Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- CreateWindowExW
- USER32.LoadCursorW+12D - E9 0788C2FD - jmp msimg32.CWEx
- USER32.CreateWindowExW - EB F9 - jmp USER32.LoadCursorW+12D
- USER32.CreateWindowExW+2- 55 - push ebp
- USER32.CreateWindowExW+3- 8B EC - mov ebp,esp
- USER32.CreateWindowExW+5- 68 00000040 - push 40000000
- msimg32.CWEx - 55 - push ebp
- msimg32.CWEx+1- 8B EC - mov ebp,esp
- msimg32.CWEx+3- 56 - push esi
- msimg32.CWEx+4- 57 - push edi
- msimg32.CWEx+5- 8B 7D 0C - mov edi,[ebp+0C]
- msimg32.CWEx+8- B9 889A1E75 - mov ecx,msimg32.dll+9A88
- msimg32.CWEx+D- 8B C7 - mov eax,edi
- msimg32.CWEx+F- 90 - nop
- msimg32.CWEx+10- 66 8B 10 - mov dx,[eax]
- msimg32.CWEx+13- 66 3B 11 - cmp dx,[ecx]
- msimg32.CWEx+16- 75 1E - jne msimg32.CWEx+36
- msimg32.CWEx+18- 66 85 D2 - test dx,dx
- msimg32.CWEx+1B- 74 15 - je msimg32.CWEx+32
- msimg32.CWEx+1D- 66 8B 50 02 - mov dx,[eax+02]
- msimg32.CWEx+21- 66 3B 51 02 - cmp dx,[ecx+02]
- msimg32.CWEx+25- 75 0F - jne msimg32.CWEx+36
- msimg32.CWEx+27- 83 C0 04 - add eax,04
- msimg32.CWEx+2A- 83 C1 04 - add ecx,04
- msimg32.CWEx+2D- 66 85 D2 - test dx,dx
- msimg32.CWEx+30- 75 DE - jne msimg32.CWEx+10
- msimg32.CWEx+32- 33 C0 - xor eax,eax
- msimg32.CWEx+34- EB 05 - jmp msimg32.CWEx+3B
- msimg32.CWEx+36- 1B C0 - sbb eax,eax
- msimg32.CWEx+38- 83 D8 FF - sbb eax,-01
- msimg32.CWEx+3B- 8B 75 10 - mov esi,[ebp+10]
- msimg32.CWEx+3E- 85 C0 - test eax,eax
- msimg32.CWEx+40- 75 78 - jne msimg32.CWEx+BA
- msimg32.CWEx+42- B9 A49A1E75 - mov ecx,msimg32.dll+9AA4
- msimg32.CWEx+47- 8B C6 - mov eax,esi
- msimg32.CWEx+49- 8D A4 24 00000000 - lea esp,[esp+00000000]
- msimg32.CWEx+50- 66 8B 10 - mov dx,[eax]
- msimg32.CWEx+53- 66 3B 11 - cmp dx,[ecx]
- msimg32.CWEx+56- 75 1E - jne msimg32.CWEx+76
- msimg32.CWEx+58- 66 85 D2 - test dx,dx
- msimg32.CWEx+5B- 74 15 - je msimg32.CWEx+72
- msimg32.CWEx+5D- 66 8B 50 02 - mov dx,[eax+02]
- msimg32.CWEx+61- 66 3B 51 02 - cmp dx,[ecx+02]
- msimg32.CWEx+65- 75 0F - jne msimg32.CWEx+76
- msimg32.CWEx+67- 83 C0 04 - add eax,04
- msimg32.CWEx+6A- 83 C1 04 - add ecx,04
- msimg32.CWEx+6D- 66 85 D2 - test dx,dx
- msimg32.CWEx+70- 75 DE - jne msimg32.CWEx+50
- msimg32.CWEx+72- 33 C0 - xor eax,eax
- msimg32.CWEx+74- EB 05 - jmp msimg32.CWEx+7B
- msimg32.CWEx+76- 1B C0 - sbb eax,eax
- msimg32.CWEx+78- 83 D8 FF - sbb eax,-01
