| ofs | hex dump | ascii |
|---|
| 0000 | 21 3c 61 72 63 68 3e 0a 2f 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 31 35 31 36 31 36 31 30 | !<arch>./...............15161610 |
| 0020 | 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 30 20 20 20 20 20 20 20 32 38 39 36 20 20 20 20 | 48..0.....0.....0.......2896.... |
| 0040 | 20 20 60 0a 00 00 00 5a 00 00 0b 94 00 00 0e 3e 00 00 11 5a 00 00 11 5a 00 00 14 3c 00 00 14 3c | ..`....Z.......>...Z...Z...<...< |
| 0060 | 00 00 17 12 00 00 17 12 00 00 1a 16 00 00 1a 16 00 00 1c de 00 00 1c de 00 00 1f ca 00 00 1f ca | ................................ |
| 0080 | 00 00 22 96 00 00 22 96 00 00 25 60 00 00 25 60 00 00 28 3e 00 00 28 3e 00 00 2b 38 00 00 2b 38 | .."..."...%`..%`..(>..(>..+8..+8 |
| 00a0 | 00 00 2e 24 00 00 2e 24 00 00 30 f6 00 00 30 f6 00 00 33 ee 00 00 33 ee 00 00 36 d6 00 00 36 d6 | ...$...$..0...0...3...3...6...6. |
| 00c0 | 00 00 39 c4 00 00 39 c4 00 00 3c ae 00 00 3c ae 00 00 3f 9a 00 00 3f 9a 00 00 42 84 00 00 42 84 | ..9...9...<...<...?...?...B...B. |
| 00e0 | 00 00 45 4c 00 00 45 4c 00 00 48 60 00 00 48 60 00 00 4b 4c 00 00 4b 4c 00 00 4e 5c 00 00 4e 5c | ..EL..EL..H`..H`..KL..KL..N\..N\ |
| 0100 | 00 00 51 7a 00 00 51 7a 00 00 54 8e 00 00 54 8e 00 00 57 9c 00 00 57 9c 00 00 5a 94 00 00 5a 94 | ..Qz..Qz..T...T...W...W...Z...Z. |
| 0120 | 00 00 5d a4 00 00 5d a4 00 00 60 8e 00 00 60 8e 00 00 63 6e 00 00 63 6e 00 00 66 7e 00 00 66 7e | ..]...]...`...`...cn..cn..f~..f~ |
| 0140 | 00 00 69 6c 00 00 69 6c 00 00 6c 68 00 00 6c 68 00 00 6f 40 00 00 6f 40 00 00 72 2e 00 00 72 2e | ..il..il..lh..lh..o@..o@..r...r. |
| 0160 | 00 00 75 32 00 00 75 32 00 00 78 12 00 00 78 12 00 00 7b 16 00 00 7b 16 00 00 7d f8 00 00 7d f8 | ..u2..u2..x...x...{...{...}...}. |
| 0180 | 00 00 80 ce 00 00 80 ce 00 00 83 c4 00 00 83 c4 00 00 86 a6 00 00 86 a6 00 00 89 6e 00 00 89 6e | ...........................n...n |
| 01a0 | 00 00 8c 42 00 00 8c 42 00 00 8f 0c 00 00 8f 0c 5f 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 | ...B...B........__C__Users_Peter |
| 01c0 | 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 | _Code_winapi_rs_i686_lib_libwina |
| 01e0 | 70 69 5f 77 65 76 74 61 70 69 5f 61 5f 69 6e 61 6d 65 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 | pi_wevtapi_a_iname.__head_C__Use |
| 0200 | 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 | rs_Peter_Code_winapi_rs_i686_lib |
| 0220 | 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 5f 45 76 74 55 70 64 61 74 65 42 | _libwinapi_wevtapi_a._EvtUpdateB |
| 0240 | 6f 6f 6b 6d 61 72 6b 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 55 70 64 61 74 65 42 6f 6f 6b 6d 61 | ookmark@8.__imp__EvtUpdateBookma |
| 0260 | 72 6b 40 38 00 5f 45 76 74 53 75 62 73 63 72 69 62 65 40 33 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 | rk@8._EvtSubscribe@32.__imp__Evt |
| 0280 | 53 75 62 73 63 72 69 62 65 40 33 32 00 5f 45 76 74 53 65 74 43 68 61 6e 6e 65 6c 43 6f 6e 66 69 | Subscribe@32._EvtSetChannelConfi |
| 02a0 | 67 50 72 6f 70 65 72 74 79 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 53 65 74 43 68 61 6e 6e 65 | gProperty@16.__imp__EvtSetChanne |
| 02c0 | 6c 43 6f 6e 66 69 67 50 72 6f 70 65 72 74 79 40 31 36 00 5f 45 76 74 53 65 65 6b 40 32 34 00 5f | lConfigProperty@16._EvtSeek@24._ |
| 02e0 | 5f 69 6d 70 5f 5f 45 76 74 53 65 65 6b 40 32 34 00 5f 45 76 74 53 61 76 65 43 68 61 6e 6e 65 6c | _imp__EvtSeek@24._EvtSaveChannel |
| 0300 | 43 6f 6e 66 69 67 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 53 61 76 65 43 68 61 6e 6e 65 6c 43 6f | Config@8.__imp__EvtSaveChannelCo |
| 0320 | 6e 66 69 67 40 38 00 5f 45 76 74 52 65 6e 64 65 72 40 32 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 52 | nfig@8._EvtRender@28.__imp__EvtR |
| 0340 | 65 6e 64 65 72 40 32 38 00 5f 45 76 74 51 75 65 72 79 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 | ender@28._EvtQuery@16.__imp__Evt |
| 0360 | 51 75 65 72 79 40 31 36 00 5f 45 76 74 4f 70 65 6e 53 65 73 73 69 6f 6e 40 31 36 00 5f 5f 69 6d | Query@16._EvtOpenSession@16.__im |
| 0380 | 70 5f 5f 45 76 74 4f 70 65 6e 53 65 73 73 69 6f 6e 40 31 36 00 5f 45 76 74 4f 70 65 6e 50 75 62 | p__EvtOpenSession@16._EvtOpenPub |
| 03a0 | 6c 69 73 68 65 72 4d 65 74 61 64 61 74 61 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e | lisherMetadata@20.__imp__EvtOpen |
| 03c0 | 50 75 62 6c 69 73 68 65 72 4d 65 74 61 64 61 74 61 40 32 30 00 5f 45 76 74 4f 70 65 6e 50 75 62 | PublisherMetadata@20._EvtOpenPub |
| 03e0 | 6c 69 73 68 65 72 45 6e 75 6d 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 50 75 62 6c 69 | lisherEnum@8.__imp__EvtOpenPubli |
| 0400 | 73 68 65 72 45 6e 75 6d 40 38 00 5f 45 76 74 4f 70 65 6e 4c 6f 67 40 31 32 00 5f 5f 69 6d 70 5f | sherEnum@8._EvtOpenLog@12.__imp_ |
| 0420 | 5f 45 76 74 4f 70 65 6e 4c 6f 67 40 31 32 00 5f 45 76 74 4f 70 65 6e 45 76 65 6e 74 4d 65 74 61 | _EvtOpenLog@12._EvtOpenEventMeta |
| 0440 | 64 61 74 61 45 6e 75 6d 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 45 76 65 6e 74 4d 65 | dataEnum@8.__imp__EvtOpenEventMe |
| 0460 | 74 61 64 61 74 61 45 6e 75 6d 40 38 00 5f 45 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 45 6e 75 6d | tadataEnum@8._EvtOpenChannelEnum |
| 0480 | 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 45 6e 75 6d 40 38 00 5f | @8.__imp__EvtOpenChannelEnum@8._ |
| 04a0 | 45 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 43 6f 6e 66 69 67 40 31 32 00 5f 5f 69 6d 70 5f 5f 45 | EvtOpenChannelConfig@12.__imp__E |
| 04c0 | 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 43 6f 6e 66 69 67 40 31 32 00 5f 45 76 74 4e 65 78 74 50 | vtOpenChannelConfig@12._EvtNextP |
| 04e0 | 75 62 6c 69 73 68 65 72 49 64 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 4e 65 78 74 50 75 62 6c | ublisherId@16.__imp__EvtNextPubl |
| 0500 | 69 73 68 65 72 49 64 40 31 36 00 5f 45 76 74 4e 65 78 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 | isherId@16._EvtNextEventMetadata |
| 0520 | 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 4e 65 78 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 40 38 | @8.__imp__EvtNextEventMetadata@8 |
| 0540 | 00 5f 45 76 74 4e 65 78 74 43 68 61 6e 6e 65 6c 50 61 74 68 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 | ._EvtNextChannelPath@16.__imp__E |
| 0560 | 76 74 4e 65 78 74 43 68 61 6e 6e 65 6c 50 61 74 68 40 31 36 00 5f 45 76 74 4e 65 78 74 40 32 34 | vtNextChannelPath@16._EvtNext@24 |
| 0580 | 00 5f 5f 69 6d 70 5f 5f 45 76 74 4e 65 78 74 40 32 34 00 5f 45 76 74 49 6e 74 57 72 69 74 65 58 | .__imp__EvtNext@24._EvtIntWriteX |
| 05a0 | 6d 6c 45 76 65 6e 74 54 6f 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 40 31 32 00 5f 5f 69 6d 70 5f 5f | mlEventToLocalLogfile@12.__imp__ |
| 05c0 | 45 76 74 49 6e 74 57 72 69 74 65 58 6d 6c 45 76 65 6e 74 54 6f 4c 6f 63 61 6c 4c 6f 67 66 69 6c | EvtIntWriteXmlEventToLocalLogfil |
| 05e0 | 65 40 31 32 00 5f 45 76 74 49 6e 74 52 65 74 72 61 63 74 43 6f 6e 66 69 67 40 31 32 00 5f 5f 69 | e@12._EvtIntRetractConfig@12.__i |
| 0600 | 6d 70 5f 5f 45 76 74 49 6e 74 52 65 74 72 61 63 74 43 6f 6e 66 69 67 40 31 32 00 5f 45 76 74 49 | mp__EvtIntRetractConfig@12._EvtI |
| 0620 | 6e 74 52 65 70 6f 72 74 45 76 65 6e 74 41 6e 64 53 6f 75 72 63 65 41 73 79 6e 63 40 34 34 00 5f | ntReportEventAndSourceAsync@44._ |
| 0640 | 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 52 65 70 6f 72 74 45 76 65 6e 74 41 6e 64 53 6f 75 72 63 65 | _imp__EvtIntReportEventAndSource |
| 0660 | 41 73 79 6e 63 40 34 34 00 5f 45 76 74 49 6e 74 52 65 70 6f 72 74 41 75 74 68 7a 45 76 65 6e 74 | Async@44._EvtIntReportAuthzEvent |
| 0680 | 41 6e 64 53 6f 75 72 63 65 41 73 79 6e 63 40 34 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 52 | AndSourceAsync@44.__imp__EvtIntR |
| 06a0 | 65 70 6f 72 74 41 75 74 68 7a 45 76 65 6e 74 41 6e 64 53 6f 75 72 63 65 41 73 79 6e 63 40 34 34 | eportAuthzEventAndSourceAsync@44 |
| 06c0 | 00 5f 45 76 74 49 6e 74 52 65 6e 64 65 72 52 65 73 6f 75 72 63 65 45 76 65 6e 74 54 65 6d 70 6c | ._EvtIntRenderResourceEventTempl |
| 06e0 | 61 74 65 40 33 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 52 65 6e 64 65 72 52 65 73 6f 75 72 | ate@32.__imp__EvtIntRenderResour |
| 0700 | 63 65 45 76 65 6e 74 54 65 6d 70 6c 61 74 65 40 33 32 00 5f 45 76 74 49 6e 74 47 65 74 43 6c 61 | ceEventTemplate@32._EvtIntGetCla |
| 0720 | 73 73 69 63 4c 6f 67 44 69 73 70 6c 61 79 4e 61 6d 65 40 32 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 | ssicLogDisplayName@28.__imp__Evt |
| 0740 | 49 6e 74 47 65 74 43 6c 61 73 73 69 63 4c 6f 67 44 69 73 70 6c 61 79 4e 61 6d 65 40 32 38 00 5f | IntGetClassicLogDisplayName@28._ |
| 0760 | 45 76 74 49 6e 74 43 72 65 61 74 65 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 40 38 00 5f 5f 69 6d 70 | EvtIntCreateLocalLogfile@8.__imp |
| 0780 | 5f 5f 45 76 74 49 6e 74 43 72 65 61 74 65 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 40 38 00 5f 45 76 | __EvtIntCreateLocalLogfile@8._Ev |
| 07a0 | 74 49 6e 74 43 72 65 61 74 65 42 69 6e 58 4d 4c 46 72 6f 6d 43 75 73 74 6f 6d 58 4d 4c 40 33 32 | tIntCreateBinXMLFromCustomXML@32 |
| 07c0 | 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 43 72 65 61 74 65 42 69 6e 58 4d 4c 46 72 6f 6d 43 75 | .__imp__EvtIntCreateBinXMLFromCu |
| 07e0 | 73 74 6f 6d 58 4d 4c 40 33 32 00 5f 45 76 74 49 6e 74 41 73 73 65 72 74 43 6f 6e 66 69 67 40 31 | stomXML@32._EvtIntAssertConfig@1 |
| 0800 | 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 41 73 73 65 72 74 43 6f 6e 66 69 67 40 31 32 00 5f | 2.__imp__EvtIntAssertConfig@12._ |
| 0820 | 45 76 74 47 65 74 51 75 65 72 79 49 6e 66 6f 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 | EvtGetQueryInfo@20.__imp__EvtGet |
| 0840 | 51 75 65 72 79 49 6e 66 6f 40 32 30 00 5f 45 76 74 47 65 74 50 75 62 6c 69 73 68 65 72 4d 65 74 | QueryInfo@20._EvtGetPublisherMet |
| 0860 | 61 64 61 74 61 50 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 50 75 | adataProperty@24.__imp__EvtGetPu |
| 0880 | 62 6c 69 73 68 65 72 4d 65 74 61 64 61 74 61 50 72 6f 70 65 72 74 79 40 32 34 00 5f 45 76 74 47 | blisherMetadataProperty@24._EvtG |
| 08a0 | 65 74 4f 62 6a 65 63 74 41 72 72 61 79 53 69 7a 65 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 | etObjectArraySize@8.__imp__EvtGe |
| 08c0 | 74 4f 62 6a 65 63 74 41 72 72 61 79 53 69 7a 65 40 38 00 5f 45 76 74 47 65 74 4f 62 6a 65 63 74 | tObjectArraySize@8._EvtGetObject |
| 08e0 | 41 72 72 61 79 50 72 6f 70 65 72 74 79 40 32 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 4f 62 | ArrayProperty@28.__imp__EvtGetOb |
| 0900 | 6a 65 63 74 41 72 72 61 79 50 72 6f 70 65 72 74 79 40 32 38 00 5f 45 76 74 47 65 74 4c 6f 67 49 | jectArrayProperty@28._EvtGetLogI |
| 0920 | 6e 66 6f 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 4c 6f 67 49 6e 66 6f 40 32 30 00 5f | nfo@20.__imp__EvtGetLogInfo@20._ |
| 0940 | 45 76 74 47 65 74 45 78 74 65 6e 64 65 64 53 74 61 74 75 73 40 31 32 00 5f 5f 69 6d 70 5f 5f 45 | EvtGetExtendedStatus@12.__imp__E |
| 0960 | 76 74 47 65 74 45 78 74 65 6e 64 65 64 53 74 61 74 75 73 40 31 32 00 5f 45 76 74 47 65 74 45 76 | vtGetExtendedStatus@12._EvtGetEv |
| 0980 | 65 6e 74 4d 65 74 61 64 61 74 61 50 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 76 | entMetadataProperty@24.__imp__Ev |
| 09a0 | 74 47 65 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 50 72 6f 70 65 72 74 79 40 32 34 00 5f 45 76 | tGetEventMetadataProperty@24._Ev |
| 09c0 | 74 47 65 74 45 76 65 6e 74 49 6e 66 6f 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 45 76 | tGetEventInfo@20.__imp__EvtGetEv |
| 09e0 | 65 6e 74 49 6e 66 6f 40 32 30 00 5f 45 76 74 47 65 74 43 68 61 6e 6e 65 6c 43 6f 6e 66 69 67 50 | entInfo@20._EvtGetChannelConfigP |
| 0a00 | 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 43 68 61 6e 6e 65 6c 43 | roperty@24.__imp__EvtGetChannelC |
| 0a20 | 6f 6e 66 69 67 50 72 6f 70 65 72 74 79 40 32 34 00 5f 45 76 74 46 6f 72 6d 61 74 4d 65 73 73 61 | onfigProperty@24._EvtFormatMessa |
| 0a40 | 67 65 40 33 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 46 6f 72 6d 61 74 4d 65 73 73 61 67 65 40 33 36 | ge@36.__imp__EvtFormatMessage@36 |
| 0a60 | 00 5f 45 76 74 45 78 70 6f 72 74 4c 6f 67 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 45 78 70 6f | ._EvtExportLog@20.__imp__EvtExpo |
| 0a80 | 72 74 4c 6f 67 40 32 30 00 5f 45 76 74 43 72 65 61 74 65 52 65 6e 64 65 72 43 6f 6e 74 65 78 74 | rtLog@20._EvtCreateRenderContext |
| 0aa0 | 40 31 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 43 72 65 61 74 65 52 65 6e 64 65 72 43 6f 6e 74 65 78 | @12.__imp__EvtCreateRenderContex |
| 0ac0 | 74 40 31 32 00 5f 45 76 74 43 72 65 61 74 65 42 6f 6f 6b 6d 61 72 6b 40 34 00 5f 5f 69 6d 70 5f | t@12._EvtCreateBookmark@4.__imp_ |
| 0ae0 | 5f 45 76 74 43 72 65 61 74 65 42 6f 6f 6b 6d 61 72 6b 40 34 00 5f 45 76 74 43 6c 6f 73 65 40 34 | _EvtCreateBookmark@4._EvtClose@4 |
| 0b00 | 00 5f 5f 69 6d 70 5f 5f 45 76 74 43 6c 6f 73 65 40 34 00 5f 45 76 74 43 6c 65 61 72 4c 6f 67 40 | .__imp__EvtClose@4._EvtClearLog@ |
| 0b20 | 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 43 6c 65 61 72 4c 6f 67 40 31 36 00 5f 45 76 74 43 61 6e | 16.__imp__EvtClearLog@16._EvtCan |
| 0b40 | 63 65 6c 40 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 43 61 6e 63 65 6c 40 34 00 5f 45 76 74 41 72 63 | cel@4.__imp__EvtCancel@4._EvtArc |
| 0b60 | 68 69 76 65 45 78 70 6f 72 74 65 64 4c 6f 67 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 41 72 63 | hiveExportedLog@16.__imp__EvtArc |
| 0b80 | 68 69 76 65 45 78 70 6f 72 74 65 64 4c 6f 67 40 31 36 00 00 64 77 76 6c 74 2e 6f 2f 20 20 20 20 | hiveExportedLog@16..dwvlt.o/.... |
| 0ba0 | 20 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 | ....1516161048..0.....0.....1006 |
| 0bc0 | 36 36 20 20 36 32 31 20 20 20 20 20 20 20 60 0a 4c 01 06 00 00 00 00 00 18 01 00 00 0f 00 00 00 | 66..621.......`.L............... |
| 0be0 | 00 00 05 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | .....text....................... |
| 0c00 | 00 00 00 00 00 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........0`.data............... |
| 0c20 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 | ................@.0..bss........ |
| 0c40 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 | ..........................0..ida |
| 0c60 | 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 04 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ta$4............................ |
| 0c80 | 40 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 08 01 00 00 00 00 00 00 | @.0..idata$5.................... |
| 0ca0 | 00 00 00 00 00 00 00 00 40 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 0c 00 00 00 | ........@.0..idata$7............ |
| 0cc0 | 0c 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 00 00 00 00 00 00 00 00 77 65 76 74 | ................@.0.........wevt |
| 0ce0 | 61 70 69 2e 64 6c 6c 00 2e 66 69 6c 65 00 00 00 00 00 00 00 fe ff 00 00 67 01 66 61 6b 65 00 00 | api.dll..file...........g.fake.. |
| 0d00 | 00 00 00 00 00 00 00 00 00 00 00 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 01 00 00 | .............text............... |
| 0d20 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 | .................data........... |
| 0d40 | 03 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 62 73 73 00 00 00 00 00 00 00 00 | .....................bss........ |
| 0d60 | 03 00 00 00 03 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 69 64 61 74 61 24 34 | .........................idata$4 |
| 0d80 | 00 00 00 00 04 00 00 00 03 01 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 69 64 61 | .............................ida |
| 0da0 | 74 61 24 35 00 00 00 00 05 00 00 00 03 01 04 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ta$5............................ |
| 0dc0 | 2e 69 64 61 74 61 24 37 00 00 00 00 06 00 00 00 03 01 0c 00 00 00 00 00 00 00 00 00 00 00 00 00 | .idata$7........................ |
| 0de0 | 00 00 00 00 00 00 00 00 04 00 00 00 00 00 00 00 06 00 00 00 02 00 47 00 00 00 5f 5f 43 5f 5f 55 | ......................G...__C__U |
| 0e00 | 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c | sers_Peter_Code_winapi_rs_i686_l |
| 0e20 | 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 5f 69 6e 61 6d 65 00 0a 64 77 | ib_libwinapi_wevtapi_a_iname..dw |
| 0e40 | 76 6c 68 2e 6f 2f 20 20 20 20 20 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 | vlh.o/........1516161048..0..... |
| 0e60 | 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 33 35 20 20 20 20 20 20 20 60 0a 4c 01 06 00 00 00 | 0.....100666..735.......`.L..... |
| 0e80 | 00 00 36 01 00 00 10 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..6............text............. |
| 0ea0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 | ....................0`.data..... |
| 0ec0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 | ..........................@.0..b |
| 0ee0 | 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ss.............................. |
| 0f00 | 00 00 80 00 30 c0 2e 69 64 61 74 61 24 32 00 00 00 00 00 00 00 00 14 00 00 00 04 01 00 00 18 01 | ....0..idata$2.................. |
| 0f20 | 00 00 00 00 00 00 03 00 00 00 40 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 00 00 | ..........@.0..idata$5.......... |
| 0f40 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 69 64 61 74 61 24 34 00 00 | ..................@.0..idata$4.. |
| 0f60 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 00 00 | ..........................@.0... |
| 0f80 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 0c 00 00 00 07 00 0c 00 00 00 | ................................ |
| 0fa0 | 0f 00 00 00 07 00 10 00 00 00 0d 00 00 00 07 00 2e 66 69 6c 65 00 00 00 00 00 00 00 fe ff 00 00 | .................file........... |
| 0fc0 | 67 01 66 61 6b 65 00 00 00 00 00 00 00 00 00 00 00 00 00 00 68 6e 61 6d 65 00 00 00 00 00 00 00 | g.fake..............hname....... |
| 0fe0 | 06 00 00 00 03 00 66 74 68 75 6e 6b 00 00 00 00 00 00 05 00 00 00 03 00 2e 74 65 78 74 00 00 00 | ......fthunk.............text... |
| 1000 | 00 00 00 00 01 00 00 00 03 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 2e 64 61 74 | .............................dat |
| 1020 | 61 00 00 00 00 00 00 00 02 00 00 00 03 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | a............................... |
| 1040 | 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | .bss............................ |
| 1060 | 00 00 00 00 2e 69 64 61 74 61 24 32 00 00 00 00 04 00 00 00 03 01 14 00 00 00 03 00 00 00 00 00 | .....idata$2.................... |
| 1080 | 00 00 00 00 00 00 00 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$4...........idata |
| 10a0 | 24 35 00 00 00 00 05 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 04 00 00 00 02 00 00 00 | $5.............................. |
| 10c0 | 00 00 46 00 00 00 00 00 00 00 00 00 00 00 02 00 89 00 00 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 | ..F.................__head_C__Us |
| 10e0 | 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 | ers_Peter_Code_winapi_rs_i686_li |
| 1100 | 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 5f 5f 43 5f 5f 55 73 65 72 73 | b_libwinapi_wevtapi_a.__C__Users |
| 1120 | 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c | _Peter_Code_winapi_rs_i686_lib_l |
| 1140 | 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 5f 69 6e 61 6d 65 00 0a 64 77 76 6c 73 30 | ibwinapi_wevtapi_a_iname..dwvls0 |
| 1160 | 30 30 34 33 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 | 0043.o/...1516161048..0.....0... |
| 1180 | 20 20 31 30 30 36 36 36 20 20 36 37 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 7c 01 | ..100666..678.......`.L.......|. |
| 11a0 | 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 | ...........text...............,. |
| 11c0 | 00 00 54 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 | ..T.............0`.data......... |
| 11e0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 | ......................@.0..bss.. |
| 1200 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 | ................................ |
| 1220 | 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 5e 01 00 00 00 00 | 0..idata$7............4...^..... |
| 1240 | 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 | ........0..idata$5............8. |
| 1260 | 00 00 68 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 | ..h.............0..idata$4...... |
| 1280 | 00 00 04 00 00 00 3c 01 00 00 72 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 | ......<...r.............0..idata |
| 12a0 | 24 36 00 00 00 00 00 00 00 00 14 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | $6............@................. |
| 12c0 | 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 2b 00 45 76 74 55 70 64 61 74 | ...%..................+.EvtUpdat |
| 12e0 | 65 42 6f 6f 6b 6d 61 72 6b 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 | eBookmark....................... |
| 1300 | 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 | ...................text......... |
| 1320 | 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 | .....data..............bss...... |
| 1340 | 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$7...........idata |
| 1360 | 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 | $5...........idata$4...........i |
| 1380 | 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 | data$6.......................... |
| 13a0 | 02 00 00 00 00 00 19 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 34 00 00 00 00 00 00 00 | ........................4....... |
| 13c0 | 00 00 00 00 02 00 76 00 00 00 5f 45 76 74 55 70 64 61 74 65 42 6f 6f 6b 6d 61 72 6b 40 38 00 5f | ......v..._EvtUpdateBookmark@8._ |
| 13e0 | 5f 69 6d 70 5f 5f 45 76 74 55 70 64 61 74 65 42 6f 6f 6b 6d 61 72 6b 40 38 00 5f 5f 68 65 61 64 | _imp__EvtUpdateBookmark@8.__head |
| 1400 | 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 | _C__Users_Peter_Code_winapi_rs_i |
| 1420 | 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c | 686_lib_libwinapi_wevtapi_a.dwvl |
| 1440 | 73 30 30 30 34 32 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 | s00042.o/...1516161048..0.....0. |
| 1460 | 20 20 20 20 31 30 30 36 36 36 20 20 36 36 36 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 | ....100666..666.......`.L....... |
| 1480 | 78 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 | x............text............... |
| 14a0 | 2c 01 00 00 50 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 | ,...P.............0`.data....... |
| 14c0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 | ........................@.0..bss |
| 14e0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
| 1500 | 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 5a 01 00 00 | ..0..idata$7............4...Z... |
| 1520 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$5............ |
| 1540 | 38 01 00 00 64 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 | 8...d.............0..idata$4.... |
| 1560 | 00 00 00 00 04 00 00 00 3c 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........<...n.............0..ida |
| 1580 | 74 61 24 36 00 00 00 00 00 00 00 00 10 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ta$6............@............... |
| 15a0 | 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 2a 00 45 76 74 53 75 62 | .....%..................*.EvtSub |
| 15c0 | 73 63 72 69 62 65 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 | scribe.......................... |
| 15e0 | 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 | .................text........... |
| 1600 | 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 | ...data..............bss........ |
| 1620 | 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 | .......idata$7...........idata$5 |
| 1640 | 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 | ...........idata$4...........ida |
| 1660 | 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 | ta$6............................ |
| 1680 | 00 00 00 00 15 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 2c 00 00 00 00 00 00 00 00 00 | ......................,......... |
| 16a0 | 00 00 02 00 6e 00 00 00 5f 45 76 74 53 75 62 73 63 72 69 62 65 40 33 32 00 5f 5f 69 6d 70 5f 5f | ....n..._EvtSubscribe@32.__imp__ |
| 16c0 | 45 76 74 53 75 62 73 63 72 69 62 65 40 33 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f | EvtSubscribe@32.__head_C__Users_ |
| 16e0 | 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 | Peter_Code_winapi_rs_i686_lib_li |
| 1700 | 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 34 31 2e 6f 2f 20 | bwinapi_wevtapi_a.dwvls00041.o/. |
| 1720 | 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 | ..1516161048..0.....0.....100666 |
| 1740 | 20 20 37 31 32 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 88 01 00 00 0a 00 00 00 00 00 | ..712.......`.L................. |
| 1760 | 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 60 01 00 00 00 00 | ...text...............,...`..... |
| 1780 | 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ........0`.data................. |
| 17a0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 | ..............@.0..bss.......... |
| 17c0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 | ........................0..idata |
| 17e0 | 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 6a 01 00 00 00 00 00 00 01 00 00 00 00 00 | $7............4...j............. |
| 1800 | 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 74 01 00 00 00 00 | 0..idata$5............8...t..... |
| 1820 | 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 | ........0..idata$4............<. |
| 1840 | 00 00 7e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 | ..~.............0..idata$6...... |
| 1860 | 00 00 1e 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 | ......@....................%.... |
| 1880 | 90 90 00 00 00 00 00 00 00 00 00 00 00 00 29 00 45 76 74 53 65 74 43 68 61 6e 6e 65 6c 43 6f 6e | ..............).EvtSetChannelCon |
| 18a0 | 66 69 67 50 72 6f 70 65 72 74 79 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 | figProperty..................... |
| 18c0 | 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 | .......................text..... |
| 18e0 | 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 | .........data..............bss.. |
| 1900 | 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 | .............idata$7...........i |
| 1920 | 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 | data$5...........idata$4........ |
| 1940 | 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...idata$6...................... |
| 1960 | 01 00 00 00 02 00 00 00 00 00 24 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 4a 00 00 00 | ..........$.................J... |
| 1980 | 00 00 00 00 00 00 00 00 02 00 8c 00 00 00 5f 45 76 74 53 65 74 43 68 61 6e 6e 65 6c 43 6f 6e 66 | .............._EvtSetChannelConf |
| 19a0 | 69 67 50 72 6f 70 65 72 74 79 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 53 65 74 43 68 61 6e 6e | igProperty@16.__imp__EvtSetChann |
| 19c0 | 65 6c 43 6f 6e 66 69 67 50 72 6f 70 65 72 74 79 40 31 36 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 | elConfigProperty@16.__head_C__Us |
| 19e0 | 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 | ers_Peter_Code_winapi_rs_i686_li |
| 1a00 | 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 34 30 | b_libwinapi_wevtapi_a.dwvls00040 |
| 1a20 | 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 | .o/...1516161048..0.....0.....10 |
| 1a40 | 30 36 36 36 20 20 36 35 32 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 74 01 00 00 0a 00 | 0666..652.......`.L.......t..... |
| 1a60 | 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 4c 01 | .......text...............,...L. |
| 1a80 | 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 | ............0`.data............. |
| 1aa0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 | ..................@.0..bss...... |
| 1ac0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 | ............................0..i |
| 1ae0 | 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 56 01 00 00 00 00 00 00 01 00 | data$7............4...V......... |
| 1b00 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 60 01 | ....0..idata$5............8...`. |
| 1b20 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 | ............0..idata$4.......... |
| 1b40 | 00 00 3c 01 00 00 6a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 | ..<...j.............0..idata$6.. |
| 1b60 | 00 00 00 00 00 00 0a 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 | ..........@....................% |
| 1b80 | 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 28 00 45 76 74 53 65 65 6b 00 00 00 02 00 | ..................(.EvtSeek..... |
| 1ba0 | 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 | ................................ |
| 1bc0 | 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 | .......text..............data... |
| 1be0 | 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 | ...........bss...............ida |
| 1c00 | 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 | ta$7...........idata$5.......... |
| 1c20 | 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 | .idata$4...........idata$6...... |
| 1c40 | 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 10 00 00 00 00 00 | ................................ |
| 1c60 | 00 00 05 00 00 00 02 00 00 00 00 00 22 00 00 00 00 00 00 00 00 00 00 00 02 00 64 00 00 00 5f 45 | ............".............d..._E |
| 1c80 | 76 74 53 65 65 6b 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 53 65 65 6b 40 32 34 00 5f 5f 68 65 | vtSeek@24.__imp__EvtSeek@24.__he |
| 1ca0 | 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 | ad_C__Users_Peter_Code_winapi_rs |
| 1cc0 | 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 | _i686_lib_libwinapi_wevtapi_a.dw |
| 1ce0 | 76 6c 73 30 30 30 33 39 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 | vls00039.o/...1516161048..0..... |
| 1d00 | 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 38 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 | 0.....100666..688.......`.L..... |
| 1d20 | 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 | ...............text............. |
| 1d40 | 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 | ..,...X.............0`.data..... |
| 1d60 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 | ..........................@.0..b |
| 1d80 | 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ss.............................. |
| 1da0 | 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 62 01 | ....0..idata$7............4...b. |
| 1dc0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 | ............0..idata$5.......... |
| 1de0 | 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 | ..8...l.............0..idata$4.. |
| 1e00 | 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........<...v.............0..i |
| 1e20 | 64 61 74 61 24 36 00 00 00 00 00 00 00 00 18 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 | data$6............@............. |
| 1e40 | 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 27 00 45 76 74 53 | .......%..................'.EvtS |
| 1e60 | 61 76 65 43 68 61 6e 6e 65 6c 43 6f 6e 66 69 67 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 | aveChannelConfig................ |
| 1e80 | 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 | ...........................text. |
| 1ea0 | 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 | .............data..............b |
| 1ec0 | 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 | ss...............idata$7........ |
| 1ee0 | 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 | ...idata$5...........idata$4.... |
| 1f00 | 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 | .......idata$6.................. |
| 1f20 | 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1c 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 | ................................ |
| 1f40 | 3a 00 00 00 00 00 00 00 00 00 00 00 02 00 7c 00 00 00 5f 45 76 74 53 61 76 65 43 68 61 6e 6e 65 | :.............|..._EvtSaveChanne |
| 1f60 | 6c 43 6f 6e 66 69 67 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 53 61 76 65 43 68 61 6e 6e 65 6c 43 | lConfig@8.__imp__EvtSaveChannelC |
| 1f80 | 6f 6e 66 69 67 40 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f | onfig@8.__head_C__Users_Peter_Co |
| 1fa0 | 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f | de_winapi_rs_i686_lib_libwinapi_ |
| 1fc0 | 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 33 38 2e 6f 2f 20 20 20 31 35 31 36 31 36 | wevtapi_a.dwvls00038.o/...151616 |
| 1fe0 | 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 35 36 20 20 20 | 1048..0.....0.....100666..656... |
| 2000 | 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 74 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 | ....`.L.......t............text. |
| 2020 | 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 4c 01 00 00 00 00 00 00 01 00 00 00 20 00 | ..............,...L............. |
| 2040 | 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | 0`.data......................... |
| 2060 | 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ......@.0..bss.................. |
| 2080 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 | ................0..idata$7...... |
| 20a0 | 00 00 04 00 00 00 34 01 00 00 56 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 | ......4...V.............0..idata |
| 20c0 | 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 60 01 00 00 00 00 00 00 01 00 00 00 00 00 | $5............8...`............. |
| 20e0 | 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 6a 01 00 00 00 00 | 0..idata$4............<...j..... |
| 2100 | 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 0c 00 00 00 40 01 | ........0..idata$6............@. |
| 2120 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 | ...................%............ |
| 2140 | 00 00 00 00 00 00 26 00 45 76 74 52 65 6e 64 65 72 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 | ......&.EvtRender............... |
| 2160 | 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 | ...........................text. |
| 2180 | 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 | .............data..............b |
| 21a0 | 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 | ss...............idata$7........ |
| 21c0 | 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 | ...idata$5...........idata$4.... |
| 21e0 | 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 | .......idata$6.................. |
| 2200 | 00 00 00 00 01 00 00 00 02 00 00 00 00 00 12 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 | ................................ |
| 2220 | 26 00 00 00 00 00 00 00 00 00 00 00 02 00 68 00 00 00 5f 45 76 74 52 65 6e 64 65 72 40 32 38 00 | &.............h..._EvtRender@28. |
| 2240 | 5f 5f 69 6d 70 5f 5f 45 76 74 52 65 6e 64 65 72 40 32 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 | __imp__EvtRender@28.__head_C__Us |
| 2260 | 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 | ers_Peter_Code_winapi_rs_i686_li |
| 2280 | 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 33 37 | b_libwinapi_wevtapi_a.dwvls00037 |
| 22a0 | 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 | .o/...1516161048..0.....0.....10 |
| 22c0 | 30 36 36 36 20 20 36 35 34 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 74 01 00 00 0a 00 | 0666..654.......`.L.......t..... |
| 22e0 | 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 4c 01 | .......text...............,...L. |
| 2300 | 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 | ............0`.data............. |
| 2320 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 | ..................@.0..bss...... |
| 2340 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 | ............................0..i |
| 2360 | 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 56 01 00 00 00 00 00 00 01 00 | data$7............4...V......... |
| 2380 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 60 01 | ....0..idata$5............8...`. |
| 23a0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 | ............0..idata$4.......... |
| 23c0 | 00 00 3c 01 00 00 6a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 | ..<...j.............0..idata$6.. |
| 23e0 | 00 00 00 00 00 00 0c 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 | ..........@....................% |
| 2400 | 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 25 00 45 76 74 51 75 65 72 79 00 00 02 00 | ..................%.EvtQuery.... |
| 2420 | 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 | ................................ |
| 2440 | 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 | .......text..............data... |
| 2460 | 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 | ...........bss...............ida |
| 2480 | 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 | ta$7...........idata$5.......... |
| 24a0 | 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 | .idata$4...........idata$6...... |
| 24c0 | 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 11 00 00 00 00 00 | ................................ |
| 24e0 | 00 00 05 00 00 00 02 00 00 00 00 00 24 00 00 00 00 00 00 00 00 00 00 00 02 00 66 00 00 00 5f 45 | ............$.............f..._E |
| 2500 | 76 74 51 75 65 72 79 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 51 75 65 72 79 40 31 36 00 5f 5f | vtQuery@16.__imp__EvtQuery@16.__ |
| 2520 | 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f | head_C__Users_Peter_Code_winapi_ |
| 2540 | 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 | rs_i686_lib_libwinapi_wevtapi_a. |
| 2560 | 64 77 76 6c 73 30 30 30 33 36 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 | dwvls00036.o/...1516161048..0... |
| 2580 | 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 37 34 20 20 20 20 20 20 20 60 0a 4c 01 07 00 | ..0.....100666..674.......`.L... |
| 25a0 | 00 00 00 00 7c 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 | ....|............text........... |
| 25c0 | 08 00 00 00 2c 01 00 00 54 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 | ....,...T.............0`.data... |
| 25e0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 | ............................@.0. |
| 2600 | 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | .bss............................ |
| 2620 | 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 | ......0..idata$7............4... |
| 2640 | 5e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 | ^.............0..idata$5........ |
| 2660 | 04 00 00 00 38 01 00 00 68 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 | ....8...h.............0..idata$4 |
| 2680 | 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 72 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 | ............<...r.............0. |
| 26a0 | 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 12 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 | .idata$6............@........... |
| 26c0 | 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 24 00 45 76 | .........%..................$.Ev |
| 26e0 | 74 4f 70 65 6e 53 65 73 73 69 6f 6e 00 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 | tOpenSession.................... |
| 2700 | 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 | .........................text... |
| 2720 | 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 | ...........data..............bss |
| 2740 | 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 | ...............idata$7.......... |
| 2760 | 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 | .idata$5...........idata$4...... |
| 2780 | 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 | .....idata$6.................... |
| 27a0 | 00 00 01 00 00 00 02 00 00 00 00 00 17 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 30 00 | ..............................0. |
| 27c0 | 00 00 00 00 00 00 00 00 00 00 02 00 72 00 00 00 5f 45 76 74 4f 70 65 6e 53 65 73 73 69 6f 6e 40 | ............r..._EvtOpenSession@ |
| 27e0 | 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 53 65 73 73 69 6f 6e 40 31 36 00 5f 5f 68 65 | 16.__imp__EvtOpenSession@16.__he |
| 2800 | 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 | ad_C__Users_Peter_Code_winapi_rs |
| 2820 | 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 | _i686_lib_libwinapi_wevtapi_a.dw |
| 2840 | 76 6c 73 30 30 30 33 35 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 | vls00035.o/...1516161048..0..... |
| 2860 | 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 30 32 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 | 0.....100666..702.......`.L..... |
| 2880 | 00 00 84 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 | ...............text............. |
| 28a0 | 00 00 2c 01 00 00 5c 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 | ..,...\.............0`.data..... |
| 28c0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 | ..........................@.0..b |
| 28e0 | 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ss.............................. |
| 2900 | 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 66 01 | ....0..idata$7............4...f. |
| 2920 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 | ............0..idata$5.......... |
| 2940 | 00 00 38 01 00 00 70 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 | ..8...p.............0..idata$4.. |
| 2960 | 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 7a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........<...z.............0..i |
| 2980 | 64 61 74 61 24 36 00 00 00 00 00 00 00 00 1c 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 | data$6............@............. |
| 29a0 | 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 23 00 45 76 74 4f | .......%..................#.EvtO |
| 29c0 | 70 65 6e 50 75 62 6c 69 73 68 65 72 4d 65 74 61 64 61 74 61 00 00 02 00 00 00 04 00 00 00 06 00 | penPublisherMetadata............ |
| 29e0 | 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 | ...............................t |
| 2a00 | 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 | ext..............data........... |
| 2a20 | 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 | ...bss...............idata$7.... |
| 2a40 | 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 | .......idata$5...........idata$4 |
| 2a60 | 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 | ...........idata$6.............. |
| 2a80 | 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 21 00 00 00 00 00 00 00 05 00 00 00 02 00 | ..................!............. |
| 2aa0 | 00 00 00 00 44 00 00 00 00 00 00 00 00 00 00 00 02 00 86 00 00 00 5f 45 76 74 4f 70 65 6e 50 75 | ....D................._EvtOpenPu |
| 2ac0 | 62 6c 69 73 68 65 72 4d 65 74 61 64 61 74 61 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 | blisherMetadata@20.__imp__EvtOpe |
| 2ae0 | 6e 50 75 62 6c 69 73 68 65 72 4d 65 74 61 64 61 74 61 40 32 30 00 5f 5f 68 65 61 64 5f 43 5f 5f | nPublisherMetadata@20.__head_C__ |
| 2b00 | 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f | Users_Peter_Code_winapi_rs_i686_ |
| 2b20 | 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 | lib_libwinapi_wevtapi_a.dwvls000 |
| 2b40 | 33 34 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 | 34.o/...1516161048..0.....0..... |
| 2b60 | 31 30 30 36 36 36 20 20 36 38 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 80 01 00 00 | 100666..688.......`.L........... |
| 2b80 | 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 | .........text...............,... |
| 2ba0 | 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 | X.............0`.data........... |
| 2bc0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 | ....................@.0..bss.... |
| 2be0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 | ..............................0. |
| 2c00 | 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 62 01 00 00 00 00 00 00 | .idata$7............4...b....... |
| 2c20 | 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 | ......0..idata$5............8... |
| 2c40 | 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 | l.............0..idata$4........ |
| 2c60 | 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 | ....<...v.............0..idata$6 |
| 2c80 | 00 00 00 00 00 00 00 00 18 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 | ............@................... |
| 2ca0 | ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 22 00 45 76 74 4f 70 65 6e 50 75 62 | .%..................".EvtOpenPub |
| 2cc0 | 6c 69 73 68 65 72 45 6e 75 6d 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 | lisherEnum...................... |
| 2ce0 | 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 | .....................text....... |
| 2d00 | 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 | .......data..............bss.... |
| 2d20 | 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 | ...........idata$7...........ida |
| 2d40 | 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 | ta$5...........idata$4.......... |
| 2d60 | 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 | .idata$6........................ |
| 2d80 | 00 00 02 00 00 00 00 00 1c 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 3a 00 00 00 00 00 | ..........................:..... |
| 2da0 | 00 00 00 00 00 00 02 00 7c 00 00 00 5f 45 76 74 4f 70 65 6e 50 75 62 6c 69 73 68 65 72 45 6e 75 | ........|..._EvtOpenPublisherEnu |
| 2dc0 | 6d 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 50 75 62 6c 69 73 68 65 72 45 6e 75 6d 40 | m@8.__imp__EvtOpenPublisherEnum@ |
| 2de0 | 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e | 8.__head_C__Users_Peter_Code_win |
| 2e00 | 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 | api_rs_i686_lib_libwinapi_wevtap |
| 2e20 | 69 5f 61 00 64 77 76 6c 73 30 30 30 33 33 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 | i_a.dwvls00033.o/...1516161048.. |
| 2e40 | 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 36 32 20 20 20 20 20 20 20 60 0a | 0.....0.....100666..662.......`. |
| 2e60 | 4c 01 07 00 00 00 00 00 78 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 | L.......x............text....... |
| 2e80 | 00 00 00 00 08 00 00 00 2c 01 00 00 50 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 | ........,...P.............0`.dat |
| 2ea0 | 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | a............................... |
| 2ec0 | 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | @.0..bss........................ |
| 2ee0 | 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$7............ |
| 2f00 | 34 01 00 00 5a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 | 4...Z.............0..idata$5.... |
| 2f20 | 00 00 00 00 04 00 00 00 38 01 00 00 64 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........8...d.............0..ida |
| 2f40 | 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 | ta$4............<...n........... |
| 2f60 | 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 0e 00 00 00 40 01 00 00 00 00 00 00 | ..0..idata$6............@....... |
| 2f80 | 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 | .............%.................. |
| 2fa0 | 21 00 45 76 74 4f 70 65 6e 4c 6f 67 00 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 | !.EvtOpenLog.................... |
| 2fc0 | 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 | .........................text... |
| 2fe0 | 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 | ...........data..............bss |
| 3000 | 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 | ...............idata$7.......... |
| 3020 | 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 | .idata$5...........idata$4...... |
| 3040 | 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 | .....idata$6.................... |
| 3060 | 00 00 01 00 00 00 02 00 00 00 00 00 13 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 28 00 | ..............................(. |
| 3080 | 00 00 00 00 00 00 00 00 00 00 02 00 6a 00 00 00 5f 45 76 74 4f 70 65 6e 4c 6f 67 40 31 32 00 5f | ............j..._EvtOpenLog@12._ |
| 30a0 | 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 4c 6f 67 40 31 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 | _imp__EvtOpenLog@12.__head_C__Us |
| 30c0 | 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 | ers_Peter_Code_winapi_rs_i686_li |
| 30e0 | 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 33 32 | b_libwinapi_wevtapi_a.dwvls00032 |
| 3100 | 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 | .o/...1516161048..0.....0.....10 |
| 3120 | 30 36 36 36 20 20 37 30 30 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 84 01 00 00 0a 00 | 0666..700.......`.L............. |
| 3140 | 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 5c 01 | .......text...............,...\. |
| 3160 | 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 | ............0`.data............. |
| 3180 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 | ..................@.0..bss...... |
| 31a0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 | ............................0..i |
| 31c0 | 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 66 01 00 00 00 00 00 00 01 00 | data$7............4...f......... |
| 31e0 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 70 01 | ....0..idata$5............8...p. |
| 3200 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 | ............0..idata$4.......... |
| 3220 | 00 00 3c 01 00 00 7a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 | ..<...z.............0..idata$6.. |
| 3240 | 00 00 00 00 00 00 1c 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 | ..........@....................% |
| 3260 | 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 20 00 45 76 74 4f 70 65 6e 45 76 65 6e 74 | ....................EvtOpenEvent |
| 3280 | 4d 65 74 61 64 61 74 61 45 6e 75 6d 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 | MetadataEnum.................... |
| 32a0 | 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 | .......................text..... |
| 32c0 | 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 | .........data..............bss.. |
| 32e0 | 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 | .............idata$7...........i |
| 3300 | 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 | data$5...........idata$4........ |
| 3320 | 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...idata$6...................... |
| 3340 | 01 00 00 00 02 00 00 00 00 00 20 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 42 00 00 00 | ............................B... |
| 3360 | 00 00 00 00 00 00 00 00 02 00 84 00 00 00 5f 45 76 74 4f 70 65 6e 45 76 65 6e 74 4d 65 74 61 64 | .............._EvtOpenEventMetad |
| 3380 | 61 74 61 45 6e 75 6d 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 45 76 65 6e 74 4d 65 74 | ataEnum@8.__imp__EvtOpenEventMet |
| 33a0 | 61 64 61 74 61 45 6e 75 6d 40 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | adataEnum@8.__head_C__Users_Pete |
| 33c0 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
| 33e0 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 33 31 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00031.o/...15 |
| 3400 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 38 | 16161048..0.....0.....100666..68 |
| 3420 | 34 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 4.......`.L....................t |
| 3440 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 | ext...............,...X......... |
| 3460 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
| 3480 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
| 34a0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
| 34c0 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 62 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...b.............0..i |
| 34e0 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 | data$5............8...l......... |
| 3500 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 | ....0..idata$4............<...v. |
| 3520 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 16 00 | ............0..idata$6.......... |
| 3540 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
| 3560 | 00 00 00 00 00 00 00 00 00 00 1f 00 45 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 45 6e 75 6d 00 00 | ............EvtOpenChannelEnum.. |
| 3580 | 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 | ................................ |
| 35a0 | 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 | ...........text..............dat |
| 35c0 | 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 | a..............bss.............. |
| 35e0 | 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 | .idata$7...........idata$5...... |
| 3600 | 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 | .....idata$4...........idata$6.. |
| 3620 | 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1a 00 | ................................ |
| 3640 | 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 36 00 00 00 00 00 00 00 00 00 00 00 02 00 78 00 | ................6.............x. |
| 3660 | 00 00 5f 45 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 45 6e 75 6d 40 38 00 5f 5f 69 6d 70 5f 5f 45 | .._EvtOpenChannelEnum@8.__imp__E |
| 3680 | 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 45 6e 75 6d 40 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 | vtOpenChannelEnum@8.__head_C__Us |
| 36a0 | 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 | ers_Peter_Code_winapi_rs_i686_li |
| 36c0 | 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 33 30 | b_libwinapi_wevtapi_a.dwvls00030 |
| 36e0 | 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 | .o/...1516161048..0.....0.....10 |
| 3700 | 30 36 36 36 20 20 36 39 30 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 80 01 00 00 0a 00 | 0666..690.......`.L............. |
| 3720 | 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 58 01 | .......text...............,...X. |
| 3740 | 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 | ............0`.data............. |
| 3760 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 | ..................@.0..bss...... |
| 3780 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 | ............................0..i |
| 37a0 | 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 62 01 00 00 00 00 00 00 01 00 | data$7............4...b......... |
| 37c0 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 6c 01 | ....0..idata$5............8...l. |
| 37e0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 | ............0..idata$4.......... |
| 3800 | 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 | ..<...v.............0..idata$6.. |
| 3820 | 00 00 00 00 00 00 18 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 | ..........@....................% |
| 3840 | 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 1e 00 45 76 74 4f 70 65 6e 43 68 61 6e 6e | ....................EvtOpenChann |
| 3860 | 65 6c 43 6f 6e 66 69 67 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 | elConfig........................ |
| 3880 | 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 | ...................text......... |
| 38a0 | 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 | .....data..............bss...... |
| 38c0 | 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$7...........idata |
| 38e0 | 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 | $5...........idata$4...........i |
| 3900 | 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 | data$6.......................... |
| 3920 | 02 00 00 00 00 00 1d 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 3c 00 00 00 00 00 00 00 | ........................<....... |
| 3940 | 00 00 00 00 02 00 7e 00 00 00 5f 45 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 43 6f 6e 66 69 67 40 | ......~..._EvtOpenChannelConfig@ |
| 3960 | 31 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 4f 70 65 6e 43 68 61 6e 6e 65 6c 43 6f 6e 66 69 67 40 31 | 12.__imp__EvtOpenChannelConfig@1 |
| 3980 | 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e | 2.__head_C__Users_Peter_Code_win |
| 39a0 | 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 | api_rs_i686_lib_libwinapi_wevtap |
| 39c0 | 69 5f 61 00 64 77 76 6c 73 30 30 30 32 39 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 | i_a.dwvls00029.o/...1516161048.. |
| 39e0 | 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 38 36 20 20 20 20 20 20 20 60 0a | 0.....0.....100666..686.......`. |
| 3a00 | 4c 01 07 00 00 00 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 | L....................text....... |
| 3a20 | 00 00 00 00 08 00 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 | ........,...X.............0`.dat |
| 3a40 | 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | a............................... |
| 3a60 | 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | @.0..bss........................ |
| 3a80 | 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$7............ |
| 3aa0 | 34 01 00 00 62 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 | 4...b.............0..idata$5.... |
| 3ac0 | 00 00 00 00 04 00 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........8...l.............0..ida |
| 3ae0 | 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 | ta$4............<...v........... |
| 3b00 | 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 16 00 00 00 40 01 00 00 00 00 00 00 | ..0..idata$6............@....... |
| 3b20 | 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 | .............%.................. |
| 3b40 | 1d 00 45 76 74 4e 65 78 74 50 75 62 6c 69 73 68 65 72 49 64 00 00 00 00 02 00 00 00 04 00 00 00 | ..EvtNextPublisherId............ |
| 3b60 | 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 | ................................ |
| 3b80 | 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 | .text..............data......... |
| 3ba0 | 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 | .....bss...............idata$7.. |
| 3bc0 | 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$5...........idata |
| 3be0 | 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 | $4...........idata$6............ |
| 3c00 | 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1b 00 00 00 00 00 00 00 05 00 00 00 | ................................ |
| 3c20 | 02 00 00 00 00 00 38 00 00 00 00 00 00 00 00 00 00 00 02 00 7a 00 00 00 5f 45 76 74 4e 65 78 74 | ......8.............z..._EvtNext |
| 3c40 | 50 75 62 6c 69 73 68 65 72 49 64 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 4e 65 78 74 50 75 62 | PublisherId@16.__imp__EvtNextPub |
| 3c60 | 6c 69 73 68 65 72 49 64 40 31 36 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | lisherId@16.__head_C__Users_Pete |
| 3c80 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
| 3ca0 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 32 38 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00028.o/...15 |
| 3cc0 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 38 | 16161048..0.....0.....100666..68 |
| 3ce0 | 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 8.......`.L....................t |
| 3d00 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 | ext...............,...X......... |
| 3d20 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
| 3d40 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
| 3d60 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
| 3d80 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 62 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...b.............0..i |
| 3da0 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 | data$5............8...l......... |
| 3dc0 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 | ....0..idata$4............<...v. |
| 3de0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 18 00 | ............0..idata$6.......... |
| 3e00 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
| 3e20 | 00 00 00 00 00 00 00 00 00 00 1c 00 45 76 74 4e 65 78 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 | ............EvtNextEventMetadata |
| 3e40 | 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 | ................................ |
| 3e60 | 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 | ...........text..............dat |
| 3e80 | 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 | a..............bss.............. |
| 3ea0 | 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 | .idata$7...........idata$5...... |
| 3ec0 | 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 | .....idata$4...........idata$6.. |
| 3ee0 | 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1c 00 | ................................ |
| 3f00 | 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 3a 00 00 00 00 00 00 00 00 00 00 00 02 00 7c 00 | ................:.............|. |
| 3f20 | 00 00 5f 45 76 74 4e 65 78 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 40 38 00 5f 5f 69 6d 70 5f | .._EvtNextEventMetadata@8.__imp_ |
| 3f40 | 5f 45 76 74 4e 65 78 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 40 38 00 5f 5f 68 65 61 64 5f 43 | _EvtNextEventMetadata@8.__head_C |
| 3f60 | 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 | __Users_Peter_Code_winapi_rs_i68 |
| 3f80 | 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 | 6_lib_libwinapi_wevtapi_a.dwvls0 |
| 3fa0 | 30 30 32 37 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 | 0027.o/...1516161048..0.....0... |
| 3fc0 | 20 20 31 30 30 36 36 36 20 20 36 38 36 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 80 01 | ..100666..686.......`.L......... |
| 3fe0 | 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 | ...........text...............,. |
| 4000 | 00 00 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 | ..X.............0`.data......... |
| 4020 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 | ......................@.0..bss.. |
| 4040 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 | ................................ |
| 4060 | 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 62 01 00 00 00 00 | 0..idata$7............4...b..... |
| 4080 | 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 | ........0..idata$5............8. |
| 40a0 | 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 | ..l.............0..idata$4...... |
| 40c0 | 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 | ......<...v.............0..idata |
| 40e0 | 24 36 00 00 00 00 00 00 00 00 16 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | $6............@................. |
| 4100 | 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 1b 00 45 76 74 4e 65 78 74 43 | ...%....................EvtNextC |
| 4120 | 68 61 6e 6e 65 6c 50 61 74 68 00 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 | hannelPath...................... |
| 4140 | 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 | .......................text..... |
| 4160 | 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 | .........data..............bss.. |
| 4180 | 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 | .............idata$7...........i |
| 41a0 | 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 | data$5...........idata$4........ |
| 41c0 | 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...idata$6...................... |
| 41e0 | 01 00 00 00 02 00 00 00 00 00 1b 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 38 00 00 00 | ............................8... |
| 4200 | 00 00 00 00 00 00 00 00 02 00 7a 00 00 00 5f 45 76 74 4e 65 78 74 43 68 61 6e 6e 65 6c 50 61 74 | ..........z..._EvtNextChannelPat |
| 4220 | 68 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 4e 65 78 74 43 68 61 6e 6e 65 6c 50 61 74 68 40 31 | h@16.__imp__EvtNextChannelPath@1 |
| 4240 | 36 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e | 6.__head_C__Users_Peter_Code_win |
| 4260 | 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 | api_rs_i686_lib_libwinapi_wevtap |
| 4280 | 69 5f 61 00 64 77 76 6c 73 30 30 30 32 36 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 | i_a.dwvls00026.o/...1516161048.. |
| 42a0 | 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 35 32 20 20 20 20 20 20 20 60 0a | 0.....0.....100666..652.......`. |
| 42c0 | 4c 01 07 00 00 00 00 00 74 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 | L.......t............text....... |
| 42e0 | 00 00 00 00 08 00 00 00 2c 01 00 00 4c 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 | ........,...L.............0`.dat |
| 4300 | 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | a............................... |
| 4320 | 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | @.0..bss........................ |
| 4340 | 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$7............ |
| 4360 | 34 01 00 00 56 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 | 4...V.............0..idata$5.... |
| 4380 | 00 00 00 00 04 00 00 00 38 01 00 00 60 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........8...`.............0..ida |
| 43a0 | 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 6a 01 00 00 00 00 00 00 01 00 00 00 | ta$4............<...j........... |
| 43c0 | 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 0a 00 00 00 40 01 00 00 00 00 00 00 | ..0..idata$6............@....... |
| 43e0 | 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 | .............%.................. |
| 4400 | 1a 00 45 76 74 4e 65 78 74 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 | ..EvtNext....................... |
| 4420 | 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 | .....................text....... |
| 4440 | 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 | .......data..............bss.... |
| 4460 | 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 | ...........idata$7...........ida |
| 4480 | 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 | ta$5...........idata$4.......... |
| 44a0 | 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 | .idata$6........................ |
| 44c0 | 00 00 02 00 00 00 00 00 10 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 22 00 00 00 00 00 | .........................."..... |
| 44e0 | 00 00 00 00 00 00 02 00 64 00 00 00 5f 45 76 74 4e 65 78 74 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 | ........d..._EvtNext@24.__imp__E |
| 4500 | 76 74 4e 65 78 74 40 32 34 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f | vtNext@24.__head_C__Users_Peter_ |
| 4520 | 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 | Code_winapi_rs_i686_lib_libwinap |
| 4540 | 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 32 35 2e 6f 2f 20 20 20 31 35 31 36 | i_wevtapi_a.dwvls00025.o/...1516 |
| 4560 | 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 32 38 20 | 161048..0.....0.....100666..728. |
| 4580 | 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 8c 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 | ......`.L....................tex |
| 45a0 | 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 64 01 00 00 00 00 00 00 01 00 00 00 | t...............,...d........... |
| 45c0 | 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..0`.data....................... |
| 45e0 | 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ........@.0..bss................ |
| 4600 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 | ..................0..idata$7.... |
| 4620 | 00 00 00 00 04 00 00 00 34 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........4...n.............0..ida |
| 4640 | 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 78 01 00 00 00 00 00 00 01 00 00 00 | ta$5............8...x........... |
| 4660 | 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 82 01 00 00 | ..0..idata$4............<....... |
| 4680 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 24 00 00 00 | ..........0..idata$6........$... |
| 46a0 | 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 | @....................%.......... |
| 46c0 | 00 00 00 00 00 00 00 00 19 00 45 76 74 49 6e 74 57 72 69 74 65 58 6d 6c 45 76 65 6e 74 54 6f 4c | ..........EvtIntWriteXmlEventToL |
| 46e0 | 6f 63 61 6c 4c 6f 67 66 69 6c 65 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 | ocalLogfile..................... |
| 4700 | 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 | .....................text....... |
| 4720 | 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 | .......data..............bss.... |
| 4740 | 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 | ...........idata$7...........ida |
| 4760 | 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 | ta$5...........idata$4.......... |
| 4780 | 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 | .idata$6........................ |
| 47a0 | 00 00 02 00 00 00 00 00 2a 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 56 00 00 00 00 00 | ........*.................V..... |
| 47c0 | 00 00 00 00 00 00 02 00 98 00 00 00 5f 45 76 74 49 6e 74 57 72 69 74 65 58 6d 6c 45 76 65 6e 74 | ............_EvtIntWriteXmlEvent |
| 47e0 | 54 6f 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 40 31 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 57 | ToLocalLogfile@12.__imp__EvtIntW |
| 4800 | 72 69 74 65 58 6d 6c 45 76 65 6e 74 54 6f 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 40 31 32 00 5f 5f | riteXmlEventToLocalLogfile@12.__ |
| 4820 | 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f | head_C__Users_Peter_Code_winapi_ |
| 4840 | 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 | rs_i686_lib_libwinapi_wevtapi_a. |
| 4860 | 64 77 76 6c 73 30 30 30 32 34 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 | dwvls00024.o/...1516161048..0... |
| 4880 | 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 38 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 | ..0.....100666..688.......`.L... |
| 48a0 | 00 00 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 | .................text........... |
| 48c0 | 08 00 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 | ....,...X.............0`.data... |
| 48e0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 | ............................@.0. |
| 4900 | 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | .bss............................ |
| 4920 | 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 | ......0..idata$7............4... |
| 4940 | 62 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 | b.............0..idata$5........ |
| 4960 | 04 00 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 | ....8...l.............0..idata$4 |
| 4980 | 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 | ............<...v.............0. |
| 49a0 | 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 16 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 | .idata$6............@........... |
| 49c0 | 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 18 00 45 76 | .........%....................Ev |
| 49e0 | 74 49 6e 74 52 65 74 72 61 63 74 43 6f 6e 66 69 67 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 | tIntRetractConfig............... |
| 4a00 | 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 | .............................tex |
| 4a20 | 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 | t..............data............. |
| 4a40 | 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 | .bss...............idata$7...... |
| 4a60 | 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 | .....idata$5...........idata$4.. |
| 4a80 | 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 | .........idata$6................ |
| 4aa0 | 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1c 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 | ................................ |
| 4ac0 | 00 00 3a 00 00 00 00 00 00 00 00 00 00 00 02 00 7c 00 00 00 5f 45 76 74 49 6e 74 52 65 74 72 61 | ..:.............|..._EvtIntRetra |
| 4ae0 | 63 74 43 6f 6e 66 69 67 40 31 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 52 65 74 72 61 63 74 | ctConfig@12.__imp__EvtIntRetract |
| 4b00 | 43 6f 6e 66 69 67 40 31 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f | Config@12.__head_C__Users_Peter_ |
| 4b20 | 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 | Code_winapi_rs_i686_lib_libwinap |
| 4b40 | 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 32 33 2e 6f 2f 20 20 20 31 35 31 36 | i_wevtapi_a.dwvls00023.o/...1516 |
| 4b60 | 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 32 34 20 | 161048..0.....0.....100666..724. |
| 4b80 | 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 8c 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 | ......`.L....................tex |
| 4ba0 | 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 64 01 00 00 00 00 00 00 01 00 00 00 | t...............,...d........... |
| 4bc0 | 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..0`.data....................... |
| 4be0 | 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ........@.0..bss................ |
| 4c00 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 | ..................0..idata$7.... |
| 4c20 | 00 00 00 00 04 00 00 00 34 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........4...n.............0..ida |
| 4c40 | 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 78 01 00 00 00 00 00 00 01 00 00 00 | ta$5............8...x........... |
| 4c60 | 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 82 01 00 00 | ..0..idata$4............<....... |
| 4c80 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 22 00 00 00 | ..........0..idata$6........"... |
| 4ca0 | 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 | @....................%.......... |
| 4cc0 | 00 00 00 00 00 00 00 00 17 00 45 76 74 49 6e 74 52 65 70 6f 72 74 45 76 65 6e 74 41 6e 64 53 6f | ..........EvtIntReportEventAndSo |
| 4ce0 | 75 72 63 65 41 73 79 6e 63 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 | urceAsync....................... |
| 4d00 | 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 | .....................text....... |
| 4d20 | 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 | .......data..............bss.... |
| 4d40 | 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 | ...........idata$7...........ida |
| 4d60 | 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 | ta$5...........idata$4.......... |
| 4d80 | 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 | .idata$6........................ |
| 4da0 | 00 00 02 00 00 00 00 00 28 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 52 00 00 00 00 00 | ........(.................R..... |
| 4dc0 | 00 00 00 00 00 00 02 00 94 00 00 00 5f 45 76 74 49 6e 74 52 65 70 6f 72 74 45 76 65 6e 74 41 6e | ............_EvtIntReportEventAn |
| 4de0 | 64 53 6f 75 72 63 65 41 73 79 6e 63 40 34 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 52 65 70 | dSourceAsync@44.__imp__EvtIntRep |
| 4e00 | 6f 72 74 45 76 65 6e 74 41 6e 64 53 6f 75 72 63 65 41 73 79 6e 63 40 34 34 00 5f 5f 68 65 61 64 | ortEventAndSourceAsync@44.__head |
| 4e20 | 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 | _C__Users_Peter_Code_winapi_rs_i |
| 4e40 | 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c | 686_lib_libwinapi_wevtapi_a.dwvl |
| 4e60 | 73 30 30 30 32 32 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 | s00022.o/...1516161048..0.....0. |
| 4e80 | 20 20 20 20 31 30 30 36 36 36 20 20 37 33 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 | ....100666..738.......`.L....... |
| 4ea0 | 90 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 | .............text............... |
| 4ec0 | 2c 01 00 00 68 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 | ,...h.............0`.data....... |
| 4ee0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 | ........................@.0..bss |
| 4f00 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
| 4f20 | 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 72 01 00 00 | ..0..idata$7............4...r... |
| 4f40 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$5............ |
| 4f60 | 38 01 00 00 7c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 | 8...|.............0..idata$4.... |
| 4f80 | 00 00 00 00 04 00 00 00 3c 01 00 00 86 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........<.................0..ida |
| 4fa0 | 74 61 24 36 00 00 00 00 00 00 00 00 28 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ta$6........(...@............... |
| 4fc0 | 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 16 00 45 76 74 49 6e 74 | .....%....................EvtInt |
| 4fe0 | 52 65 70 6f 72 74 41 75 74 68 7a 45 76 65 6e 74 41 6e 64 53 6f 75 72 63 65 41 73 79 6e 63 00 00 | ReportAuthzEventAndSourceAsync.. |
| 5000 | 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 | ................................ |
| 5020 | 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 | .........text..............data. |
| 5040 | 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 | .............bss...............i |
| 5060 | 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 | data$7...........idata$5........ |
| 5080 | 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 | ...idata$4...........idata$6.... |
| 50a0 | 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 2d 00 00 00 | ............................-... |
| 50c0 | 00 00 00 00 05 00 00 00 02 00 00 00 00 00 5c 00 00 00 00 00 00 00 00 00 00 00 02 00 9e 00 00 00 | ..............\................. |
| 50e0 | 5f 45 76 74 49 6e 74 52 65 70 6f 72 74 41 75 74 68 7a 45 76 65 6e 74 41 6e 64 53 6f 75 72 63 65 | _EvtIntReportAuthzEventAndSource |
| 5100 | 41 73 79 6e 63 40 34 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 52 65 70 6f 72 74 41 75 74 68 | Async@44.__imp__EvtIntReportAuth |
| 5120 | 7a 45 76 65 6e 74 41 6e 64 53 6f 75 72 63 65 41 73 79 6e 63 40 34 34 00 5f 5f 68 65 61 64 5f 43 | zEventAndSourceAsync@44.__head_C |
| 5140 | 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 | __Users_Peter_Code_winapi_rs_i68 |
| 5160 | 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 | 6_lib_libwinapi_wevtapi_a.dwvls0 |
| 5180 | 30 30 32 31 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 | 0021.o/...1516161048..0.....0... |
| 51a0 | 20 20 31 30 30 36 36 36 20 20 37 32 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 8c 01 | ..100666..728.......`.L......... |
| 51c0 | 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 | ...........text...............,. |
| 51e0 | 00 00 64 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 | ..d.............0`.data......... |
| 5200 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 | ......................@.0..bss.. |
| 5220 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 | ................................ |
| 5240 | 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 6e 01 00 00 00 00 | 0..idata$7............4...n..... |
| 5260 | 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 | ........0..idata$5............8. |
| 5280 | 00 00 78 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 | ..x.............0..idata$4...... |
| 52a0 | 00 00 04 00 00 00 3c 01 00 00 82 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 | ......<.................0..idata |
| 52c0 | 24 36 00 00 00 00 00 00 00 00 24 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | $6........$...@................. |
| 52e0 | 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 15 00 45 76 74 49 6e 74 52 65 | ...%....................EvtIntRe |
| 5300 | 6e 64 65 72 52 65 73 6f 75 72 63 65 45 76 65 6e 74 54 65 6d 70 6c 61 74 65 00 02 00 00 00 04 00 | nderResourceEventTemplate....... |
| 5320 | 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 | ................................ |
| 5340 | 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 | ...text..............data....... |
| 5360 | 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 | .......bss...............idata$7 |
| 5380 | 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 | ...........idata$5...........ida |
| 53a0 | 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 | ta$4...........idata$6.......... |
| 53c0 | 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 2a 00 00 00 00 00 00 00 05 00 | ......................*......... |
| 53e0 | 00 00 02 00 00 00 00 00 56 00 00 00 00 00 00 00 00 00 00 00 02 00 98 00 00 00 5f 45 76 74 49 6e | ........V................._EvtIn |
| 5400 | 74 52 65 6e 64 65 72 52 65 73 6f 75 72 63 65 45 76 65 6e 74 54 65 6d 70 6c 61 74 65 40 33 32 00 | tRenderResourceEventTemplate@32. |
| 5420 | 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 52 65 6e 64 65 72 52 65 73 6f 75 72 63 65 45 76 65 6e 74 | __imp__EvtIntRenderResourceEvent |
| 5440 | 54 65 6d 70 6c 61 74 65 40 33 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | Template@32.__head_C__Users_Pete |
| 5460 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
| 5480 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 32 30 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00020.o/...15 |
| 54a0 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 32 | 16161048..0.....0.....100666..72 |
| 54c0 | 32 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 8c 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 2.......`.L....................t |
| 54e0 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 64 01 00 00 00 00 00 00 01 00 | ext...............,...d......... |
| 5500 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
| 5520 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
| 5540 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
| 5560 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...n.............0..i |
| 5580 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 78 01 00 00 00 00 00 00 01 00 | data$5............8...x......... |
| 55a0 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 82 01 | ....0..idata$4............<..... |
| 55c0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 22 00 | ............0..idata$6........". |
| 55e0 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
| 5600 | 00 00 00 00 00 00 00 00 00 00 14 00 45 76 74 49 6e 74 47 65 74 43 6c 61 73 73 69 63 4c 6f 67 44 | ............EvtIntGetClassicLogD |
| 5620 | 69 73 70 6c 61 79 4e 61 6d 65 00 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 | isplayName...................... |
| 5640 | 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 | .......................text..... |
| 5660 | 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 | .........data..............bss.. |
| 5680 | 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 | .............idata$7...........i |
| 56a0 | 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 | data$5...........idata$4........ |
| 56c0 | 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...idata$6...................... |
| 56e0 | 01 00 00 00 02 00 00 00 00 00 27 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 50 00 00 00 | ..........'.................P... |
| 5700 | 00 00 00 00 00 00 00 00 02 00 92 00 00 00 5f 45 76 74 49 6e 74 47 65 74 43 6c 61 73 73 69 63 4c | .............._EvtIntGetClassicL |
| 5720 | 6f 67 44 69 73 70 6c 61 79 4e 61 6d 65 40 32 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 47 65 | ogDisplayName@28.__imp__EvtIntGe |
| 5740 | 74 43 6c 61 73 73 69 63 4c 6f 67 44 69 73 70 6c 61 79 4e 61 6d 65 40 32 38 00 5f 5f 68 65 61 64 | tClassicLogDisplayName@28.__head |
| 5760 | 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 | _C__Users_Peter_Code_winapi_rs_i |
| 5780 | 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c | 686_lib_libwinapi_wevtapi_a.dwvl |
| 57a0 | 73 30 30 30 31 39 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 | s00019.o/...1516161048..0.....0. |
| 57c0 | 20 20 20 20 31 30 30 36 36 36 20 20 37 30 30 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 | ....100666..700.......`.L....... |
| 57e0 | 84 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 | .............text............... |
| 5800 | 2c 01 00 00 5c 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 | ,...\.............0`.data....... |
| 5820 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 | ........................@.0..bss |
| 5840 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ................................ |
| 5860 | 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 66 01 00 00 | ..0..idata$7............4...f... |
| 5880 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$5............ |
| 58a0 | 38 01 00 00 70 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 | 8...p.............0..idata$4.... |
| 58c0 | 00 00 00 00 04 00 00 00 3c 01 00 00 7a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........<...z.............0..ida |
| 58e0 | 74 61 24 36 00 00 00 00 00 00 00 00 1c 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ta$6............@............... |
| 5900 | 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 13 00 45 76 74 49 6e 74 | .....%....................EvtInt |
| 5920 | 43 72 65 61 74 65 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 00 00 02 00 00 00 04 00 00 00 06 00 00 00 | CreateLocalLogfile.............. |
| 5940 | 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 | .............................tex |
| 5960 | 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 | t..............data............. |
| 5980 | 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 | .bss...............idata$7...... |
| 59a0 | 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 | .....idata$5...........idata$4.. |
| 59c0 | 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 | .........idata$6................ |
| 59e0 | 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 20 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 | ................................ |
| 5a00 | 00 00 42 00 00 00 00 00 00 00 00 00 00 00 02 00 84 00 00 00 5f 45 76 74 49 6e 74 43 72 65 61 74 | ..B................._EvtIntCreat |
| 5a20 | 65 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 43 72 65 | eLocalLogfile@8.__imp__EvtIntCre |
| 5a40 | 61 74 65 4c 6f 63 61 6c 4c 6f 67 66 69 6c 65 40 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 | ateLocalLogfile@8.__head_C__User |
| 5a60 | 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f | s_Peter_Code_winapi_rs_i686_lib_ |
| 5a80 | 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 31 38 2e 6f | libwinapi_wevtapi_a.dwvls00018.o |
| 5aa0 | 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 | /...1516161048..0.....0.....1006 |
| 5ac0 | 36 36 20 20 37 32 34 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 8c 01 00 00 0a 00 00 00 | 66..724.......`.L............... |
| 5ae0 | 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 64 01 00 00 | .....text...............,...d... |
| 5b00 | 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........0`.data............... |
| 5b20 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 | ................@.0..bss........ |
| 5b40 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 | ..........................0..ida |
| 5b60 | 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 | ta$7............4...n........... |
| 5b80 | 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 78 01 00 00 | ..0..idata$5............8...x... |
| 5ba0 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$4............ |
| 5bc0 | 3c 01 00 00 82 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 | <.................0..idata$6.... |
| 5be0 | 00 00 00 00 22 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 | ...."...@....................%.. |
| 5c00 | 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 12 00 45 76 74 49 6e 74 43 72 65 61 74 65 42 69 | ..................EvtIntCreateBi |
| 5c20 | 6e 58 4d 4c 46 72 6f 6d 43 75 73 74 6f 6d 58 4d 4c 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 | nXMLFromCustomXML............... |
| 5c40 | 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 | .............................tex |
| 5c60 | 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 | t..............data............. |
| 5c80 | 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 | .bss...............idata$7...... |
| 5ca0 | 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 | .....idata$5...........idata$4.. |
| 5cc0 | 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 | .........idata$6................ |
| 5ce0 | 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 28 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 | ................(............... |
| 5d00 | 00 00 52 00 00 00 00 00 00 00 00 00 00 00 02 00 94 00 00 00 5f 45 76 74 49 6e 74 43 72 65 61 74 | ..R................._EvtIntCreat |
| 5d20 | 65 42 69 6e 58 4d 4c 46 72 6f 6d 43 75 73 74 6f 6d 58 4d 4c 40 33 32 00 5f 5f 69 6d 70 5f 5f 45 | eBinXMLFromCustomXML@32.__imp__E |
| 5d40 | 76 74 49 6e 74 43 72 65 61 74 65 42 69 6e 58 4d 4c 46 72 6f 6d 43 75 73 74 6f 6d 58 4d 4c 40 33 | vtIntCreateBinXMLFromCustomXML@3 |
| 5d60 | 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e | 2.__head_C__Users_Peter_Code_win |
| 5d80 | 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 | api_rs_i686_lib_libwinapi_wevtap |
| 5da0 | 69 5f 61 00 64 77 76 6c 73 30 30 30 31 37 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 | i_a.dwvls00017.o/...1516161048.. |
| 5dc0 | 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 38 36 20 20 20 20 20 20 20 60 0a | 0.....0.....100666..686.......`. |
| 5de0 | 4c 01 07 00 00 00 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 | L....................text....... |
| 5e00 | 00 00 00 00 08 00 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 | ........,...X.............0`.dat |
| 5e20 | 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | a............................... |
| 5e40 | 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | @.0..bss........................ |
| 5e60 | 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$7............ |
| 5e80 | 34 01 00 00 62 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 | 4...b.............0..idata$5.... |
| 5ea0 | 00 00 00 00 04 00 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........8...l.............0..ida |
| 5ec0 | 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 | ta$4............<...v........... |
| 5ee0 | 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 16 00 00 00 40 01 00 00 00 00 00 00 | ..0..idata$6............@....... |
| 5f00 | 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 | .............%.................. |
| 5f20 | 11 00 45 76 74 49 6e 74 41 73 73 65 72 74 43 6f 6e 66 69 67 00 00 00 00 02 00 00 00 04 00 00 00 | ..EvtIntAssertConfig............ |
| 5f40 | 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 | ................................ |
| 5f60 | 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 | .text..............data......... |
| 5f80 | 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 | .....bss...............idata$7.. |
| 5fa0 | 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$5...........idata |
| 5fc0 | 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 | $4...........idata$6............ |
| 5fe0 | 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1b 00 00 00 00 00 00 00 05 00 00 00 | ................................ |
| 6000 | 02 00 00 00 00 00 38 00 00 00 00 00 00 00 00 00 00 00 02 00 7a 00 00 00 5f 45 76 74 49 6e 74 41 | ......8.............z..._EvtIntA |
| 6020 | 73 73 65 72 74 43 6f 6e 66 69 67 40 31 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 49 6e 74 41 73 73 65 | ssertConfig@12.__imp__EvtIntAsse |
| 6040 | 72 74 43 6f 6e 66 69 67 40 31 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | rtConfig@12.__head_C__Users_Pete |
| 6060 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
| 6080 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 31 36 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00016.o/...15 |
| 60a0 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 37 | 16161048..0.....0.....100666..67 |
| 60c0 | 36 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 7c 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 6.......`.L.......|............t |
| 60e0 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 54 01 00 00 00 00 00 00 01 00 | ext...............,...T......... |
| 6100 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
| 6120 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
| 6140 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
| 6160 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 5e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...^.............0..i |
| 6180 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 68 01 00 00 00 00 00 00 01 00 | data$5............8...h......... |
| 61a0 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 72 01 | ....0..idata$4............<...r. |
| 61c0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 12 00 | ............0..idata$6.......... |
| 61e0 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
| 6200 | 00 00 00 00 00 00 00 00 00 00 10 00 45 76 74 47 65 74 51 75 65 72 79 49 6e 66 6f 00 00 00 02 00 | ............EvtGetQueryInfo..... |
| 6220 | 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 | ................................ |
| 6240 | 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 | .......text..............data... |
| 6260 | 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 | ...........bss...............ida |
| 6280 | 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 | ta$7...........idata$5.......... |
| 62a0 | 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 | .idata$4...........idata$6...... |
| 62c0 | 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 18 00 00 00 00 00 | ................................ |
| 62e0 | 00 00 05 00 00 00 02 00 00 00 00 00 32 00 00 00 00 00 00 00 00 00 00 00 02 00 74 00 00 00 5f 45 | ............2.............t..._E |
| 6300 | 76 74 47 65 74 51 75 65 72 79 49 6e 66 6f 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 51 | vtGetQueryInfo@20.__imp__EvtGetQ |
| 6320 | 75 65 72 79 49 6e 66 6f 40 32 30 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | ueryInfo@20.__head_C__Users_Pete |
| 6340 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
| 6360 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 31 35 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00015.o/...15 |
| 6380 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 32 | 16161048..0.....0.....100666..72 |
| 63a0 | 34 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 8c 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 4.......`.L....................t |
| 63c0 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 64 01 00 00 00 00 00 00 01 00 | ext...............,...d......... |
| 63e0 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
| 6400 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
| 6420 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
| 6440 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...n.............0..i |
| 6460 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 78 01 00 00 00 00 00 00 01 00 | data$5............8...x......... |
| 6480 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 82 01 | ....0..idata$4............<..... |
| 64a0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 22 00 | ............0..idata$6........". |
| 64c0 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
| 64e0 | 00 00 00 00 00 00 00 00 00 00 0f 00 45 76 74 47 65 74 50 75 62 6c 69 73 68 65 72 4d 65 74 61 64 | ............EvtGetPublisherMetad |
| 6500 | 61 74 61 50 72 6f 70 65 72 74 79 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 | ataProperty..................... |
| 6520 | 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 | .......................text..... |
| 6540 | 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 | .........data..............bss.. |
| 6560 | 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 | .............idata$7...........i |
| 6580 | 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 | data$5...........idata$4........ |
| 65a0 | 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...idata$6...................... |
| 65c0 | 01 00 00 00 02 00 00 00 00 00 28 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 52 00 00 00 | ..........(.................R... |
| 65e0 | 00 00 00 00 00 00 00 00 02 00 94 00 00 00 5f 45 76 74 47 65 74 50 75 62 6c 69 73 68 65 72 4d 65 | .............._EvtGetPublisherMe |
| 6600 | 74 61 64 61 74 61 50 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 50 | tadataProperty@24.__imp__EvtGetP |
| 6620 | 75 62 6c 69 73 68 65 72 4d 65 74 61 64 61 74 61 50 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 68 65 | ublisherMetadataProperty@24.__he |
| 6640 | 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 | ad_C__Users_Peter_Code_winapi_rs |
| 6660 | 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 | _i686_lib_libwinapi_wevtapi_a.dw |
| 6680 | 76 6c 73 30 30 30 31 34 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 | vls00014.o/...1516161048..0..... |
| 66a0 | 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 39 30 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 | 0.....100666..690.......`.L..... |
| 66c0 | 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 | ...............text............. |
| 66e0 | 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 | ..,...X.............0`.data..... |
| 6700 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 | ..........................@.0..b |
| 6720 | 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ss.............................. |
| 6740 | 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 62 01 | ....0..idata$7............4...b. |
| 6760 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 | ............0..idata$5.......... |
| 6780 | 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 | ..8...l.............0..idata$4.. |
| 67a0 | 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........<...v.............0..i |
| 67c0 | 64 61 74 61 24 36 00 00 00 00 00 00 00 00 18 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 | data$6............@............. |
| 67e0 | 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 0e 00 45 76 74 47 | .......%....................EvtG |
| 6800 | 65 74 4f 62 6a 65 63 74 41 72 72 61 79 53 69 7a 65 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 | etObjectArraySize............... |
| 6820 | 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 | ...........................text. |
| 6840 | 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 | .............data..............b |
| 6860 | 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 | ss...............idata$7........ |
| 6880 | 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 | ...idata$5...........idata$4.... |
| 68a0 | 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 | .......idata$6.................. |
| 68c0 | 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1d 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 | ................................ |
| 68e0 | 3c 00 00 00 00 00 00 00 00 00 00 00 02 00 7e 00 00 00 5f 45 76 74 47 65 74 4f 62 6a 65 63 74 41 | <.............~..._EvtGetObjectA |
| 6900 | 72 72 61 79 53 69 7a 65 40 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 4f 62 6a 65 63 74 41 72 | rraySize@8.__imp__EvtGetObjectAr |
| 6920 | 72 61 79 53 69 7a 65 40 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f | raySize@8.__head_C__Users_Peter_ |
| 6940 | 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 | Code_winapi_rs_i686_lib_libwinap |
| 6960 | 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 31 33 2e 6f 2f 20 20 20 31 35 31 36 | i_wevtapi_a.dwvls00013.o/...1516 |
| 6980 | 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 30 34 20 | 161048..0.....0.....100666..704. |
| 69a0 | 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 84 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 | ......`.L....................tex |
| 69c0 | 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 5c 01 00 00 00 00 00 00 01 00 00 00 | t...............,...\........... |
| 69e0 | 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..0`.data....................... |
| 6a00 | 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ........@.0..bss................ |
| 6a20 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 | ..................0..idata$7.... |
| 6a40 | 00 00 00 00 04 00 00 00 34 01 00 00 66 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........4...f.............0..ida |
| 6a60 | 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 70 01 00 00 00 00 00 00 01 00 00 00 | ta$5............8...p........... |
| 6a80 | 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 7a 01 00 00 | ..0..idata$4............<...z... |
| 6aa0 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 1c 00 00 00 | ..........0..idata$6............ |
| 6ac0 | 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 | @....................%.......... |
| 6ae0 | 00 00 00 00 00 00 00 00 0d 00 45 76 74 47 65 74 4f 62 6a 65 63 74 41 72 72 61 79 50 72 6f 70 65 | ..........EvtGetObjectArrayPrope |
| 6b00 | 72 74 79 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 | rty............................. |
| 6b20 | 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 | .............text..............d |
| 6b40 | 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 | ata..............bss............ |
| 6b60 | 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 | ...idata$7...........idata$5.... |
| 6b80 | 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 | .......idata$4...........idata$6 |
| 6ba0 | 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 | ................................ |
| 6bc0 | 22 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 46 00 00 00 00 00 00 00 00 00 00 00 02 00 | ".................F............. |
| 6be0 | 88 00 00 00 5f 45 76 74 47 65 74 4f 62 6a 65 63 74 41 72 72 61 79 50 72 6f 70 65 72 74 79 40 32 | ...._EvtGetObjectArrayProperty@2 |
| 6c00 | 38 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 4f 62 6a 65 63 74 41 72 72 61 79 50 72 6f 70 65 72 | 8.__imp__EvtGetObjectArrayProper |
| 6c20 | 74 79 40 32 38 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 | ty@28.__head_C__Users_Peter_Code |
| 6c40 | 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 | _winapi_rs_i686_lib_libwinapi_we |
| 6c60 | 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 31 32 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 | vtapi_a.dwvls00012.o/...15161610 |
| 6c80 | 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 36 38 20 20 20 20 20 | 48..0.....0.....100666..668..... |
| 6ca0 | 20 20 60 0a 4c 01 07 00 00 00 00 00 78 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 | ..`.L.......x............text... |
| 6cc0 | 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 50 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 | ............,...P.............0` |
| 6ce0 | 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | .data........................... |
| 6d00 | 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....@.0..bss.................... |
| 6d20 | 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 | ..............0..idata$7........ |
| 6d40 | 04 00 00 00 34 01 00 00 5a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 | ....4...Z.............0..idata$5 |
