ..u2..u2..x...x...{...{...}...}. |
0180 | 00 00 80 ce 00 00 80 ce 00 00 83 c4 00 00 83 c4 00 00 86 a6 00 00 86 a6 00 00 89 6e 00 00 89 6e | ...........................n...n |
01a0 | 00 00 8c 42 00 00 8c 42 00 00 8f 0c 00 00 8f 0c 5f 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 | ...B...B........__C__Users_Peter |
01c0 | 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 | _Code_winapi_rs_i686_lib_libwina |
01e0 | 70 69 5f 77 65 76 74 61 70 69 5f 61 5f 69 6e 61 6d 65 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 | pi_wevtapi_a_iname.__head_C__Use |
0200 | 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 | rs_Peter_Code_winapi_rs_i686_lib |
0220 | 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 5f 45 76 74 55 70 64 61 74 65 42 | _libwinapi_wevtapi_a._EvtUpdateB |
0240 | 6f 6f 6b 6d 61 72 6b 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 55 70 64 61 74 65 42 6f 6f 6b 6d 61 | ookmark@8.__imp__EvtUpdateBookma |
0260 | 72 6b 40 38 00 5f 45 76 74 53 75 62 73 63 72 69 62 65 40 33 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 | rk@8._EvtSubscribe@32.__imp__Evt |
0280 | 53 75 62 73 63 72 69 62 65 40 33 32 00 5f 45 76 74 53 65 74 43 68 61 6e 6e 65 6c 43 6f 6e 66 69 | Subscribe@32._EvtSetChannelConfi |
02a0 | 67 50 72 6f 70 65 72 74 79 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 53 65 74 43 68 61 6e 6e 65 | gProperty@16.__imp__EvtSetChanne |
02c0 | 6c 43 6f 6e 66 69 67 50 72 6f 70 65 72 74 79 40 31 36 00 5f 45 76 74 53 65 65 6b 40 32 34 00 5f | lConfigProperty@16._EvtSeek@24._ |
02e0 | 5f 69 6d 70 5f 5f 45 76 74 53 65 65 6b 40 32 34 00 5f 45 76 74 53 61 76 65 43 68 61 6e 6e 65 6c | _imp__EvtSeek@24._EvtSaveChannel |
0300 | 43 6f 6e 66 69 67 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 53 61 76 65 43 68 61 6e 6e 65 6c 43 6f | Config@8.__imp__EvtSaveChannelCo |
0320 | 6e 66 69 67 40 38 00 5f 45 76 74 52 65 6e 64 65 72 40 32 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 52 | nfig@8._EvtRender@28.__imp__EvtR |
0340 | 65 6e 64 65 72 40 32 38 00 5f 45 76 74 51 75 65 72 79 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 | ender@28._EvtQuery@16.__imp__Evt |
0360 | 51 75 65 72 79 40 31 36 00 5f 45 76 74 4f 70 65 6e 53 65 73 73 69 6f 6e 40 31 36 00 5f 5f 69 6d | Query@16._EvtOpenSession@16.__im |
0380 | 70 5f 5f 45 76 74 4f 70 65 6e 53 65 73 73 69 6f 6e 40 31 36 00 5f 45 76 74 4f 70 65 6e 50 75 62 | p__EvtOpenSession@16._EvtOpenPub |
03a0 | 6c 69 73 68 65 72 4d 65 74 61 64 61 74 61 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e | lisherMetadata@20.__imp__EvtOpen |
03c0 | 50 75 62 6c 69 73 68 65 72 4d 65 74 61 64 61 74 61 40 32 30 00 5f 45 76 74 4f 70 65 6e 50 75 62 | PublisherMetadata@20._EvtOpenPub |
03e0 | 6c 69 73 68 65 72 45 6e 75 6d 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 50 75 62 6c 69 | lisherEnum@8.__imp__EvtOpenPubli |
0400 | 73 68 65 72 45 6e 75 6d 40 38 00 5f 45 76 74 4f 70 65 6e 4c 6f 67 40 31 32 00 5f 5f 69 6d 70 5f | sherEnum@8._EvtOpenLog@12.__imp_ |
0420 | 5f 45 76 74 4f 70 65 6e 4c 6f 67 40 31 32 00 5f 45 76 74 4f 70 65 6e 45 76 65 6e 74 4d 65 74 61 | _EvtOpenLog@12._EvtOpenEventMeta |
0440 | 64 61 74 61 45 6e 75 6d 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 45 76 65 6e 74 4d 65 | dataEnum@8.__imp__EvtOpenEventMe |
0460 | 74 61 64 61 74 61 45 6e 75 6d 40 38 00 5f 45 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 45 6e 75 6d | tadataEnum@8._EvtOpenChannelEnum |
0480 | 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 45 6e 75 6d 40 38 00 5f | @8.__imp__EvtOpenChannelEnum@8._ |
04a0 | 45 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 43 6f 6e 66 69 67 40 31 32 00 5f 5f 69 6d 70 5f 5f 45 | EvtOpenChannelConfig@12.__imp__E |
04c0 | 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 43 6f 6e 66 69 67 40 31 32 00 5f 45 76 74 4e 65 78 74 50 | vtOpenChannelConfig@12._EvtNextP |
04e0 | 75 62 6c 69 73 68 65 72 49 64 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 4e 65 78 74 50 75 62 6c | ublisherId@16.__imp__EvtNextPubl |
0500 | 69 73 68 65 72 49 64 40 31 36 00 5f 45 76 74 4e 65 78 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 | isherId@16._EvtNextEventMetadata |
0520 | 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 4e 65 78 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 40 38 | @8.__imp__EvtNextEventMetadata@8 |
0540 | 00 5f 45 76 74 4e 65 78 74 43 68 61 6e 6e 65 6c 50 61 74 68 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 | ._EvtNextChannelPath@16.__imp__E |
0560 | 76 74 4e 65 78 74 43 68 61 6e 6e 65 6c 50 61 74 68 40 31 36 00 5f 45 76 74 4e 65 78 74 40 32 34 | vtNextChannelPath@16._EvtNext@24 |
0580 | 00 5f 5f 69 6d 70 5f 5f 45 76 74 4e 65 78 74 40 32 34 00 5f 45 76 74 49 6e 74 57 72 69 74 65 58 | .__imp__EvtNext@24._EvtIntWriteX |
05a0 | 6d 6c 45 76 65 6e 74 54 6f 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 40 31 32 00 5f 5f 69 6d 70 5f 5f | mlEventToLocalLogfile@12.__imp__ |
05c0 | 45 76 74 49 6e 74 57 72 69 74 65 58 6d 6c 45 76 65 6e 74 54 6f 4c 6f 63 61 6c 4c 6f 67 66 69 6c | EvtIntWriteXmlEventToLocalLogfil |
05e0 | 65 40 31 32 00 5f 45 76 74 49 6e 74 52 65 74 72 61 63 74 43 6f 6e 66 69 67 40 31 32 00 5f 5f 69 | e@12._EvtIntRetractConfig@12.__i |
0600 | 6d 70 5f 5f 45 76 74 49 6e 74 52 65 74 72 61 63 74 43 6f 6e 66 69 67 40 31 32 00 5f 45 76 74 49 | mp__EvtIntRetractConfig@12._EvtI |
0620 | 6e 74 52 65 70 6f 72 74 45 76 65 6e 74 41 6e 64 53 6f 75 72 63 65 41 73 79 6e 63 40 34 34 00 5f | ntReportEventAndSourceAsync@44._ |
0640 | 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 52 65 70 6f 72 74 45 76 65 6e 74 41 6e 64 53 6f 75 72 63 65 | _imp__EvtIntReportEventAndSource |
0660 | 41 73 79 6e 63 40 34 34 00 5f 45 76 74 49 6e 74 52 65 70 6f 72 74 41 75 74 68 7a 45 76 65 6e 74 | Async@44._EvtIntReportAuthzEvent |
0680 | 41 6e 64 53 6f 75 72 63 65 41 73 79 6e 63 40 34 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 52 | AndSourceAsync@44.__imp__EvtIntR |
06a0 | 65 70 6f 72 74 41 75 74 68 7a 45 76 65 6e 74 41 6e 64 53 6f 75 72 63 65 41 73 79 6e 63 40 34 34 | eportAuthzEventAndSourceAsync@44 |
06c0 | 00 5f 45 76 74 49 6e 74 52 65 6e 64 65 72 52 65 73 6f 75 72 63 65 45 76 65 6e 74 54 65 6d 70 6c | ._EvtIntRenderResourceEventTempl |
06e0 | 61 74 65 40 33 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 52 65 6e 64 65 72 52 65 73 6f 75 72 | ate@32.__imp__EvtIntRenderResour |
0700 | 63 65 45 76 65 6e 74 54 65 6d 70 6c 61 74 65 40 33 32 00 5f 45 76 74 49 6e 74 47 65 74 43 6c 61 | ceEventTemplate@32._EvtIntGetCla |
0720 | 73 73 69 63 4c 6f 67 44 69 73 70 6c 61 79 4e 61 6d 65 40 32 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 | ssicLogDisplayName@28.__imp__Evt |
0740 | 49 6e 74 47 65 74 43 6c 61 73 73 69 63 4c 6f 67 44 69 73 70 6c 61 79 4e 61 6d 65 40 32 38 00 5f | IntGetClassicLogDisplayName@28._ |
0760 | 45 76 74 49 6e 74 43 72 65 61 74 65 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 40 38 00 5f 5f 69 6d 70 | EvtIntCreateLocalLogfile@8.__imp |
0780 | 5f 5f 45 76 74 49 6e 74 43 72 65 61 74 65 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 40 38 00 5f 45 76 | __EvtIntCreateLocalLogfile@8._Ev |
07a0 | 74 49 6e 74 43 72 65 61 74 65 42 69 6e 58 4d 4c 46 72 6f 6d 43 75 73 74 6f 6d 58 4d 4c 40 33 32 | tIntCreateBinXMLFromCustomXML@32 |
07c0 | 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 43 72 65 61 74 65 42 69 6e 58 4d 4c 46 72 6f 6d 43 75 | .__imp__EvtIntCreateBinXMLFromCu |
07e0 | 73 74 6f 6d 58 4d 4c 40 33 32 00 5f 45 76 74 49 6e 74 41 73 73 65 72 74 43 6f 6e 66 69 67 40 31 | stomXML@32._EvtIntAssertConfig@1 |
0800 | 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 41 73 73 65 72 74 43 6f 6e 66 69 67 40 31 32 00 5f | 2.__imp__EvtIntAssertConfig@12._ |
0820 | 45 76 74 47 65 74 51 75 65 72 79 49 6e 66 6f 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 | EvtGetQueryInfo@20.__imp__EvtGet |
0840 | 51 75 65 72 79 49 6e 66 6f 40 32 30 00 5f 45 76 74 47 65 74 50 75 62 6c 69 73 68 65 72 4d 65 74 | QueryInfo@20._EvtGetPublisherMet |
0860 | 61 64 61 74 61 50 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 50 75 | adataProperty@24.__imp__EvtGetPu |
0880 | 62 6c 69 73 68 65 72 4d 65 74 61 64 61 74 61 50 72 6f 70 65 72 74 79 40 32 34 00 5f 45 76 74 47 | blisherMetadataProperty@24._EvtG |
08a0 | 65 74 4f 62 6a 65 63 74 41 72 72 61 79 53 69 7a 65 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 | etObjectArraySize@8.__imp__EvtGe |
08c0 | 74 4f 62 6a 65 63 74 41 72 72 61 79 53 69 7a 65 40 38 00 5f 45 76 74 47 65 74 4f 62 6a 65 63 74 | tObjectArraySize@8._EvtGetObject |
08e0 | 41 72 72 61 79 50 72 6f 70 65 72 74 79 40 32 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 4f 62 | ArrayProperty@28.__imp__EvtGetOb |
0900 | 6a 65 63 74 41 72 72 61 79 50 72 6f 70 65 72 74 79 40 32 38 00 5f 45 76 74 47 65 74 4c 6f 67 49 | jectArrayProperty@28._EvtGetLogI |
0920 | 6e 66 6f 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 4c 6f 67 49 6e 66 6f 40 32 30 00 5f | nfo@20.__imp__EvtGetLogInfo@20._ |
0940 | 45 76 74 47 65 74 45 78 74 65 6e 64 65 64 53 74 61 74 75 73 40 31 32 00 5f 5f 69 6d 70 5f 5f 45 | EvtGetExtendedStatus@12.__imp__E |
0960 | 76 74 47 65 74 45 78 74 65 6e 64 65 64 53 74 61 74 75 73 40 31 32 00 5f 45 76 74 47 65 74 45 76 | vtGetExtendedStatus@12._EvtGetEv |
0980 | 65 6e 74 4d 65 74 61 64 61 74 61 50 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 76 | entMetadataProperty@24.__imp__Ev |
09a0 | 74 47 65 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 50 72 6f 70 65 72 74 79 40 32 34 00 5f 45 76 | tGetEventMetadataProperty@24._Ev |
09c0 | 74 47 65 74 45 76 65 6e 74 49 6e 66 6f 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 45 76 | tGetEventInfo@20.__imp__EvtGetEv |
09e0 | 65 6e 74 49 6e 66 6f 40 32 30 00 5f 45 76 74 47 65 74 43 68 61 6e 6e 65 6c 43 6f 6e 66 69 67 50 | entInfo@20._EvtGetChannelConfigP |
0a00 | 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 43 68 61 6e 6e 65 6c 43 | roperty@24.__imp__EvtGetChannelC |
0a20 | 6f 6e 66 69 67 50 72 6f 70 65 72 74 79 40 32 34 00 5f 45 76 74 46 6f 72 6d 61 74 4d 65 73 73 61 | onfigProperty@24._EvtFormatMessa |
0a40 | 67 65 40 33 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 46 6f 72 6d 61 74 4d 65 73 73 61 67 65 40 33 36 | ge@36.__imp__EvtFormatMessage@36 |
0a60 | 00 5f 45 76 74 45 78 70 6f 72 74 4c 6f 67 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 45 78 70 6f | ._EvtExportLog@20.__imp__EvtExpo |
0a80 | 72 74 4c 6f 67 40 32 30 00 5f 45 76 74 43 72 65 61 74 65 52 65 6e 64 65 72 43 6f 6e 74 65 78 74 | rtLog@20._EvtCreateRenderContext |
0aa0 | 40 31 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 43 72 65 61 74 65 52 65 6e 64 65 72 43 6f 6e 74 65 78 | @12.__imp__EvtCreateRenderContex |
0ac0 | 74 40 31 32 00 5f 45 76 74 43 72 65 61 74 65 42 6f 6f 6b 6d 61 72 6b 40 34 00 5f 5f 69 6d 70 5f | t@12._EvtCreateBookmark@4.__imp_ |
0ae0 | 5f 45 76 74 43 72 65 61 74 65 42 6f 6f 6b 6d 61 72 6b 40 34 00 5f 45 76 74 43 6c 6f 73 65 40 34 | _EvtCreateBookmark@4._EvtClose@4 |
0b00 | 00 5f 5f 69 6d 70 5f 5f 45 76 74 43 6c 6f 73 65 40 34 00 5f 45 76 74 43 6c 65 61 72 4c 6f 67 40 | .__imp__EvtClose@4._EvtClearLog@ |
0b20 | 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 43 6c 65 61 72 4c 6f 67 40 31 36 00 5f 45 76 74 43 61 6e | 16.__imp__EvtClearLog@16._EvtCan |
0b40 | 63 65 6c 40 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 43 61 6e 63 65 6c 40 34 00 5f 45 76 74 41 72 63 | cel@4.__imp__EvtCancel@4._EvtArc |
0b60 | 68 69 76 65 45 78 70 6f 72 74 65 64 4c 6f 67 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 41 72 63 | hiveExportedLog@16.__imp__EvtArc |
0b80 | 68 69 76 65 45 78 70 6f 72 74 65 64 4c 6f 67 40 31 36 00 00 64 77 76 6c 74 2e 6f 2f 20 20 20 20 | hiveExportedLog@16..dwvlt.o/.... |
0ba0 | 20 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 | ....1516161048..0.....0.....1006 |
0bc0 | 36 36 20 20 36 32 31 20 20 20 20 20 20 20 60 0a 4c 01 06 00 00 00 00 00 18 01 00 00 0f 00 00 00 | 66..621.......`.L............... |
0be0 | 00 00 05 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | .....text....................... |
0c00 | 00 00 00 00 00 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........0`.data............... |
0c20 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 | ................@.0..bss........ |
0c40 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 | ..........................0..ida |
0c60 | 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 04 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ta$4............................ |
0c80 | 40 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 08 01 00 00 00 00 00 00 | @.0..idata$5.................... |
0ca0 | 00 00 00 00 00 00 00 00 40 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 0c 00 00 00 | ........@.0..idata$7............ |
0cc0 | 0c 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 00 00 00 00 00 00 00 00 77 65 76 74 | ................@.0.........wevt |
0ce0 | 61 70 69 2e 64 6c 6c 00 2e 66 69 6c 65 00 00 00 00 00 00 00 fe ff 00 00 67 01 66 61 6b 65 00 00 | api.dll..file...........g.fake.. |
0d00 | 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 01 00 00 | .............text............... |
0d20 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 | .................data........... |
0d40 | 03 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 62 73 73 00 00 00 00 00 00 00 00 | .....................bss........ |
0d60 | 03 00 00 00 03 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 69 64 61 74 61 24 34 | .........................idata$4 |
0d80 | 00 00 00 00 04 00 00 00 03 01 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 69 64 61 | .............................ida |
0da0 | 74 61 24 35 00 00 00 00 05 00 00 00 03 01 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ta$5............................ |
0dc0 | 2e 69 64 61 74 61 24 37 00 00 00 00 06 00 00 00 03 01 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 | .idata$7........................ |
0de0 | 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 06 00 00 00 02 00 47 00 00 00 5f 5f 43 5f 5f 55 | ......................G...__C__U |
0e00 | 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c | sers_Peter_Code_winapi_rs_i686_l |
0e20 | 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 5f 69 6e 61 6d 65 00 0a 64 77 | ib_libwinapi_wevtapi_a_iname..dw |
0e40 | 76 6c 68 2e 6f 2f 20 20 20 20 20 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 | vlh.o/........1516161048..0..... |
0e60 | 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 33 35 20 20 20 20 20 20 20 60 0a 4c 01 06 00 00 00 | 0.....100666..735.......`.L..... |
0e80 | 00 00 36 01 00 00 10 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..6............text............. |
0ea0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 | ....................0`.data..... |
0ec0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 | ..........................@.0..b |
0ee0 | 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ss.............................. |
0f00 | 00 00 80 00 30 c0 2e 69 64 61 74 61 24 32 00 00 00 00 00 00 00 00 14 00 00 00 04 01 00 00 18 01 | ....0..idata$2.................. |
0f20 | 00 00 00 00 00 00 03 00 00 00 40 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 00 00 | ..........@.0..idata$5.......... |
0f40 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 69 64 61 74 61 24 34 00 00 | ..................@.0..idata$4.. |
0f60 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 00 00 | ..........................@.0... |
0f80 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0c 00 00 00 07 00 0c 00 00 00 | ................................ |
0fa0 | 0f 00 00 00 07 00 10 00 00 00 0d 00 00 00 07 00 2e 66 69 6c 65 00 00 00 00 00 00 00 fe ff 00 00 | .................file........... |
0fc0 | 67 01 66 61 6b 65 00 00 00 00 00 00 00 00 00 00 00 00 00 00 68 6e 61 6d 65 00 00 00 00 00 00 00 | g.fake..............hname....... |
0fe0 | 06 00 00 00 03 00 66 74 68 75 6e 6b 00 00 00 00 00 00 05 00 00 00 03 00 2e 74 65 78 74 00 00 00 | ......fthunk.............text... |
1000 | 00 00 00 00 01 00 00 00 03 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 64 61 74 | .............................dat |
1020 | 61 00 00 00 00 00 00 00 02 00 00 00 03 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | a............................... |
1040 | 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | .bss............................ |
1060 | 00 00 00 00 2e 69 64 61 74 61 24 32 00 00 00 00 04 00 00 00 03 01 14 00 00 00 03 00 00 00 00 00 | .....idata$2.................... |
1080 | 00 00 00 00 00 00 00 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$4...........idata |
