Code:
5F831000 /$ 53 PUSH EBX
5F831001 |. 56 PUSH ESI
5F831002 |. 57 PUSH EDI
5F831003 |. 68 D820835F PUSH test.5F8320D8 ; UNICODE "CShell.dll"
5F831008 |. E8 F3EFFAA0 CALL 007E0000
5F83100D |. 90 NOP
5F83100E |. 8B3D 9420835F MOV EDI,DWORD PTR DS:[5F832094]
5F831014 |. 8B98 74EAC800 MOV EBX,DWORD PTR DS:[EAX+C8EA74]
5F83101A |. 8BB0 E4C74400 MOV ESI,DWORD PTR DS:[EAX+44C7E4]
5F831020 |. 68 A0000000 PUSH 0A0
5F831025 |. FFD7 CALL EDI
5F831027 |. 66:85C0 TEST AX,AX
5F83102A |. 74 5D JE SHORT test.5F831089
5F83102C |. 85F6 TEST ESI,ESI
5F83102E |. 74 59 JE SHORT test.5F831089
5F831030 |. D986 BC010000 FLD DWORD PTR DS:[ESI+1BC]
5F831036 |. D9EE FLDZ
5F831038 |. D9C0 FLD ST
5F83103A |. DDEA FUCOMP ST(2)
5F83103C |. DFE0 FSTSW AX
5F83103E |. DDD9 FSTP ST(1)
5F831040 |. D905 4421835F FLD DWORD PTR DS:[5F832144]
5F831046 |. F6C4 44 TEST AH,44
5F831049 |. 7B 06 JPO SHORT test.5F831051
5F83104B |. D996 BC010000 FST DWORD PTR DS:[ESI+1BC]
5F831051 |> D986 C0010000 FLD DWORD PTR DS:[ESI+1C0]
5F831057 |. D9C2 FLD ST(2)
5F831059 |. DAE9 FUCOMPP
5F83105B |. DFE0 FSTSW AX
5F83105D |. F6C4 44 TEST AH,44
5F831060 |. 7B 0C JPO SHORT test.5F83106E
5F831062 |. D905 4021835F FLD DWORD PTR DS:[5F832140]
5F831068 |. D99E C0010000 FSTP DWORD PTR DS:[ESI+1C0]
5F83106E |> D986 C4010000 FLD DWORD PTR DS:[ESI+1C4]
5F831074 |. DDEA FUCOMP ST(2)
5F831076 |. DFE0 FSTSW AX
5F831078 |. DDD9 FSTP ST(1)
5F83107A |. F6C4 44 TEST AH,44
5F83107D |. 7B 08 JPO SHORT test.5F831087
5F83107F |. D99E C4010000 FSTP DWORD PTR DS:[ESI+1C4]
5F831085 |. EB 02 JMP SHORT test.5F831089
5F831087 |> DDD8 FSTP ST
5F831089 |> 6A 71 PUSH 71
5F83108B |. FFD7 CALL EDI
5F83108D |. 66:85C0 TEST AX,AX
5F831090 |. 75 08 JNZ SHORT test.5F83109A
5F831092 |. 6A 71 PUSH 71
5F831094 |. FFD7 CALL EDI
5F831096 |. A8 01 TEST AL,1
5F831098 |. 74 2F JE SHORT test.5F8310C9
5F83109A |> 803D 7033835F >CMP BYTE PTR DS:[5F833370],0
5F8310A1 |. 74 26 JE SHORT test.5F8310C9
5F8310A3 |. D9E8 FLD1
5F8310A5 |. 8D83 6C050000 LEA EAX,DWORD PTR DS:[EBX+56C]
5F8310AB |. B9 40000000 MOV ECX,40
5F8310B0 |> D950 FC /FST DWORD PTR DS:[EAX-4]
5F8310B3 |. 05 F4040000 |ADD EAX,4F4
5F8310B8 |. 49 |DEC ECX
5F8310B9 |. D990 0CFBFFFF |FST DWORD PTR DS:[EAX-4F4]
5F8310BF |. D990 10FBFFFF |FST DWORD PTR DS:[EAX-4F0]
5F8310C5 |.^75 E9 \JNZ SHORT test.5F8310B0
5F8310C7 |. DDD8 FSTP ST
5F8310C9 |> 5F POP EDI
5F8310CA |. 5E POP ESI
5F8310CB |. 5B POP EBX
5F8310CC \. C3 RETN
5F8310CD CC INT3
5F8310CE CC INT3
5F8310CF CC INT3
5F8310D0 . 3E:8B10 MOV EDX,DWORD PTR DS:[EAX]
5F8310D3 . 3E:8B92 480100>MOV EDX,DWORD PTR DS:[EDX+148]
5F8310DA . 3E:A3 7433835F MOV DWORD PTR DS:[5F833374],EAX
5F8310E0 . 60 PUSHAD
5F8310E1 . E8 1AFFFFFF CALL test.5F831000
5F8310E6 . 6A 72 PUSH 72
5F8310E8 . E8 77F3FDA0 CALL 00810464
5F8310ED . 90 NOP
5F8310EE . 98 CWDE
5F8310EF . 83E0 01 AND EAX,1
5F8310F2 . 74 12 JE SHORT test.5F831106
5F8310F4 . 33C9 XOR ECX,ECX
5F8310F6 . 833D 6C33835F >CMP DWORD PTR DS:[5F83336C],0
5F8310FD . 0F94C1 SETE CL
5F831100 . 890D 6C33835F MOV DWORD PTR DS:[5F83336C],ECX
5F831106 > 6A 73 PUSH 73
5F831108 . E8 57F3FDA0 CALL 00810464
5F83110D . 90 NOP
5F83110E . 0FBFD0 MOVSX EDX,AX
5F831111 . 83E2 01 AND EDX,1
5F831114 . 74 0D JE SHORT test.5F831123
5F831116 . A1 6833835F MOV EAX,DWORD PTR DS:[5F833368]
5F83111B . 83C0 01 ADD EAX,1
5F83111E . A3 6833835F MOV DWORD PTR DS:[5F833368],EAX
5F831123 > 6A 74 PUSH 74
5F831125 . E8 3AF3FDA0 CALL 00810464
5F83112A . 90 NOP
5F83112B . 0FBFC8 MOVSX ECX,AX
5F83112E . 83E1 01 AND ECX,1
5F831131 . 74 12 JE SHORT test.5F831145
5F831133 . 33D2 XOR EDX,EDX
5F831135 . 833D 5C33835F >CMP DWORD PTR DS:[5F83335C],0
5F83113C . 0F94C2 SETE DL
5F83113F . 8915 5C33835F MOV DWORD PTR DS:[5F83335C],EDX
5F831145 > 6A 75 PUSH 75
5F831147 . E8 18F3FDA0 CALL 00810464
5F83114C . 90 NOP
5F83114D . 98 CWDE
5F83114E . 83E0 01 AND EAX,1
5F831151 . 74 12 JE SHORT test.5F831165
5F831153 . 33C9 XOR ECX,ECX
5F831155 . 833D 5833835F >CMP DWORD PTR DS:[5F833358],0
5F83115C . 0F94C1 SETE CL
5F83115F . 890D 5833835F MOV DWORD PTR DS:[5F833358],ECX
5F831165 > 6A 76 PUSH 76
5F831167 . E8 F8F2FDA0 CALL 00810464
5F83116C . 90 NOP
5F83116D . 0FBFD0 MOVSX EDX,AX
5F831170 . 83E2 01 AND EDX,1
5F831173 . 74 11 JE SHORT test.5F831186
5F831175 . 33C0 XOR EAX,EAX
5F831177 . 833D 6033835F >CMP DWORD PTR DS:[5F833360],0
5F83117E . 0F94C0 SETE AL
5F831181 . A3 6033835F MOV DWORD PTR DS:[5F833360],EAX
5F831186 > 6A 77 PUSH 77
5F831188 . E8 D7F2FDA0 CALL 00810464
5F83118D . 90 NOP
5F83118E . 0FBFC8 MOVSX ECX,AX
5F831191 . 83E1 01 AND ECX,1
5F831194 . 74 12 JE SHORT test.5F8311A8
5F831196 . 33D2 XOR EDX,EDX
5F831198 . 833D 5433835F >CMP DWORD PTR DS:[5F833354],0
5F83119F . 0F94C2 SETE DL
5F8311A2 . 8915 5433835F MOV DWORD PTR DS:[5F833354],EDX
5F8311A8 > 6A 78 PUSH 78
5F8311AA . E8 B5F2FDA0 CALL 00810464
5F8311AF . 90 NOP
5F8311B0 . 98 CWDE
5F8311B1 . 83E0 01 AND EAX,1
5F8311B4 . 74 12 JE SHORT test.5F8311C8
5F8311B6 . 33C9 XOR ECX,ECX
5F8311B8 . 833D 6433835F >CMP DWORD PTR DS:[5F833364],0
5F8311BF . 0F94C1 SETE CL
5F8311C2 . 890D 6433835F MOV DWORD PTR DS:[5F833364],ECX
5F8311C8 > 833D 6833835F >CMP DWORD PTR DS:[5F833368],4
5F8311CF . 7E 0A JLE SHORT test.5F8311DB
5F8311D1 . C705 6833835F >MOV DWORD PTR DS:[5F833368],0
5F8311DB > 833D 6C33835F >CMP DWORD PTR DS:[5F83336C],0
5F8311E2 . 0F84 C0000000 JE test.5F8312A8
5F8311E8 . 6A 00 PUSH 0
5F8311EA . 6A 07 PUSH 7
5F8311EC . 8B15 7433835F MOV EDX,DWORD PTR DS:[5F833374]
5F8311F2 . 8B02 MOV EAX,DWORD PTR DS:[EDX]
5F8311F4 . 8B0D 7433835F MOV ECX,DWORD PTR DS:[5F833374]
5F8311FA . 51 PUSH ECX
5F8311FB . 8B90 E4000000 MOV EDX,DWORD PTR DS:[EAX+E4]
5F831201 . FFD2 CALL EDX
5F831203 . 833D 6833835F >CMP DWORD PTR DS:[5F833368],1
5F83120A . 75 20 JNZ SHORT test.5F83122C
5F83120C . 68 0000FFFF PUSH FFFF0000
5F831211 . 68 8B000000 PUSH 8B
5F831216 . A1 7433835F MOV EAX,DWORD PTR DS:[5F833374]
5F83121B . 8B08 MOV ECX,DWORD PTR DS:[EAX]
5F83121D . 8B15 7433835F MOV EDX,DWORD PTR DS:[5F833374]
5F831223 . 52 PUSH EDX
5F831224 . 8B81 E4000000 MOV EAX,DWORD PTR DS:[ECX+E4]
5F83122A . FFD0 CALL EAX
5F83122C > 833D 6833835F >CMP DWORD PTR DS:[5F833368],2
5F831233 . 75 20 JNZ SHORT test.5F831255
5F831235 . 68 00FF00FF PUSH FF00FF00
5F83123A . 68 8B000000 PUSH 8B
5F83123F . 8B0D 7433835F MOV ECX,DWORD PTR DS:[5F833374]
5F831245 . 8B11 MOV EDX,DWORD PTR DS:[ECX]
5F831247 . A1 7433835F MOV EAX,DWORD PTR DS:[5F833374]
5F83124C . 50 PUSH EAX
5F83124D . 8B8A E4000000 MOV ECX,DWORD PTR DS:[EDX+E4]
5F831253 . FFD1 CALL ECX
5F831255 > 833D 6833835F >CMP DWORD PTR DS:[5F833368],3
5F83125C . 75 21 JNZ SHORT test.5F83127F
5F83125E . 68 FF0000FF PUSH FF0000FF
5F831263 . 68 8B000000 PUSH 8B
5F831268 . 8B15 7433835F MOV EDX,DWORD PTR DS:[5F833374]
5F83126E . 8B02 MOV EAX,DWORD PTR DS:[EDX]
5F831270 . 8B0D 7433835F MOV ECX,DWORD PTR DS:[5F833374]
5F831276 . 51 PUSH ECX
5F831277 . 8B90 E4000000 MOV EDX,DWORD PTR DS:[EAX+E4]
5F83127D . FFD2 CALL EDX
5F83127F > 833D 6833835F >CMP DWORD PTR DS:[5F833368],4
5F831286 . 75 20 JNZ SHORT test.5F8312A8
5F831288 . 68 000000FF PUSH FF000000
5F83128D . 68 8B000000 PUSH 8B
5F831292 . A1 7433835F MOV EAX,DWORD PTR DS:[5F833374]
5F831297 . 8B08 MOV ECX,DWORD PTR DS:[EAX]
5F831299 . 8B15 7433835F MOV EDX,DWORD PTR DS:[5F833374]
5F83129F . 52 PUSH EDX
5F8312A0 . 8B81 E4000000 MOV EAX,DWORD PTR DS:[ECX+E4]
5F8312A6 . FFD0 CALL EAX
5F8312A8 > 833D 5833835F >CMP DWORD PTR DS:[5F833358],0
5F8312AF . 74 1A JE SHORT test.5F8312CB
5F8312B1 . 6A 02 PUSH 2
5F8312B3 . 6A 08 PUSH 8
5F8312B5 . 8B0D 7433835F MOV ECX,DWORD PTR DS:[5F833374]
5F8312BB . 8B11 MOV EDX,DWORD PTR DS:[ECX]
5F8312BD . A1 7433835F MOV EAX,DWORD PTR DS:[5F833374]
5F8312C2 . 50 PUSH EAX
5F8312C3 . 8B8A E4000000 MOV ECX,DWORD PTR DS:[EDX+E4]
5F8312C9 . FFD1 CALL ECX
5F8312CB > 833D 6033835F >CMP DWORD PTR DS:[5F833360],0
5F8312D2 . 74 4F JE SHORT test.5F831323
5F8312D4 . 6A 01 PUSH 1
5F8312D6 . 6A 1B PUSH 1B
5F8312D8 . 8B15 7433835F MOV EDX,DWORD PTR DS:[5F833374]
5F8312DE . 8B02 MOV EAX,DWORD PTR DS:[EDX]
5F8312E0 . 8B0D 7433835F MOV ECX,DWORD PTR DS:[5F833374]
5F8312E6 . 51 PUSH ECX
5F8312E7 . 8B90 E4000000 MOV EDX,DWORD PTR DS:[EAX+E4]
5F8312ED . FFD2 CALL EDX
5F8312EF . 6A 0A PUSH 0A
5F8312F1 . 6A 14 PUSH 14
5F8312F3 . A1 7433835F MOV EAX,DWORD PTR DS:[5F833374]
5F8312F8 . 8B08 MOV ECX,DWORD PTR DS:[EAX]
5F8312FA . 8B15 7433835F MOV EDX,DWORD PTR DS:[5F833374]
5F831300 . 52 PUSH EDX
5F831301 . 8B81 E4000000 MOV EAX,DWORD PTR DS:[ECX+E4]
5F831307 . FFD0 CALL EAX
5F831309 . 6A 06 PUSH 6
5F83130B . 6A 13 PUSH 13
5F83130D . 8B0D 7433835F MOV ECX,DWORD PTR DS:[5F833374]
5F831313 . 8B11 MOV EDX,DWORD PTR DS:[ECX]
5F831315 . A1 7433835F MOV EAX,DWORD PTR DS:[5F833374]
5F83131A . 50 PUSH EAX
5F83131B . 8B8A E4000000 MOV ECX,DWORD PTR DS:[EDX+E4]
5F831321 . FFD1 CALL ECX
5F831323 > 833D 6433835F >CMP DWORD PTR DS:[5F833364],0
5F83132A . 74 4F JE SHORT test.5F83137B
5F83132C . 6A 01 PUSH 1
5F83132E . 6A 1B PUSH 1B
5F831330 . 8B15 7433835F MOV EDX,DWORD PTR DS:[5F833374]
5F831336 . 8B02 MOV EAX,DWORD PTR DS:[EDX]
5F831338 . 8B0D 7433835F MOV ECX,DWORD PTR DS:[5F833374]
5F83133E . 51 PUSH ECX
5F83133F . 8B90 E4000000 MOV EDX,DWORD PTR DS:[EAX+E4]
5F831345 . FFD2 CALL EDX
5F831347 . 6A 0A PUSH 0A
5F831349 . 6A 14 PUSH 14
5F83134B . A1 7433835F MOV EAX,DWORD PTR DS:[5F833374]
5F831350 . 8B08 MOV ECX,DWORD PTR DS:[EAX]
5F831352 . 8B15 7433835F MOV EDX,DWORD PTR DS:[5F833374]
5F831358 . 52 PUSH EDX
5F831359 . 8B81 E4000000 MOV EAX,DWORD PTR DS:[ECX+E4]
5F83135F . FFD0 CALL EAX
5F831361 . 6A 04 PUSH 4
5F831363 . 6A 13 PUSH 13
5F831365 . 8B0D 7433835F MOV ECX,DWORD PTR DS:[5F833374]
5F83136B . 8B11 MOV EDX,DWORD PTR DS:[ECX]
5F83136D . A1 7433835F MOV EAX,DWORD PTR DS:[5F833374]
5F831372 . 50 PUSH EAX
5F831373 . 8B8A E4000000 MOV ECX,DWORD PTR DS:[EDX+E4]
5F831379 . FFD1 CALL ECX
5F83137B > 833D 5C33835F >CMP DWORD PTR DS:[5F83335C],0
5F831382 . 0F84 8A000000 JE test.5F831412
5F831388 . 6A 00 PUSH 0
5F83138A . 6A 07 PUSH 7
5F83138C . 8B15 7433835F MOV EDX,DWORD PTR DS:[5F833374]
5F831392 . 8B02 MOV EAX,DWORD PTR DS:[EDX]
5F831394 . 8B0D 7433835F MOV ECX,DWORD PTR DS:[5F833374]
5F83139A . 51 PUSH ECX
5F83139B . 8B90 E4000000 MOV EDX,DWORD PTR DS:[EAX+E4]
5F8313A1 . FFD2 CALL EDX
5F8313A3 . 6A 01 PUSH 1
5F8313A5 . 6A 17 PUSH 17
5F8313A7 . A1 7433835F MOV EAX,DWORD PTR DS:[5F833374]
5F8313AC . 8B08 MOV ECX,DWORD PTR DS:[EAX]
5F8313AE . 8B15 7433835F MOV EDX,DWORD PTR DS:[5F833374]
5F8313B4 . 52 PUSH EDX
5F8313B5 . 8B81 E4000000 MOV EAX,DWORD PTR DS:[ECX+E4]
5F8313BB . FFD0 CALL EAX
5F8313BD . 6A 00 PUSH 0
5F8313BF . 68 89000000 PUSH 89
5F8313C4 . 8B0D 7433835F MOV ECX,DWORD PTR DS:[5F833374]
5F8313CA . 8B11 MOV EDX,DWORD PTR DS:[ECX]
5F8313CC . A1 7433835F MOV EAX,DWORD PTR DS:[5F833374]
5F8313D1 . 50 PUSH EAX
5F8313D2 . 8B8A E4000000 MOV ECX,DWORD PTR DS:[EDX+E4]
5F8313D8 . FFD1 CALL ECX
5F8313DA . 6A FF PUSH -1
5F8313DC . 68 8B000000 PUSH 8B
5F8313E1 . 8B15 7433835F MOV EDX,DWORD PTR DS:[5F833374]
5F8313E7 . 8B02 MOV EAX,DWORD PTR DS:[EDX]
5F8313E9 . 8B0D 7433835F MOV ECX,DWORD PTR DS:[5F833374]
5F8313EF . 51 PUSH ECX
5F8313F0 . 8B90 E4000000 MOV EDX,DWORD PTR DS:[EAX+E4]
5F8313F6 . FFD2 CALL EDX
5F8313F8 . 6A 00 PUSH 0
5F8313FA . 6A 1C PUSH 1C
5F8313FC . A1 7433835F MOV EAX,DWORD PTR DS:[5F833374]
5F831401 . 8B08 MOV ECX,DWORD PTR DS:[EAX]
5F831403 . 8B15 7433835F MOV EDX,DWORD PTR DS:[5F833374]
5F831409 . 52 PUSH EDX
5F83140A . 8B81 E4000000 MOV EAX,DWORD PTR DS:[ECX+E4]
5F831410 . FFD0 CALL EAX
5F831412 > 833D 6C33835F >CMP DWORD PTR DS:[5F83336C],0
5F831419 . 74 67 JE SHORT test.5F831482
5F83141B . 6A 00 PUSH 0
5F83141D . 6A 07 PUSH 7
5F83141F . 8B0D 7433835F MOV ECX,DWORD PTR DS:[5F833374]
5F831425 . 8B11 MOV EDX,DWORD PTR DS:[ECX]
5F831427 . A1 7433835F MOV EAX,DWORD PTR DS:[5F833374]
5F83142C . 50 PUSH EAX
5F83142D . 8B8A E4000000 MOV ECX,DWORD PTR DS:[EDX+E4]
5F831433 . FFD1 CALL ECX
5F831435 . 833D 6833835F >CMP DWORD PTR DS:[5F833368],1
5F83143C . 75 21 JNZ SHORT test.5F83145F
5F83143E . 68 0000FFFF PUSH FFFF0000
5F831443 . 68 8B000000 PUSH 8B
5F831448 . 8B15 7433835F MOV EDX,DWORD PTR DS:[5F833374]
5F83144E . 8B02 MOV EAX,DWORD PTR DS:[EDX]
5F831450 . 8B0D 7433835F MOV ECX,DWORD PTR DS:[5F833374]
5F831456 . 51 PUSH ECX
5F831457 . 8B90 E4000000 MOV EDX,DWORD PTR DS:[EAX+E4]
5F83145D . FFD2 CALL EDX
5F83145F > 833D 5433835F >CMP DWORD PTR DS:[5F833354],0
5F831466 . 74 1A JE SHORT test.5F831482
5F831468 . 6A 01 PUSH 1
5F83146A . 6A 08 PUSH 8
5F83146C . A1 7433835F MOV EAX,DWORD PTR DS:[5F833374]
5F831471 . 8B08 MOV ECX,DWORD PTR DS:[EAX]
5F831473 . 8B15 7433835F MOV EDX,DWORD PTR DS:[5F833374]
5F831479 . 52 PUSH EDX
5F83147A . 8B81 E4000000 MOV EAX,DWORD PTR DS:[ECX+E4]
5F831480 . FFD0 CALL EAX
5F831482 > 61 POPAD
5F831483 .-FF25 1030835F JMP DWORD PTR DS:[5F833010]
5F831489 CC INT3
5F83148A CC INT3
5F83148B CC INT3
5F83148C CC INT3
5F83148D CC INT3
5F83148E CC INT3
5F83148F CC INT3
5F831490 55 DB 55 ; CHAR 'U'
5F831491 8B DB 8B
5F831492 EC DB EC
5F831493 51 DB 51 ; CHAR 'Q'
5F831494 53 DB 53 ; CHAR 'S'
5F831495 8B DB 8B
5F831496 1D DB 1D
5F831497 0420835F DD test.5F832004
5F83149B 56 DB 56 ; CHAR 'V'
5F83149C 57 DB 57 ; CHAR 'W'
5F83149D 8B DB 8B
5F83149E 3D DB 3D ; CHAR '='
5F83149F 0C20835F DD test.5F83200C
5F8314A3 EB DB EB
5F8314A4 0B DB 0B
5F8314A5 8D DB 8D
5F8314A6 A4 DB A4
5F8314A7 24 DB 24 ; CHAR '$'
5F8314A8 00 DB 00
5F8314A9 00 DB 00
5F8314AA 00 DB 00
5F8314AB 00 DB 00
5F8314AC 8D6424 00 LEA ESP,DWORD PTR SS:[ESP]
5F8314B0 B8 DB B8
5F8314B1 . 2D 75 4B 00 ASCII "-uK",0
5F8314B5 80 DB 80
5F8314B6 38 DB 38 ; CHAR '8'
5F8314B7 8B DB 8B
5F8314B8 0F DB 0F
5F8314B9 85 DB 85
5F8314BA 81 DB 81
5F8314BB 00 DB 00
5F8314BC 00 DB 00
5F8314BD 00 DB 00
5F8314BE 80 DB 80
5F8314BF . 3D 2E 75 4B 00>ASCII "=.uK",0
5F8314C4 10 DB 10
5F8314C5 75 DB 75 ; CHAR 'u'
5F8314C6 78 DB 78 ; CHAR 'x'
5F8314C7 6A DB 6A ; CHAR 'j'
5F8314C8 64 DB 64 ; CHAR 'd'
5F8314C9 FF DB FF
5F8314CA D3 DB D3
5F8314CB 6A DB 6A ; CHAR 'j'
5F8314CC 0D DB 0D
5F8314CD E8 DB E8
5F8314CE 61 DB 61 ; CHAR 'a'
5F8314CF ED DB ED
5F8314D0 4F DB 4F ; CHAR 'O'
5F8314D1 FD DB FD
5F8314D2 90 NOP
5F8314D3 83 DB 83
5F8314D4 C4 DB C4
5F8314D5 04 DB 04
5F8314D6 8B DB 8B
5F8314D7 F0 DB F0
5F8314D8 8D DB 8D
5F8314D9 45 DB 45 ; CHAR 'E'
5F8314DA FC DB FC
5F8314DB 50 DB 50 ; CHAR 'P'
5F8314DC 6A DB 6A ; CHAR 'j'
5F8314DD 04 DB 04
5F8314DE 6A DB 6A ; CHAR 'j'
5F8314DF 08 DB 08
5F8314E0 . 68 2D 75 4B 00>ASCII "h-uK",0
5F8314E5 FF DB FF
5F8314E6 D7 DB D7
5F8314E7 B8 DB B8
5F8314E8 . 2D 75 4B 00 ASCII "-uK",0
5F8314EC 8B DB 8B
5F8314ED 08 DB 08
5F8314EE 89 DB 89
5F8314EF 0E DB 0E
5F8314F0 8B DB 8B
5F8314F1 50 DB 50 ; CHAR 'P'
5F8314F2 04 DB 04
5F8314F3 89 DB 89
5F8314F4 56 DB 56 ; CHAR 'V'
5F8314F5 04 DB 04
5F8314F6 83 DB 83
5F8314F7 C6 DB C6
5F8314F8 08 DB 08
5F8314F9 C6 DB C6
5F8314FA 06 DB 06
5F8314FB E9 DB E9
5F8314FC B8 DB B8
5F8314FD . 30 75 4B 00 ASCII "0uK",0
5F831501 2B DB 2B ; CHAR '+'
5F831502 C6 DB C6
5F831503 89 DB 89
5F831504 46 DB 46 ; CHAR 'F'
5F831505 01 DB 01
5F831506 C6 DB C6
5F831507 05 DB 05
5F831508 . 2D 75 4B 00 ASCII "-uK",0
5F83150C E9 DB E9
5F83150D B9 DB B9
5F83150E D010835F DD test.5F8310D0
5F831512 81 DB 81
5F831513 E9 DB E9
5F831514 . 32 75 4B 00 ASCII "2uK",0
5F831518 89 DB 89
5F831519 . 0D 2E 75 4B 00>ASCII "
.uK",0
5F83151E B8 DB B8
5F83151F 90 NOP
5F831520 90 NOP
5F831521 90 NOP
5F831522 90 NOP
5F831523 B9 DB B9
5F831524 . 32 75 4B 00 ASCII "2uK",0
5F831528 66 DB 66 ; CHAR 'f'
5F831529 89 DB 89
5F83152A 01 DB 01
5F83152B 8D DB 8D
5F83152C 55 DB 55 ; CHAR 'U'
5F83152D FC DB FC
5F83152E 52 DB 52 ; CHAR 'R'
5F83152F 88 DB 88
5F831530 41 DB 41 ; CHAR 'A'
5F831531 02 DB 02
5F831532 8B DB 8B
5F831533 45 DB 45 ; CHAR 'E'
5F831534 FC DB FC
5F831535 50 DB 50 ; CHAR 'P'
5F831536 6A DB 6A ; CHAR 'j'
5F831537 08 DB 08
5F831538 . 68 2D 75 4B 00>ASCII "h-uK",0
5F83153D FF DB FF
5F83153E D7 DB D7
5F83153F 6A DB 6A ; CHAR 'j'
5F831540 32 DB 32 ; CHAR '2'
5F831541 FF DB FF
5F831542 D3 DB D3
5F831543 E9 DB E9
5F831544 68 DB 68 ; CHAR 'h'
5F831545 FF DB FF
5F831546 FF DB FF
5F831547 FF DB FF
5F831548 CC INT3
5F831549 CC INT3
5F83154A CC INT3
5F83154B CC INT3
5F83154C CC INT3
5F83154D CC INT3
5F83154E CC INT3
5F83154F CC INT3
5F831550 /$ 55 PUSH EBP
5F831551 |. 8BEC MOV EBP,ESP
5F831553 |. 837D 0C 01 CMP DWORD PTR SS:[EBP+C],1
5F831557 |. 75 33 JNZ SHORT test.5F83158C
5F831559 |. 6A 00 PUSH 0
5F83155B |. 68 F020835F PUSH test.5F8320F0 ; ASCII "Kareem111'Hack"
5F831560 |. 68 0021835F PUSH test.5F832100 ; ASCII "Cridets:
Kareem111
Dragon(H)ell
i-[f]LuX
ramo
Lightning"
5F831565 |. 6A 00 PUSH 0
5F831567 |. E8 B0EBFDA0 CALL 0081011C
5F83156C |. 90 NOP
5F83156D |. 8B45 08 MOV EAX,DWORD PTR SS:[EBP+8]
5F831570 |. 50 PUSH EAX
5F831571 |. E8 90ECFAA0 CALL 007E0206
5F831576 |. 90 NOP
5F831577 |. 6A 00 PUSH 0
5F831579 |. 6A 00 PUSH 0
5F83157B |. 6A 00 PUSH 0
5F83157D |. 68 9014835F PUSH test.5F831490
5F831582 |. 6A 00 PUSH 0
5F831584 |. 6A 00 PUSH 0
5F831586 |. E8 E1EDFAA0 CALL 007E036C
5F83158B |. 90 NOP
5F83158C |> B8 01000000 MOV EAX,1
5F831591 |. 5D POP EBP
5F831592 \. C2 0C00 RETN 0C
5F831595 . 3B 0D 00 ASCII ";
",0
5F831598 30 DB 30 ; CHAR '0'
5F831599 83 DB 83