| 6d60 | 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 64 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 | ............8...d.............0. |
| 6d80 | 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 6e 01 00 00 00 00 00 00 | .idata$4............<...n....... |
| 6da0 | 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 10 00 00 00 40 01 00 00 | ......0..idata$6............@... |
| 6dc0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 | .................%.............. |
| 6de0 | 00 00 00 00 0c 00 45 76 74 47 65 74 4c 6f 67 49 6e 66 6f 00 02 00 00 00 04 00 00 00 06 00 00 00 | ......EvtGetLogInfo............. |
| 6e00 | 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 | .............................tex |
| 6e20 | 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 | t..............data............. |
| 6e40 | 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 | .bss...............idata$7...... |
| 6e60 | 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 | .....idata$5...........idata$4.. |
| 6e80 | 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 | .........idata$6................ |
| 6ea0 | 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 16 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 | ................................ |
| 6ec0 | 00 00 2e 00 00 00 00 00 00 00 00 00 00 00 02 00 70 00 00 00 5f 45 76 74 47 65 74 4c 6f 67 49 6e | ................p..._EvtGetLogIn |
| 6ee0 | 66 6f 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 4c 6f 67 49 6e 66 6f 40 32 30 00 5f 5f | fo@20.__imp__EvtGetLogInfo@20.__ |
| 6f00 | 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f | head_C__Users_Peter_Code_winapi_ |
| 6f20 | 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 | rs_i686_lib_libwinapi_wevtapi_a. |
| 6f40 | 64 77 76 6c 73 30 30 30 31 31 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 | dwvls00011.o/...1516161048..0... |
| 6f60 | 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 39 30 20 20 20 20 20 20 20 60 0a 4c 01 07 00 | ..0.....100666..690.......`.L... |
| 6f80 | 00 00 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 | .................text........... |
| 6fa0 | 08 00 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 | ....,...X.............0`.data... |
| 6fc0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 | ............................@.0. |
| 6fe0 | 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | .bss............................ |
| 7000 | 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 | ......0..idata$7............4... |
| 7020 | 62 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 | b.............0..idata$5........ |
| 7040 | 04 00 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 | ....8...l.............0..idata$4 |
| 7060 | 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 | ............<...v.............0. |
| 7080 | 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 18 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 | .idata$6............@........... |
| 70a0 | 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 0b 00 45 76 | .........%....................Ev |
| 70c0 | 74 47 65 74 45 78 74 65 6e 64 65 64 53 74 61 74 75 73 00 00 02 00 00 00 04 00 00 00 06 00 00 00 | tGetExtendedStatus.............. |
| 70e0 | 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 | .............................tex |
| 7100 | 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 | t..............data............. |
| 7120 | 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 | .bss...............idata$7...... |
| 7140 | 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 | .....idata$5...........idata$4.. |
| 7160 | 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 | .........idata$6................ |
| 7180 | 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1d 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 | ................................ |
| 71a0 | 00 00 3c 00 00 00 00 00 00 00 00 00 00 00 02 00 7e 00 00 00 5f 45 76 74 47 65 74 45 78 74 65 6e | ..<.............~..._EvtGetExten |
| 71c0 | 64 65 64 53 74 61 74 75 73 40 31 32 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 45 78 74 65 6e 64 | dedStatus@12.__imp__EvtGetExtend |
| 71e0 | 65 64 53 74 61 74 75 73 40 31 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | edStatus@12.__head_C__Users_Pete |
| 7200 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
| 7220 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 31 30 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00010.o/...15 |
| 7240 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 37 31 | 16161048..0.....0.....100666..71 |
| 7260 | 32 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 88 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 2.......`.L....................t |
| 7280 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 60 01 00 00 00 00 00 00 01 00 | ext...............,...`......... |
| 72a0 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
| 72c0 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
| 72e0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
| 7300 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 6a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...j.............0..i |
| 7320 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 74 01 00 00 00 00 00 00 01 00 | data$5............8...t......... |
| 7340 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 7e 01 | ....0..idata$4............<...~. |
| 7360 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 1e 00 | ............0..idata$6.......... |
| 7380 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
| 73a0 | 00 00 00 00 00 00 00 00 00 00 0a 00 45 76 74 47 65 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 50 | ............EvtGetEventMetadataP |
| 73c0 | 72 6f 70 65 72 74 79 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 | roperty......................... |
| 73e0 | 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 | ...................text......... |
| 7400 | 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 | .....data..............bss...... |
| 7420 | 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$7...........idata |
| 7440 | 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 | $5...........idata$4...........i |
| 7460 | 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 | data$6.......................... |
| 7480 | 02 00 00 00 00 00 24 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 4a 00 00 00 00 00 00 00 | ......$.................J....... |
| 74a0 | 00 00 00 00 02 00 8c 00 00 00 5f 45 76 74 47 65 74 45 76 65 6e 74 4d 65 74 61 64 61 74 61 50 72 | .........._EvtGetEventMetadataPr |
| 74c0 | 6f 70 65 72 74 79 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 45 76 65 6e 74 4d 65 74 61 | operty@24.__imp__EvtGetEventMeta |
| 74e0 | 64 61 74 61 50 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f | dataProperty@24.__head_C__Users_ |
| 7500 | 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 | Peter_Code_winapi_rs_i686_lib_li |
| 7520 | 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 30 39 2e 6f 2f 20 | bwinapi_wevtapi_a.dwvls00009.o/. |
| 7540 | 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 | ..1516161048..0.....0.....100666 |
| 7560 | 20 20 36 37 36 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 7c 01 00 00 0a 00 00 00 00 00 | ..676.......`.L.......|......... |
| 7580 | 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 54 01 00 00 00 00 | ...text...............,...T..... |
| 75a0 | 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ........0`.data................. |
| 75c0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 | ..............@.0..bss.......... |
| 75e0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 | ........................0..idata |
| 7600 | 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 5e 01 00 00 00 00 00 00 01 00 00 00 00 00 | $7............4...^............. |
| 7620 | 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 68 01 00 00 00 00 | 0..idata$5............8...h..... |
| 7640 | 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 | ........0..idata$4............<. |
| 7660 | 00 00 72 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 | ..r.............0..idata$6...... |
| 7680 | 00 00 12 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 | ......@....................%.... |
| 76a0 | 90 90 00 00 00 00 00 00 00 00 00 00 00 00 09 00 45 76 74 47 65 74 45 76 65 6e 74 49 6e 66 6f 00 | ................EvtGetEventInfo. |
| 76c0 | 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 | ................................ |
| 76e0 | 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 | ...........text..............dat |
| 7700 | 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 | a..............bss.............. |
| 7720 | 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 | .idata$7...........idata$5...... |
| 7740 | 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 | .....idata$4...........idata$6.. |
| 7760 | 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 18 00 | ................................ |
| 7780 | 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 32 00 00 00 00 00 00 00 00 00 00 00 02 00 74 00 | ................2.............t. |
| 77a0 | 00 00 5f 45 76 74 47 65 74 45 76 65 6e 74 49 6e 66 6f 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 | .._EvtGetEventInfo@20.__imp__Evt |
| 77c0 | 47 65 74 45 76 65 6e 74 49 6e 66 6f 40 32 30 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f | GetEventInfo@20.__head_C__Users_ |
| 77e0 | 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 | Peter_Code_winapi_rs_i686_lib_li |
| 7800 | 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 30 38 2e 6f 2f 20 | bwinapi_wevtapi_a.dwvls00008.o/. |
| 7820 | 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 | ..1516161048..0.....0.....100666 |
| 7840 | 20 20 37 31 32 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 88 01 00 00 0a 00 00 00 00 00 | ..712.......`.L................. |
| 7860 | 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 60 01 00 00 00 00 | ...text...............,...`..... |
| 7880 | 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ........0`.data................. |
| 78a0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 | ..............@.0..bss.......... |
| 78c0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 | ........................0..idata |
| 78e0 | 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 6a 01 00 00 00 00 00 00 01 00 00 00 00 00 | $7............4...j............. |
| 7900 | 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 74 01 00 00 00 00 | 0..idata$5............8...t..... |
| 7920 | 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 | ........0..idata$4............<. |
| 7940 | 00 00 7e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 | ..~.............0..idata$6...... |
| 7960 | 00 00 1e 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 | ......@....................%.... |
| 7980 | 90 90 00 00 00 00 00 00 00 00 00 00 00 00 08 00 45 76 74 47 65 74 43 68 61 6e 6e 65 6c 43 6f 6e | ................EvtGetChannelCon |
| 79a0 | 66 69 67 50 72 6f 70 65 72 74 79 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 | figProperty..................... |
| 79c0 | 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 | .......................text..... |
| 79e0 | 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 | .........data..............bss.. |
| 7a00 | 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 | .............idata$7...........i |
| 7a20 | 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 | data$5...........idata$4........ |
| 7a40 | 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...idata$6...................... |
| 7a60 | 01 00 00 00 02 00 00 00 00 00 24 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 4a 00 00 00 | ..........$.................J... |
| 7a80 | 00 00 00 00 00 00 00 00 02 00 8c 00 00 00 5f 45 76 74 47 65 74 43 68 61 6e 6e 65 6c 43 6f 6e 66 | .............._EvtGetChannelConf |
| 7aa0 | 69 67 50 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 47 65 74 43 68 61 6e 6e | igProperty@24.__imp__EvtGetChann |
| 7ac0 | 65 6c 43 6f 6e 66 69 67 50 72 6f 70 65 72 74 79 40 32 34 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 | elConfigProperty@24.__head_C__Us |
| 7ae0 | 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 | ers_Peter_Code_winapi_rs_i686_li |
| 7b00 | 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 30 37 | b_libwinapi_wevtapi_a.dwvls00007 |
| 7b20 | 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 | .o/...1516161048..0.....0.....10 |
| 7b40 | 30 36 36 36 20 20 36 37 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 7c 01 00 00 0a 00 | 0666..678.......`.L.......|..... |
| 7b60 | 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 54 01 | .......text...............,...T. |
| 7b80 | 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 | ............0`.data............. |
| 7ba0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 | ..................@.0..bss...... |
| 7bc0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 | ............................0..i |
| 7be0 | 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 5e 01 00 00 00 00 00 00 01 00 | data$7............4...^......... |
| 7c00 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 68 01 | ....0..idata$5............8...h. |
| 7c20 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 | ............0..idata$4.......... |
| 7c40 | 00 00 3c 01 00 00 72 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 | ..<...r.............0..idata$6.. |
| 7c60 | 00 00 00 00 00 00 14 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 | ..........@....................% |
| 7c80 | 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 07 00 45 76 74 46 6f 72 6d 61 74 4d 65 73 | ....................EvtFormatMes |
| 7ca0 | 73 61 67 65 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 | sage............................ |
| 7cc0 | 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 | ...............text............. |
| 7ce0 | 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 | .data..............bss.......... |
| 7d00 | 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 | .....idata$7...........idata$5.. |
| 7d20 | 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$4...........idata |
| 7d40 | 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 | $6.............................. |
| 7d60 | 00 00 19 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 34 00 00 00 00 00 00 00 00 00 00 00 | ....................4........... |
| 7d80 | 02 00 76 00 00 00 5f 45 76 74 46 6f 72 6d 61 74 4d 65 73 73 61 67 65 40 33 36 00 5f 5f 69 6d 70 | ..v..._EvtFormatMessage@36.__imp |
| 7da0 | 5f 5f 45 76 74 46 6f 72 6d 61 74 4d 65 73 73 61 67 65 40 33 36 00 5f 5f 68 65 61 64 5f 43 5f 5f | __EvtFormatMessage@36.__head_C__ |
| 7dc0 | 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f | Users_Peter_Code_winapi_rs_i686_ |
| 7de0 | 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 | lib_libwinapi_wevtapi_a.dwvls000 |
| 7e00 | 30 36 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 | 06.o/...1516161048..0.....0..... |
| 7e20 | 31 30 30 36 36 36 20 20 36 36 36 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 78 01 00 00 | 100666..666.......`.L.......x... |
| 7e40 | 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 | .........text...............,... |
| 7e60 | 50 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 | P.............0`.data........... |
| 7e80 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 | ....................@.0..bss.... |
| 7ea0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 | ..............................0. |
| 7ec0 | 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 00 00 5a 01 00 00 00 00 00 00 | .idata$7............4...Z....... |
| 7ee0 | 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 | ......0..idata$5............8... |
| 7f00 | 64 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 | d.............0..idata$4........ |
| 7f20 | 04 00 00 00 3c 01 00 00 6e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 | ....<...n.............0..idata$6 |
| 7f40 | 00 00 00 00 00 00 00 00 10 00 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 | ............@................... |
| 7f60 | ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 06 00 45 76 74 45 78 70 6f 72 74 4c | .%....................EvtExportL |
| 7f80 | 6f 67 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 | og.............................. |
| 7fa0 | 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 | .............text..............d |
| 7fc0 | 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 | ata..............bss............ |
| 7fe0 | 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 | ...idata$7...........idata$5.... |
| 8000 | 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 | .......idata$4...........idata$6 |
| 8020 | 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 | ................................ |
| 8040 | 15 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 2c 00 00 00 00 00 00 00 00 00 00 00 02 00 | ..................,............. |
