Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- // === break on load module ===
- mov sApi, "ReadFile"
- mov sDLL, "kernel32"
- gpa sApi, sDLL
- // store address
- mov handle, $RESULT
- log handle
- cmp handle, 0
- je abort
- lbl_bp:
- // run
- go handle
- mov adrRet, [esp]
- mov hFile, [esp+4.]
- mov InBuffer, [esp+8.]
- mov nNumberOfBytesToRead, [esp+12.]
- mov lpNumberOfBytesRead, [esp+16.]
- mov lpOverlapped, [esp+20.]
- log InBuffer
- log hFile
- log nNumberOfBytesToRead
- log lpNumberOfBytesRead
- log lpOverlapped
- cmp InBuffer,0
- je noIn
- mov INN, [InBuffer], nNumberOfBytesToRead
- log INN
- jmp lbl_bp
- noIn:
- jmp lbl_bp
- abort:
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement