Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Function: ntdll!LdrVerifyImageMatchesChecksumEx
- 0x77a5deea <+0x00fe> pushl 0x0
- 0x77a5def0 <+0x0104> mov 0x10(%esp),%eax
- 0x77a5def4 <+0x0108> mov %ebp,0x10(%esp)
- 0x77a5def8 <+0x010c> lea 0x10(%esp),%ebp
- 0x77a5defc <+0x0110> sub %eax,%esp
- 0x77a5defe <+0x0112> push %ebx
- 0x77a5deff <+0x0113> push %esi
- 0x77a5df00 <+0x0114> push %edi
- 0x77a5df01 <+0x0115> mov 0x77b32088,%eax
- 0x77a5df06 <+0x011a> xor %eax,-0x4(%ebp)
- 0x77a5df09 <+0x011d> xor %ebp,%eax
- 0x77a5df0b <+0x011f> push %eax
- 0x77a5df0c <+0x0120> mov %esp,-0x18(%ebp)
- 0x77a5df0f <+0x0123> pushl -0x8(%ebp)
- 0x77a5df12 <+0x0126> mov -0x4(%ebp),%eax
- 0x77a5df15 <+0x0129> movl $0xfffffffe,-0x4(%ebp)
- 0x77a5df1c <+0x0130> mov %eax,-0x8(%ebp)
- 0x77a5df1f <+0x0133> lea -0x10(%ebp),%eax
- 0x77a5df22 <+0x0136> mov %eax,%fs:0x0
- 0x77a5df28 <+0x013c> ret
- 0x77a5df29 <+0x013d> mov -0x10(%ebp),%ecx
- 0x77a5df2c <+0x0140> mov %ecx,%fs:0x0
- 0x77a5df33 <+0x0147> pop %ecx
- 0x77a5df34 <+0x0148> pop %edi
- 0x77a5df35 <+0x0149> pop %edi
- 0x77a5df36 <+0x014a> pop %esi
- 0x77a5df37 <+0x014b> pop %ebx
- 0x77a5df38 <+0x014c> mov %ebp,%esp
- 0x77a5df3a <+0x014e> pop %ebp
- 0x77a5df3b <+0x014f> push %ecx
- 0x77a5df3c <+0x0150> ret
- 0x77a5df3d <+0x0151> nop
- 0x77a5df3e <+0x0152> nop
- 0x77a5df3f <+0x0153> nop
- 0x77a5df40 <+0x0154> mov 0xc(%esp),%edx
- 0x77a5df44 <+0x0158> mov 0x4(%esp),%ecx
- 0x77a5df48 <+0x015c> test %edx,%edx
- 0x77a5df4a <+0x015e> je 0x77a5df9b <ntdll!LdrVerifyImageMatchesChecksumEx+431>
- 0x77a5df4c <+0x0160> xor %eax,%eax
- 0x77a5df4e <+0x0162> mov 0x8(%esp),%al
- 0x77a5df52 <+0x0166> push %edi
- 0x77a5df53 <+0x0167> mov %ecx,%edi
- 0x77a5df55 <+0x0169> cmp $0x4,%edx
- 0x77a5df58 <+0x016c> jb 0x77a5df8b <ntdll!LdrVerifyImageMatchesChecksumEx+415>
- 0x77a5df5a <+0x016e> neg %ecx
- 0x77a5df5c <+0x0170> and $0x3,%ecx
- 0x77a5df5f <+0x0173> je 0x77a5df6d <ntdll!LdrVerifyImageMatchesChecksumEx+385>
- 0x77a5df61 <+0x0175> sub %ecx,%edx
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement