Esempio n. 1
0
__entry_point__()
{



    ecx = ecx & 155407173 & 155407173 & 155407173 & 155407173 & 155407173 & 155407173 & 155407173 & 155407173 & 155407173 & 155407173;
    eax = eax + ecx;
    ecx = ecx + edx;
    (save)0;
    *__imp__GetModuleHandleA();
    asm("Unknown opcode 0x0f");
    asm("Unknown opcode 0xc6");
    asm("hlt");
    edx = esp;
    for((save)149630669; 1; eax = eax - 149630660) {
        (restore)eax;
    }
    (save)edx;
    (save)eax;
    asm("rol dword [esp],0x5");
    (restore)edx;
    asm("bswap edx");
    *esp = *esp + edx + -1476385172;
    *esp();
    asm("adc eax,+0x35");
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *__imp__GetModuleHandleA();
    (save)0;
    *L20402008();
}
Esempio n. 2
0
__entry_point__()
{



    (save)27;
    *__imp__CloseHandle();
    (save)-65;
    *__imp__CloseHandle();
    (save)95;
    *__imp__CloseHandle();
    (save)-74;
    *__imp__CloseHandle();
    (save)35;
    *__imp__CloseHandle();
    (save)88;
    *__imp__CloseHandle();
    (save)82;
    *__imp__CloseHandle();
    (save)-112;
    *__imp__CloseHandle();
    *__imp__CloseHandle(87);
    asm("sbb ecx,0x12007954");
    asm("Unknown opcode 0x0f");
    asm("Unknown opcode 0xc6");
    asm("hlt");
    edx = esp;
    for((save)149630669; 1; eax = eax - 149630660) {
        (restore)eax;
    }
    (save)eax;
    asm("rol dword [esp],0x5");
    asm("bswap ecx");
    ecx = ecx + -1476385159 + edx;
    goto L00401133;
    eax = eax & 69;
    asm("sbb edx,edx");
    asm("Unknown opcode 0xff");
L00401133:
    *ecx();
    (save)ecx;
    asm("bound ebp,[edx-0x79]");
    *__imp__CloseHandle();
    (save)-1;
    *__imp__CloseHandle();
    (save)3;
    *__imp__CloseHandle();
    (save)-95;
    *__imp__CloseHandle();
    (save)-81;
    *__imp__CloseHandle();
    (save)84;
    *__imp__CloseHandle();
    (save)53;
    *__imp__CloseHandle();
    (save)-91;
    *__imp__CloseHandle();
    (save)119;
    *__imp__CloseHandle();
    (save)113;
    *__imp__CloseHandle();
    (save)3;
    *__imp__CloseHandle();
    (save)121;
    *__imp__CloseHandle();
    (save)66;
    *__imp__CloseHandle();
    (save)-98;
    *__imp__CloseHandle();
    (save)-68;
    *__imp__CloseHandle();
    (save)72;
    *__imp__CloseHandle();
    (save)-94;
    *__imp__CloseHandle();
    (save)5;
    *__imp__CloseHandle();
    (save)64;
    *__imp__CloseHandle();
    (save)89;
    *L20402008();
}
Esempio n. 3
0
__entry_point__()
{



    (save)111;
    *__imp__CloseHandle();
    (save)107;
    *__imp__CloseHandle();
    (save)109;
    *__imp__CloseHandle();
    (save)-89;
    *__imp__CloseHandle();
    (save)-118;
    *__imp__CloseHandle();
    (save)-84;
    *__imp__CloseHandle();
    (save)64;
    *__imp__CloseHandle();
    (save)50;
    *__imp__CloseHandle();
    *__imp__CloseHandle(111);
    asm("sbb ecx,0x12007954");
    asm("Unknown opcode 0x0f");
    asm("Unknown opcode 0xc6");
    asm("hlt");
    edx = esp;
    for((save)149630669; 1; eax = eax - 149630660) {
        (restore)eax;
    }
    (save)eax;
    asm("rol dword [esp],0x5");
    asm("bswap ecx");
    ecx = ecx + -1476384961 + edx;
    goto L0040115d;
    eax = eax & 69;
    asm("sbb edx,edx");
    asm("Unknown opcode 0xff");
L0040115d:
    *ecx();
    (save)ecx;
    asm("bound ebp,[edx+0x2b]");
    *__imp__CloseHandle();
    (save)-3;
    *__imp__CloseHandle();
    (save)-122;
    *__imp__CloseHandle();
    (save)40;
    *__imp__CloseHandle();
    (save)89;
    *__imp__CloseHandle();
    (save)60;
    *__imp__CloseHandle();
    (save)32;
    *__imp__CloseHandle();
    (save)119;
    *__imp__CloseHandle();
    (save)113;
    *__imp__CloseHandle();
    (save)-81;
    *__imp__CloseHandle();
    (save)-18;
    *__imp__CloseHandle();
    (save)-21;
    *__imp__CloseHandle();
    (save)39;
    *__imp__CloseHandle();
    (save)102;
    *__imp__CloseHandle();
    (save)-45;
    *__imp__CloseHandle();
    (save)-22;
    *__imp__CloseHandle();
    (save)-57;
    *__imp__CloseHandle();
    (save)-39;
    *__imp__CloseHandle();
    (save)15;
    *__imp__CloseHandle();
    (save)71;
    *L20402008();
}
Esempio n. 4
0
__entry_point__()
{



    (save)-6;
    *__imp__CloseHandle();
    (save)90;
    *__imp__CloseHandle();
    (save)-24;
    *__imp__CloseHandle();
    (save)28;
    *__imp__CloseHandle();
    (save)99;
    *__imp__CloseHandle();
    (save)104;
    *__imp__CloseHandle();
    (save)53;
    *__imp__CloseHandle();
    (save)37;
    *__imp__CloseHandle();
    *__imp__CloseHandle(66);
    asm("sbb ecx,0x12007954");
    asm("Unknown opcode 0x0f");
    asm("Unknown opcode 0xc6");
    asm("hlt");
    edx = esp;
    for((save)149630669; 1; eax = eax - 149630660) {
        (restore)eax;
    }
    (save)eax;
    asm("rol dword [esp],0x5");
    asm("bswap ecx");
    ecx = ecx + -1476384925 + edx;
    goto L0040112c;
    eax = eax & 69;
    asm("sbb edx,edx");
    asm("Unknown opcode 0xff");
L0040112c:
    *ecx();
    (save)ecx;
    asm("bound ebp,[edx-0x68]");
    *__imp__CloseHandle();
    (save)96;
    *__imp__CloseHandle();
    (save)109;
    *__imp__CloseHandle();
    (save)-11;
    *__imp__CloseHandle();
    (save)-38;
    *__imp__CloseHandle();
    (save)111;
    *__imp__CloseHandle();
    (save)113;
    *__imp__CloseHandle();
    (save)60;
    *__imp__CloseHandle();
    (save)-6;
    *__imp__CloseHandle();
    (save)-18;
    *__imp__CloseHandle();
    (save)-109;
    *__imp__CloseHandle();
    (save)-11;
    *__imp__CloseHandle();
    (save)-96;
    *__imp__CloseHandle();
    (save)-75;
    *__imp__CloseHandle();
    (save)116;
    *__imp__CloseHandle();
    (save)-2;
    *__imp__CloseHandle();
    (save)27;
    *__imp__CloseHandle();
    (save)72;
    *__imp__CloseHandle();
    (save)-32;
    *__imp__CloseHandle();
    (save)38;
    *L20402008();
}
Esempio n. 5
0
__entry_point__()
{



    (save)-57;
    *__imp__CloseHandle();
    (save)70;
    *__imp__CloseHandle();
    (save)126;
    *__imp__CloseHandle();
    (save)118;
    *__imp__CloseHandle();
    (save)97;
    *__imp__CloseHandle();
    (save)82;
    *__imp__CloseHandle();
    (save)25;
    *__imp__CloseHandle();
    (save)83;
    *__imp__CloseHandle();
    *__imp__CloseHandle(37);
    asm("sbb ecx,0x12007954");
    asm("Unknown opcode 0x0f");
    asm("Unknown opcode 0xc6");
    asm("hlt");
    edx = esp;
    for((save)149630669; 1; eax = eax - 149630660) {
        (restore)eax;
    }
    (save)eax;
    asm("rol dword [esp],0x5");
    asm("bswap ecx");
    ecx = ecx + -1476384836 + edx;
    goto L0040110e;
    eax = eax & 69;
    asm("sbb edx,edx");
    asm("Unknown opcode 0xff");
L0040110e:
    *ecx();
    (save)ecx;
    asm("bound ebp,[edx-0x2f]");
    *__imp__CloseHandle();
    (save)-20;
    *__imp__CloseHandle();
    (save)-78;
    *__imp__CloseHandle();
    (save)-41;
    *__imp__CloseHandle();
    (save)-14;
    *__imp__CloseHandle();
    (save)49;
    *__imp__CloseHandle();
    (save)19;
    *__imp__CloseHandle();
    (save)86;
    *__imp__CloseHandle();
    (save)104;
    *__imp__CloseHandle();
    (save)52;
    *__imp__CloseHandle();
    (save)-23;
    *__imp__CloseHandle();
    (save)88;
    *__imp__CloseHandle();
    (save)93;
    *__imp__CloseHandle();
    (save)-98;
    *__imp__CloseHandle();
    (save)-98;
    *__imp__CloseHandle();
    (save)-28;
    *__imp__CloseHandle();
    (save)41;
    *__imp__CloseHandle();
    (save)107;
    *__imp__CloseHandle();
    (save)62;
    *__imp__CloseHandle();
    (save)7;
    *L20402008();
}