10a0 | 24 35 00 00 00 00 05 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 04 00 00 00 02 00 00 00 | $5.............................. |
10c0 | 00 00 46 00 00 00 00 00 00 00 00 00 00 00 02 00 89 00 00 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 | ..F.................__head_C__Us |
10e0 | 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 | ers_Peter_Code_winapi_rs_i686_li |
1100 | 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 5f 5f 43 5f 5f 55 73 65 72 73 | b_libwinapi_wevtapi_a.__C__Users |
1120 | 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c | _Peter_Code_winapi_rs_i686_lib_l |
1140 | 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 5f 69 6e 61 6d 65 00 0a 64 77 76 6c 73 30 | ibwinapi_wevtapi_a_iname..dwvls0 |
1160 | 30 30 34 33 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 | 0043.o/...1516161048..0.....0... |
1180 | 20 20 31 30 30 36 36 36 20 20 36 37 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 7c 01 | ..100666..678.......`.L.......|. |
11a0 | 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 | ...........text...............,. |
11c0 | 00 00 54 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 | ..T.............0`.data......... |
11e0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 | ......................@.0..bss.. |
1200 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 | ................................ |
1220 | 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 5e 01 00 00 00 00 | 0..idata$7............4...^..... |
1240 | 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 | ........0..idata$5............8. |
1260 | 00 00 68 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 | ..h.............0..idata$4...... |
1280 | 00 00 04 00 00 00 3c 01 00 00 72 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 | ......<...r.............0..idata |
12a0 | 24 36 00 00 00 00 00 00 00 00 14 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | $6............@................. |
12c0 | 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 2b 00 45 76 74 55 70 64 61 74 | ...%..................+.EvtUpdat |
12e0 | 65 42 6f 6f 6b 6d 61 72 6b 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 | eBookmark....................... |
1300 | 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 | ...................text......... |
1320 | 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 | .....data..............bss...... |
1340 | 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$7...........idata |
1360 | 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 | $5...........idata$4...........i |
1380 | 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 | data$6.......................... |
13a0 | 02 00 00 00 00 00 19 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 34 00 00 00 00 00 00 00 | ........................4....... |
13c0 | 00 00 00 00 02 00 76 00 00 00 5f 45 76 74 55 70 64 61 74 65 42 6f 6f 6b 6d 61 72 6b 40 38 00 5f | ......v..._EvtUpdateBookmark@8._ |
13e0 | 5f 69 6d 70 5f 5f 45 76 74 55 70 64 61 74 65 42 6f 6f 6b 6d 61 72 6b 40 38 00 5f 5f 68 65 61 64 | _imp__EvtUpdateBookmark@8.__head |
1400 | 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 | _C__Users_Peter_Code_winapi_rs_i |
1420 | 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c | 686_lib_libwinapi_wevtapi_a.dwvl |
1440 | 73 30 30 30 34 32 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 | s00042.o/...1516161048..0.....0. |
1460 | 20 20 20 20 31 30 30 36 36 36 20 20 36 36 36 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 | ....100666..666.......`.L....... |
1480 | 78 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 | x............text............... |
14a0 | 2c 01 00 00 50 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 | ,...P.............0`.data....... |
14c0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 | ........................@.0..bss |
14e0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
1500 | 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 5a 01 00 00 | ..0..idata$7............4...Z... |
1520 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$5............ |
1540 | 38 01 00 00 64 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 | 8...d.............0..idata$4.... |
1560 | 00 00 00 00 04 00 00 00 3c 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........<...n.............0..ida |
1580 | 74 61 24 36 00 00 00 00 00 00 00 00 10 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ta$6............@............... |
15a0 | 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 2a 00 45 76 74 53 75 62 | .....%..................*.EvtSub |
15c0 | 73 63 72 69 62 65 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 | scribe.......................... |
15e0 | 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 | .................text........... |
1600 | 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 | ...data..............bss........ |
1620 | 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 | .......idata$7...........idata$5 |
1640 | 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 | ...........idata$4...........ida |
1660 | 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 | ta$6............................ |
1680 | 00 00 00 00 15 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 2c 00 00 00 00 00 00 00 00 00 | ......................,......... |
16a0 | 00 00 02 00 6e 00 00 00 5f 45 76 74 53 75 62 73 63 72 69 62 65 40 33 32 00 5f 5f 69 6d 70 5f 5f | ....n..._EvtSubscribe@32.__imp__ |
16c0 | 45 76 74 53 75 62 73 63 72 69 62 65 40 33 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f | EvtSubscribe@32.__head_C__Users_ |
16e0 | 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 | Peter_Code_winapi_rs_i686_lib_li |
1700 | 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 34 31 2e 6f 2f 20 | bwinapi_wevtapi_a.dwvls00041.o/. |
1720 | 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 | ..1516161048..0.....0.....100666 |
1740 | 20 20 37 31 32 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 88 01 00 00 0a 00 00 00 00 00 | ..712.......`.L................. |
1760 | 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 60 01 00 00 00 00 | ...text...............,...`..... |
1780 | 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ........0`.data................. |
17a0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 | ..............@.0..bss.......... |
17c0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 | ........................0..idata |
17e0 | 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 6a 01 00 00 00 00 00 00 01 00 00 00 00 00 | $7............4...j............. |
1800 | 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 74 01 00 00 00 00 | 0..idata$5............8...t..... |
1820 | 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 | ........0..idata$4............<. |
1840 | 00 00 7e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 | ..~.............0..idata$6...... |
1860 | 00 00 1e 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 | ......@....................%.... |
1880 | 90 90 00 00 00 00 00 00 00 00 00 00 00 00 29 00 45 76 74 53 65 74 43 68 61 6e 6e 65 6c 43 6f 6e | ..............).EvtSetChannelCon |
18a0 | 66 69 67 50 72 6f 70 65 72 74 79 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 | figProperty..................... |
18c0 | 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 | .......................text..... |
18e0 | 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 | .........data..............bss.. |
1900 | 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 | .............idata$7...........i |
1920 | 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 | data$5...........idata$4........ |
1940 | 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...idata$6...................... |
1960 | 01 00 00 00 02 00 00 00 00 00 24 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 4a 00 00 00 | ..........$.................J... |
1980 | 00 00 00 00 00 00 00 00 02 00 8c 00 00 00 5f 45 76 74 53 65 74 43 68 61 6e 6e 65 6c 43 6f 6e 66 | .............._EvtSetChannelConf |
19a0 | 69 67 50 72 6f 70 65 72 74 79 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 53 65 74 43 68 61 6e 6e | igProperty@16.__imp__EvtSetChann |
19c0 | 65 6c 43 6f 6e 66 69 67 50 72 6f 70 65 72 74 79 40 31 36 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 | elConfigProperty@16.__head_C__Us |
19e0 | 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 | ers_Peter_Code_winapi_rs_i686_li |
1a00 | 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 34 30 | b_libwinapi_wevtapi_a.dwvls00040 |
1a20 | 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 | .o/...1516161048..0.....0.....10 |
1a40 | 30 36 36 36 20 20 36 35 32 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 74 01 00 00 0a 00 | 0666..652.......`.L.......t..... |
1a60 | 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 4c 01 | .......text...............,...L. |
1a80 | 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 | ............0`.data............. |
1aa0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 | ..................@.0..bss...... |
1ac0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 | ............................0..i |
1ae0 | 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 56 01 00 00 00 00 00 00 01 00 | data$7............4...V......... |
1b00 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 60 01 | ....0..idata$5............8...`. |
1b20 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 | ............0..idata$4.......... |
1b40 | 00 00 3c 01 00 00 6a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 | ..<...j.............0..idata$6.. |
1b60 | 00 00 00 00 00 00 0a 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 | ..........@....................% |
1b80 | 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 28 00 45 76 74 53 65 65 6b 00 00 00 02 00 | ..................(.EvtSeek..... |
1ba0 | 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 | ................................ |
1bc0 | 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 | .......text..............data... |
1be0 | 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 | ...........bss...............ida |
1c00 | 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 | ta$7...........idata$5.......... |
1c20 | 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 | .idata$4...........idata$6...... |
1c40 | 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 10 00 00 00 00 00 | ................................ |
1c60 | 00 00 05 00 00 00 02 00 00 00 00 00 22 00 00 00 00 00 00 00 00 00 00 00 02 00 64 00 00 00 5f 45 | ............".............d..._E |
1c80 | 76 74 53 65 65 6b 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 53 65 65 6b 40 32 34 00 5f 5f 68 65 | vtSeek@24.__imp__EvtSeek@24.__he |
1ca0 | 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 | ad_C__Users_Peter_Code_winapi_rs |
1cc0 | 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 | _i686_lib_libwinapi_wevtapi_a.dw |
1ce0 | 76 6c 73 30 30 30 33 39 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 | vls00039.o/...1516161048..0..... |
1d00 | 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 38 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 | 0.....100666..688.......`.L..... |
1d20 | 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 | ...............text............. |
1d40 | 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 | ..,...X.............0`.data..... |
1d60 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 | ..........................@.0..b |
1d80 | 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ss.............................. |
1da0 | 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 62 01 | ....0..idata$7............4...b. |
1dc0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 | ............0..idata$5.......... |
1de0 | 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 | ..8...l.............0..idata$4.. |
1e00 | 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........<...v.............0..i |
1e20 | 64 61 74 61 24 36 00 00 00 00 00 00 00 00 18 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 | data$6............@............. |
1e40 | 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 27 00 45 76 74 53 | .......%..................'.EvtS |
1e60 | 61 76 65 43 68 61 6e 6e 65 6c 43 6f 6e 66 69 67 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 | aveChannelConfig................ |
1e80 | 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 | ...........................text. |
1ea0 | 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 | .............data..............b |
1ec0 | 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 | ss...............idata$7........ |
1ee0 | 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 | ...idata$5...........idata$4.... |
1f00 | 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 | .......idata$6.................. |
1f20 | 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1c 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 | ................................ |
1f40 | 3a 00 00 00 00 00 00 00 00 00 00 00 02 00 7c 00 00 00 5f 45 76 74 53 61 76 65 43 68 61 6e 6e 65 | :.............|..._EvtSaveChanne |
1f60 | 6c 43 6f 6e 66 69 67 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 53 61 76 65 43 68 61 6e 6e 65 6c 43 | lConfig@8.__imp__EvtSaveChannelC |
1f80 | 6f 6e 66 69 67 40 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f | onfig@8.__head_C__Users_Peter_Co |
1fa0 | 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f | de_winapi_rs_i686_lib_libwinapi_ |
1fc0 | 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 33 38 2e 6f 2f 20 20 20 31 35 31 36 31 36 | wevtapi_a.dwvls00038.o/...151616 |
1fe0 | 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 35 36 20 20 20 | 1048..0.....0.....100666..656... |
2000 | 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 74 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 | ....`.L.......t............text. |
2020 | 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 4c 01 00 00 00 00 00 00 01 00 00 00 20 00 | ..............,...L............. |
2040 | 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | 0`.data......................... |
2060 | 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ......@.0..bss.................. |
2080 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 | ................0..idata$7...... |
20a0 | 00 00 04 00 00 00 34 01 00 00 56 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 | ......4...V.............0..idata |
20c0 | 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 60 01 00 00 00 00 00 00 01 00 00 00 00 00 | $5............8...`............. |
20e0 | 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 6a 01 00 00 00 00 | 0..idata$4............<...j..... |
2100 | 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 0c 00 00 00 40 01 | ........0..idata$6............@. |
2120 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 | ...................%............ |
2140 | 00 00 00 00 00 00 26 00 45 76 74 52 65 6e 64 65 72 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 | ......&.EvtRender............... |
2160 | 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 | ...........................text. |
2180 | 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 | .............data..............b |
21a0 | 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 | ss...............idata$7........ |
21c0 | 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 | ...idata$5...........idata$4.... |
21e0 | 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 | .......idata$6.................. |
2200 | 00 00 00 00 01 00 00 00 02 00 00 00 00 00 12 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 | ................................ |
2220 | 26 00 00 00 00 00 00 00 00 00 00 00 02 00 68 00 00 00 5f 45 76 74 52 65 6e 64 65 72 40 32 38 00 | &.............h..._EvtRender@28. |
2240 | 5f 5f 69 6d 70 5f 5f 45 76 74 52 65 6e 64 65 72 40 32 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 | __imp__EvtRender@28.__head_C__Us |
2260 | 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 | ers_Peter_Code_winapi_rs_i686_li |
2280 | 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 33 37 | b_libwinapi_wevtapi_a.dwvls00037 |
22a0 | 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 | .o/...1516161048..0.....0.....10 |
22c0 | 30 36 36 36 20 20 36 35 34 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 74 01 00 00 0a 00 | 0666..654.......`.L.......t..... |
22e0 | 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 4c 01 | .......text...............,...L. |
2300 | 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 | ............0`.data............. |
2320 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 | ..................@.0..bss...... |
2340 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 | ............................0..i |
2360 | 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 56 01 00 00 00 00 00 00 01 00 | data$7............4...V......... |
2380 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 60 01 | ....0..idata$5............8...`. |
23a0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 | ............0..idata$4.......... |
23c0 | 00 00 3c 01 00 00 6a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 | ..<...j.............0..idata$6.. |
23e0 | 00 00 00 00 00 00 0c 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 | ..........@....................% |
2400 | 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 25 00 45 76 74 51 75 65 72 79 00 00 02 00 | ..................%.EvtQuery.... |
2420 | 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 | ................................ |
2440 | 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 | .......text..............data... |
2460 | 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 | ...........bss...............ida |
2480 | 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 | ta$7...........idata$5.......... |
24a0 | 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 | .idata$4...........idata$6...... |
24c0 | 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 11 00 00 00 00 00 | ................................ |
24e0 | 00 00 05 00 00 00 02 00 00 00 00 00 24 00 00 00 00 00 00 00 00 00 00 00 02 00 66 00 00 00 5f 45 | ............$.............f..._E |
2500 | 76 74 51 75 65 72 79 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 51 75 65 72 79 40 31 36 00 5f 5f | vtQuery@16.__imp__EvtQuery@16.__ |
2520 | 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f | head_C__Users_Peter_Code_winapi_ |
2540 | 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 | rs_i686_lib_libwinapi_wevtapi_a. |
2560 | 64 77 76 6c 73 30 30 30 33 36 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 | dwvls00036.o/...1516161048..0... |
2580 | 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 37 34 20 20 20 20 20 20 20 60 0a 4c 01 07 00 | ..0.....100666..674.......`.L... |
25a0 | 00 00 00 00 7c 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 | ....|............text........... |
25c0 | 08 00 00 00 2c 01 00 00 54 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 | ....,...T.............0`.data... |
25e0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 | ............................@.0. |
2600 | 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | .bss............................ |
2620 | 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 | ......0..idata$7............4... |
2640 | 5e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 | ^.............0..idata$5........ |
2660 | 04 00 00 00 38 01 00 00 68 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 | ....8...h.............0..idata$4 |
2680 | 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 72 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 | ............<...r.............0. |
26a0 | 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 12 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 | .idata$6............@........... |
26c0 | 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 24 00 45 76 | .........%..................$.Ev |
26e0 | 74 4f 70 65 6e 53 65 73 73 69 6f 6e 00 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 | tOpenSession.................... |
2700 | 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 | .........................text... |
2720 | 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 | ...........data..............bss |
2740 | 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 | ...............idata$7.......... |
2760 | 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 | .idata$5...........idata$4...... |
2780 | 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 | .....idata$6.................... |
27a0 | 00 00 01 00 00 00 02 00 00 00 00 00 17 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 30 00 | ..............................0. |
27c0 | 00 00 00 00 00 00 00 00 00 00 02 00 72 00 00 00 5f 45 76 74 4f 70 65 6e 53 65 73 73 69 6f 6e 40 | ............r..._EvtOpenSession@ |
27e0 | 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 53 65 73 73 69 6f 6e 40 31 36 00 5f 5f 68 65 | 16.__imp__EvtOpenSession@16.__he |
2800 | 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 | ad_C__Users_Peter_Code_winapi_rs |
2820 | 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 | _i686_lib_libwinapi_wevtapi_a.dw |
2840 | 76 6c 73 30 30 30 33 35 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 | vls00035.o/...1516161048..0..... |
2860 | 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 30 32 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 | 0.....100666..702.......`.L..... |
2880 | 00 00 84 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 | ...............text............. |
28a0 | 00 00 2c 01 00 00 5c 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 | ..,...\.............0`.data..... |
28c0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 | ..........................@.0..b |
28e0 | 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ss.............................. |
2900 | 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 66 01 | ....0..idata$7............4...f. |
2920 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 | ............0..idata$5.......... |
2940 | 00 00 38 01 00 00 70 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 | ..8...p.............0..idata$4.. |
2960 | 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 7a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........<...z.............0..i |
2980 | 64 61 74 61 24 36 00 00 00 00 00 00 00 00 1c 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 | data$6............@............. |
29a0 | 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 23 00 45 76 74 4f | .......%..................#.EvtO |
29c0 | 70 65 6e 50 75 62 6c 69 73 68 65 72 4d 65 74 61 64 61 74 61 00 00 02 00 00 00 04 00 00 00 06 00 | penPublisherMetadata............ |
29e0 | 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 | ...............................t |
2a00 | 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 | ext..............data........... |
2a20 | 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 | ...bss...............idata$7.... |
2a40 | 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 | .......idata$5...........idata$4 |
2a60 | 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 | ...........idata$6.............. |
2a80 | 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 21 00 00 00 00 00 00 00 05 00 00 00 02 00 | ..................!............. |
2aa0 | 00 00 00 00 44 00 00 00 00 00 00 00 00 00 00 00 02 00 86 00 00 00 5f 45 76 74 4f 70 65 6e 50 75 | ....D................._EvtOpenPu |
2ac0 | 62 6c 69 73 68 65 72 4d 65 74 61 64 61 74 61 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 | blisherMetadata@20.__imp__EvtOpe |
2ae0 | 6e 50 75 62 6c 69 73 68 65 72 4d 65 74 61 64 61 74 61 40 32 30 00 5f 5f 68 65 61 64 5f 43 5f 5f | nPublisherMetadata@20.__head_C__ |
2b00 | 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f | Users_Peter_Code_winapi_rs_i686_ |
2b20 | 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 | lib_libwinapi_wevtapi_a.dwvls000 |
2b40 | 33 34 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 | 34.o/...1516161048..0.....0..... |
2b60 | 31 30 30 36 36 36 20 20 36 38 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 80 01 00 00 | 100666..688.......`.L........... |
2b80 | 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 | .........text...............,... |
2ba0 | 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 | X.............0`.data........... |
2bc0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 | ....................@.0..bss.... |
2be0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 | ..............................0. |
2c00 | 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 62 01 00 00 00 00 00 00 | .idata$7............4...b....... |
2c20 | 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 | ......0..idata$5............8... |
2c40 | 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 | l.............0..idata$4........ |
2c60 | 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 | ....<...v.............0..idata$6 |
2c80 | 00 00 00 00 00 00 00 00 18 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 | ............@................... |
2ca0 | ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 22 00 45 76 74 4f 70 65 6e 50 75 62 | .%..................".EvtOpenPub |
2cc0 | 6c 69 73 68 65 72 45 6e 75 6d 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 | lisherEnum...................... |
2ce0 | 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 | .....................text....... |
2d00 | 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 | .......data..............bss.... |
2d20 | 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 | ...........idata$7...........ida |
2d40 | 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 | ta$5...........idata$4.......... |
2d60 | 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 | .idata$6........................ |
2d80 | 00 00 02 00 00 00 00 00 1c 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 3a 00 00 00 00 00 | ..........................:..... |
2da0 | 00 00 00 00 00 00 02 00 7c 00 00 00 5f 45 76 74 4f 70 65 6e 50 75 62 6c 69 73 68 65 72 45 6e 75 | ........|..._EvtOpenPublisherEnu |
2dc0 | 6d 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 50 75 62 6c 69 73 68 65 72 45 6e 75 6d 40 | m@8.__imp__EvtOpenPublisherEnum@ |
2de0 | 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e | 8.__head_C__Users_Peter_Code_win |
2e00 | 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 | api_rs_i686_lib_libwinapi_wevtap |
2e20 | 69 5f 61 00 64 77 76 6c 73 30 30 30 33 33 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 | i_a.dwvls00033.o/...1516161048.. |
2e40 | 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 36 32 20 20 20 20 20 20 20 60 0a | 0.....0.....100666..662.......`. |
2e60 | 4c 01 07 00 00 00 00 00 78 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 | L.......x............text....... |
2e80 | 00 00 00 00 08 00 00 00 2c 01 00 00 50 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 | ........,...P.............0`.dat |
2ea0 | 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | a............................... |
2ec0 | 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | @.0..bss........................ |
2ee0 | 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$7............ |
2f00 | 34 01 00 00 5a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 | 4...Z.............0..idata$5.... |
2f20 | 00 00 00 00 04 00 00 00 38 01 00 00 64 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........8...d.............0..ida |
2f40 | 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 | ta$4............<...n........... |
2f60 | 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 0e 00 00 00 40 01 00 00 00 00 00 00 | ..0..idata$6............@....... |
2f80 | 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 | .............%.................. |
2fa0 | 21 00 45 76 74 4f 70 65 6e 4c 6f 67 00 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 | !.EvtOpenLog.................... |
2fc0 | 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 | .........................text... |
2fe0 | 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 | ...........data..............bss |
3000 | 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 | ...............idata$7.......... |
3020 | 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 | .idata$5...........idata$4...... |
3040 | 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 | .....idata$6.................... |
3060 | 00 00 01 00 00 00 02 00 00 00 00 00 13 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 28 00 | ..............................(. |
3080 | 00 00 00 00 00 00 00 00 00 00 02 00 6a 00 00 00 5f 45 76 74 4f 70 65 6e 4c 6f 67 40 31 32 00 5f | ............j..._EvtOpenLog@12._ |
30a0 | 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 4c 6f 67 40 31 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 | _imp__EvtOpenLog@12.__head_C__Us |
30c0 | 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 | ers_Peter_Code_winapi_rs_i686_li |
30e0 | 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 33 32 | b_libwinapi_wevtapi_a.dwvls00032 |
3100 | 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 | .o/...1516161048..0.....0.....10 |
3120 | 30 36 36 36 20 20 37 30 30 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 84 01 00 00 0a 00 | 0666..700.......`.L............. |
3140 | 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 5c 01 | .......text...............,...\. |
3160 | 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 | ............0`.data............. |
3180 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 | ..................@.0..bss...... |
31a0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 | ............................0..i |
31c0 | 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 66 01 00 00 00 00 00 00 01 00 | data$7............4...f......... |
31e0 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 70 01 | ....0..idata$5............8...p. |
3200 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 | ............0..idata$4.......... |
3220 | 00 00 3c 01 00 00 7a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 | ..<...z.............0..idata$6.. |
3240 | 00 00 00 00 00 00 1c 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 | ..........@....................% |
3260 | 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 20 00 45 76 74 4f 70 65 6e 45 76 65 6e 74 | ....................EvtOpenEvent |
3280 | 4d 65 74 61 64 61 74 61 45 6e 75 6d 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 | MetadataEnum.................... |
32a0 | 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 | .......................text..... |
32c0 | 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 | .........data..............bss.. |
32e0 | 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 | .............idata$7...........i |
3300 | 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 | data$5...........idata$4........ |
3320 | 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...idata$6...................... |
3340 | 01 00 00 00 02 00 00 00 00 00 20 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 42 00 00 00 | ............................B... |
3360 | 00 00 00 00 00 00 00 00 02 00 84 00 00 00 5f 45 76 74 4f 70 65 6e 45 76 65 6e 74 4d 65 74 61 64 | .............._EvtOpenEventMetad |
3380 | 61 74 61 45 6e 75 6d 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 45 76 65 6e 74 4d 65 74 | ataEnum@8.__imp__EvtOpenEventMet |
33a0 | 61 64 61 74 61 45 6e 75 6d 40 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | adataEnum@8.__head_C__Users_Pete |
33c0 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
33e0 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 33 31 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00031.o/...15 |
3400 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 38 | 16161048..0.....0.....100666..68 |
3420 | 34 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 4.......`.L....................t |
3440 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 | ext...............,...X......... |
3460 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
3480 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
34a0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
34c0 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 62 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...b.............0..i |
34e0 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 | data$5............8...l......... |
3500 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 | ....0..idata$4............<...v. |
3520 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 16 00 | ............0..idata$6.......... |
3540 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
3560 | 00 00 00 00 00 00 00 00 00 00 1f 00 45 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 45 6e 75 6d 00 00 | ............EvtOpenChannelEnum.. |
3580 | 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 | ................................ |
35a0 | 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 | ...........text..............dat |
35c0 | 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 | a..............bss.............. |
35e0 | 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 | .idata$7...........idata$5...... |
3600 | 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 | .....idata$4...........idata$6.. |
3620 | 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1a 00 | ................................ |
3640 | 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 36 00 00 00 00 00 00 00 00 00 00 00 02 00 78 00 | ................6.............x. |
3660 | 00 00 5f 45 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 45 6e 75 6d 40 38 00 5f 5f 69 6d 70 5f 5f 45 | .._EvtOpenChannelEnum@8.__imp__E |
3680 | 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 45 6e 75 6d 40 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 | vtOpenChannelEnum@8.__head_C__Us |
36a0 | 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 | ers_Peter_Code_winapi_rs_i686_li |
36c0 | 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 33 30 | b_libwinapi_wevtapi_a.dwvls00030 |
36e0 | 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 | .o/...1516161048..0.....0.....10 |
3700 | 30 36 36 36 20 20 36 39 30 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 80 01 00 00 0a 00 | 0666..690.......`.L............. |
3720 | 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 58 01 | .......text...............,...X. |
3740 | 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 | ............0`.data............. |
3760 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 | ..................@.0..bss...... |
3780 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 | ............................0..i |
37a0 | 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 62 01 00 00 00 00 00 00 01 00 | data$7............4...b......... |
37c0 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 6c 01 | ....0..idata$5............8...l. |
37e0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 | ............0..idata$4.......... |
3800 | 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 | ..<...v.............0..idata$6.. |
3820 | 00 00 00 00 00 00 18 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 | ..........@....................% |
3840 | 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 1e 00 45 76 74 4f 70 65 6e 43 68 61 6e 6e | ....................EvtOpenChann |
3860 | 65 6c 43 6f 6e 66 69 67 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 | elConfig........................ |
3880 | 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 | ...................text......... |
38a0 | 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 | .....data..............bss...... |
38c0 | 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$7...........idata |
38e0 | 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 | $5...........idata$4...........i |
3900 | 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 | data$6.......................... |
3920 | 02 00 00 00 00 00 1d 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 3c 00 00 00 00 00 00 00 | ........................<....... |
3940 | 00 00 00 00 02 00 7e 00 00 00 5f 45 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 43 6f 6e 66 69 67 40 | ......~..._EvtOpenChannelConfig@ |
3960 | 31 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 43 6f 6e 66 69 67 40 31 | 12.__imp__EvtOpenChannelConfig@1 |
3980 | 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e | 2.__head_C__Users_Peter_Code_win |
39a0 | 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 | api_rs_i686_lib_libwinapi_wevtap |
39c0 | 69 5f 61 00 64 77 76 6c 73 30 30 30 32 39 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 | i_a.dwvls00029.o/...1516161048.. |
39e0 | 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 38 36 20 20 20 20 20 20 20 60 0a | 0.....0.....100666..686.......`. |
3a00 | 4c 01 07 00 00 00 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 | L....................text....... |
3a20 | 00 00 00 00 08 00 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 | ........,...X.............0`.dat |
3a40 | 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | a............................... |
3a60 | 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | @.0..bss........................ |
3a80 | 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$7............ |
3aa0 | 34 01 00 00 62 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 | 4...b.............0..idata$5.... |
3ac0 | 00 00 00 00 04 00 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........8...l.............0..ida |
3ae0 | 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 | ta$4............<...v........... |
3b00 | 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 16 00 00 00 40 01 00 00 00 00 00 00 | ..0..idata$6............@....... |
3b20 | 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 | .............%.................. |
3b40 | 1d 00 45 76 74 4e 65 78 74 50 75 62 6c 69 73 68 65 72 49 64 00 00 00 00 02 00 00 00 04 00 00 00 | ..EvtNextPublisherId............ |
3b60 | 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 | ................................ |
3b80 | 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 | .text..............data......... |
3ba0 | 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 | .....bss...............idata$7.. |
3bc0 | 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$5...........idata |
3be0 | 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 | $4...........idata$6............ |
3c00 | 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1b 00 00 00 00 00 00 00 05 00 00 00 | ................................ |
3c20 | 02 00 00 00 00 00 38 00 00 00 00 00 00 00 00 00 00 00 02 00 7a 00 00 00 5f 45 76 74 4e 65 78 74 | ......8.............z..._EvtNext |
3c40 | 50 75 62 6c 69 73 68 65 72 49 64 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 4e 65 78 74 50 75 62 | PublisherId@16.__imp__EvtNextPub |
3c60 | 6c 69 73 68 65 72 49 64 40 31 36 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | lisherId@16.__head_C__Users_Pete |
3c80 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
3ca0 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 32 38 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00028.o/...15 |
3cc0 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 38 | 16161048..0.....0.....100666..68 |
3ce0 | 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 8.......`.L....................t |
3d00 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 | ext...............,...X......... |
3d20 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
3d40 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
3d60 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
3d80 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 62 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...b.............0..i |
3da0 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 | data$5............8...l......... |
3dc0 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 | ....0..idata$4............<...v. |
3de0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 18 00 | ............0..idata$6.......... |
3e00 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
3e20 | 00 00 00 00 00 00 00 00 00 00 1c 00 45 76 74 4e 65 78 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 | ............EvtNextEventMetadata |
3e40 | 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 | ................................ |
3e60 | 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 | ...........text..............dat |
3e80 | 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 | a..............bss.............. |
3ea0 | 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 | .idata$7...........idata$5...... |
3ec0 | 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 | .....idata$4...........idata$6.. |
3ee0 | 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1c 00 | ................................ |
3f00 | 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 3a 00 00 00 00 00 00 00 00 00 00 00 02 00 7c 00 | ................:.............|. |
3f20 | 00 00 5f 45 76 74 4e 65 78 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 40 38 00 5f 5f 69 6d 70 5f | .._EvtNextEventMetadata@8.__imp_ |
3f40 | 5f 45 76 74 4e 65 78 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 40 38 00 5f 5f 68 65 61 64 5f 43 | _EvtNextEventMetadata@8.__head_C |
3f60 | 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 | __Users_Peter_Code_winapi_rs_i68 |
3f80 | 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 | 6_lib_libwinapi_wevtapi_a.dwvls0 |
3fa0 | 30 30 32 37 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 | 0027.o/...1516161048..0.....0... |
3fc0 | 20 20 31 30 30 36 36 36 20 20 36 38 36 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 80 01 | ..100666..686.......`.L......... |
3fe0 | 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 | ...........text...............,. |
4000 | 00 00 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 | ..X.............0`.data......... |
4020 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 | ......................@.0..bss.. |
4040 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 | ................................ |
4060 | 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 62 01 00 00 00 00 | 0..idata$7............4...b..... |
4080 | 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 | ........0..idata$5............8. |
40a0 | 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 | ..l.............0..idata$4...... |
40c0 | 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 | ......<...v.............0..idata |
40e0 | 24 36 00 00 00 00 00 00 00 00 16 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | $6............@................. |
4100 | 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 1b 00 45 76 74 4e 65 78 74 43 | ...%....................EvtNextC |
4120 | 68 61 6e 6e 65 6c 50 61 74 68 00 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 | hannelPath...................... |
4140 | 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 | .......................text..... |
4160 | 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 | .........data..............bss.. |
4180 | 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 | .............idata$7...........i |
41a0 | 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 | data$5...........idata$4........ |
41c0 | 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...idata$6...................... |
41e0 | 01 00 00 00 02 00 00 00 00 00 1b 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 38 00 00 00 | ............................8... |
4200 | 00 00 00 00 00 00 00 00 02 00 7a 00 00 00 5f 45 76 74 4e 65 78 74 43 68 61 6e 6e 65 6c 50 61 74 | ..........z..._EvtNextChannelPat |
4220 | 68 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 4e 65 78 74 43 68 61 6e 6e 65 6c 50 61 74 68 40 31 | h@16.__imp__EvtNextChannelPath@1 |
4240 | 36 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e | 6.__head_C__Users_Peter_Code_win |
4260 | 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 | api_rs_i686_lib_libwinapi_wevtap |
4280 | 69 5f 61 00 64 77 76 6c 73 30 30 30 32 36 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 | i_a.dwvls00026.o/...1516161048.. |
42a0 | 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 35 32 20 20 20 20 20 20 20 60 0a | 0.....0.....100666..652.......`. |
42c0 | 4c 01 07 00 00 00 00 00 74 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 | L.......t............text....... |
42e0 | 00 00 00 00 08 00 00 00 2c 01 00 00 4c 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 | ........,...L.............0`.dat |
4300 | 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | a............................... |
4320 | 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | @.0..bss........................ |
4340 | 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$7............ |
4360 | 34 01 00 00 56 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 | 4...V.............0..idata$5.... |
4380 | 00 00 00 00 04 00 00 00 38 01 00 00 60 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........8...`.............0..ida |
43a0 | 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 6a 01 00 00 00 00 00 00 01 00 00 00 | ta$4............<...j........... |
43c0 | 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 0a 00 00 00 40 01 00 00 00 00 00 00 | ..0..idata$6............@....... |
43e0 | 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 | .............%.................. |
4400 | 1a 00 45 76 74 4e 65 78 74 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 | ..EvtNext....................... |
4420 | 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 | .....................text....... |
4440 | 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 | .......data..............bss.... |
4460 | 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 | ...........idata$7...........ida |
4480 | 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 | ta$5...........idata$4.......... |
44a0 | 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 | .idata$6........................ |
44c0 | 00 00 02 00 00 00 00 00 10 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 22 00 00 00 00 00 | .........................."..... |
44e0 | 00 00 00 00 00 00 02 00 64 00 00 00 5f 45 76 74 4e 65 78 74 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 | ........d..._EvtNext@24.__imp__E |
4500 | 76 74 4e 65 78 74 40 32 34 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f | vtNext@24.__head_C__Users_Peter_ |
4520 | 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 | Code_winapi_rs_i686_lib_libwinap |
4540 | 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 32 35 2e 6f 2f 20 20 20 31 35 31 36 | i_wevtapi_a.dwvls00025.o/...1516 |
4560 | 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 32 38 20 | 161048..0.....0.....100666..728. |
4580 | 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 8c 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 | ......`.L....................tex |
45a0 | 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 64 01 00 00 00 00 00 00 01 00 00 00 | t...............,...d........... |
45c0 | 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..0`.data....................... |
45e0 | 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ........@.0..bss................ |
4600 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 | ..................0..idata$7.... |
4620 | 00 00 00 00 04 00 00 00 34 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........4...n.............0..ida |
4640 | 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 78 01 00 00 00 00 00 00 01 00 00 00 | ta$5............8...x........... |
4660 | 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 82 01 00 00 | ..0..idata$4............<....... |
4680 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 24 00 00 00 | ..........0..idata$6........$... |
46a0 | 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 | @....................%.......... |
46c0 | 00 00 00 00 00 00 00 00 19 00 45 76 74 49 6e 74 57 72 69 74 65 58 6d 6c 45 76 65 6e 74 54 6f 4c | ..........EvtIntWriteXmlEventToL |
46e0 | 6f 63 61 6c 4c 6f 67 66 69 6c 65 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 | ocalLogfile..................... |
4700 | 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 | .....................text....... |
4720 | 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 | .......data..............bss.... |
4740 | 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 | ...........idata$7...........ida |
4760 | 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 | ta$5...........idata$4.......... |
4780 | 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 | .idata$6........................ |
47a0 | 00 00 02 00 00 00 00 00 2a 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 56 00 00 00 00 00 | ........*.................V..... |
47c0 | 00 00 00 00 00 00 02 00 98 00 00 00 5f 45 76 74 49 6e 74 57 72 69 74 65 58 6d 6c 45 76 65 6e 74 | ............_EvtIntWriteXmlEvent |
