Guest User

Ollydbg

a guest
Mar 10th, 2017
166
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. 008CD915 Main     CALL DWORD PTR [<&KERNEL32.EncodePointer>]
  2. RtlEncodePointer  MOV EDI,EDI
  3. 7725D042 Main     PUSH EBP
  4. 7725D043 Main     MOV EBP,ESP                               ; EBP=0115F910
  5. 7725D045 Main     PUSH ECX
  6. 7725D046 Main     PUSH 0
  7. 7725D048 Main     PUSH 4
  8. 7725D04A Main     LEA EAX,DWORD PTR [EBP-4]                 ; EAX=0115F90C
  9. 7725D04D Main     PUSH EAX
  10. 7725D04E Main     PUSH 24
  11. 7725D050 Main     PUSH -1
  12. 7725D052 Main     CALL ntdll.ZwQueryInformationProcess
  13. ZwQueryInformatio>MOV EAX,19                                ; EAX=00000019
  14. 7726E745 Main     CALL ntdll.7726E74A
  15. 7726E74A Main     POP EDX                                   ; EDX=7726E74A
  16. 7726E74B Main     CMP BYTE PTR [EDX+14],4B
  17. 7726E74F Main     JNZ SHORT ntdll.7726E75F
  18. 7726E75F Main     MOV EDX,ntdll.77282CF0                    ; EDX=77282CF0
  19. 7726E764 Main     CALL EDX
  20. 77282CF0 Main     JMP DWORD PTR [Wow64Transition]
  21. 62857000 Main     JMP FAR 0033:62857009                     ; EAX=008CD978, ECX=00000000, EDX=00000000, EBX=00F6E000, EBP=00000000, ESI=00000000, EDI=00000000
  22. RtlUserThreadStar>MOV DWORD PTR [ESP+4],EAX                 ; EAX=00000000, EBX=00800000, EBP=0115F0C8, EDI=00F71000
  23. 7726E85C Main     RET 28                                    ; EBP=0115F0B0
  24. 7726E85C Main     RET 28                                    ; EBP=0115EB48
  25. 7726E85C Main     RET 28                                    ; EBP=0115E308
  26. 7726E85C Main     RET 28                                    ; EBX=7730F9A0, EBP=0115F8B0, EDI=00000000
  27.     Process terminated, exit code 0
  28. 7726E89C Main     RET 8
  29.     Run trace closed
RAW Paste Data