5F83159A 5F DB 5F ; CHAR '_'
5F83159B 75 DB 75 ; CHAR 'u'
5F83159C . 02F3 ADD DH,BL
5F83159E . C3 RETN
5F83159F E9 DB E9
5F8315A0 91 DB 91
5F8315A1 03 DB 03
5F8315A2 00 DB 00
5F8315A3 00 DB 00
5F8315A4 8BFF MOV EDI,EDI
5F8315A6 . 56 PUSH ESI
5F8315A7 . 68 80000000 PUSH 80
5F8315AC . E8 80F54FFD CALL MSVCR1_1._malloc_crt
5F8315B1 . 90 NOP
5F8315B2 . 59 POP ECX
5F8315B3 . 8BF0 MOV ESI,EAX
5F8315B5 . 56 PUSH ESI
5F8315B6 . E8 F105FDA0 CALL 00801BAC
5F8315BB . 90 NOP
5F8315BC . A3 8433835F MOV DWORD PTR DS:[5F833384],EAX
5F8315C1 . A3 8033835F MOV DWORD PTR DS:[5F833380],EAX
5F8315C6 . 85F6 TEST ESI,ESI
5F8315C8 . 75 05 JNZ SHORT test.5F8315CF
5F8315CA . 33C0 XOR EAX,EAX
5F8315CC . 40 INC EAX
5F8315CD . 5E POP ESI
5F8315CE . C3 RETN
5F8315CF > 8326 00 AND DWORD PTR DS:[ESI],0
5F8315D2 . E8 28050000 CALL test.5F831AFF
5F8315D7 . 68 251B835F PUSH test.5F831B25
5F8315DC . E8 07050000 CALL test.5F831AE8
5F8315E1 . C70424 3B1A835>MOV DWORD PTR SS:[ESP],test.5F831A3B ; |
5F8315E8 . E8 FB040000 CALL test.5F831AE8 ; \test.5F831AE8
5F8315ED . 59 POP ECX
5F8315EE . 33C0 XOR EAX,EAX
5F8315F0 . 5E POP ESI
5F8315F1 . C3 RETN
5F8315F2 /$ 8BFF MOV EDI,EDI
5F8315F4 |. 55 PUSH EBP
5F8315F5 |. 8BEC MOV EBP,ESP
5F8315F7 |. 51 PUSH ECX
5F8315F8 |. 51 PUSH ECX
5F8315F9 |. 53 PUSH EBX
5F8315FA |. 33C0 XOR EAX,EAX
5F8315FC |. 56 PUSH ESI
5F8315FD |. 57 PUSH EDI
5F8315FE |. 3945 0C CMP DWORD PTR SS:[EBP+C],EAX
5F831601 |. 75 32 JNZ SHORT test.5F831635
5F831603 |. 3905 2030835F CMP DWORD PTR DS:[5F833020],EAX
5F831609 |. 7E 23 JLE SHORT test.5F83162E
5F83160B |. 64:A1 18000000 MOV EAX,DWORD PTR FS:[18]
5F831611 |. FF0D 2030835F DEC DWORD PTR DS:[5F833020]
5F831617 |. 8B58 04 MOV EBX,DWORD PTR DS:[EAX+4]
5F83161A |. 8365 FC 00 AND DWORD PTR SS:[EBP-4],0
5F83161E |. 8B35 3820835F MOV ESI,DWORD PTR DS:[5F832038]
5F831624 |. BF 7C33835F MOV EDI,test.5F83337C
5F831629 |. E9 EA000000 JMP test.5F831718
5F83162E |> 33C0 XOR EAX,EAX
5F831630 |. E9 C0010000 JMP test.5F8317F5
5F831635 |> 837D 0C 01 CMP DWORD PTR SS:[EBP+C],1
5F831639 |. 0F85 B3010000 JNZ test.5F8317F2
5F83163F |. 64:8B0D 180000>MOV ECX,DWORD PTR FS:[18]
5F831646 |. 8B59 04 MOV EBX,DWORD PTR DS:[ECX+4]
5F831649 |. 8B35 3820835F MOV ESI,DWORD PTR DS:[5F832038]
5F83164F |. 8945 0C MOV DWORD PTR SS:[EBP+C],EAX
5F831652 |. 50 PUSH EAX
5F831653 |. BF 7C33835F MOV EDI,test.5F83337C
5F831658 |. EB 11 JMP SHORT test.5F83166B
5F83165A |> 3BC3 /CMP EAX,EBX
5F83165C |. 74 17 |JE SHORT test.5F831675
5F83165E |. 68 E8030000 |PUSH 3E8
5F831663 |. E8 89EAFAA0 |CALL 007E00F1
5F831668 |. 90 |NOP
5F831669 |. 6A 00 |PUSH 0
5F83166B |> 53 PUSH EBX
5F83166C |. 57 |PUSH EDI
5F83166D |. FFD6 |CALL ESI
5F83166F |. 85C0 |TEST EAX,EAX
5F831671 |.^75 E7 \JNZ SHORT test.5F83165A
5F831673 |. EB 07 JMP SHORT test.5F83167C
5F831675 |> C745 0C 010000>MOV DWORD PTR SS:[EBP+C],1
5F83167C |> A1 7833835F MOV EAX,DWORD PTR DS:[5F833378]
5F831681 |. 6A 02 PUSH 2
5F831683 |. 5E POP ESI
5F831684 |. 85C0 TEST EAX,EAX
5F831686 |. 74 09 JE SHORT test.5F831691
5F831688 |. 6A 1F PUSH 1F
5F83168A |. E8 19060000 CALL test.5F831CA8
5F83168F |. EB 39 JMP SHORT test.5F8316CA
5F831691 |> 68 AC20835F PUSH test.5F8320AC
5F831696 |. 68 A420835F PUSH test.5F8320A4
5F83169B |. C705 7833835F >MOV DWORD PTR DS:[5F833378],1
5F8316A5 |. E8 F8050000 CALL test.5F831CA2
5F8316AA |. 59 POP ECX
5F8316AB |. 59 POP ECX
5F8316AC |. 85C0 TEST EAX,EAX
5F8316AE |.^0F85 7AFFFFFF JNZ test.5F83162E
5F8316B4 |. 68 A020835F PUSH test.5F8320A0
5F8316B9 |. 68 9C20835F PUSH test.5F83209C
5F8316BE |. E8 D9050000 CALL test.5F831C9C
5F8316C3 |. 59 POP ECX
5F8316C4 |. 8935 7833835F MOV DWORD PTR DS:[5F833378],ESI
5F8316CA |> 33DB XOR EBX,EBX
5F8316CC |. 59 POP ECX
5F8316CD |. 395D 0C CMP DWORD PTR SS:[EBP+C],EBX
5F8316D0 |. 75 08 JNZ SHORT test.5F8316DA
5F8316D2 |. 53 PUSH EBX
5F8316D3 |. 57 PUSH EDI
5F8316D4 |. E8 ED00FDA0 CALL 008017C6
5F8316D9 |. 90 NOP
5F8316DA |> 391D 8833835F CMP DWORD PTR DS:[5F833388],EBX
5F8316E0 |. 74 1C JE SHORT test.5F8316FE
5F8316E2 |. 68 8833835F PUSH test.5F833388
5F8316E7 |. E8 F4040000 CALL test.5F831BE0
5F8316EC |. 59 POP ECX
5F8316ED |. 85C0 TEST EAX,EAX
5F8316EF |. 74 0D JE SHORT test.5F8316FE
5F8316F1 |. FF75 10 PUSH DWORD PTR SS:[EBP+10]
5F8316F4 |. 56 PUSH ESI
5F8316F5 |. FF75 08 PUSH DWORD PTR SS:[EBP+8]
5F8316F8 |. FF15 8833835F CALL DWORD PTR DS:[5F833388]
5F8316FE |> FF05 2030835F INC DWORD PTR DS:[5F833020]
5F831704 |. E9 E9000000 JMP test.5F8317F2
5F831709 |> 3BC3 /CMP EAX,EBX
5F83170B |. 74 17 |JE SHORT test.5F831724
5F83170D |. 68 E8030000 |PUSH 3E8
5F831712 |. E8 DAE9FAA0 |CALL 007E00F1
5F831717 |. 90 |NOP
5F831718 |> 6A 00 PUSH 0
5F83171A |. 53 |PUSH EBX
5F83171B |. 57 |PUSH EDI
5F83171C |. FFD6 |CALL ESI
5F83171E |. 85C0 |TEST EAX,EAX
5F831720 |.^75 E7 \JNZ SHORT test.5F831709
5F831722 |. EB 07 JMP SHORT test.5F83172B
5F831724 |> C745 FC 010000>MOV DWORD PTR SS:[EBP-4],1
5F83172B |> A1 7833835F MOV EAX,DWORD PTR DS:[5F833378]
5F831730 |. 83F8 02 CMP EAX,2
5F831733 |. 74 0D JE SHORT test.5F831742
5F831735 |. 6A 1F PUSH 1F
5F831737 |. E8 6C050000 CALL test.5F831CA8
5F83173C |. 59 POP ECX
5F83173D |. E9 B0000000 JMP test.5F8317F2
5F831742 |> FF35 8433835F PUSH DWORD PTR DS:[5F833384]
5F831748 |. 8B35 4020835F MOV ESI,DWORD PTR DS:[5F832040]
5F83174E |. FFD6 CALL ESI
5F831750 |. 8945 0C MOV DWORD PTR SS:[EBP+C],EAX
5F831753 |. 85C0 TEST EAX,EAX
5F831755 |. 0F84 83000000 JE test.5F8317DE
5F83175B |. FF35 8033835F PUSH DWORD PTR DS:[5F833380]
5F831761 |. FFD6 CALL ESI
5F831763 |. 8BD8 MOV EBX,EAX
5F831765 |. 8B45 0C MOV EAX,DWORD PTR SS:[EBP+C]
5F831768 |. 8945 10 MOV DWORD PTR SS:[EBP+10],EAX
5F83176B |. 895D 08 MOV DWORD PTR SS:[EBP+8],EBX
5F83176E |> 83EB 04 /SUB EBX,4