47e0 | 54 6f 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 40 31 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 57 | ToLocalLogfile@12.__imp__EvtIntW |
4800 | 72 69 74 65 58 6d 6c 45 76 65 6e 74 54 6f 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 40 31 32 00 5f 5f | riteXmlEventToLocalLogfile@12.__ |
4820 | 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f | head_C__Users_Peter_Code_winapi_ |
4840 | 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 | rs_i686_lib_libwinapi_wevtapi_a. |
4860 | 64 77 76 6c 73 30 30 30 32 34 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 | dwvls00024.o/...1516161048..0... |
4880 | 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 38 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 | ..0.....100666..688.......`.L... |
48a0 | 00 00 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 | .................text........... |
48c0 | 08 00 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 | ....,...X.............0`.data... |
48e0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 | ............................@.0. |
4900 | 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | .bss............................ |
4920 | 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 | ......0..idata$7............4... |
4940 | 62 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 | b.............0..idata$5........ |
4960 | 04 00 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 | ....8...l.............0..idata$4 |
4980 | 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 | ............<...v.............0. |
49a0 | 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 16 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 | .idata$6............@........... |
49c0 | 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 18 00 45 76 | .........%....................Ev |
49e0 | 74 49 6e 74 52 65 74 72 61 63 74 43 6f 6e 66 69 67 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 | tIntRetractConfig............... |
4a00 | 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 | .............................tex |
4a20 | 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 | t..............data............. |
4a40 | 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 | .bss...............idata$7...... |
4a60 | 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 | .....idata$5...........idata$4.. |
4a80 | 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 | .........idata$6................ |
4aa0 | 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1c 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 | ................................ |
4ac0 | 00 00 3a 00 00 00 00 00 00 00 00 00 00 00 02 00 7c 00 00 00 5f 45 76 74 49 6e 74 52 65 74 72 61 | ..:.............|..._EvtIntRetra |
4ae0 | 63 74 43 6f 6e 66 69 67 40 31 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 52 65 74 72 61 63 74 | ctConfig@12.__imp__EvtIntRetract |
4b00 | 43 6f 6e 66 69 67 40 31 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f | Config@12.__head_C__Users_Peter_ |
4b20 | 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 | Code_winapi_rs_i686_lib_libwinap |
4b40 | 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 32 33 2e 6f 2f 20 20 20 31 35 31 36 | i_wevtapi_a.dwvls00023.o/...1516 |
4b60 | 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 32 34 20 | 161048..0.....0.....100666..724. |
4b80 | 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 8c 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 | ......`.L....................tex |
4ba0 | 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 64 01 00 00 00 00 00 00 01 00 00 00 | t...............,...d........... |
4bc0 | 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..0`.data....................... |
4be0 | 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ........@.0..bss................ |
4c00 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 | ..................0..idata$7.... |
4c20 | 00 00 00 00 04 00 00 00 34 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........4...n.............0..ida |
4c40 | 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 78 01 00 00 00 00 00 00 01 00 00 00 | ta$5............8...x........... |
4c60 | 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 82 01 00 00 | ..0..idata$4............<....... |
4c80 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 22 00 00 00 | ..........0..idata$6........"... |
4ca0 | 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 | @....................%.......... |
4cc0 | 00 00 00 00 00 00 00 00 17 00 45 76 74 49 6e 74 52 65 70 6f 72 74 45 76 65 6e 74 41 6e 64 53 6f | ..........EvtIntReportEventAndSo |
4ce0 | 75 72 63 65 41 73 79 6e 63 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 | urceAsync....................... |
4d00 | 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 | .....................text....... |
4d20 | 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 | .......data..............bss.... |
4d40 | 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 | ...........idata$7...........ida |
4d60 | 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 | ta$5...........idata$4.......... |
4d80 | 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 | .idata$6........................ |
4da0 | 00 00 02 00 00 00 00 00 28 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 52 00 00 00 00 00 | ........(.................R..... |
4dc0 | 00 00 00 00 00 00 02 00 94 00 00 00 5f 45 76 74 49 6e 74 52 65 70 6f 72 74 45 76 65 6e 74 41 6e | ............_EvtIntReportEventAn |
4de0 | 64 53 6f 75 72 63 65 41 73 79 6e 63 40 34 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 52 65 70 | dSourceAsync@44.__imp__EvtIntRep |
4e00 | 6f 72 74 45 76 65 6e 74 41 6e 64 53 6f 75 72 63 65 41 73 79 6e 63 40 34 34 00 5f 5f 68 65 61 64 | ortEventAndSourceAsync@44.__head |
4e20 | 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 | _C__Users_Peter_Code_winapi_rs_i |
4e40 | 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c | 686_lib_libwinapi_wevtapi_a.dwvl |
4e60 | 73 30 30 30 32 32 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 | s00022.o/...1516161048..0.....0. |
4e80 | 20 20 20 20 31 30 30 36 36 36 20 20 37 33 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 | ....100666..738.......`.L....... |
4ea0 | 90 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 | .............text............... |
4ec0 | 2c 01 00 00 68 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 | ,...h.............0`.data....... |
4ee0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 | ........................@.0..bss |
4f00 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
4f20 | 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 72 01 00 00 | ..0..idata$7............4...r... |
4f40 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$5............ |
4f60 | 38 01 00 00 7c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 | 8...|.............0..idata$4.... |
4f80 | 00 00 00 00 04 00 00 00 3c 01 00 00 86 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........<.................0..ida |
4fa0 | 74 61 24 36 00 00 00 00 00 00 00 00 28 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ta$6........(...@............... |
4fc0 | 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 16 00 45 76 74 49 6e 74 | .....%....................EvtInt |
4fe0 | 52 65 70 6f 72 74 41 75 74 68 7a 45 76 65 6e 74 41 6e 64 53 6f 75 72 63 65 41 73 79 6e 63 00 00 | ReportAuthzEventAndSourceAsync.. |
5000 | 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 | ................................ |
5020 | 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 | .........text..............data. |
5040 | 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 | .............bss...............i |
5060 | 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 | data$7...........idata$5........ |
5080 | 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 | ...idata$4...........idata$6.... |
50a0 | 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 2d 00 00 00 | ............................-... |
50c0 | 00 00 00 00 05 00 00 00 02 00 00 00 00 00 5c 00 00 00 00 00 00 00 00 00 00 00 02 00 9e 00 00 00 | ..............\................. |
50e0 | 5f 45 76 74 49 6e 74 52 65 70 6f 72 74 41 75 74 68 7a 45 76 65 6e 74 41 6e 64 53 6f 75 72 63 65 | _EvtIntReportAuthzEventAndSource |
5100 | 41 73 79 6e 63 40 34 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 52 65 70 6f 72 74 41 75 74 68 | Async@44.__imp__EvtIntReportAuth |
5120 | 7a 45 76 65 6e 74 41 6e 64 53 6f 75 72 63 65 41 73 79 6e 63 40 34 34 00 5f 5f 68 65 61 64 5f 43 | zEventAndSourceAsync@44.__head_C |
5140 | 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 | __Users_Peter_Code_winapi_rs_i68 |
5160 | 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 | 6_lib_libwinapi_wevtapi_a.dwvls0 |
5180 | 30 30 32 31 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 | 0021.o/...1516161048..0.....0... |
51a0 | 20 20 31 30 30 36 36 36 20 20 37 32 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 8c 01 | ..100666..728.......`.L......... |
51c0 | 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 | ...........text...............,. |
51e0 | 00 00 64 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 | ..d.............0`.data......... |
5200 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 | ......................@.0..bss.. |
5220 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 | ................................ |
5240 | 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 6e 01 00 00 00 00 | 0..idata$7............4...n..... |
5260 | 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 | ........0..idata$5............8. |
5280 | 00 00 78 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 | ..x.............0..idata$4...... |
52a0 | 00 00 04 00 00 00 3c 01 00 00 82 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 | ......<.................0..idata |
52c0 | 24 36 00 00 00 00 00 00 00 00 24 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | $6........$...@................. |
52e0 | 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 15 00 45 76 74 49 6e 74 52 65 | ...%....................EvtIntRe |
5300 | 6e 64 65 72 52 65 73 6f 75 72 63 65 45 76 65 6e 74 54 65 6d 70 6c 61 74 65 00 02 00 00 00 04 00 | nderResourceEventTemplate....... |
5320 | 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 | ................................ |
5340 | 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 | ...text..............data....... |
5360 | 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 | .......bss...............idata$7 |
5380 | 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 | ...........idata$5...........ida |
53a0 | 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 | ta$4...........idata$6.......... |
53c0 | 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 2a 00 00 00 00 00 00 00 05 00 | ......................*......... |
53e0 | 00 00 02 00 00 00 00 00 56 00 00 00 00 00 00 00 00 00 00 00 02 00 98 00 00 00 5f 45 76 74 49 6e | ........V................._EvtIn |
5400 | 74 52 65 6e 64 65 72 52 65 73 6f 75 72 63 65 45 76 65 6e 74 54 65 6d 70 6c 61 74 65 40 33 32 00 | tRenderResourceEventTemplate@32. |
5420 | 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 52 65 6e 64 65 72 52 65 73 6f 75 72 63 65 45 76 65 6e 74 | __imp__EvtIntRenderResourceEvent |
5440 | 54 65 6d 70 6c 61 74 65 40 33 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | Template@32.__head_C__Users_Pete |
5460 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
5480 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 32 30 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00020.o/...15 |
54a0 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 32 | 16161048..0.....0.....100666..72 |
54c0 | 32 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 8c 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 2.......`.L....................t |
54e0 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 64 01 00 00 00 00 00 00 01 00 | ext...............,...d......... |
5500 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
5520 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
5540 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
5560 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...n.............0..i |
5580 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 78 01 00 00 00 00 00 00 01 00 | data$5............8...x......... |
55a0 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 82 01 | ....0..idata$4............<..... |
55c0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 22 00 | ............0..idata$6........". |
55e0 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
5600 | 00 00 00 00 00 00 00 00 00 00 14 00 45 76 74 49 6e 74 47 65 74 43 6c 61 73 73 69 63 4c 6f 67 44 | ............EvtIntGetClassicLogD |
5620 | 69 73 70 6c 61 79 4e 61 6d 65 00 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 | isplayName...................... |
5640 | 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 | .......................text..... |
5660 | 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 | .........data..............bss.. |
5680 | 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 | .............idata$7...........i |
56a0 | 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 | data$5...........idata$4........ |
56c0 | 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...idata$6...................... |
56e0 | 01 00 00 00 02 00 00 00 00 00 27 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 50 00 00 00 | ..........'.................P... |
5700 | 00 00 00 00 00 00 00 00 02 00 92 00 00 00 5f 45 76 74 49 6e 74 47 65 74 43 6c 61 73 73 69 63 4c | .............._EvtIntGetClassicL |
5720 | 6f 67 44 69 73 70 6c 61 79 4e 61 6d 65 40 32 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 47 65 | ogDisplayName@28.__imp__EvtIntGe |
5740 | 74 43 6c 61 73 73 69 63 4c 6f 67 44 69 73 70 6c 61 79 4e 61 6d 65 40 32 38 00 5f 5f 68 65 61 64 | tClassicLogDisplayName@28.__head |
5760 | 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 | _C__Users_Peter_Code_winapi_rs_i |
5780 | 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c | 686_lib_libwinapi_wevtapi_a.dwvl |
57a0 | 73 30 30 30 31 39 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 | s00019.o/...1516161048..0.....0. |
57c0 | 20 20 20 20 31 30 30 36 36 36 20 20 37 30 30 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 | ....100666..700.......`.L....... |
57e0 | 84 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 | .............text............... |
5800 | 2c 01 00 00 5c 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 | ,...\.............0`.data....... |
5820 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 | ........................@.0..bss |
5840 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
5860 | 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 66 01 00 00 | ..0..idata$7............4...f... |
5880 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$5............ |
58a0 | 38 01 00 00 70 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 | 8...p.............0..idata$4.... |
58c0 | 00 00 00 00 04 00 00 00 3c 01 00 00 7a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........<...z.............0..ida |
58e0 | 74 61 24 36 00 00 00 00 00 00 00 00 1c 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ta$6............@............... |
5900 | 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 13 00 45 76 74 49 6e 74 | .....%....................EvtInt |
5920 | 43 72 65 61 74 65 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 00 00 02 00 00 00 04 00 00 00 06 00 00 00 | CreateLocalLogfile.............. |
5940 | 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 | .............................tex |
5960 | 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 | t..............data............. |
5980 | 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 | .bss...............idata$7...... |
59a0 | 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 | .....idata$5...........idata$4.. |
59c0 | 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 | .........idata$6................ |
59e0 | 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 20 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 | ................................ |
5a00 | 00 00 42 00 00 00 00 00 00 00 00 00 00 00 02 00 84 00 00 00 5f 45 76 74 49 6e 74 43 72 65 61 74 | ..B................._EvtIntCreat |
5a20 | 65 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 43 72 65 | eLocalLogfile@8.__imp__EvtIntCre |
5a40 | 61 74 65 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 40 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 | ateLocalLogfile@8.__head_C__User |
5a60 | 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f | s_Peter_Code_winapi_rs_i686_lib_ |
5a80 | 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 31 38 2e 6f | libwinapi_wevtapi_a.dwvls00018.o |
5aa0 | 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 | /...1516161048..0.....0.....1006 |
5ac0 | 36 36 20 20 37 32 34 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 8c 01 00 00 0a 00 00 00 | 66..724.......`.L............... |
5ae0 | 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 64 01 00 00 | .....text...............,...d... |
5b00 | 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........0`.data............... |
5b20 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 | ................@.0..bss........ |
5b40 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 | ..........................0..ida |
5b60 | 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 | ta$7............4...n........... |
5b80 | 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 78 01 00 00 | ..0..idata$5............8...x... |
5ba0 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$4............ |
5bc0 | 3c 01 00 00 82 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 | <.................0..idata$6.... |
5be0 | 00 00 00 00 22 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 | ...."...@....................%.. |
5c00 | 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 12 00 45 76 74 49 6e 74 43 72 65 61 74 65 42 69 | ..................EvtIntCreateBi |
5c20 | 6e 58 4d 4c 46 72 6f 6d 43 75 73 74 6f 6d 58 4d 4c 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 | nXMLFromCustomXML............... |
5c40 | 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 | .............................tex |
5c60 | 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 | t..............data............. |
5c80 | 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 | .bss...............idata$7...... |
5ca0 | 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 | .....idata$5...........idata$4.. |
5cc0 | 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 | .........idata$6................ |
5ce0 | 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 28 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 | ................(............... |
5d00 | 00 00 52 00 00 00 00 00 00 00 00 00 00 00 02 00 94 00 00 00 5f 45 76 74 49 6e 74 43 72 65 61 74 | ..R................._EvtIntCreat |
5d20 | 65 42 69 6e 58 4d 4c 46 72 6f 6d 43 75 73 74 6f 6d 58 4d 4c 40 33 32 00 5f 5f 69 6d 70 5f 5f 45 | eBinXMLFromCustomXML@32.__imp__E |
5d40 | 76 74 49 6e 74 43 72 65 61 74 65 42 69 6e 58 4d 4c 46 72 6f 6d 43 75 73 74 6f 6d 58 4d 4c 40 33 | vtIntCreateBinXMLFromCustomXML@3 |
5d60 | 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e | 2.__head_C__Users_Peter_Code_win |
5d80 | 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 | api_rs_i686_lib_libwinapi_wevtap |
5da0 | 69 5f 61 00 64 77 76 6c 73 30 30 30 31 37 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 | i_a.dwvls00017.o/...1516161048.. |
5dc0 | 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 38 36 20 20 20 20 20 20 20 60 0a | 0.....0.....100666..686.......`. |
5de0 | 4c 01 07 00 00 00 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 | L....................text....... |
5e00 | 00 00 00 00 08 00 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 | ........,...X.............0`.dat |
5e20 | 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | a............................... |
5e40 | 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | @.0..bss........................ |
5e60 | 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$7............ |
5e80 | 34 01 00 00 62 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 | 4...b.............0..idata$5.... |
5ea0 | 00 00 00 00 04 00 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........8...l.............0..ida |
5ec0 | 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 | ta$4............<...v........... |
5ee0 | 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 16 00 00 00 40 01 00 00 00 00 00 00 | ..0..idata$6............@....... |
5f00 | 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 | .............%.................. |
5f20 | 11 00 45 76 74 49 6e 74 41 73 73 65 72 74 43 6f 6e 66 69 67 00 00 00 00 02 00 00 00 04 00 00 00 | ..EvtIntAssertConfig............ |
5f40 | 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 | ................................ |
5f60 | 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 | .text..............data......... |
5f80 | 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 | .....bss...............idata$7.. |
5fa0 | 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$5...........idata |
5fc0 | 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 | $4...........idata$6............ |
5fe0 | 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1b 00 00 00 00 00 00 00 05 00 00 00 | ................................ |
6000 | 02 00 00 00 00 00 38 00 00 00 00 00 00 00 00 00 00 00 02 00 7a 00 00 00 5f 45 76 74 49 6e 74 41 | ......8.............z..._EvtIntA |
6020 | 73 73 65 72 74 43 6f 6e 66 69 67 40 31 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 41 73 73 65 | ssertConfig@12.__imp__EvtIntAsse |
6040 | 72 74 43 6f 6e 66 69 67 40 31 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | rtConfig@12.__head_C__Users_Pete |
6060 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
6080 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 31 36 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00016.o/...15 |
60a0 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 37 | 16161048..0.....0.....100666..67 |
60c0 | 36 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 7c 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 6.......`.L.......|............t |
60e0 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 54 01 00 00 00 00 00 00 01 00 | ext...............,...T......... |
6100 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
6120 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
6140 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
6160 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 5e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...^.............0..i |
6180 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 68 01 00 00 00 00 00 00 01 00 | data$5............8...h......... |
61a0 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 72 01 | ....0..idata$4............<...r. |
61c0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 12 00 | ............0..idata$6.......... |
61e0 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
6200 | 00 00 00 00 00 00 00 00 00 00 10 00 45 76 74 47 65 74 51 75 65 72 79 49 6e 66 6f 00 00 00 02 00 | ............EvtGetQueryInfo..... |
6220 | 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 | ................................ |
6240 | 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 | .......text..............data... |
6260 | 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 | ...........bss...............ida |
6280 | 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 | ta$7...........idata$5.......... |
62a0 | 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 | .idata$4...........idata$6...... |
62c0 | 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 18 00 00 00 00 00 | ................................ |
62e0 | 00 00 05 00 00 00 02 00 00 00 00 00 32 00 00 00 00 00 00 00 00 00 00 00 02 00 74 00 00 00 5f 45 | ............2.............t..._E |
6300 | 76 74 47 65 74 51 75 65 72 79 49 6e 66 6f 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 51 | vtGetQueryInfo@20.__imp__EvtGetQ |
6320 | 75 65 72 79 49 6e 66 6f 40 32 30 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | ueryInfo@20.__head_C__Users_Pete |
6340 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
6360 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 31 35 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00015.o/...15 |
6380 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 32 | 16161048..0.....0.....100666..72 |
63a0 | 34 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 8c 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 4.......`.L....................t |
63c0 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 64 01 00 00 00 00 00 00 01 00 | ext...............,...d......... |
63e0 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
6400 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
6420 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
6440 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...n.............0..i |
6460 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 78 01 00 00 00 00 00 00 01 00 | data$5............8...x......... |
6480 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 82 01 | ....0..idata$4............<..... |
64a0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 22 00 | ............0..idata$6........". |
64c0 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
64e0 | 00 00 00 00 00 00 00 00 00 00 0f 00 45 76 74 47 65 74 50 75 62 6c 69 73 68 65 72 4d 65 74 61 64 | ............EvtGetPublisherMetad |
6500 | 61 74 61 50 72 6f 70 65 72 74 79 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 | ataProperty..................... |
6520 | 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 | .......................text..... |
6540 | 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 | .........data..............bss.. |
6560 | 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 | .............idata$7...........i |
6580 | 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 | data$5...........idata$4........ |
65a0 | 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...idata$6...................... |
65c0 | 01 00 00 00 02 00 00 00 00 00 28 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 52 00 00 00 | ..........(.................R... |
65e0 | 00 00 00 00 00 00 00 00 02 00 94 00 00 00 5f 45 76 74 47 65 74 50 75 62 6c 69 73 68 65 72 4d 65 | .............._EvtGetPublisherMe |
6600 | 74 61 64 61 74 61 50 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 50 | tadataProperty@24.__imp__EvtGetP |
6620 | 75 62 6c 69 73 68 65 72 4d 65 74 61 64 61 74 61 50 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 68 65 | ublisherMetadataProperty@24.__he |
6640 | 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 | ad_C__Users_Peter_Code_winapi_rs |
6660 | 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 | _i686_lib_libwinapi_wevtapi_a.dw |
6680 | 76 6c 73 30 30 30 31 34 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 | vls00014.o/...1516161048..0..... |
66a0 | 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 39 30 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 | 0.....100666..690.......`.L..... |
66c0 | 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 | ...............text............. |
66e0 | 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 | ..,...X.............0`.data..... |
6700 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 | ..........................@.0..b |
6720 | 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ss.............................. |
6740 | 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 62 01 | ....0..idata$7............4...b. |
6760 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 | ............0..idata$5.......... |
6780 | 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 | ..8...l.............0..idata$4.. |
67a0 | 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........<...v.............0..i |
67c0 | 64 61 74 61 24 36 00 00 00 00 00 00 00 00 18 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 | data$6............@............. |
67e0 | 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 0e 00 45 76 74 47 | .......%....................EvtG |
6800 | 65 74 4f 62 6a 65 63 74 41 72 72 61 79 53 69 7a 65 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 | etObjectArraySize............... |
6820 | 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 | ...........................text. |
6840 | 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 | .............data..............b |
6860 | 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 | ss...............idata$7........ |
6880 | 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 | ...idata$5...........idata$4.... |
68a0 | 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 | .......idata$6.................. |
68c0 | 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1d 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 | ................................ |
68e0 | 3c 00 00 00 00 00 00 00 00 00 00 00 02 00 7e 00 00 00 5f 45 76 74 47 65 74 4f 62 6a 65 63 74 41 | <.............~..._EvtGetObjectA |
6900 | 72 72 61 79 53 69 7a 65 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 4f 62 6a 65 63 74 41 72 | rraySize@8.__imp__EvtGetObjectAr |
6920 | 72 61 79 53 69 7a 65 40 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f | raySize@8.__head_C__Users_Peter_ |
6940 | 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 | Code_winapi_rs_i686_lib_libwinap |
6960 | 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 31 33 2e 6f 2f 20 20 20 31 35 31 36 | i_wevtapi_a.dwvls00013.o/...1516 |
6980 | 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 30 34 20 | 161048..0.....0.....100666..704. |
69a0 | 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 84 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 | ......`.L....................tex |
69c0 | 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 5c 01 00 00 00 00 00 00 01 00 00 00 | t...............,...\........... |
69e0 | 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..0`.data....................... |
6a00 | 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ........@.0..bss................ |
6a20 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 | ..................0..idata$7.... |
6a40 | 00 00 00 00 04 00 00 00 34 01 00 00 66 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........4...f.............0..ida |
6a60 | 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 70 01 00 00 00 00 00 00 01 00 00 00 | ta$5............8...p........... |
6a80 | 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 7a 01 00 00 | ..0..idata$4............<...z... |
6aa0 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 1c 00 00 00 | ..........0..idata$6............ |
6ac0 | 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 | @....................%.......... |
6ae0 | 00 00 00 00 00 00 00 00 0d 00 45 76 74 47 65 74 4f 62 6a 65 63 74 41 72 72 61 79 50 72 6f 70 65 | ..........EvtGetObjectArrayPrope |
6b00 | 72 74 79 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 | rty............................. |
6b20 | 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 | .............text..............d |
6b40 | 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 | ata..............bss............ |
6b60 | 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 | ...idata$7...........idata$5.... |
6b80 | 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 | .......idata$4...........idata$6 |
6ba0 | 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 | ................................ |
6bc0 | 22 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 46 00 00 00 00 00 00 00 00 00 00 00 02 00 | ".................F............. |
6be0 | 88 00 00 00 5f 45 76 74 47 65 74 4f 62 6a 65 63 74 41 72 72 61 79 50 72 6f 70 65 72 74 79 40 32 | ...._EvtGetObjectArrayProperty@2 |
6c00 | 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 4f 62 6a 65 63 74 41 72 72 61 79 50 72 6f 70 65 72 | 8.__imp__EvtGetObjectArrayProper |
6c20 | 74 79 40 32 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 | ty@28.__head_C__Users_Peter_Code |
6c40 | 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 | _winapi_rs_i686_lib_libwinapi_we |
6c60 | 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 31 32 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 | vtapi_a.dwvls00012.o/...15161610 |
6c80 | 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 36 38 20 20 20 20 20 | 48..0.....0.....100666..668..... |
6ca0 | 20 20 60 0a 4c 01 07 00 00 00 00 00 78 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 | ..`.L.......x............text... |
6cc0 | 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 50 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 | ............,...P.............0` |
6ce0 | 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | .data........................... |
6d00 | 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....@.0..bss.................... |
6d20 | 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 | ..............0..idata$7........ |
6d40 | 04 00 00 00 34 01 00 00 5a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 | ....4...Z.............0..idata$5 |
6d60 | 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 64 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 | ............8...d.............0. |
6d80 | 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 6e 01 00 00 00 00 00 00 | .idata$4............<...n....... |
6da0 | 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 10 00 00 00 40 01 00 00 | ......0..idata$6............@... |
6dc0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 | .................%.............. |
6de0 | 00 00 00 00 0c 00 45 76 74 47 65 74 4c 6f 67 49 6e 66 6f 00 02 00 00 00 04 00 00 00 06 00 00 00 | ......EvtGetLogInfo............. |
6e00 | 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 | .............................tex |
6e20 | 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 | t..............data............. |
6e40 | 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 | .bss...............idata$7...... |
6e60 | 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 | .....idata$5...........idata$4.. |
6e80 | 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 | .........idata$6................ |
6ea0 | 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 16 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 | ................................ |
6ec0 | 00 00 2e 00 00 00 00 00 00 00 00 00 00 00 02 00 70 00 00 00 5f 45 76 74 47 65 74 4c 6f 67 49 6e | ................p..._EvtGetLogIn |
6ee0 | 66 6f 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 4c 6f 67 49 6e 66 6f 40 32 30 00 5f 5f | fo@20.__imp__EvtGetLogInfo@20.__ |
6f00 | 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f | head_C__Users_Peter_Code_winapi_ |
6f20 | 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 | rs_i686_lib_libwinapi_wevtapi_a. |
6f40 | 64 77 76 6c 73 30 30 30 31 31 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 | dwvls00011.o/...1516161048..0... |
6f60 | 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 39 30 20 20 20 20 20 20 20 60 0a 4c 01 07 00 | ..0.....100666..690.......`.L... |
6f80 | 00 00 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 | .................text........... |
6fa0 | 08 00 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 | ....,...X.............0`.data... |
6fc0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 | ............................@.0. |
6fe0 | 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | .bss............................ |
7000 | 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 | ......0..idata$7............4... |
7020 | 62 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 | b.............0..idata$5........ |
7040 | 04 00 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 | ....8...l.............0..idata$4 |
7060 | 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 | ............<...v.............0. |
7080 | 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 18 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 | .idata$6............@........... |
70a0 | 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 0b 00 45 76 | .........%....................Ev |
70c0 | 74 47 65 74 45 78 74 65 6e 64 65 64 53 74 61 74 75 73 00 00 02 00 00 00 04 00 00 00 06 00 00 00 | tGetExtendedStatus.............. |
70e0 | 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 | .............................tex |
7100 | 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 | t..............data............. |
7120 | 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 | .bss...............idata$7...... |
7140 | 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 | .....idata$5...........idata$4.. |
7160 | 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 | .........idata$6................ |
7180 | 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1d 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 | ................................ |
71a0 | 00 00 3c 00 00 00 00 00 00 00 00 00 00 00 02 00 7e 00 00 00 5f 45 76 74 47 65 74 45 78 74 65 6e | ..<.............~..._EvtGetExten |
71c0 | 64 65 64 53 74 61 74 75 73 40 31 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 45 78 74 65 6e 64 | dedStatus@12.__imp__EvtGetExtend |
71e0 | 65 64 53 74 61 74 75 73 40 31 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | edStatus@12.__head_C__Users_Pete |
7200 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
7220 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 31 30 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00010.o/...15 |
7240 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 31 | 16161048..0.....0.....100666..71 |
7260 | 32 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 88 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 2.......`.L....................t |
7280 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 60 01 00 00 00 00 00 00 01 00 | ext...............,...`......... |
72a0 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
72c0 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
72e0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
7300 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 6a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...j.............0..i |
7320 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 74 01 00 00 00 00 00 00 01 00 | data$5............8...t......... |
7340 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 7e 01 | ....0..idata$4............<...~. |
7360 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 1e 00 | ............0..idata$6.......... |
7380 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
73a0 | 00 00 00 00 00 00 00 00 00 00 0a 00 45 76 74 47 65 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 50 | ............EvtGetEventMetadataP |
73c0 | 72 6f 70 65 72 74 79 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 | roperty......................... |
73e0 | 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 | ...................text......... |
7400 | 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 | .....data..............bss...... |
7420 | 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$7...........idata |
7440 | 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 | $5...........idata$4...........i |
7460 | 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 | data$6.......................... |
7480 | 02 00 00 00 00 00 24 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 4a 00 00 00 00 00 00 00 | ......$.................J....... |
74a0 | 00 00 00 00 02 00 8c 00 00 00 5f 45 76 74 47 65 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 50 72 | .........._EvtGetEventMetadataPr |
74c0 | 6f 70 65 72 74 79 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 45 76 65 6e 74 4d 65 74 61 | operty@24.__imp__EvtGetEventMeta |
74e0 | 64 61 74 61 50 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f | dataProperty@24.__head_C__Users_ |
7500 | 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 | Peter_Code_winapi_rs_i686_lib_li |
7520 | 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 30 39 2e 6f 2f 20 | bwinapi_wevtapi_a.dwvls00009.o/. |
7540 | 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 | ..1516161048..0.....0.....100666 |
7560 | 20 20 36 37 36 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 7c 01 00 00 0a 00 00 00 00 00 | ..676.......`.L.......|......... |
7580 | 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 54 01 00 00 00 00 | ...text...............,...T..... |
75a0 | 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ........0`.data................. |
75c0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 | ..............@.0..bss.......... |
75e0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 | ........................0..idata |
7600 | 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 5e 01 00 00 00 00 00 00 01 00 00 00 00 00 | $7............4...^............. |
7620 | 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 68 01 00 00 00 00 | 0..idata$5............8...h..... |
7640 | 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 | ........0..idata$4............<. |
7660 | 00 00 72 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 | ..r.............0..idata$6...... |
7680 | 00 00 12 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 | ......@....................%.... |
76a0 | 90 90 00 00 00 00 00 00 00 00 00 00 00 00 09 00 45 76 74 47 65 74 45 76 65 6e 74 49 6e 66 6f 00 | ................EvtGetEventInfo. |
76c0 | 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 | ................................ |
76e0 | 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 | ...........text..............dat |
7700 | 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 | a..............bss.............. |
7720 | 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 | .idata$7...........idata$5...... |
7740 | 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 | .....idata$4...........idata$6.. |
7760 | 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 18 00 | ................................ |
7780 | 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 32 00 00 00 00 00 00 00 00 00 00 00 02 00 74 00 | ................2.............t. |
77a0 | 00 00 5f 45 76 74 47 65 74 45 76 65 6e 74 49 6e 66 6f 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 | .._EvtGetEventInfo@20.__imp__Evt |
77c0 | 47 65 74 45 76 65 6e 74 49 6e 66 6f 40 32 30 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f | GetEventInfo@20.__head_C__Users_ |
77e0 | 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 | Peter_Code_winapi_rs_i686_lib_li |
7800 | 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 30 38 2e 6f 2f 20 | bwinapi_wevtapi_a.dwvls00008.o/. |
7820 | 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 | ..1516161048..0.....0.....100666 |
7840 | 20 20 37 31 32 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 88 01 00 00 0a 00 00 00 00 00 | ..712.......`.L................. |
7860 | 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 60 01 00 00 00 00 | ...text...............,...`..... |
7880 | 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ........0`.data................. |
78a0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 | ..............@.0..bss.......... |
78c0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 | ........................0..idata |
78e0 | 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 6a 01 00 00 00 00 00 00 01 00 00 00 00 00 | $7............4...j............. |
7900 | 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 74 01 00 00 00 00 | 0..idata$5............8...t..... |
7920 | 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 | ........0..idata$4............<. |
7940 | 00 00 7e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 | ..~.............0..idata$6...... |
7960 | 00 00 1e 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 | ......@....................%.... |
7980 | 90 90 00 00 00 00 00 00 00 00 00 00 00 00 08 00 45 76 74 47 65 74 43 68 61 6e 6e 65 6c 43 6f 6e | ................EvtGetChannelCon |
79a0 | 66 69 67 50 72 6f 70 65 72 74 79 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 | figProperty..................... |
79c0 | 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 | .......................text..... |
79e0 | 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 | .........data..............bss.. |
7a00 | 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 | .............idata$7...........i |
7a20 | 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 | data$5...........idata$4........ |
7a40 | 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...idata$6...................... |
7a60 | 01 00 00 00 02 00 00 00 00 00 24 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 4a 00 00 00 | ..........$.................J... |
7a80 | 00 00 00 00 00 00 00 00 02 00 8c 00 00 00 5f 45 76 74 47 65 74 43 68 61 6e 6e 65 6c 43 6f 6e 66 | .............._EvtGetChannelConf |
7aa0 | 69 67 50 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 43 68 61 6e 6e | igProperty@24.__imp__EvtGetChann |
7ac0 | 65 6c 43 6f 6e 66 69 67 50 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 | elConfigProperty@24.__head_C__Us |
7ae0 | 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 | ers_Peter_Code_winapi_rs_i686_li |
7b00 | 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 30 37 | b_libwinapi_wevtapi_a.dwvls00007 |
7b20 | 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 | .o/...1516161048..0.....0.....10 |
7b40 | 30 36 36 36 20 20 36 37 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 7c 01 00 00 0a 00 | 0666..678.......`.L.......|..... |
7b60 | 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 54 01 | .......text...............,...T. |
7b80 | 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 | ............0`.data............. |
7ba0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 | ..................@.0..bss...... |
7bc0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 | ............................0..i |
7be0 | 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 5e 01 00 00 00 00 00 00 01 00 | data$7............4...^......... |
7c00 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 68 01 | ....0..idata$5............8...h. |
7c20 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 | ............0..idata$4.......... |
7c40 | 00 00 3c 01 00 00 72 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 | ..<...r.............0..idata$6.. |
7c60 | 00 00 00 00 00 00 14 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 | ..........@....................% |
7c80 | 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 07 00 45 76 74 46 6f 72 6d 61 74 4d 65 73 | ....................EvtFormatMes |
7ca0 | 73 61 67 65 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 | sage............................ |
7cc0 | 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 | ...............text............. |
7ce0 | 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 | .data..............bss.......... |
7d00 | 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 | .....idata$7...........idata$5.. |
7d20 | 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$4...........idata |
7d40 | 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 | $6.............................. |
7d60 | 00 00 19 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 34 00 00 00 00 00 00 00 00 00 00 00 | ....................4........... |
7d80 | 02 00 76 00 00 00 5f 45 76 74 46 6f 72 6d 61 74 4d 65 73 73 61 67 65 40 33 36 00 5f 5f 69 6d 70 | ..v..._EvtFormatMessage@36.__imp |
7da0 | 5f 5f 45 76 74 46 6f 72 6d 61 74 4d 65 73 73 61 67 65 40 33 36 00 5f 5f 68 65 61 64 5f 43 5f 5f | __EvtFormatMessage@36.__head_C__ |
7dc0 | 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f | Users_Peter_Code_winapi_rs_i686_ |
7de0 | 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 | lib_libwinapi_wevtapi_a.dwvls000 |
7e00 | 30 36 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 | 06.o/...1516161048..0.....0..... |
7e20 | 31 30 30 36 36 36 20 20 36 36 36 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 78 01 00 00 | 100666..666.......`.L.......x... |
7e40 | 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 | .........text...............,... |
7e60 | 50 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 | P.............0`.data........... |
7e80 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 | ....................@.0..bss.... |
7ea0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 | ..............................0. |
7ec0 | 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 5a 01 00 00 00 00 00 00 | .idata$7............4...Z....... |
7ee0 | 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 | ......0..idata$5............8... |
7f00 | 64 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 | d.............0..idata$4........ |
7f20 | 04 00 00 00 3c 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 | ....<...n.............0..idata$6 |
7f40 | 00 00 00 00 00 00 00 00 10 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 | ............@................... |
7f60 | ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 06 00 45 76 74 45 78 70 6f 72 74 4c | .%....................EvtExportL |
7f80 | 6f 67 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 | og.............................. |
7fa0 | 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 | .............text..............d |
7fc0 | 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 | ata..............bss............ |
7fe0 | 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 | ...idata$7...........idata$5.... |
8000 | 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 | .......idata$4...........idata$6 |
8020 | 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 | ................................ |
8040 | 15 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 2c 00 00 00 00 00 00 00 00 00 00 00 02 00 | ..................,............. |
8060 | 6e 00 00 00 5f 45 76 74 45 78 70 6f 72 74 4c 6f 67 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 45 | n..._EvtExportLog@20.__imp__EvtE |
8080 | 78 70 6f 72 74 4c 6f 67 40 32 30 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | xportLog@20.__head_C__Users_Pete |
80a0 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
80c0 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 30 35 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00005.o/...15 |
80e0 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 39 | 16161048..0.....0.....100666..69 |
8100 | 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 84 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 8.......`.L....................t |
8120 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 5c 01 00 00 00 00 00 00 01 00 | ext...............,...\......... |
8140 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
8160 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
8180 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
81a0 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 66 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...f.............0..i |
81c0 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 70 01 00 00 00 00 00 00 01 00 | data$5............8...p......... |
81e0 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 7a 01 | ....0..idata$4............<...z. |
8200 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 1a 00 | ............0..idata$6.......... |
8220 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
8240 | 00 00 00 00 00 00 00 00 00 00 05 00 45 76 74 43 72 65 61 74 65 52 65 6e 64 65 72 43 6f 6e 74 65 | ............EvtCreateRenderConte |
8260 | 78 74 00 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 | xt.............................. |
8280 | 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 | ...............text............. |
82a0 | 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 | .data..............bss.......... |
82c0 | 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 | .....idata$7...........idata$5.. |
82e0 | 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$4...........idata |
8300 | 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 | $6.............................. |
8320 | 00 00 1f 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 | ....................@........... |
8340 | 02 00 82 00 00 00 5f 45 76 74 43 72 65 61 74 65 52 65 6e 64 65 72 43 6f 6e 74 65 78 74 40 31 32 | ......_EvtCreateRenderContext@12 |
8360 | 00 5f 5f 69 6d 70 5f 5f 45 76 74 43 72 65 61 74 65 52 65 6e 64 65 72 43 6f 6e 74 65 78 74 40 31 | .__imp__EvtCreateRenderContext@1 |
8380 | 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e | 2.__head_C__Users_Peter_Code_win |
83a0 | 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 | api_rs_i686_lib_libwinapi_wevtap |
83c0 | 69 5f 61 00 64 77 76 6c 73 30 30 30 30 34 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 | i_a.dwvls00004.o/...1516161048.. |
83e0 | 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 37 38 20 20 20 20 20 20 20 60 0a | 0.....0.....100666..678.......`. |
8400 | 4c 01 07 00 00 00 00 00 7c 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 | L.......|............text....... |
8420 | 00 00 00 00 08 00 00 00 2c 01 00 00 54 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 | ........,...T.............0`.dat |
8440 | 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | a............................... |
8460 | 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | @.0..bss........................ |
8480 | 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$7............ |
84a0 | 34 01 00 00 5e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 | 4...^.............0..idata$5.... |
84c0 | 00 00 00 00 04 00 00 00 38 01 00 00 68 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........8...h.............0..ida |
84e0 | 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 72 01 00 00 00 00 00 00 01 00 00 00 | ta$4............<...r........... |
8500 | 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 14 00 00 00 40 01 00 00 00 00 00 00 | ..0..idata$6............@....... |
8520 | 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 | .............%.................. |
8540 | 04 00 45 76 74 43 72 65 61 74 65 42 6f 6f 6b 6d 61 72 6b 00 02 00 00 00 04 00 00 00 06 00 00 00 | ..EvtCreateBookmark............. |
8560 | 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 | .............................tex |
8580 | 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 | t..............data............. |
85a0 | 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 | .bss...............idata$7...... |
85c0 | 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 | .....idata$5...........idata$4.. |
85e0 | 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 | .........idata$6................ |
8600 | 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 19 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 | ................................ |
8620 | 00 00 34 00 00 00 00 00 00 00 00 00 00 00 02 00 76 00 00 00 5f 45 76 74 43 72 65 61 74 65 42 6f | ..4.............v..._EvtCreateBo |
8640 | 6f 6b 6d 61 72 6b 40 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 43 72 65 61 74 65 42 6f 6f 6b 6d 61 72 | okmark@4.__imp__EvtCreateBookmar |
8660 | 6b 40 34 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 | k@4.__head_C__Users_Peter_Code_w |
8680 | 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 | inapi_rs_i686_lib_libwinapi_wevt |
86a0 | 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 30 33 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 | api_a.dwvls00003.o/...1516161048 |
86c0 | 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 35 32 20 20 20 20 20 20 20 | ..0.....0.....100666..652....... |
86e0 | 60 0a 4c 01 07 00 00 00 00 00 74 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 | `.L.......t............text..... |
8700 | 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 4c 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 | ..........,...L.............0`.d |
8720 | 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ata............................. |
8740 | 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..@.0..bss...................... |
8760 | 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 | ............0..idata$7.......... |
8780 | 00 00 34 01 00 00 56 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 | ..4...V.............0..idata$5.. |
87a0 | 00 00 00 00 00 00 04 00 00 00 38 01 00 00 60 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........8...`.............0..i |
87c0 | 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 6a 01 00 00 00 00 00 00 01 00 | data$4............<...j......... |
87e0 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 0c 00 00 00 40 01 00 00 00 00 | ....0..idata$6............@..... |
8800 | 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 | ...............%................ |
8820 | 00 00 03 00 45 76 74 43 6c 6f 73 65 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 | ....EvtClose.................... |
8840 | 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 | .......................text..... |
8860 | 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 | .........data..............bss.. |
8880 | 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 | .............idata$7...........i |
88a0 | 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 | data$5...........idata$4........ |
88c0 | 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...idata$6...................... |
88e0 | 01 00 00 00 02 00 00 00 00 00 10 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 22 00 00 00 | ............................"... |
8900 | 00 00 00 00 00 00 00 00 02 00 64 00 00 00 5f 45 76 74 43 6c 6f 73 65 40 34 00 5f 5f 69 6d 70 5f | ..........d..._EvtClose@4.__imp_ |
8920 | 5f 45 76 74 43 6c 6f 73 65 40 34 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | _EvtClose@4.__head_C__Users_Pete |
8940 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
8960 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 30 32 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00002.o/...15 |
8980 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 36 | 16161048..0.....0.....100666..66 |
89a0 | 34 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 78 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 4.......`.L.......x............t |
89c0 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 50 01 00 00 00 00 00 00 01 00 | ext...............,...P......... |
89e0 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
8a00 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
8a20 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
8a40 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 5a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...Z.............0..i |
8a60 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 64 01 00 00 00 00 00 00 01 00 | data$5............8...d......... |
8a80 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 6e 01 | ....0..idata$4............<...n. |
8aa0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 0e 00 | ............0..idata$6.......... |
8ac0 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
8ae0 | 00 00 00 00 00 00 00 00 00 00 02 00 45 76 74 43 6c 65 61 72 4c 6f 67 00 00 00 02 00 00 00 04 00 | ............EvtClearLog......... |
8b00 | 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 | ................................ |
8b20 | 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 | ...text..............data....... |
8b40 | 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 | .......bss...............idata$7 |
8b60 | 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 | ...........idata$5...........ida |
8b80 | 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 | ta$4...........idata$6.......... |
8ba0 | 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 14 00 00 00 00 00 00 00 05 00 | ................................ |
8bc0 | 00 00 02 00 00 00 00 00 2a 00 00 00 00 00 00 00 00 00 00 00 02 00 6c 00 00 00 5f 45 76 74 43 6c | ........*.............l..._EvtCl |
8be0 | 65 61 72 4c 6f 67 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 43 6c 65 61 72 4c 6f 67 40 31 36 00 | earLog@16.__imp__EvtClearLog@16. |
8c00 | 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 | __head_C__Users_Peter_Code_winap |
8c20 | 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f | i_rs_i686_lib_libwinapi_wevtapi_ |
8c40 | 61 00 64 77 76 6c 73 30 30 30 30 31 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 | a.dwvls00001.o/...1516161048..0. |
8c60 | 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 35 34 20 20 20 20 20 20 20 60 0a 4c 01 | ....0.....100666..654.......`.L. |
8c80 | 07 00 00 00 00 00 74 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 | ......t............text......... |
8ca0 | 00 00 08 00 00 00 2c 01 00 00 4c 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 | ......,...L.............0`.data. |
8cc0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 | ..............................@. |
8ce0 | 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | 0..bss.......................... |
8d00 | 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 | ........0..idata$7............4. |
8d20 | 00 00 56 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 | ..V.............0..idata$5...... |
8d40 | 00 00 04 00 00 00 38 01 00 00 60 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 | ......8...`.............0..idata |
8d60 | 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 6a 01 00 00 00 00 00 00 01 00 00 00 00 00 | $4............<...j............. |
8d80 | 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 0c 00 00 00 40 01 00 00 00 00 00 00 00 00 | 0..idata$6............@......... |
8da0 | 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 01 00 | ...........%.................... |
8dc0 | 45 76 74 43 61 6e 63 65 6c 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 | EvtCancel....................... |
8de0 | 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 | ...................text......... |
8e00 | 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 | .....data..............bss...... |
8e20 | 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$7...........idata |
8e40 | 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 | $5...........idata$4...........i |
8e60 | 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 | data$6.......................... |
8e80 | 02 00 00 00 00 00 11 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 24 00 00 00 00 00 00 00 | ........................$....... |
8ea0 | 00 00 00 00 02 00 66 00 00 00 5f 45 76 74 43 61 6e 63 65 6c 40 34 00 5f 5f 69 6d 70 5f 5f 45 76 | ......f..._EvtCancel@4.__imp__Ev |
8ec0 | 74 43 61 6e 63 65 6c 40 34 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f | tCancel@4.__head_C__Users_Peter_ |
8ee0 | 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 | Code_winapi_rs_i686_lib_libwinap |
8f00 | 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 30 30 2e 6f 2f 20 20 20 31 35 31 36 | i_wevtapi_a.dwvls00000.o/...1516 |
8f20 | 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 39 32 20 | 161048..0.....0.....100666..692. |
8f40 | 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 | ......`.L....................tex |
8f60 | 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 00 00 | t...............,...X........... |
8f80 | 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..0`.data....................... |
8fa0 | 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ........@.0..bss................ |
8fc0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 | ..................0..idata$7.... |
8fe0 | 00 00 00 00 04 00 00 00 34 01 00 00 62 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........4...b.............0..ida |
9000 | 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 | ta$5............8...l........... |
9020 | 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 | ..0..idata$4............<...v... |
9040 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 18 00 00 00 | ..........0..idata$6............ |
9060 | 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 | @....................%.......... |
9080 | 00 00 00 00 00 00 00 00 00 00 45 76 74 41 72 63 68 69 76 65 45 78 70 6f 72 74 65 64 4c 6f 67 00 | ..........EvtArchiveExportedLog. |
90a0 | 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 | ................................ |
90c0 | 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 | .........text..............data. |
90e0 | 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 | .............bss...............i |
9100 | 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 | data$7...........idata$5........ |
9120 | 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 | ...idata$4...........idata$6.... |
9140 | 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1e 00 00 00 | ................................ |
9160 | 00 00 00 00 05 00 00 00 02 00 00 00 00 00 3e 00 00 00 00 00 00 00 00 00 00 00 02 00 80 00 00 00 | ..............>................. |
9180 | 5f 45 76 74 41 72 63 68 69 76 65 45 78 70 6f 72 74 65 64 4c 6f 67 40 31 36 00 5f 5f 69 6d 70 5f | _EvtArchiveExportedLog@16.__imp_ |
91a0 | 5f 45 76 74 41 72 63 68 69 76 65 45 78 70 6f 72 74 65 64 4c 6f 67 40 31 36 00 5f 5f 68 65 61 64 | _EvtArchiveExportedLog@16.__head |
91c0 | 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 | _C__Users_Peter_Code_winapi_rs_i |
91e0 | 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 | 686_lib_libwinapi_wevtapi_a. |