| 8060 | 6e 00 00 00 5f 45 76 74 45 78 70 6f 72 74 4c 6f 67 40 32 30 00 5f 5f 69 6d 70 5f 5f 45 76 74 45 | n..._EvtExportLog@20.__imp__EvtE |
| 8080 | 78 70 6f 72 74 4c 6f 67 40 32 30 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | xportLog@20.__head_C__Users_Pete |
| 80a0 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
| 80c0 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 30 35 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00005.o/...15 |
| 80e0 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 39 | 16161048..0.....0.....100666..69 |
| 8100 | 38 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 84 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 8.......`.L....................t |
| 8120 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 5c 01 00 00 00 00 00 00 01 00 | ext...............,...\......... |
| 8140 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
| 8160 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
| 8180 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
| 81a0 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 66 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...f.............0..i |
| 81c0 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 70 01 00 00 00 00 00 00 01 00 | data$5............8...p......... |
| 81e0 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 7a 01 | ....0..idata$4............<...z. |
| 8200 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 1a 00 | ............0..idata$6.......... |
| 8220 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
| 8240 | 00 00 00 00 00 00 00 00 00 00 05 00 45 76 74 43 72 65 61 74 65 52 65 6e 64 65 72 43 6f 6e 74 65 | ............EvtCreateRenderConte |
| 8260 | 78 74 00 00 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 | xt.............................. |
| 8280 | 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 | ...............text............. |
| 82a0 | 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 | .data..............bss.......... |
| 82c0 | 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 | .....idata$7...........idata$5.. |
| 82e0 | 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$4...........idata |
| 8300 | 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 | $6.............................. |
| 8320 | 00 00 1f 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 | ....................@........... |
| 8340 | 02 00 82 00 00 00 5f 45 76 74 43 72 65 61 74 65 52 65 6e 64 65 72 43 6f 6e 74 65 78 74 40 31 32 | ......_EvtCreateRenderContext@12 |
| 8360 | 00 5f 5f 69 6d 70 5f 5f 45 76 74 43 72 65 61 74 65 52 65 6e 64 65 72 43 6f 6e 74 65 78 74 40 31 | .__imp__EvtCreateRenderContext@1 |
| 8380 | 32 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e | 2.__head_C__Users_Peter_Code_win |
| 83a0 | 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 | api_rs_i686_lib_libwinapi_wevtap |
| 83c0 | 69 5f 61 00 64 77 76 6c 73 30 30 30 30 34 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 | i_a.dwvls00004.o/...1516161048.. |
| 83e0 | 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 37 38 20 20 20 20 20 20 20 60 0a | 0.....0.....100666..678.......`. |
| 8400 | 4c 01 07 00 00 00 00 00 7c 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 | L.......|............text....... |
| 8420 | 00 00 00 00 08 00 00 00 2c 01 00 00 54 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 | ........,...T.............0`.dat |
| 8440 | 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | a............................... |
| 8460 | 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | @.0..bss........................ |
| 8480 | 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 | ..........0..idata$7............ |
| 84a0 | 34 01 00 00 5e 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 | 4...^.............0..idata$5.... |
| 84c0 | 00 00 00 00 04 00 00 00 38 01 00 00 68 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........8...h.............0..ida |
| 84e0 | 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 72 01 00 00 00 00 00 00 01 00 00 00 | ta$4............<...r........... |
| 8500 | 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 14 00 00 00 40 01 00 00 00 00 00 00 | ..0..idata$6............@....... |
| 8520 | 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 | .............%.................. |
| 8540 | 04 00 45 76 74 43 72 65 61 74 65 42 6f 6f 6b 6d 61 72 6b 00 02 00 00 00 04 00 00 00 06 00 00 00 | ..EvtCreateBookmark............. |
| 8560 | 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 | .............................tex |
| 8580 | 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 | t..............data............. |
| 85a0 | 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 | .bss...............idata$7...... |
| 85c0 | 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 | .....idata$5...........idata$4.. |
| 85e0 | 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 | .........idata$6................ |
| 8600 | 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 19 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 | ................................ |
| 8620 | 00 00 34 00 00 00 00 00 00 00 00 00 00 00 02 00 76 00 00 00 5f 45 76 74 43 72 65 61 74 65 42 6f | ..4.............v..._EvtCreateBo |
| 8640 | 6f 6b 6d 61 72 6b 40 34 00 5f 5f 69 6d 70 5f 5f 45 76 74 43 72 65 61 74 65 42 6f 6f 6b 6d 61 72 | okmark@4.__imp__EvtCreateBookmar |
| 8660 | 6b 40 34 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 | k@4.__head_C__Users_Peter_Code_w |
| 8680 | 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 | inapi_rs_i686_lib_libwinapi_wevt |
| 86a0 | 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 30 33 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 | api_a.dwvls00003.o/...1516161048 |
| 86c0 | 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 35 32 20 20 20 20 20 20 20 | ..0.....0.....100666..652....... |
| 86e0 | 60 0a 4c 01 07 00 00 00 00 00 74 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 | `.L.......t............text..... |
| 8700 | 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 4c 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 | ..........,...L.............0`.d |
| 8720 | 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ata............................. |
| 8740 | 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..@.0..bss...................... |
| 8760 | 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 | ............0..idata$7.......... |
| 8780 | 00 00 34 01 00 00 56 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 | ..4...V.............0..idata$5.. |
| 87a0 | 00 00 00 00 00 00 04 00 00 00 38 01 00 00 60 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........8...`.............0..i |
| 87c0 | 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 6a 01 00 00 00 00 00 00 01 00 | data$4............<...j......... |
| 87e0 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 0c 00 00 00 40 01 00 00 00 00 | ....0..idata$6............@..... |
| 8800 | 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 | ...............%................ |
| 8820 | 00 00 03 00 45 76 74 43 6c 6f 73 65 00 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 | ....EvtClose.................... |
| 8840 | 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 | .......................text..... |
| 8860 | 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 | .........data..............bss.. |
| 8880 | 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 | .............idata$7...........i |
| 88a0 | 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 | data$5...........idata$4........ |
| 88c0 | 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 | ...idata$6...................... |
| 88e0 | 01 00 00 00 02 00 00 00 00 00 10 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 22 00 00 00 | ............................"... |
| 8900 | 00 00 00 00 00 00 00 00 02 00 64 00 00 00 5f 45 76 74 43 6c 6f 73 65 40 34 00 5f 5f 69 6d 70 5f | ..........d..._EvtClose@4.__imp_ |
| 8920 | 5f 45 76 74 43 6c 6f 73 65 40 34 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 | _EvtClose@4.__head_C__Users_Pete |
| 8940 | 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e | r_Code_winapi_rs_i686_lib_libwin |
| 8960 | 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 30 32 2e 6f 2f 20 20 20 31 35 | api_wevtapi_a.dwvls00002.o/...15 |
| 8980 | 31 36 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 36 | 16161048..0.....0.....100666..66 |
| 89a0 | 34 20 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 78 01 00 00 0a 00 00 00 00 00 04 01 2e 74 | 4.......`.L.......x............t |
| 89c0 | 65 78 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 50 01 00 00 00 00 00 00 01 00 | ext...............,...P......... |
| 89e0 | 00 00 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ....0`.data..................... |
| 8a00 | 00 00 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..........@.0..bss.............. |
| 8a20 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 | ....................0..idata$7.. |
| 8a40 | 00 00 00 00 00 00 04 00 00 00 34 01 00 00 5a 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 | ..........4...Z.............0..i |
| 8a60 | 64 61 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 64 01 00 00 00 00 00 00 01 00 | data$5............8...d......... |
| 8a80 | 00 00 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 6e 01 | ....0..idata$4............<...n. |
| 8aa0 | 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 0e 00 | ............0..idata$6.......... |
| 8ac0 | 00 00 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 | ..@....................%........ |
| 8ae0 | 00 00 00 00 00 00 00 00 00 00 02 00 45 76 74 43 6c 65 61 72 4c 6f 67 00 00 00 02 00 00 00 04 00 | ............EvtClearLog......... |
| 8b00 | 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 | ................................ |
| 8b20 | 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 | ...text..............data....... |
| 8b40 | 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 | .......bss...............idata$7 |
| 8b60 | 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 | ...........idata$5...........ida |
| 8b80 | 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 | ta$4...........idata$6.......... |
| 8ba0 | 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 14 00 00 00 00 00 00 00 05 00 | ................................ |
| 8bc0 | 00 00 02 00 00 00 00 00 2a 00 00 00 00 00 00 00 00 00 00 00 02 00 6c 00 00 00 5f 45 76 74 43 6c | ........*.............l..._EvtCl |
| 8be0 | 65 61 72 4c 6f 67 40 31 36 00 5f 5f 69 6d 70 5f 5f 45 76 74 43 6c 65 61 72 4c 6f 67 40 31 36 00 | earLog@16.__imp__EvtClearLog@16. |
| 8c00 | 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 | __head_C__Users_Peter_Code_winap |
| 8c20 | 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f | i_rs_i686_lib_libwinapi_wevtapi_ |
| 8c40 | 61 00 64 77 76 6c 73 30 30 30 30 31 2e 6f 2f 20 20 20 31 35 31 36 31 36 31 30 34 38 20 20 30 20 | a.dwvls00001.o/...1516161048..0. |
| 8c60 | 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 35 34 20 20 20 20 20 20 20 60 0a 4c 01 | ....0.....100666..654.......`.L. |
| 8c80 | 07 00 00 00 00 00 74 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 74 00 00 00 00 00 00 00 00 00 | ......t............text......... |
| 8ca0 | 00 00 08 00 00 00 2c 01 00 00 4c 01 00 00 00 00 00 00 01 00 00 00 20 00 30 60 2e 64 61 74 61 00 | ......,...L.............0`.data. |
| 8cc0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 40 00 | ..............................@. |
| 8ce0 | 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | 0..bss.......................... |
| 8d00 | 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 00 00 00 00 04 00 00 00 34 01 | ........0..idata$7............4. |
| 8d20 | 00 00 56 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 35 00 00 00 00 00 00 | ..V.............0..idata$5...... |
| 8d40 | 00 00 04 00 00 00 38 01 00 00 60 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 | ......8...`.............0..idata |
| 8d60 | 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 6a 01 00 00 00 00 00 00 01 00 00 00 00 00 | $4............<...j............. |
| 8d80 | 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 0c 00 00 00 40 01 00 00 00 00 00 00 00 00 | 0..idata$6............@......... |
| 8da0 | 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 00 00 00 00 00 00 00 00 01 00 | ...........%.................... |
| 8dc0 | 45 76 74 43 61 6e 63 65 6c 00 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 | EvtCancel....................... |
| 8de0 | 00 00 06 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 | ...................text......... |
| 8e00 | 00 00 03 00 2e 64 61 74 61 00 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 | .....data..............bss...... |
| 8e20 | 00 00 03 00 00 00 03 00 2e 69 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 | .........idata$7...........idata |
| 8e40 | 24 35 00 00 00 00 05 00 00 00 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 | $5...........idata$4...........i |
| 8e60 | 64 61 74 61 24 36 00 00 00 00 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 | data$6.......................... |
| 8e80 | 02 00 00 00 00 00 11 00 00 00 00 00 00 00 05 00 00 00 02 00 00 00 00 00 24 00 00 00 00 00 00 00 | ........................$....... |
| 8ea0 | 00 00 00 00 02 00 66 00 00 00 5f 45 76 74 43 61 6e 63 65 6c 40 34 00 5f 5f 69 6d 70 5f 5f 45 76 | ......f..._EvtCancel@4.__imp__Ev |
| 8ec0 | 74 43 61 6e 63 65 6c 40 34 00 5f 5f 68 65 61 64 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f | tCancel@4.__head_C__Users_Peter_ |
| 8ee0 | 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 | Code_winapi_rs_i686_lib_libwinap |
| 8f00 | 69 5f 77 65 76 74 61 70 69 5f 61 00 64 77 76 6c 73 30 30 30 30 30 2e 6f 2f 20 20 20 31 35 31 36 | i_wevtapi_a.dwvls00000.o/...1516 |
| 8f20 | 31 36 31 30 34 38 20 20 30 20 20 20 20 20 30 20 20 20 20 20 31 30 30 36 36 36 20 20 36 39 32 20 | 161048..0.....0.....100666..692. |
| 8f40 | 20 20 20 20 20 20 60 0a 4c 01 07 00 00 00 00 00 80 01 00 00 0a 00 00 00 00 00 04 01 2e 74 65 78 | ......`.L....................tex |
| 8f60 | 74 00 00 00 00 00 00 00 00 00 00 00 08 00 00 00 2c 01 00 00 58 01 00 00 00 00 00 00 01 00 00 00 | t...............,...X........... |
| 8f80 | 20 00 30 60 2e 64 61 74 61 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ..0`.data....................... |
| 8fa0 | 00 00 00 00 00 00 00 00 40 00 30 c0 2e 62 73 73 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 | ........@.0..bss................ |
| 8fc0 | 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 30 c0 2e 69 64 61 74 61 24 37 00 00 00 00 | ..................0..idata$7.... |
| 8fe0 | 00 00 00 00 04 00 00 00 34 01 00 00 62 01 00 00 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 | ........4...b.............0..ida |
| 9000 | 74 61 24 35 00 00 00 00 00 00 00 00 04 00 00 00 38 01 00 00 6c 01 00 00 00 00 00 00 01 00 00 00 | ta$5............8...l........... |
| 9020 | 00 00 30 c0 2e 69 64 61 74 61 24 34 00 00 00 00 00 00 00 00 04 00 00 00 3c 01 00 00 76 01 00 00 | ..0..idata$4............<...v... |
| 9040 | 00 00 00 00 01 00 00 00 00 00 30 c0 2e 69 64 61 74 61 24 36 00 00 00 00 00 00 00 00 18 00 00 00 | ..........0..idata$6............ |
| 9060 | 40 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 20 c0 ff 25 00 00 00 00 90 90 00 00 00 00 | @....................%.......... |
| 9080 | 00 00 00 00 00 00 00 00 00 00 45 76 74 41 72 63 68 69 76 65 45 78 70 6f 72 74 65 64 4c 6f 67 00 | ..........EvtArchiveExportedLog. |
| 90a0 | 02 00 00 00 04 00 00 00 06 00 00 00 00 00 09 00 00 00 07 00 00 00 00 00 06 00 00 00 07 00 00 00 | ................................ |
| 90c0 | 00 00 06 00 00 00 07 00 2e 74 65 78 74 00 00 00 00 00 00 00 01 00 00 00 03 00 2e 64 61 74 61 00 | .........text..............data. |
| 90e0 | 00 00 00 00 00 00 02 00 00 00 03 00 2e 62 73 73 00 00 00 00 00 00 00 00 03 00 00 00 03 00 2e 69 | .............bss...............i |
| 9100 | 64 61 74 61 24 37 00 00 00 00 04 00 00 00 03 00 2e 69 64 61 74 61 24 35 00 00 00 00 05 00 00 00 | data$7...........idata$5........ |
| 9120 | 03 00 2e 69 64 61 74 61 24 34 00 00 00 00 06 00 00 00 03 00 2e 69 64 61 74 61 24 36 00 00 00 00 | ...idata$4...........idata$6.... |
| 9140 | 07 00 00 00 03 00 00 00 00 00 04 00 00 00 00 00 00 00 01 00 00 00 02 00 00 00 00 00 1e 00 00 00 | ................................ |
| 9160 | 00 00 00 00 05 00 00 00 02 00 00 00 00 00 3e 00 00 00 00 00 00 00 00 00 00 00 02 00 80 00 00 00 | ..............>................. |
| 9180 | 5f 45 76 74 41 72 63 68 69 76 65 45 78 70 6f 72 74 65 64 4c 6f 67 40 31 36 00 5f 5f 69 6d 70 5f | _EvtArchiveExportedLog@16.__imp_ |
| 91a0 | 5f 45 76 74 41 72 63 68 69 76 65 45 78 70 6f 72 74 65 64 4c 6f 67 40 31 36 00 5f 5f 68 65 61 64 | _EvtArchiveExportedLog@16.__head |
| 91c0 | 5f 43 5f 5f 55 73 65 72 73 5f 50 65 74 65 72 5f 43 6f 64 65 5f 77 69 6e 61 70 69 5f 72 73 5f 69 | _C__Users_Peter_Code_winapi_rs_i |
| 91e0 | 36 38 36 5f 6c 69 62 5f 6c 69 62 77 69 6e 61 70 69 5f 77 65 76 74 61 70 69 5f 61 00 | 686_lib_libwinapi_wevtapi_a. |