Code:005DED81 /$ A1 F0696500 MOV EAX,DWORD PTR DS:[6569F0] 005DED86 |. 60 PUSHAD 005DED87 |. 3E:8D8C24 7402>LEA ECX,DWORD PTR DS:[ESP+274] 005DED8F |. 8039 3E CMP BYTE PTR DS:[ECX],3E 005DED92 |. 75 11 JNZ SHORT Viral.005DEDA5 005DED94 |. 41 INC ECX 005DED95 |. 8139 68656C70 CMP DWORD PTR DS:[ECX],706C6568 005DED9B |. 75 08 JNZ SHORT Viral.005DEDA5 005DED9D |. 83C1 05 ADD ECX,5 005DEDA0 |. 8039 00 CMP BYTE PTR DS:[ECX],0 005DEDA3 |. 75 02 JNZ SHORT Viral.005DEDA7 005DEDA5 |> 61 POPAD 005DEDA6 |. C3 RETN 005DEDA7 |> 60 PUSHAD 005DEDA8 |. BF 3CC76600 MOV EDI,Viral.0066C73C 005DEDAD |. BA 00006F00 MOV EDX,Viral.006F0000 005DEDB2 |. 57 PUSH EDI 005DEDB3 |. E8 A857E4FF CALL Viral.00424560 005DEDB8 |. 2BC9 SUB ECX,ECX 005DEDBA |> 8A0439 /MOV AL,BYTE PTR DS:[ECX+EDI] 005DEDBD |. 3C 00 |CMP AL,0 005DEDBF |. 74 06 |JE SHORT Viral.005DEDC7 005DEDC1 |. 880411 |MOV BYTE PTR DS:[ECX+EDX],AL 005DEDC4 |. 41 |INC ECX 005DEDC5 |.^EB F3 \JMP SHORT Viral.005DEDBA 005DEDC7 |> B0 20 MOV AL,20 005DEDC9 |. 880411 MOV BYTE PTR DS:[ECX+EDX],AL 005DEDCC |. 41 INC ECX 005DEDCD |. 66:C70411 203A MOV WORD PTR DS:[ECX+EDX],3A20 005DEDD3 |. 83C1 03 ADD ECX,3 005DEDD6 |. 03D1 ADD EDX,ECX 005DEDD8 |. 2BC9 SUB ECX,ECX 005DEDDA |. 8B7C24 08 MOV EDI,DWORD PTR SS:[ESP+8] 005DEDDE |. 8A0439 MOV AL,BYTE PTR DS:[ECX+EDI] 005DEDE1 |> 3C 00 /CMP AL,0 005DEDE3 |. 74 06 |JE SHORT Viral.005DEDEB 005DEDE5 |. 880411 |MOV BYTE PTR DS:[ECX+EDX],AL 005DEDE8 |. 41 |INC ECX 005DEDE9 |.^EB F6 \JMP SHORT Viral.005DEDE1 005DEDEB |> 880411 MOV BYTE PTR DS:[ECX+EDX],AL 005DEDEE |. 66:C705 FEFF6E>MOV WORD PTR DS:[6EFFFE],3B5E 005DEDF7 |. 61 POPAD 005DEDF8 |. 8D0D FEFF6E00 LEA ECX,DWORD PTR DS:[6EFFFE] 005DEDFE |. 83E9 06 SUB ECX,6 005DEE01 |. C701 3E68656C MOV DWORD PTR DS:[ECX],6C65683E 005DEE07 |. 66:C741 04 702>MOV WORD PTR DS:[ECX+4],2070 005DEE0D |. 83C1 07 ADD ECX,7 005DEE10 |. 61 POPAD 005DEE11 |. 8D0D F8FF6E00 LEA ECX,DWORD PTR DS:[6EFFF8] 005DEE17 |. E8 B4AAE4FF CALL Viral.004298D0 005DEE1C |. B8 00000000 MOV EAX,0 005DEE21 |. 90 NOP 005DEE22 |. 6A 00 PUSH 0 005DEE24 6A 00 PUSH 0 005DEE26 90 NOP 005DEE27 |. 51 PUSH ECX 005DEE28 |. 8D4424 04 LEA EAX,DWORD PTR SS:[ESP+4] 005DEE2C |. 50 PUSH EAX 005DEE2D |. 8D4424 14 LEA EAX,DWORD PTR SS:[ESP+14] 005DEE31 |. 50 PUSH EAX 005DEE32 |. E8 99AAE4FF CALL Viral.004298D0 005DEE37 |. 81C4 44020000 ADD ESP,244 005DEE3D |. 83C4 1C ADD ESP,1C 005DEE40 |. B0 01 MOV AL,1 005DEE42 \. C2 0400 RETN 4
Yay for olly + code caving. Note : thi sis client sided, l0l.


Reply With Quote