5F831771 |. 3B5D 0C |CMP EBX,DWORD PTR SS:[EBP+C]
5F831774 |. 72 4E |JB SHORT test.5F8317C4
5F831776 |. 833B 00 |CMP DWORD PTR DS:[EBX],0
5F831779 |.^74 F3 |JE SHORT test.5F83176E
5F83177B |. 90 |NOP
5F83177C |. E8 F69B50FD |CALL MSVCR1_1._encoded_null
5F831781 |. 3903 |CMP DWORD PTR DS:[EBX],EAX
5F831783 |.^74 E9 |JE SHORT test.5F83176E
5F831785 |. FF33 |PUSH DWORD PTR DS:[EBX]
5F831787 |. FFD6 |CALL ESI
5F831789 |. 8945 F8 |MOV DWORD PTR SS:[EBP-8],EAX
5F83178C |. E8 E69B50FD |CALL MSVCR1_1._encoded_null
5F831791 |. 90 |NOP
5F831792 |. 8903 |MOV DWORD PTR DS:[EBX],EAX
5F831794 |. FF55 F8 |CALL DWORD PTR SS:[EBP-8]
5F831797 |. FF35 8433835F |PUSH DWORD PTR DS:[5F833384]
5F83179D |. FFD6 |CALL ESI
5F83179F |. FF35 8033835F |PUSH DWORD PTR DS:[5F833380]
5F8317A5 |. 8945 F8 |MOV DWORD PTR SS:[EBP-8],EAX
5F8317A8 |. FFD6 |CALL ESI
5F8317AA |. 8B4D F8 |MOV ECX,DWORD PTR SS:[EBP-8]
5F8317AD |. 394D 10 |CMP DWORD PTR SS:[EBP+10],ECX
5F8317B0 |. 75 05 |JNZ SHORT test.5F8317B7
5F8317B2 |. 3945 08 |CMP DWORD PTR SS:[EBP+8],EAX
5F8317B5 |.^74 B7 |JE SHORT test.5F83176E
5F8317B7 |> 894D 10 |MOV DWORD PTR SS:[EBP+10],ECX
5F8317BA |. 894D 0C |MOV DWORD PTR SS:[EBP+C],ECX
5F8317BD |. 8945 08 |MOV DWORD PTR SS:[EBP+8],EAX
5F8317C0 |. 8BD8 |MOV EBX,EAX
5F8317C2 |.^EB AA \JMP SHORT test.5F83176E
5F8317C4 |> FF75 0C PUSH DWORD PTR SS:[EBP+C] ; /block
5F8317C7 |. 90 NOP ; |
5F8317C8 |. E8 81E94FFD CALL MSVCR1_1.free ; \free
5F8317CD |. 59 POP ECX
5F8317CE |. 90 NOP
5F8317CF |. E8 A39B50FD CALL MSVCR1_1._encoded_null
5F8317D4 |. A3 8033835F MOV DWORD PTR DS:[5F833380],EAX
5F8317D9 |. A3 8433835F MOV DWORD PTR DS:[5F833384],EAX
5F8317DE |> 33C0 XOR EAX,EAX
5F8317E0 |. A3 7833835F MOV DWORD PTR DS:[5F833378],EAX
5F8317E5 |. 3945 FC CMP DWORD PTR SS:[EBP-4],EAX
5F8317E8 |. 75 08 JNZ SHORT test.5F8317F2
5F8317EA |. 50 PUSH EAX
5F8317EB |. 57 PUSH EDI
5F8317EC |. E8 D5FFFCA0 CALL 008017C6
5F8317F1 |. 90 NOP
5F8317F2 |> 33C0 XOR EAX,EAX
5F8317F4 |. 40 INC EAX
5F8317F5 |> 5F POP EDI
5F8317F6 |. 5E POP ESI
5F8317F7 |. 5B POP EBX
5F8317F8 |. C9 LEAVE
5F8317F9 \. C2 0C00 RETN 0C
5F8317FC . 6A 10 PUSH 10
5F8317FE . 68 1822835F PUSH test.5F832218
5F831803 . E8 B8040000 CALL test.5F831CC0
5F831808 . 8BF9 MOV EDI,ECX
5F83180A . 8BF2 MOV ESI,EDX
5F83180C . 8B5D 08 MOV EBX,DWORD PTR SS:[EBP+8]
5F83180F . 33C0 XOR EAX,EAX
5F831811 . 40 INC EAX
5F831812 . 8945 E4 MOV DWORD PTR SS:[EBP-1C],EAX
5F831815 . 33C9 XOR ECX,ECX
5F831817 . 894D FC MOV DWORD PTR SS:[EBP-4],ECX
5F83181A . 8935 0830835F MOV DWORD PTR DS:[5F833008],ESI
5F831820 . 8945 FC MOV DWORD PTR SS:[EBP-4],EAX
5F831823 . 3BF1 CMP ESI,ECX
5F831825 . 75 10 JNZ SHORT test.5F831837
5F831827 . 390D 2030835F CMP DWORD PTR DS:[5F833020],ECX
5F83182D . 75 08 JNZ SHORT test.5F831837
5F83182F . 894D E4 MOV DWORD PTR SS:[EBP-1C],ECX
5F831832 . E9 B7000000 JMP test.5F8318EE
5F831837 > 3BF0 CMP ESI,EAX
5F831839 . 74 05 JE SHORT test.5F831840
5F83183B . 83FE 02 CMP ESI,2
5F83183E . 75 2E JNZ SHORT test.5F83186E
5F831840 > A1 CC20835F MOV EAX,DWORD PTR DS:[5F8320CC]
5F831845 . 3BC1 CMP EAX,ECX
5F831847 . 74 08 JE SHORT test.5F831851
5F831849 . 57 PUSH EDI
5F83184A . 56 PUSH ESI
5F83184B . 53 PUSH EBX
5F83184C . FFD0 CALL EAX
5F83184E . 8945 E4 MOV DWORD PTR SS:[EBP-1C],EAX
5F831851 > 837D E4 00 CMP DWORD PTR SS:[EBP-1C],0
5F831855 . 0F84 93000000 JE test.5F8318EE
5F83185B . 57 PUSH EDI
5F83185C . 56 PUSH ESI
5F83185D . 53 PUSH EBX
5F83185E . E8 8FFDFFFF CALL test.5F8315F2
5F831863 . 8945 E4 MOV DWORD PTR SS:[EBP-1C],EAX
5F831866 . 85C0 TEST EAX,EAX
5F831868 . 0F84 80000000 JE test.5F8318EE
5F83186E > 57 PUSH EDI ; /Arg3
5F83186F . 56 PUSH ESI ; |Arg2
5F831870 . 53 PUSH EBX ; |Arg1
5F831871 . E8 DAFCFFFF CALL test.5F831550 ; \test.5F831550
5F831876 . 8945 E4 MOV DWORD PTR SS:[EBP-1C],EAX
5F831879 . 83FE 01 CMP ESI,1
5F83187C . 75 24 JNZ SHORT test.5F8318A2
5F83187E . 85C0 TEST EAX,EAX
5F831880 . 75 20 JNZ SHORT test.5F8318A2
5F831882 . 57 PUSH EDI ; /Arg3
5F831883 . 50 PUSH EAX ; |Arg2
5F831884 . 53 PUSH EBX ; |Arg1
5F831885 . E8 C6FCFFFF CALL test.5F831550 ; \test.5F831550
5F83188A . 57 PUSH EDI
5F83188B . 6A 00 PUSH 0
5F83188D . 53 PUSH EBX
5F83188E . E8 5FFDFFFF CALL test.5F8315F2
5F831893 . A1 CC20835F MOV EAX,DWORD PTR DS:[5F8320CC]
5F831898 . 85C0 TEST EAX,EAX
5F83189A . 74 06 JE SHORT test.5F8318A2
5F83189C . 57 PUSH EDI
5F83189D . 6A 00 PUSH 0
5F83189F . 53 PUSH EBX
5F8318A0 . FFD0 CALL EAX
5F8318A2 > 85F6 TEST ESI,ESI
5F8318A4 . 74 05 JE SHORT test.5F8318AB
5F8318A6 . 83FE 03 CMP ESI,3
5F8318A9 . 75 43 JNZ SHORT test.5F8318EE
5F8318AB > 57 PUSH EDI
5F8318AC . 56 PUSH ESI
5F8318AD . 53 PUSH EBX
5F8318AE . E8 3FFDFFFF CALL test.5F8315F2
5F8318B3 . 85C0 TEST EAX,EAX
5F8318B5 . 75 03 JNZ SHORT test.5F8318BA
5F8318B7 . 2145 E4 AND DWORD PTR SS:[EBP-1C],EAX
5F8318BA > 837D E4 00 CMP DWORD PTR SS:[EBP-1C],0
5F8318BE . 74 2E JE SHORT test.5F8318EE
5F8318C0 . A1 CC20835F MOV EAX,DWORD PTR DS:[5F8320CC]
5F8318C5 . 85C0 TEST EAX,EAX
5F8318C7 . 74 25 JE SHORT test.5F8318EE
5F8318C9 . 57 PUSH EDI
5F8318CA . 56 PUSH ESI
5F8318CB . 53 PUSH EBX
5F8318CC . FFD0 CALL EAX
5F8318CE . 8945 E4 MOV DWORD PTR SS:[EBP-1C],EAX
5F8318D1 . EB 1B JMP SHORT test.5F8318EE
5F8318D3 . 8B45 EC MOV EAX,DWORD PTR SS:[EBP-14]
5F8318D6 . 8B08 MOV ECX,DWORD PTR DS:[EAX]
5F8318D8 . 8B09 MOV ECX,DWORD PTR DS:[ECX]
5F8318DA . 894D E0 MOV DWORD PTR SS:[EBP-20],ECX
5F8318DD . 50 PUSH EAX
5F8318DE . 51 PUSH ECX
5F8318DF . E8 CA030000 CALL test.5F831CAE
5F8318E4 . 59 POP ECX
5F8318E5 . 59 POP ECX
5F8318E6 . C3 RETN
5F8318E7 . 8B65 E8 MOV ESP,DWORD PTR SS:[EBP-18]
5F8318EA . 8365 E4 00 AND DWORD PTR SS:[EBP-1C],0
5F8318EE > 8365 FC 00 AND DWORD PTR SS:[EBP-4],0
5F8318F2 . C745 FC FEFFFF>MOV DWORD PTR SS:[EBP-4],-2
5F8318F9 . E8 09000000 CALL test.5F831907
5F8318FE . 8B45 E4 MOV EAX,DWORD PTR SS:[EBP-1C]
5F831901 . E8 FF030000 CALL test.5F831D05
5F831906 . C3 RETN
5F831907 /$ C705 0830835F >MOV DWORD PTR DS:[5F833008],-1
5F831911 \. C3 RETN
5F831912 .-E9 2A311400 JMP test.5F974A41
5F831917 09 DB 09
5F831918 . C3 RETN
5F831919 48 DB 48 ; CHAR 'H'
5F83191A AB DB AB
5F83191B 20 DB 20 ; CHAR ' '
5F83191C B3 DB B3
5F83191D 4F DB 4F ; CHAR 'O'
5F83191E 31 DB 31 ; CHAR '1'
5F83191F 9A DB 9A
5F831920 7E DB 7E ; CHAR '~'
5F831921 BC DB BC
5F831922 A0 DB A0
5F831923 EC DB EC
5F831924 4F DB 4F ; CHAR 'O'
5F831925 70 DB 70 ; CHAR 'p'
5F831926 54 DB 54 ; CHAR 'T'
5F831927 EA DB EA
5F831928 24 DB 24 ; CHAR '$'
5F831929 2A DB 2A ; CHAR '*'
5F83192A AE DB AE
5F83192B E1 DB E1
5F83192C C7 DB C7
5F83192D 1E DB 1E
5F83192E 3C DB 3C ; CHAR '<'
5F83192F 91 DB 91
5F831930 46 DB 46 ; CHAR 'F'
5F831931 36 DB 36 ; CHAR '6'
5F831932 . C2 0C00 RETN 0C
5F831935 8BFF MOV EDI,EDI
5F831937 55 DB 55 ; CHAR 'U'
5F831938 8B DB 8B
5F831939 EC DB EC
5F83193A 81 DB 81
5F83193B EC DB EC
5F83193C 28 DB 28 ; CHAR '('
5F83193D 03 DB 03
5F83193E 00 DB 00
5F83193F 00 DB 00
5F831940 A3 DB A3
5F831941 3031835F DD test.5F833130
5F831945 89 DB 89
5F831946 0D DB 0D
5F831947 2C31835F DD test.5F83312C
5F83194B 89 DB 89
5F83194C 15 DB 15
5F83194D 2831835F DD test.5F833128
5F831951 89 DB 89
5F831952 1D DB 1D
5F831953 2431835F DD test.5F833124
5F831957 89 DB 89
5F831958 35 DB 35 ; CHAR '5'
5F831959 2031835F DD test.5F833120
5F83195D 89 DB 89
5F83195E 3D DB 3D ; CHAR '='
5F83195F 1C31835F DD test.5F83311C
5F831963 66 DB 66 ; CHAR 'f'
5F831964 8C DB 8C
5F831965 15 DB 15
5F831966 4831835F DD test.5F833148
5F83196A 66 DB 66 ; CHAR 'f'
5F83196B 8C DB 8C
5F83196C . 0D 3C31835F OR EAX,5F83313C
5F831971 . 66:8C1D 183183>MOV WORD PTR DS:[5F833118],DS
5F831978 . 66:8C05 143183>MOV WORD PTR DS:[5F833114],ES
5F83197F . 66:8C25 103183>MOV WORD PTR DS:[5F833110],FS
5F831986 . 66:8C2D 0C3183>MOV WORD PTR DS:[5F83310C],GS
5F83198D . 9C PUSHFD
5F83198E . 8F05 4031835F POP DWORD PTR DS:[5F833140]
5F831994 . 8B45 00 MOV EAX,DWORD PTR SS:[EBP]
5F831997 . A3 3431835F MOV DWORD PTR DS:[5F833134],EAX
5F83199C . 8B45 04 MOV EAX,DWORD PTR SS:[EBP+4]
5F83199F . A3 3831835F MOV DWORD PTR DS:[5F833138],EAX
5F8319A4 . 8D45 08 LEA EAX,DWORD PTR SS:[EBP+8]
5F8319A7 . A3 4431835F MOV DWORD PTR DS:[5F833144],EAX
5F8319AC . 8B85 E0FCFFFF MOV EAX,DWORD PTR SS:[EBP-320]
5F8319B2 . C705 8030835F >MOV DWORD PTR DS:[5F833080],10001
5F8319BC . A1 3831835F MOV EAX,DWORD PTR DS:[5F833138]
5F8319C1 . A3 3430835F MOV DWORD PTR DS:[5F833034],EAX
5F8319C6 . C705 2830835F >MOV DWORD PTR DS:[5F833028],C0000409
5F8319D0 . C705 2C30835F >MOV DWORD PTR DS:[5F83302C],1
5F8319DA . A1 0030835F MOV EAX,DWORD PTR DS:[5F833000]
5F8319DF . 8985 D8FCFFFF MOV DWORD PTR SS:[EBP-328],EAX
5F8319E5 . A1 0430835F MOV EAX,DWORD PTR DS:[5F833004]
5F8319EA . 8985 DCFCFFFF MOV DWORD PTR SS:[EBP-324],EAX
5F8319F0 . E8 3CECFAA0 CALL 007E0631
5F8319F5 . 90 NOP
5F8319F6 . A3 7830835F MOV DWORD PTR DS:[5F833078],EAX
5F8319FB . 6A 01 PUSH 1
5F8319FD . E8 D8030000 CALL test.5F831DDA
5F831A02 . 59 POP ECX
5F831A03 . 6A 00 PUSH 0
5F831A05 . E8 F6E5FBA0 CALL 007F0000
5F831A0A . 90 NOP
5F831A0B . 68 D020835F PUSH test.5F8320D0
5F831A10 . E8 EBE5FCA0 CALL 00800000
5F831A15 . 90 NOP
5F831A16 . 833D 7830835F >CMP DWORD PTR DS:[5F833078],0
5F831A1D . 75 08 JNZ SHORT test.5F831A27
5F831A1F . 6A 01 PUSH 1
5F831A21 . E8 B4030000 CALL test.5F831DDA
5F831A26 . 59 POP ECX
5F831A27 > 68 090400C0 PUSH C0000409
5F831A2C . E8 5BFCFCA0 CALL 0080168C
5F831A31 . 90 NOP
5F831A32 . 50 PUSH EAX
5F831A33 . E8 59FCFCA0 CALL 00801691
5F831A38 . 90 NOP
5F831A39 . C9 LEAVE
5F831A3A . C3 RETN
5F831A3B . 68 4C33835F PUSH test.5F83334C
5F831A40 . E8 9B030000 CALL test.5F831DE0
5F831A45 . 59 POP ECX
5F831A46 . C3 RETN
5F831A47 /$ 6A 14 PUSH 14
5F831A49 |. 68 4022835F PUSH test.5F832240
5F831A4E |. E8 6D020000 CALL test.5F831CC0
5F831A53 |. FF35 8433835F PUSH DWORD PTR DS:[5F833384]
5F831A59 |. 8B35 4020835F MOV ESI,DWORD PTR DS:[5F832040]
5F831A5F |. FFD6 CALL ESI
5F831A61 |. 8945 E4 MOV DWORD PTR SS:[EBP-1C],EAX
5F831A64 |. 83F8 FF CMP EAX,-1
5F831A67 |. 75 0C JNZ SHORT test.5F831A75
5F831A69 |. FF75 08 PUSH DWORD PTR SS:[EBP+8] ; /func
5F831A6C |. E8 758F50FD CALL MSVCR1_1._onexit ; \_onexit
5F831A71 |. 90 NOP
5F831A72 |. 59 POP ECX
5F831A73 |. EB 64 JMP SHORT test.5F831AD9
5F831A75 |> 6A 08 PUSH 8
5F831A77 |. E8 76030000 CALL test.5F831DF2
5F831A7C |. 59 POP ECX
5F831A7D |. 8365 FC 00 AND DWORD PTR SS:[EBP-4],0
5F831A81 |. FF35 8433835F PUSH DWORD PTR DS:[5F833384]
5F831A87 |. FFD6 CALL ESI
5F831A89 |. 8945 E4 MOV DWORD PTR SS:[EBP-1C],EAX
5F831A8C |. FF35 8033835F PUSH DWORD PTR DS:[5F833380]
5F831A92 |. FFD6 CALL ESI
5F831A94 |. 8945 E0 MOV DWORD PTR SS:[EBP-20],EAX
5F831A97 |. 8D45 E0 LEA EAX,DWORD PTR SS:[EBP-20]
5F831A9A |. 50 PUSH EAX
5F831A9B |. 8D45 E4 LEA EAX,DWORD PTR SS:[EBP-1C]
5F831A9E |. 50 PUSH EAX
5F831A9F |. FF75 08 PUSH DWORD PTR SS:[EBP+8]
5F831AA2 |. 8B35 4420835F MOV ESI,DWORD PTR DS:[5F832044]
5F831AA8 |. FFD6 CALL ESI
5F831AAA |. 50 PUSH EAX
5F831AAB |. E8 3C030000 CALL test.5F831DEC
5F831AB0 |. 83C4 0C ADD ESP,0C
5F831AB3 |. 8945 DC MOV DWORD PTR SS:[EBP-24],EAX
5F831AB6 |. FF75 E4 PUSH DWORD PTR SS:[EBP-1C]
5F831AB9 |. FFD6 CALL ESI
5F831ABB |. A3 8433835F MOV DWORD PTR DS:[5F833384],EAX
5F831AC0 |. FF75 E0 PUSH DWORD PTR SS:[EBP-20]
5F831AC3 |. FFD6 CALL ESI
5F831AC5 |. A3 8033835F MOV DWORD PTR DS:[5F833380],EAX
5F831ACA |. C745 FC FEFFFF>MOV DWORD PTR SS:[EBP-4],-2
5F831AD1 |. E8 09000000 CALL test.5F831ADF
5F831AD6 |. 8B45 DC MOV EAX,DWORD PTR SS:[EBP-24]
5F831AD9 |> E8 27020000 CALL test.5F831D05
5F831ADE \. C3 RETN
5F831ADF /$ 6A 08 PUSH 8
5F831AE1 |. E8 00030000 CALL test.5F831DE6
5F831AE6 |. 59 POP ECX
5F831AE7 \. C3 RETN
5F831AE8 /$ 8BFF MOV EDI,EDI
5F831AEA |. 55 PUSH EBP
5F831AEB |. 8BEC MOV EBP,ESP
5F831AED |. FF75 08 PUSH DWORD PTR SS:[EBP+8]
5F831AF0 |. E8 52FFFFFF CALL test.5F831A47
5F831AF5 |. F7D8 NEG EAX
5F831AF7 |. 1BC0 SBB EAX,EAX
5F831AF9 |. F7D8 NEG EAX
5F831AFB |. 59 POP ECX
5F831AFC |. 48 DEC EAX
5F831AFD |. 5D POP EBP
5F831AFE \. C3 RETN
5F831AFF /$ 8BFF MOV EDI,EDI
5F831B01 |. 56 PUSH ESI
5F831B02 |. B8 0822835F MOV EAX,test.5F832208
5F831B07 |. BE 0822835F MOV ESI,test.5F832208
5F831B0C |. 57 PUSH EDI
5F831B0D |. 8BF8 MOV EDI,EAX
5F831B0F |. 3BC6 CMP EAX,ESI
5F831B11 |. 73 0F JNB SHORT test.5F831B22
5F831B13 |> 8B07 /MOV EAX,DWORD PTR DS:[EDI]
5F831B15 |. 85C0 |TEST EAX,EAX
5F831B17 |. 74 02 |JE SHORT test.5F831B1B
5F831B19 |. FFD0 |CALL EAX
5F831B1B |> 83C7 04 |ADD EDI,4
5F831B1E |. 3BFE |CMP EDI,ESI
5F831B20 |.^72 F1 \JB SHORT test.5F831B13
5F831B22 |> 5F POP EDI
5F831B23 |. 5E POP ESI
5F831B24 \. C3 RETN
5F831B25 8BFF MOV EDI,EDI
5F831B27 . 56 PUSH ESI
5F831B28 . B8 1022835F MOV EAX,test.5F832210
5F831B2D . BE 1022835F MOV ESI,test.5F832210
5F831B32 . 57 PUSH EDI
5F831B33 . 8BF8 MOV EDI,EAX
5F831B35 . 3BC6 CMP EAX,ESI
5F831B37 . 73 0F JNB SHORT test.5F831B48
5F831B39 > 8B07 MOV EAX,DWORD PTR DS:[EDI]
5F831B3B . 85C0 TEST EAX,EAX
5F831B3D . 74 02 JE SHORT test.5F831B41
5F831B3F . FFD0 CALL EAX
5F831B41 > 83C7 04 ADD EDI,4
5F831B44 . 3BFE CMP EDI,ESI
5F831B46 .^72 F1 JB SHORT test.5F831B39
5F831B48 > 5F POP EDI
5F831B49 . 5E POP ESI
5F831B4A . C3 RETN
5F831B4B CC INT3
5F831B4C CC INT3
5F831B4D CC INT3
5F831B4E CC INT3
5F831B4F CC INT3
5F831B50 /$ 8BFF MOV EDI,EDI
5F831B52 |. 55 PUSH EBP
5F831B53 |. 8BEC MOV EBP,ESP
5F831B55 |. 8B4D 08 MOV ECX,DWORD PTR SS:[EBP+8]
5F831B58 |. B8 4D5A0000 MOV EAX,5A4D
5F831B5D |. 66:3901 CMP WORD PTR DS:[ECX],AX
5F831B60 |. 74 04 JE SHORT test.5F831B66
5F831B62 |> 33C0 XOR EAX,EAX
5F831B64 |. 5D POP EBP
5F831B65 |. C3 RETN
5F831B66 |> 8B41 3C MOV EAX,DWORD PTR DS:[ECX+3C]
5F831B69 |. 03C1 ADD EAX,ECX
5F831B6B |. 8138 50450000 CMP DWORD PTR DS:[EAX],4550
5F831B71 |.^75 EF JNZ SHORT test.5F831B62
5F831B73 |. 33D2 XOR EDX,EDX
5F831B75 |. B9 0B010000 MOV ECX,10B
5F831B7A |. 66:3948 18 CMP WORD PTR DS:[EAX+18],CX
5F831B7E |. 0F94C2 SETE DL
5F831B81 |. 8BC2 MOV EAX,EDX
5F831B83 |. 5D POP EBP
5F831B84 \. C3 RETN
5F831B85 CC INT3
5F831B86 CC INT3
5F831B87 CC INT3
5F831B88 CC INT3
5F831B89 CC INT3
5F831B8A CC INT3
5F831B8B CC INT3
5F831B8C CC INT3
5F831B8D CC INT3
5F831B8E CC INT3
5F831B8F CC INT3
5F831B90 /$ 8BFF MOV EDI,EDI
5F831B92 |. 55 PUSH EBP
5F831B93 |. 8BEC MOV EBP,ESP
5F831B95 |. 8B45 08 MOV EAX,DWORD PTR SS:[EBP+8]
5F831B98 |. 8B48 3C MOV ECX,DWORD PTR DS:[EAX+3C]
5F831B9B |. 03C8 ADD ECX,EAX
5F831B9D |. 0FB741 14 MOVZX EAX,WORD PTR DS:[ECX+14]
5F831BA1 |. 53 PUSH EBX
5F831BA2 |. 56 PUSH ESI
5F831BA3 |. 0FB771 06 MOVZX ESI,WORD PTR DS:[ECX+6]
5F831BA7 |. 33D2 XOR EDX,EDX
5F831BA9 |. 57 PUSH EDI
5F831BAA |. 8D4408 18 LEA EAX,DWORD PTR DS:[EAX+ECX+18]
5F831BAE |. 85F6 TEST ESI,ESI
5F831BB0 |. 74 1B JE SHORT test.5F831BCD
5F831BB2 |. 8B7D 0C MOV EDI,DWORD PTR SS:[EBP+C]
5F831BB5 |> 8B48 0C /MOV ECX,DWORD PTR DS:[EAX+C]
5F831BB8 |. 3BF9 |CMP EDI,ECX
5F831BBA |. 72 09 |JB SHORT test.5F831BC5
5F831BBC |. 8B58 08 |MOV EBX,DWORD PTR DS:[EAX+8]
5F831BBF |. 03D9 |ADD EBX,ECX
5F831BC1 |. 3BFB |CMP EDI,EBX
5F831BC3 |. 72 0A |JB SHORT test.5F831BCF
5F831BC5 |> 42 |INC EDX
5F831BC6 |. 83C0 28 |ADD EAX,28
5F831BC9 |. 3BD6 |CMP EDX,ESI
5F831BCB |.^72 E8 \JB SHORT test.5F831BB5
5F831BCD |> 33C0 XOR EAX,EAX
5F831BCF |> 5F POP EDI
5F831BD0 |. 5E POP ESI
5F831BD1 |. 5B POP EBX
5F831BD2 |. 5D POP EBP
5F831BD3 \. C3 RETN
5F831BD4 CC INT3
5F831BD5 CC INT3
5F831BD6 CC INT3
5F831BD7 CC INT3
5F831BD8 CC INT3
5F831BD9 CC INT3
5F831BDA CC INT3
5F831BDB CC INT3
5F831BDC CC INT3
5F831BDD CC INT3
5F831BDE CC INT3
5F831BDF CC INT3
5F831BE0 $ 8BFF MOV EDI,EDI
5F831BE2 . 55 PUSH EBP
5F831BE3 . 8BEC MOV EBP,ESP
5F831BE5 . 6A FE PUSH -2
5F831BE7 . 68 6022835F PUSH test.5F832260
5F831BEC . 68 191D835F PUSH test.5F831D19
5F831BF1 . 64:A1 00000000 MOV EAX,DWORD PTR FS:[0]
5F831BF7 . 50 PUSH EAX
5F831BF8 . 83EC 08 SUB ESP,8
5F831BFB . 53 PUSH EBX
5F831BFC . 56 PUSH ESI
5F831BFD . 57 PUSH EDI
5F831BFE . A1 0030835F MOV EAX,DWORD PTR DS:[5F833000]
5F831C03 . 3145 F8 XOR DWORD PTR SS:[EBP-8],EAX
5F831C06 . 33C5 XOR EAX,EBP
5F831C08 . 50 PUSH EAX
5F831C09 . 8D45 F0 LEA EAX,DWORD PTR SS:[EBP-10]
5F831C0C . 64:A3 00000000 MOV DWORD PTR FS:[0],EAX
5F831C12 . 8965 E8 MOV DWORD PTR SS:[EBP-18],ESP
5F831C15 . C745 FC 000000>MOV DWORD PTR SS:[EBP-4],0
5F831C1C . 68 0000835F PUSH test.5F830000 ; /Arg1 = 5F830000
5F831C21 . E8 2AFFFFFF CALL test.5F831B50 ; \test.5F831B50
5F831C26 . 83C4 04 ADD ESP,4
5F831C29 . 85C0 TEST EAX,EAX
5F831C2B . 74 54 JE SHORT test.5F831C81
5F831C2D . 8B45 08 MOV EAX,DWORD PTR SS:[EBP+8]
5F831C30 . 2D 0000835F SUB EAX,test.5F830000
5F831C35 . 50 PUSH EAX ; /Arg2
5F831C36 . 68 0000835F PUSH test.5F830000 ; |Arg1 = 5F830000
5F831C3B . E8 50FFFFFF CALL test.5F831B90 ; \test.5F831B90
5F831C40 . 83C4 08 ADD ESP,8
5F831C43 . 85C0 TEST EAX,EAX
5F831C45 . 74 3A JE SHORT test.5F831C81
5F831C47 . 8B40 24 MOV EAX,DWORD PTR DS:[EAX+24]
5F831C4A . C1E8 1F SHR EAX,1F
5F831C4D . F7D0 NOT EAX
5F831C4F . 83E0 01 AND EAX,1
5F831C52 . C745 FC FEFFFF>MOV DWORD PTR SS:[EBP-4],-2
5F831C59 . 8B4D F0 MOV ECX,DWORD PTR SS:[EBP-10]
5F831C5C . 64:890D 000000>MOV DWORD PTR FS:[0],ECX
5F831C63 . 59 POP ECX
5F831C64 . 5F POP EDI
5F831C65 . 5E POP ESI
5F831C66 . 5B POP EBX
5F831C67 . 8BE5 MOV ESP,EBP
5F831C69 . 5D POP EBP
5F831C6A . C3 RETN
5F831C6B . 8B45 EC MOV EAX,DWORD PTR SS:[EBP-14]
5F831C6E . 8B08 MOV ECX,DWORD PTR DS:[EAX]
5F831C70 . 33D2 XOR EDX,EDX
5F831C72 . 8139 050000C0 CMP DWORD PTR DS:[ECX],C0000005
5F831C78 . 0F94C2 SETE DL
5F831C7B . 8BC2 MOV EAX,EDX
5F831C7D . C3 RETN
5F831C7E . 8B65 E8 MOV ESP,DWORD PTR SS:[EBP-18]
5F831C81 > C745 FC FEFFFF>MOV DWORD PTR SS:[EBP-4],-2
5F831C88 . 33C0 XOR EAX,EAX
5F831C8A . 8B4D F0 MOV ECX,DWORD PTR SS:[EBP-10]
5F831C8D . 64:890D 000000>MOV DWORD PTR FS:[0],ECX
5F831C94 . 59 POP ECX
5F831C95 . 5F POP EDI
5F831C96 . 5E POP ESI
5F831C97 . 5B POP EBX
5F831C98 . 8BE5 MOV ESP,EBP
5F831C9A . 5D POP EBP
5F831C9B . C3 RETN
5F831C9C $-E9 860950FD JMP MSVCR1_1._initterm
5F831CA1 37 DB 37 ; CHAR '7'
5F831CA2 $ 90 NOP
5F831CA3 .-E9 9D0950FD JMP MSVCR1_1._initterm_e
5F831CA8 $ 90 NOP
5F831CA9 .-E9 ADA254FD JMP MSVCR1_1._amsg_exit
5F831CAE $ 90 NOP
5F831CAF .-E9 379D57FD JMP MSVCR1_1.__CppXcptFilter
5F831CB4 CC INT3
5F831CB5 CC INT3
5F831CB6 CC INT3
5F831CB7 CC INT3
5F831CB8 CC INT3
5F831CB9 CC INT3
5F831CBA CC INT3
5F831CBB CC INT3
5F831CBC CC INT3
5F831CBD CC INT3
5F831CBE CC INT3
5F831CBF CC INT3
5F831CC0 /$ 68 191D835F PUSH test.5F831D19
5F831CC5 |. 64:FF35 000000>PUSH DWORD PTR FS:[0]
5F831CCC |. 8B4424 10 MOV EAX,DWORD PTR SS:[ESP+10]
5F831CD0 |. 896C24 10 MOV DWORD PTR SS:[ESP+10],EBP
5F831CD4 |. 8D6C24 10 LEA EBP,DWORD PTR SS:[ESP+10]
5F831CD8 |. 2BE0 SUB ESP,EAX
5F831CDA |. 53 PUSH EBX
5F831CDB |. 56 PUSH ESI
5F831CDC |. 57 PUSH EDI
5F831CDD |. A1 0030835F MOV EAX,DWORD PTR DS:[5F833000]
5F831CE2 |. 3145 FC XOR DWORD PTR SS:[EBP-4],EAX
5F831CE5 |. 33C5 XOR EAX,EBP
5F831CE7 |. 50 PUSH EAX
5F831CE8 |. 8965 E8 MOV DWORD PTR SS:[EBP-18],ESP
5F831CEB |. FF75 F8 PUSH DWORD PTR SS:[EBP-8]
5F831CEE |. 8B45 FC MOV EAX,DWORD PTR SS:[EBP-4]
5F831CF1 |. C745 FC FEFFFF>MOV DWORD PTR SS:[EBP-4],-2
5F831CF8 |. 8945 F8 MOV DWORD PTR SS:[EBP-8],EAX
5F831CFB |. 8D45 F0 LEA EAX,DWORD PTR SS:[EBP-10]
5F831CFE |. 64:A3 00000000 MOV DWORD PTR FS:[0],EAX
5F831D04 \. C3 RETN
5F831D05 /$ 8B4D F0 MOV ECX,DWORD PTR SS:[EBP-10]
5F831D08 |. 64:890D 000000>MOV DWORD PTR FS:[0],ECX
5F831D0F |. 59 POP ECX
5F831D10 |. 5F POP EDI
5F831D11 |. 5F POP EDI
5F831D12 |. 5E POP ESI
5F831D13 |. 5B POP EBX
5F831D14 |. 8BE5 MOV ESP,EBP
5F831D16 |. 5D POP EBP
5F831D17 |. 51 PUSH ECX
5F831D18 \. C3 RETN
5F831D19 8BFF MOV EDI,EDI
5F831D1B /. 55 PUSH EBP
5F831D1C |. 8BEC MOV EBP,ESP
5F831D1E |. FF75 14 PUSH DWORD PTR SS:[EBP+14]
5F831D21 |. FF75 10 PUSH DWORD PTR SS:[EBP+10]
5F831D24 |. FF75 0C PUSH DWORD PTR SS:[EBP+C]
5F831D27 |. FF75 08 PUSH DWORD PTR SS:[EBP+8]
5F831D2A |. 68 9515835F PUSH test.5F831595 ; ASCII ";
"
5F831D2F |. 68 0030835F PUSH test.5F833000
5F831D34 |. E8 BF000000 CALL test.5F831DF8
5F831D39 |. 83C4 18 ADD ESP,18
5F831D3C |. 5D POP EBP
5F831D3D \. C3 RETN
5F831D3E 8BFF MOV EDI,EDI
5F831D40 /. 55 PUSH EBP
5F831D41 |. 8BEC MOV EBP,ESP
5F831D43 |. 83EC 10 SUB ESP,10
5F831D46 |. A1 0030835F MOV EAX,DWORD PTR DS:[5F833000]
5F831D4B |. 8365 F8 00 AND DWORD PTR SS:[EBP-8],0
5F831D4F |. 8365 FC 00 AND DWORD PTR SS:[EBP-4],0
5F831D53 |. 53 PUSH EBX
5F831D54 |. 57 PUSH EDI
5F831D55 |. BF 4EE640BB MOV EDI,BB40E64E
5F831D5A |. BB 0000FFFF MOV EBX,FFFF0000
5F831D5F |. 3BC7 CMP EAX,EDI
5F831D61 |. 74 0D JE SHORT test.5F831D70
5F831D63 |. 85C3 TEST EBX,EAX
5F831D65 |. 74 09 JE SHORT test.5F831D70
5F831D67 |. F7D0 NOT EAX
5F831D69 |. A3 0430835F MOV DWORD PTR DS:[5F833004],EAX
5F831D6E |. EB 65 JMP SHORT test.5F831DD5
5F831D70 |> 56 PUSH ESI
5F831D71 |. 8D45 F8 LEA EAX,DWORD PTR SS:[EBP-8]
5F831D74 |. 50 PUSH EAX
5F831D75 |. E8 86E2FDA0 CALL 00810000
5F831D7A |. 90 NOP
5F831D7B |. 8B75 FC MOV ESI,DWORD PTR SS:[EBP-4]
5F831D7E |. 3375 F8 XOR ESI,DWORD PTR SS:[EBP-8]
5F831D81 |. E8 15E8FAA0 CALL 007E059B
5F831D86 |. 90 NOP
5F831D87 |. 33F0 XOR ESI,EAX
5F831D89 |. E8 12E8FAA0 CALL 007E05A0
5F831D8E |. 90 NOP
5F831D8F |. 33F0 XOR ESI,EAX
5F831D91 |. E8 0FE8FAA0 CALL 007E05A5
5F831D96 |. 90 NOP
5F831D97 |. 33F0 XOR ESI,EAX
5F831D99 |. 8D45 F0 LEA EAX,DWORD PTR SS:[EBP-10]
5F831D9C |. 50 PUSH EAX
5F831D9D |. E8 08E8FAA0 CALL 007E05AA
5F831DA2 |. 90 NOP
5F831DA3 |. 8B45 F4 MOV EAX,DWORD PTR SS:[EBP-C]
5F831DA6 |. 3345 F0 XOR EAX,DWORD PTR SS:[EBP-10]
5F831DA9 |. 33F0 XOR ESI,EAX
5F831DAB |. 3BF7 CMP ESI,EDI
5F831DAD |. 75 07 JNZ SHORT test.5F831DB6
5F831DAF |. BE 4FE640BB MOV ESI,BB40E64F
5F831DB4 |. EB 10 JMP SHORT test.5F831DC6
5F831DB6 |> 85F3 TEST EBX,ESI
5F831DB8 |. 75 0C JNZ SHORT test.5F831DC6
5F831DBA |. 8BC6 MOV EAX,ESI
5F831DBC |. 0D 11470000 OR EAX,4711
5F831DC1 |. C1E0 10 SHL EAX,10
5F831DC4 |. 0BF0 OR ESI,EAX
5F831DC6 |> 8935 0030835F MOV DWORD PTR DS:[5F833000],ESI
5F831DCC |. F7D6 NOT ESI
5F831DCE |. 8935 0430835F MOV DWORD PTR DS:[5F833004],ESI
5F831DD4 |. 5E POP ESI
5F831DD5 |> 5F POP EDI
5F831DD6 |. 5B POP EBX
5F831DD7 |. C9 LEAVE
5F831DD8 \. C3 RETN
5F831DD9 CC INT3
5F831DDA $ 90 NOP
5F831DDB .-E9 24AE57FD JMP MSVCR1_1._crt_debugger_hook
5F831DE0 $-E9 6F6951FD JMP MSVCR1_1.__clean_type_info_names_int>
5F831DE5 2F DB 2F ; CHAR '/'
5F831DE6 $ 90 NOP
5F831DE7 .-E9 48EB4FFD JMP MSVCR1_1._unlock
5F831DEC $ 90 NOP
5F831DED .-E9 7D0850FD JMP MSVCR1_1.__dllonexit
5F831DF2 $ 90 NOP
5F831DF3 .-E9 18EB4FFD JMP MSVCR1_1._lock
5F831DF8 $-E9 0FAE57FD JMP MSVCR1_1._except_handler4_common
5F831DFD 55 DB 55 ; CHAR 'U'
5F831DFE 00 DB 00
5F8320D8 . 4300 5300 6800>UNICODE "CShell.d"
5F8320E8 . 6C00 6C00 0000>UNICODE "ll",0
5F8320EE 00 DB 00
5F8320EF 00 DB 00
5F8320F0 . 4B 61 72 65 65>ASCII "Kareem111'Hack",0
5F8320FF 00 DB 00
5F832100 . 43 72 69 64 65>ASCII "Cridets:
Kareem"
5F832110 . 31 31 31 0A 0A>ASCII "111
Dragon(H)el"
5F832120 . 6C 0A 0A 69 2D>ASCII "l
i-[f]LuX
ram"
5F832130 . 6F 0A 0A 4C 69>ASCII "o
; CHAR 'H'
hhhhhhhhhhhhhhhhh nob