Riremito

Untitled

Apr 17th, 2021
706
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. [Enable]
  2. Alloc(IAT_Hook_GetLastError, 256)
  3. Label(Return)
  4. Label(IAT)
  5. Label(ModifyGMFlag)
  6.  
  7. IAT_Hook_GetLastError:
  8. // Return Address Filter
  9. cmp [esp],03182616
  10. jne Return
  11. cmp [esp+C],0316B355
  12. jne Return
  13. cmp [esp+10],02F76072
  14. jne Return
  15. mov [esp+10],ModifyGMFlag
  16. Return:
  17. jmp dword ptr [IAT]
  18.  
  19. ModifyGMFlag:
  20. mov ecx,[edi+00002230]
  21. mov edx,00009A65
  22. mov [ecx+01],al
  23. mov ecx,[edi+00002230]
  24. mov al,[ecx+01]
  25. mov [ecx+04],dx
  26. test al,al
  27. movzx ebx,al
  28. mov edx,0000002A
  29. cmove ebx,edx
  30. mov al,bl
  31. mov byte ptr [ebp+0C],01
  32. xor al,[ebp+0C]
  33. mov [ecx],al
  34. jmp 02F760A1
  35.  
  36. IAT:
  37. dd KERNEL32.GetLastError
  38.  
  39.  
  40. 037430FC:
  41. dd IAT_Hook_GetLastError
  42.  
  43. [Disable]
  44. 037430FC:
  45. dd KERNEL32.GetLastError
  46.  
  47. DeAlloc(IAT_Hook_GetLastError)
RAW Paste Data

Adblocker detected! Please consider disabling it...

We've detected AdBlock Plus or some other adblocking software preventing Pastebin.com from fully loading.

We don't have any obnoxious sound, or popup ads, we actively block these annoying types of ads!

Please add Pastebin.com to your ad blocker whitelist or disable your adblocking software.

×