- Joined
- Sep 10, 2007
- Messages
- 970
- Reaction score
- 815
Code:
005DED81 /$ A1 F0696500 MOV EAX,DWORD PTR DS:[6569F0]
005DED86 |. 60 PUSHAD
005DED87 |. 3E:8D8C24 7402>LEA ECX,DWORD PTR DS:[ESP+274]
005DED8F |. 8039 3E CMP BYTE PTR DS:[ECX],3E
005DED92 |. 75 11 JNZ SHORT Viral.005DEDA5
005DED94 |. 41 INC ECX
005DED95 |. 8139 68656C70 CMP DWORD PTR DS:[ECX],706C6568
005DED9B |. 75 08 JNZ SHORT Viral.005DEDA5
005DED9D |. 83C1 05 ADD ECX,5
005DEDA0 |. 8039 00 CMP BYTE PTR DS:[ECX],0
005DEDA3 |. 75 02 JNZ SHORT Viral.005DEDA7
005DEDA5 |> 61 POPAD
005DEDA6 |. C3 RETN
005DEDA7 |> 60 PUSHAD
005DEDA8 |. BF 3CC76600 MOV EDI,Viral.0066C73C
005DEDAD |. BA 00006F00 MOV EDX,Viral.006F0000
005DEDB2 |. 57 PUSH EDI
005DEDB3 |. E8 A857E4FF CALL Viral.00424560
005DEDB8 |. 2BC9 SUB ECX,ECX
005DEDBA |> 8A0439 /MOV AL,BYTE PTR DS:[ECX+EDI]
005DEDBD |. 3C 00 |CMP AL,0
005DEDBF |. 74 06 |JE SHORT Viral.005DEDC7
005DEDC1 |. 880411 |MOV BYTE PTR DS:[ECX+EDX],AL
005DEDC4 |. 41 |INC ECX
005DEDC5 |.^EB F3 \JMP SHORT Viral.005DEDBA
005DEDC7 |> B0 20 MOV AL,20
005DEDC9 |. 880411 MOV BYTE PTR DS:[ECX+EDX],AL
005DEDCC |. 41 INC ECX
005DEDCD |. 66:C70411 203A MOV WORD PTR DS:[ECX+EDX],3A20
005DEDD3 |. 83C1 03 ADD ECX,3
005DEDD6 |. 03D1 ADD EDX,ECX
005DEDD8 |. 2BC9 SUB ECX,ECX
005DEDDA |. 8B7C24 08 MOV EDI,DWORD PTR SS:[ESP+8]
005DEDDE |. 8A0439 MOV AL,BYTE PTR DS:[ECX+EDI]
005DEDE1 |> 3C 00 /CMP AL,0
005DEDE3 |. 74 06 |JE SHORT Viral.005DEDEB
005DEDE5 |. 880411 |MOV BYTE PTR DS:[ECX+EDX],AL
005DEDE8 |. 41 |INC ECX
005DEDE9 |.^EB F6 \JMP SHORT Viral.005DEDE1
005DEDEB |> 880411 MOV BYTE PTR DS:[ECX+EDX],AL
005DEDEE |. 66:C705 FEFF6E>MOV WORD PTR DS:[6EFFFE],3B5E
005DEDF7 |. 61 POPAD
005DEDF8 |. 8D0D FEFF6E00 LEA ECX,DWORD PTR DS:[6EFFFE]
005DEDFE |. 83E9 06 SUB ECX,6
005DEE01 |. C701 3E68656C MOV DWORD PTR DS:[ECX],6C65683E
005DEE07 |. 66:C741 04 702>MOV WORD PTR DS:[ECX+4],2070
005DEE0D |. 83C1 07 ADD ECX,7
005DEE10 |. 61 POPAD
005DEE11 |. 8D0D F8FF6E00 LEA ECX,DWORD PTR DS:[6EFFF8]
005DEE17 |. E8 B4AAE4FF CALL Viral.004298D0
005DEE1C |. B8 00000000 MOV EAX,0
005DEE21 |. 90 NOP
005DEE22 |. 6A 00 PUSH 0
005DEE24 6A 00 PUSH 0
005DEE26 90 NOP
005DEE27 |. 51 PUSH ECX
005DEE28 |. 8D4424 04 LEA EAX,DWORD PTR SS:[ESP+4]
005DEE2C |. 50 PUSH EAX
005DEE2D |. 8D4424 14 LEA EAX,DWORD PTR SS:[ESP+14]
005DEE31 |. 50 PUSH EAX
005DEE32 |. E8 99AAE4FF CALL Viral.004298D0
005DEE37 |. 81C4 44020000 ADD ESP,244
005DEE3D |. 83C4 1C ADD ESP,1C
005DEE40 |. B0 01 MOV AL,1
005DEE42 \. C2 0400 RETN 4
Yay for olly + code caving. Note : thi sis client sided, l0l.