- msimg32.CWEx+7B- 85 C0 - test eax,eax
- msimg32.CWEx+7D- 75 3B - jne msimg32.CWEx+BA
- msimg32.CWEx+7F- 8B 45 34 - mov eax,[ebp+34]
- msimg32.CWEx+82- 8B 4D 30 - mov ecx,[ebp+30]
- msimg32.CWEx+85- 8B 55 2C - mov edx,[ebp+2C]
- msimg32.CWEx+88- 50 - push eax
- msimg32.CWEx+89- 8B 45 28 - mov eax,[ebp+28]
- msimg32.CWEx+8C- 51 - push ecx
- msimg32.CWEx+8D- 8B 4D 24 - mov ecx,[ebp+24]
- msimg32.CWEx+90- 52 - push edx
- msimg32.CWEx+91- 8B 55 20 - mov edx,[ebp+20]
- msimg32.CWEx+94- 50 - push eax
- msimg32.CWEx+95- 8B 45 1C - mov eax,[ebp+1C]
- msimg32.CWEx+98- 51 - push ecx
- msimg32.CWEx+99- 8B 4D 18 - mov ecx,[ebp+18]
- msimg32.CWEx+9C- 52 - push edx
- msimg32.CWEx+9D- 8B 55 14 - mov edx,[ebp+14]
- msimg32.CWEx+A0- 50 - push eax
- msimg32.CWEx+A1- 8B 45 08 - mov eax,[ebp+08]
- msimg32.CWEx+A4- 51 - push ecx
- msimg32.CWEx+A5- 52 - push edx
- msimg32.CWEx+A6- 56 - push esi
- msimg32.CWEx+A7- 57 - push edi
- msimg32.CWEx+A8- 50 - push eax
- msimg32.CWEx+A9- FF 15 14811E75 - call dword ptr [msimg32._imp__CreateWindowExW]
- msimg32.CWEx+AF- 5F - pop edi
- msimg32.CWEx+B0- A3 A0CB1E75 - mov [msimg32.hWndUW],eax
- msimg32.CWEx+B5- 5E - pop esi
- msimg32.CWEx+B6- 5D - pop ebp
- msimg32.CWEx+B7- C2 3000 - ret 0030
- msimg32.CWEx+BA- 8B 4D 34 - mov ecx,[ebp+34]
- msimg32.CWEx+BD- 8B 55 30 - mov edx,[ebp+30]
- msimg32.CWEx+C0- 8B 45 2C - mov eax,[ebp+2C]
- msimg32.CWEx+C3- 51 - push ecx
- msimg32.CWEx+C4- 8B 4D 28 - mov ecx,[ebp+28]
- msimg32.CWEx+C7- 52 - push edx
- msimg32.CWEx+C8- 8B 55 24 - mov edx,[ebp+24]
- msimg32.CWEx+CB- 50 - push eax
- msimg32.CWEx+CC- 8B 45 20 - mov eax,[ebp+20]
- msimg32.CWEx+CF- 51 - push ecx
- msimg32.CWEx+D0- 8B 4D 1C - mov ecx,[ebp+1C]
- msimg32.CWEx+D3- 52 - push edx
- msimg32.CWEx+D4- 8B 55 18 - mov edx,[ebp+18]
- msimg32.CWEx+D7- 50 - push eax
- msimg32.CWEx+D8- 8B 45 14 - mov eax,[ebp+14]
- msimg32.CWEx+DB- 51 - push ecx
- msimg32.CWEx+DC- 8B 4D 08 - mov ecx,[ebp+08]
- msimg32.CWEx+DF- 52 - push edx
- msimg32.CWEx+E0- 50 - push eax
- msimg32.CWEx+E1- 56 - push esi
- msimg32.CWEx+E2- 57 - push edi
- msimg32.CWEx+E3- 51 - push ecx
- msimg32.CWEx+E4- FF 15 8CCB1E75 - call dword ptr [msimg32._CWEx]
- msimg32.CWEx+EA- 5F - pop edi
- msimg32.CWEx+EB- 5E - pop esi
- msimg32.CWEx+EC- 5D - pop ebp
- msimg32.CWEx+ED- C2 3000 - ret 0030
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement