Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 0F4F0033 - 55 - push ebp
- 0F4F0034 - 8B EC - mov ebp,esp
- 0F4F0036 - 6A FF - push -01
- 0F4F0038 - 68 002C2C1A - push EHSvc.dll+132C00
- 0F4F003D - 68 9834271A - push EHSvc.dll+E3498
- 0F4F0042 - 64 A1 00000000 - mov eax,fs:[00000000]
- 0F4F0048 - 50 - push eax
- 0F4F0049 - 64 89 25 00000000 - mov fs:[00000000],esp
- 0F4F0050 - 83 EC 20 - sub esp,20
- 0F4F0053 - 53 - push ebx
- 0F4F0054 - 56 - push esi
- 0F4F0055 - 57 - push edi
- 0F4F0056 - 89 65 E8 - mov [ebp-18],esp
- 0F4F0059 - 33 FF - xor edi,edi
- 0F4F005B - 33 F6 - xor esi,esi
- 0F4F005D - 89 75 E0 - mov [ebp-20],esi
- 0F4F0060 - 33 DB - xor ebx,ebx
- 0F4F0062 - 89 5D D8 - mov [ebp-28],ebx
- 0F4F0065 - B8 FFFFFF0F - mov eax,0FFFFFFF : [905A4D00]
- 0F4F006A - 89 45 E4 - mov [ebp-1C],eax
- 0F4F006D - 89 7D FC - mov [ebp-04],edi
- 0F4F0070 - 8B 4D 08 - mov ecx,[ebp+08]
- 0F4F0073 - 3B CF - cmp ecx,edi
- 0F4F0075 - 74 12 - je 0F4F0089
- 0F4F0077 - 8B 55 0C - mov edx,[ebp+0C]
- 0F4F007A - 85 D2 - test edx,edx
- 0F4F007C - 74 0B - je 0F4F0089
- 0F4F007E - 8B F1 - mov esi,ecx
- 0F4F0080 - 89 75 E0 - mov [ebp-20],esi
- 0F4F0083 - 8D 1C 11 - lea ebx,[ecx+edx]
- 0F4F0086 - 89 5D D8 - mov [ebp-28],ebx
- 0F4F0089 - 81 3D 50602F1A 18C8221A - cmp [EHSvc.dll+166050],EHSvc.dll+9C818
- 0F4F0093 - 74 1A - je 0F4F00AF
- 0F4F0095 - C7 45 FC FFFFFFFF - mov [ebp-04],FFFFFFFF
- 0F4F009C - 33 C0 - xor eax,eax
- 0F4F009E - 8B 4D F0 - mov ecx,[ebp-10]
- 0F4F00A1 - 64 89 0D 00000000 - mov fs:[00000000],ecx
- 0F4F00A8 - 5F - pop edi
- 0F4F00A9 - 5E - pop esi
- 0F4F00AA - 5B - pop ebx
- 0F4F00AB - 8B E5 - mov esp,ebp
- 0F4F00AD - 5D - pop ebp
- 0F4F00AE - C3 - ret
- 0F4F00AF - 8B 0D 58602F1A - mov ecx,[EHSvc.dll+166058]
- 0F4F00B5 - 3B 0D 2C602F1A - cmp ecx,[EHSvc.dll+16602C]
- 0F4F00BB - 74 1A - je 0F4F00D7
- 0F4F00BD - C7 45 FC FFFFFFFF - mov [ebp-04],FFFFFFFF
- 0F4F00C4 - 33 C0 - xor eax,eax
- 0F4F00C6 - 8B 4D F0 - mov ecx,[ebp-10]
- 0F4F00C9 - 64 89 0D 00000000 - mov fs:[00000000],ecx
- 0F4F00D0 - 5F - pop edi
- 0F4F00D1 - 5E - pop esi
- 0F4F00D2 - 5B - pop ebx
- 0F4F00D3 - 8B E5 - mov esp,ebp
- 0F4F00D5 - 5D - pop ebp
- 0F4F00D6 - C3 - ret
- 0F4F00D7 - 8B 15 60602F1A - mov edx,[EHSvc.dll+166060]
- 0F4F00DD - 3B 15 34602F1A - cmp edx,[EHSvc.dll+166034]
- 0F4F00E3 - 74 1A - je 0F4F00FF
- 0F4F00E5 - C7 45 FC FFFFFFFF - mov [ebp-04],FFFFFFFF
- 0F4F00EC - 33 C0 - xor eax,eax
- 0F4F00EE - 8B 4D F0 - mov ecx,[ebp-10]
- 0F4F00F1 - 64 89 0D 00000000 - mov fs:[00000000],ecx
- 0F4F00F8 - 5F - pop edi
- 0F4F00F9 - 5E - pop esi
- 0F4F00FA - 5B - pop ebx
- 0F4F00FB - 8B E5 - mov esp,ebp
- 0F4F00FD - 5D - pop ebp
- 0F4F00FE - C3 - ret
- 0F4F00FF - 8B 0D 68602F1A - mov ecx,[EHSvc.dll+166068]
- 0F4F0105 - 3B 0D 3C602F1A - cmp ecx,[EHSvc.dll+16603C]
- 0F4F010B - 74 1A - je 0F4F0127
- 0F4F010D - C7 45 FC FFFFFFFF - mov [ebp-04],FFFFFFFF
- 0F4F0114 - 33 C0 - xor eax,eax
- 0F4F0116 - 8B 4D F0 - mov ecx,[ebp-10]
- 0F4F0119 - 64 89 0D 00000000 - mov fs:[00000000],ecx
- 0F4F0120 - 5F - pop edi
- 0F4F0121 - 5E - pop esi
- 0F4F0122 - 5B - pop ebx
- 0F4F0123 - 8B E5 - mov esp,ebp
- 0F4F0125 - 5D - pop ebp
- 0F4F0126 - C3 - ret
- 0F4F0127 - 8B 15 70602F1A - mov edx,[EHSvc.dll+166070]
- 0F4F012D - 3B 15 44602F1A - cmp edx,[EHSvc.dll+166044]
- 0F4F0133 - 74 1A - je 0F4F014F
- 0F4F0135 - C7 45 FC FFFFFFFF - mov [ebp-04],FFFFFFFF
- 0F4F013C - 33 C0 - xor eax,eax
- 0F4F013E - 8B 4D F0 - mov ecx,[ebp-10]
- 0F4F0141 - 64 89 0D 00000000 - mov fs:[00000000],ecx
- 0F4F0148 - 5F - pop edi
- 0F4F0149 - 5E - pop esi
- 0F4F014A - 5B - pop ebx
- 0F4F014B - 8B E5 - mov esp,ebp
- 0F4F014D - 5D - pop ebp
- 0F4F014E - C3 - ret
- 0F4F014F - 8B 0C FD 50602F1A - mov ecx,[edi*8+EHSvc.dll+166050]
- 0F4F0156 - 85 C9 - test ecx,ecx
- 0F4F0158 - 0F84 80000000 - je 0F4F01DE
- 0F4F015E - 85 F6 - test esi,esi
- 0F4F0160 - 74 26 - je 0F4F0188
- 0F4F0162 - 85 DB - test ebx,ebx
- 0F4F0164 - 74 22 - je 0F4F0188
- 0F4F0166 - 3B CE - cmp ecx,esi
- 0F4F0168 - 72 04 - jb 0F4F016E
- 0F4F016A - 3B CB - cmp ecx,ebx
- 0F4F016C - 76 1A - jna 0F4F0188
- 0F4F016E - C7 45 FC FFFFFFFF - mov [ebp-04],FFFFFFFF
- 0F4F0175 - 33 C0 - xor eax,eax
- 0F4F0177 - 8B 4D F0 - mov ecx,[ebp-10]
- 0F4F017A - 64 89 0D 00000000 - mov fs:[00000000],ecx
- 0F4F0181 - 5F - pop edi
- 0F4F0182 - 5E - pop esi
- 0F4F0183 - 5B - pop ebx
- 0F4F0184 - 8B E5 - mov esp,ebp
- 0F4F0186 - 5D - pop ebp
- 0F4F0187 - C3 - ret
- 0F4F0188 - 89 4D D4 - mov [ebp-2C],ecx
- 0F4F018B - 8B 34 FD 54602F1A - mov esi,[edi*8+EHSvc.dll+166054]
- 0F4F0192 - 89 75 D0 - mov [ebp-30],esi
- 0F4F0195 - 85 F6 - test esi,esi
- 0F4F0197 - 75 08 - jne 0F4F01A1
- 0F4F0199 - BE 40000000 - mov esi,00000040
- 0F4F019E - 89 75 D0 - mov [ebp-30],esi
- 0F4F01A1 - 8B D6 - mov edx,esi
- 0F4F01A3 - 4E - dec esi
- 0F4F01A4 - 89 75 D0 - mov [ebp-30],esi
- 0F4F01A7 - 85 D2 - test edx,edx
- 0F4F01A9 - 74 24 - je 0F4F01CF
- 0F4F01AB - C1 E8 08 - shr eax,08
- 0F4F01AE - 89 45 E4 - mov [ebp-1C],eax
- 0F4F01B1 - 8B D0 - mov edx,eax
- 0F4F01B3 - 81 E2 FF000000 - and edx,000000FF
- 0F4F01B9 - 33 DB - xor ebx,ebx
- 0F4F01BB - 8A 19 - mov bl,[ecx]
- 0F4F01BD - 33 D3 - xor edx,ebx
- 0F4F01BF - 33 04 95 84602F1A - xor eax,[edx*4+EHSvc.dll+166084]
- 0F4F01C6 - 89 45 E4 - mov [ebp-1C],eax
- 0F4F01C9 - 41 - inc ecx
- 0F4F01CA - 89 4D D4 - mov [ebp-2C],ecx
- 0F4F01CD - EB D2 - jmp 0F4F01A1
- 0F4F01CF - 47 - inc edi
- 0F4F01D0 - 89 7D DC - mov [ebp-24],edi
- 0F4F01D3 - 8B 5D D8 - mov ebx,[ebp-28]
- 0F4F01D6 - 8B 75 E0 - mov esi,[ebp-20]
- 0F4F01D9 - E9 71FFFFFF - jmp 0F4F014F
- 0F4F01DE - C7 45 FC FFFFFFFF - mov [ebp-04],FFFFFFFF
- 0F4F01E5 - 8B 4D F0 - mov ecx,[ebp-10]
- 0F4F01E8 - 64 89 0D 00000000 - mov fs:[00000000],ecx
- 0F4F01EF - 5F - pop edi
- 0F4F01F0 - 5E - pop esi
- 0F4F01F1 - 5B - pop ebx
- 0F4F01F2 - 8B E5 - mov esp,ebp
- 0F4F01F4 - 5D - pop ebp
- 0F4F01F5 - C3 - ret
- 0F4F01F6 - B8 01000000 - mov eax,00000001
- 0F4F01FB - C3 - ret
- 0F4F01FC - 8B 65 E8 - mov esp,[ebp-18]
- 0F4F01FF - C7 45 FC FFFFFFFF - mov [ebp-04],FFFFFFFF
- 0F4F0206 - 8B 45 E4 - mov eax,[ebp-1C]
- 0F4F0209 - 8B 4D F0 - mov ecx,[ebp-10]
- 0F4F020C - 64 89 0D 00000000 - mov fs:[00000000],ecx
- 0F4F0213 - 5F - pop edi
- 0F4F0214 - 5E - pop esi
- 0F4F0215 - 5B - pop ebx
- 0F4F0216 - 8B E5 - mov esp,ebp
- 0F4F0218 - 5D - pop ebp
- 0F4F0219 - C3 - ret
- 0F4F021A - 90 - nop
- 0F4F021B - 90 - nop
- 0F4F021C - 90 - nop
- 0F4F021D - 90 - nop
- 0F4F021E - 90 - nop
- 0F4F021F - 90 - nop
- 0F4F0220 - 90 - nop
- 0F4F0221 - 90 - nop
- 0F4F0222 - 90 - nop
- 0F4F0223 - B8 50942A1A - mov eax,EHSvc.dll+119450
- 0F4F0228 - 2D 50922A1A - sub eax,EHSvc.dll+119250
- 0F4F022D - C3 - ret
- 0F4F022E - 90 - nop
- 0F4F022F - 90 - nop
- 0F4F0230 - 90 - nop
- 0F4F0231 - 90 - nop
- 0F4F0232 - 90 - nop
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement