Disassembly of File: C:\Documents and Settings\Desktop\New Folder\SFC.DLL Code Offset = 00001000, Code Size = 00006000 Data Offset = 00007000, Data Size = 00001000 Number of Objects = 0004 (dec), Imagebase = 76110000h Object01: .text RVA: 00001000 Offset: 00001000 Size: 00006000 Flags: 60000020 Object02: .data RVA: 00007000 Offset: 00007000 Size: 00001000 Flags: C0000040 Object03: .rsrc RVA: 00008000 Offset: 00008000 Size: 00001000 Flags: 40000040 Object04: .reloc RVA: 00009000 Offset: 00009000 Size: 00001000 Flags: 42000040 +++++++++++++++++++ MENU INFORMATION ++++++++++++++++++ There Are No Menu Resources in This Application +++++++++++++++++ DIALOG INFORMATION ++++++++++++++++++ There Are No Dialog Resources in This Application +++++++++++++++++++ IMPORTED FUNCTIONS ++++++++++++++++++ Number of Imported Modules = 7 (decimal) Import Module 001: MSVCRT.dll Import Module 002: RPCRT4.dll Import Module 003: WINTRUST.dll Import Module 004: atrace.dll Import Module 005: KERNEL32.dll Import Module 006: USER32.dll Import Module 007: ADVAPI32.dll +++++++++++++++++++ IMPORT MODULE DETAILS +++++++++++++++ Import Module 001: MSVCRT.dll Addr:77F744D7 hint(02AA) Name: setlocale Addr:77F827CE hint(02B4) Name: strchr Addr:77F953CA hint(02AF) Name: sprintf Addr:77F7F56A hint(00C7) Name: _except_handler3 Addr:77F7C7D0 hint(023A) Name: atoi Addr:77F710ED hint(025B) Name: free Addr:77F71000 hint(028E) Name: malloc Import Module 002: RPCRT4.dll Addr:7FAB1F1B hint(007F) Name: NdrClientInitializeNew Addr:7FABA9AD hint(0090) Name: NdrConformantStringMarshall Addr:7FABF784 hint(00C0) Name: NdrGetBuffer Addr:7FAB582D hint(0132) Name: RpcBindingFree Addr:7FABEE9B hint(01B0) Name: RpcStringBindingComposeA Addr:7FAB3801 hint(00EB) Name: NdrPointerBufferSize Addr:7FAB36E1 hint(00ED) Name: NdrPointerMarshall Addr:7FAB9512 hint(01B4) Name: RpcStringFreeA Addr:7FAB4720 hint(0089) Name: NdrComplexStructUnmarshall Addr:7FABAA9A hint(0092) Name: NdrConformantStringUnmarshall Addr:7FAB7243 hint(010B) Name: NdrSimpleStructBufferSize Addr:7FAB396F hint(010D) Name: NdrSimpleStructMarshall Addr:7FAB39C9 hint(010F) Name: NdrSimpleStructUnmarshall Addr:7FAB66A2 hint(017A) Name: RpcRaiseException Addr:7FAB74CE hint(0133) Name: RpcBindingFromStringBindingA Addr:7FABA8FE hint(008F) Name: NdrConformantStringBufferSize Addr:7FABF7C4 hint(00FD) Name: NdrSendReceive Addr:7FABF60E hint(00A4) Name: NdrConvert Addr:7FABF75A hint(00B9) Name: NdrFreeBuffer Import Module 003: WINTRUST.dll Addr:741E79C6 hint(0011) Name: CryptCATClose Import Module 004: atrace.dll Addr:7E4A7350 hint(0008) Name: __dwEnabledTraces Addr:7E4A17B6 hint(0001) Name: _AsyncStringTrace@12 Addr:7E4A16A3 hint(0006) Name: _SetAsyncTraceParams@16 Import Module 005: KERNEL32.dll Addr:BFF70173 hint(029C) Name: SetLastError Addr:BFF92068 hint(002B) Name: CopyFileA Addr:BFF67347 hint(0326) Name: lstrcatA Addr:BFF67A27 hint(0114) Name: GetDiskFreeSpaceExA Addr:BFF6791A hint(0170) Name: GetSystemDirectoryA Addr:BFF67D83 hint(0202) Name: MultiByteToWideChar Addr:BFF66EE8 hint(01BA) Name: HeapFree Addr:BFF7CF67 hint(0155) Name: GetProcessHeap Addr:BFF66E9C hint(01B4) Name: HeapAlloc Addr:BFF672D0 hint(032F) Name: lstrcpyA Addr:BFF67B08 hint(0120) Name: GetFileAttributesA Addr:BFF676A8 hint(01DF) Name: LoadLibraryA Addr:BFF66D80 hint(0153) Name: GetProcAddress Addr:BFF7558E hint(012D) Name: GetLastError Addr:BFF67DA1 hint(0301) Name: WideCharToMultiByte Addr:BFF67950 hint(0197) Name: GetWindowsDirectoryA Addr:BFF67381 hint(0335) Name: lstrlenA Addr:BFF7E559 hint(00C3) Name: FreeLibrary Import Module 006: USER32.dll Addr:BFF456B5 hint(02B3) Name: wsprintfA Import Module 007: ADVAPI32.dll Addr:BFE61501 hint(019D) Name: RegOpenKeyExA Addr:BFE613E7 hint(0194) Name: RegEnumValueA Addr:BFE6161A hint(01B2) Name: RegSetValueExA Addr:BFE61564 hint(01A7) Name: RegQueryValueExA Addr:BFE61674 hint(0184) Name: RegCloseKey +++++++++++++++++++ EXPORTED FUNCTIONS ++++++++++++++++++ Number of Exported Functions = 0019 (decimal) Addr:76113A82 Ord: 8 (0008h) Name: Ordinal:0008 Addr:76113CB5 Ord: 9 (0009h) Name: Ordinal:0009 Addr:761155B0 Ord: 10 (000Ah) Name: SRDetectUndoer Addr:76114DBC Ord: 11 (000Bh) Name: DisableFIFO Addr:761142E4 Ord: 12 (000Ch) Name: DisableSFP Addr:761149CD Ord: 13 (000Dh) Name: DisableSR Addr:76114EE5 Ord: 14 (000Eh) Name: EnableFIFO Addr:7611447B Ord: 15 (000Fh) Name: GetStateMgrDiskMax Addr:76114415 Ord: 16 (0010h) Name: GetWindowsDiskFreeSpace Addr:7611488A Ord: 17 (0011h) Name: IsSREnabled Addr:76114749 Ord: 18 (0012h) Name: RunDisableSR Addr:76114C29 Ord: 19 (0013h) Name: SRSetRestorePoint Addr:76114AFB Ord: 20 (0014h) Name: SRUpdateMonitoredList Addr:7611461B Ord: 21 (0015h) Name: SetStateMgrDiskMax Addr:76114037 Ord: 22 (0016h) Name: SfcGetNextProtectedFile Addr:76113E29 Ord: 23 (0017h) Name: SfcIsFileProtected Addr:76115006 Ord: 24 (0018h) Name: SfpDuplicateCatalog Addr:761151C9 Ord: 25 (0019h) Name: SfpQueryCatalog Addr:761141B6 Ord: 26 (001Ah) Name: SfpVerifyFile +++++++++++++++++++ ASSEMBLY CODE LISTING ++++++++++++++++++ //********************** Start of Code in Object .text ************** Program Entry Point = 7611390B (C:\Documents and Settings\Desktop\New Folder\SFC.DLL File Offset:0000A90B) :76111000 0115E6BFE713 add dword ptr [13E7BFE6], edx :76111006 E6BF out BF, al :76111008 1A16 sbb dl, byte ptr [esi] :7611100A E6BF out BF, al :7611100C 64 BYTE 064h :7611100D 15E6BF7416 adc eax, 1674BFE6 :76111012 E6BF out BF, al :76111014 00000000 BYTE 4 DUP(0) :76111018 7301 jnb 7611101B :7611101A F7BF6820F9BF idiv dword ptr [edi+BFF92068] :76111020 47 inc edi :76111021 73F6 jnb 76111019 :76111023 BF277AF6BF mov edi, BFF67A27 :76111028 1A79F6 sbb bh, byte ptr [ecx-0A] :7611102B BF837DF6BF mov edi, BFF67D83 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111093(C) | :76111030 E86EF6BF67 call DDD106A3 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611103D(C) | :76111035 CF iret * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111087(C) | :76111036 F7BF9C6EF6BF idiv dword ptr [edi+BFF66E9C] :7611103C D0 BYTE 0d0h :7611103D 72F6 jb 76111035 :7611103F BF087BF6BF mov edi, BFF67B08 :76111044 A876 test al, 76 :76111046 F6BF806DF6BF idiv byte ptr [edi+BFF66D80] :7611104C 8E55F7 mov ss, [ebp-09] :7611104F BFA17DF6BF mov edi, BFF67DA1 :76111054 50 push eax :76111055 79F6 jns 7611104D :76111057 BF8173F6BF mov edi, BFF67381 :7611105C 59 pop ecx :7611105D E5F7 in ax, F7 :7611105F BF00000000 mov edi, 00000000 :76111064 D7 xlat :76111065 44 inc esp :76111066 F777CE div [edi-32] :76111069 27 daa * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761110BD(C) | :7611106A F8 clc :7611106B 77CA ja 76111037 :7611106D 53 push ebx :7611106E F9 stc :7611106F 776A ja 761110DB :76111071 F5 cmc :76111072 F777D0 div [edi-30] :76111075 C7F777ED10F7 mov edi, F710ED77 :7611107B 7700 ja 7611107D * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611107B(C) | :7611107D 10F7 adc bh, dh :7611107F 7700 ja 76111081 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611107F(C) | :76111081 000000 BYTE 3 DUP(0) :76111084 1B1F sbb ebx, dword ptr [edi] :76111086 AB stosd :76111087 7FAD jg 76111036 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761110C3(C) | :76111089 A9AB7F84F7 test eax, F7847FAB :7611108E AB stosd :7611108F 7F2D jg 761110BE :76111091 58 pop eax :76111092 AB stosd :76111093 7F9B jg 76111030 :76111095 EE out dx, al :76111096 AB stosd :76111097 7F01 jg 7611109A :76111099 38AB7FE136AB cmp byte ptr [ebx+AB36E17F], ch * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761110E7(C) | :7611109F 7F12 jg 761110B3 :761110A1 95 xchg eax,ebp :761110A2 AB stosd :761110A3 7F20 jg 761110C5 :761110A5 47 inc edi :761110A6 AB stosd :761110A7 7F9A jg 76111043 :761110A9 AA stosb :761110AA AB stosd :761110AB 7F43 jg 761110F0 :761110AD 72AB jb 7611105A :761110AF 7F6F jg 76111120 :761110B1 39AB7FC939AB cmp dword ptr [ebx+AB39C97F], ebp :761110B7 7FA2 jg 7611105B :761110B9 66AB stosw :761110BB 7FCE jg 7611108B :761110BD 74AB je 7611106A * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761110BF(C) | :761110BF 7FFE jg 761110BF :761110C1 A8AB test al, AB :761110C3 7FC4 jg 76111089 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761110A3(C) | :761110C5 F7AB7F0EF6AB imul dword ptr [ebx+ABF60E7F] :761110CB 7F5A jg 76111127 :761110CD F7AB7F000000 imul dword ptr [ebx+0000007F] :761110D3 00B556F4BF00 add byte ptr [ebp+00BFF456], dh :761110D9 000000 BYTE 3 DUP(0) :761110DC C6791E74 mov [ecx+1E], 74 :761110E0 00000000 BYTE 4 DUP(0) :761110E4 50 push eax :761110E5 734A jnb 76111131 :761110E7 7EB6 jle 7611109F :761110E9 17 pop ss :761110EA 4A dec edx :761110EB 7EA3 jle 76111090 :761110ED 16 push ss :761110EE 4A dec edx :761110EF 7E00 jle 761110F1 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761110EF(C) | :761110F1 00000000000000000000 BYTE 10 DUP(0) :761110FB 000000000000000000 BYTE 9 DUP(0) :76111104 1138 adc dword ptr [eax], edi :76111106 3539000000 xor eax, 00000039 :7611110B 000400 add byte ptr [eax+eax], al :7611110E 0000 add byte ptr [eax], al :76111110 1001 adc byte ptr [ecx], al :76111112 00000000000000 BYTE 7 DUP(0) :76111119 A000000000 mov al, byte ptr [00000000] :7611111E 0000 add byte ptr [eax], al * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761110AF(C) | :76111120 1138 adc dword ptr [eax], edi :76111122 3539000000 xor eax, 00000039 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761110CB(C) | :76111127 000400 add byte ptr [eax+eax], al :7611112A 0000 add byte ptr [eax], al :7611112C 1001 adc byte ptr [ecx], al :7611112E 000000000000 BYTE 6 DUP(0) :76111134 0459 add al, 59 :76111136 0100 add dword ptr [eax], eax :76111138 00000000 BYTE 4 DUP(0) :7611113C 1138 adc dword ptr [eax], edi :7611113E 3539000000 xor eax, 00000039 :76111143 0002 add byte ptr [edx], al :76111145 000000 BYTE 3 DUP(0) :76111148 1800 sbb byte ptr [eax], al :7611114A 000000000000 BYTE 6 DUP(0) :76111150 90 nop :76111151 FE BYTE 0feh :76111152 A3FF000000 mov dword ptr [000000FF], eax :76111157 00440000 add byte ptr [eax+eax], al :7611115B 00E0 add al, ah :7611115D 0C6B or al, 6B :7611115F 90 nop :76111160 0BC7 or eax, edi :76111162 6710B31700 adc [bp+di+0017], dh :76111167 DD01 fld qword ptr [ecx] :76111169 06 push es :7611116A 62DA bound ebx, edx :7611116C 0100 add dword ptr [eax], eax :7611116E 0000 add byte ptr [eax], al :76111170 045D add al, 5D :76111172 888AEB1CC911 mov byte ptr [edx+11C91CEB], cl :76111178 9F lahf :76111179 E808002B10 call 863C1186 :7611117E 48 dec eax :7611117F 60 pushad :76111180 0200 add al, byte ptr [eax] :76111182 00000000000000000000 BYTE 10 DUP(0) :7611118C 00000000000000000000 BYTE 10 DUP(0) :76111196 00000000000000000000 BYTE 10 DUP(0) :761111A0 58111176 DWORD 76111158 :761111A4 EF581176 DWORD 761158EF :761111A8 FB581176 DWORD 761158FB :761111AC E0791176 DWORD 761179E0 :761111B0 00000000000000000000 BYTE 10 DUP(0) :761111BA 000000000000 BYTE 6 DUP(0) * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761111AD(C) | :761111C0 DA12 ficom dword ptr [edx] :761111C2 117600 adc dword ptr [esi+00], esi :761111C5 000000 BYTE 3 DUP(0) :761111C8 0100 add dword ptr [eax], eax :761111CA 0100 add dword ptr [eax], eax :761111CC 00000000 BYTE 4 DUP(0) :761111D0 17 pop ss :761111D1 0103 add dword ptr [ebx], eax :761111D3 0500000000 add eax, 00000000 :761111D8 0000000000000000 BYTE 8 DUP(0) :761111E0 0100 add dword ptr [eax], eax :761111E2 00000000000000000000 BYTE 10 DUP(0) :761111EC 00000000 BYTE 4 DUP(0) :761111F0 44 inc esp :761111F1 000000 BYTE 3 DUP(0) :761111F4 86B0773F173A xchg byte ptr [eax+3A173F77], dh :761111FA D311 rcl dword ptr [ecx], cl :761111FC 91 xchg eax,ecx :761111FD 6600C0 add al, al :76111200 4F dec edi :76111201 688E280100 push 0001288E :76111206 0000 add byte ptr [eax], al :76111208 045D add al, 5D :7611120A 888AEB1CC911 mov byte ptr [edx+11C91CEB], cl :76111210 9F lahf :76111211 E808002B10 call 863C121E :76111216 48 dec eax :76111217 60 pushad :76111218 0200 add al, byte ptr [eax] :7611121A 00000000000000000000 BYTE 10 DUP(0) :76111224 00000000000000000000 BYTE 10 DUP(0) :7611122E 00000000000000000000 BYTE 10 DUP(0) :76111238 F0111176 DWORD 761111F0 :7611123C EF581176 DWORD 761158EF :76111240 FB581176 DWORD 761158FB :76111244 E4791176 DWORD 761179E4 :76111248 00000000000000000000 BYTE 10 DUP(0) :76111252 000000000000 BYTE 6 DUP(0) * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111245(C) | :76111258 DA12 ficom dword ptr [edx] :7611125A 117600 adc dword ptr [esi+00], esi :7611125D 000000 BYTE 3 DUP(0) :76111260 0100 add dword ptr [eax], eax :76111262 0100 add dword ptr [eax], eax :76111264 00000000 BYTE 4 DUP(0) :76111268 17 pop ss :76111269 0103 add dword ptr [ebx], eax :7611126B 0500000000 add eax, 00000000 :76111270 0000000000000000 BYTE 8 DUP(0) :76111278 0100 add dword ptr [eax], eax :7611127A 00000000000000000000 BYTE 10 DUP(0) :76111284 000000000000 BYTE 6 DUP(0) :7611128A 4D dec ebp :7611128B 0102 add dword ptr [edx], eax :7611128D 004D01 add byte ptr [ebp+01], cl :76111290 06 push es :76111291 005308 add byte ptr [ebx+08], dl :76111294 4D dec ebp :76111295 0102 add dword ptr [edx], eax :76111297 004E08 add byte ptr [esi+08], cl :7611129A 53 push ebx :7611129B 084D01 or byte ptr [ebp+01], cl :7611129E 0200 add al, byte ptr [eax] :761112A0 53 push ebx :761112A1 085001 or byte ptr [eax+01], dl :761112A4 0A00 or al, byte ptr [eax] :761112A6 53 push ebx :761112A7 084D01 or byte ptr [ebp+01], cl :761112AA 0200 add al, byte ptr [eax] :761112AC 51 push ecx :761112AD 011E add dword ptr [esi], ebx :761112AF 004E08 add byte ptr [esi+08], cl :761112B2 53 push ebx :761112B3 084E08 or byte ptr [esi+08], cl :761112B6 4D dec ebp :761112B7 0102 add dword ptr [edx], eax :761112B9 005308 add byte ptr [ebx+08], dl :761112BC 4E dec esi :761112BD 085308 or byte ptr [ebx+08], dl :761112C0 53 push ebx :761112C1 084D01 or byte ptr [ebp+01], cl :761112C4 2800 sub byte ptr [eax], al :761112C6 51 push ecx :761112C7 013E add dword ptr [esi], edi :761112C9 005308 add byte ptr [ebx+08], dl :761112CC 4E dec esi :761112CD 0B5B5C or ebx, dword ptr [ebx+5C] :761112D0 5B pop ebx :761112D1 5C pop esp :761112D2 00000000000000000000 BYTE 10 DUP(0) :761112DC 1108 adc dword ptr [eax], ecx :761112DE 225C1208 and bl, byte ptr [edx+edx+08] :761112E2 225C1100 and bl, byte ptr [ecx+edx] :761112E6 0800 or byte ptr [eax], al :761112E8 1D01080205 sbb eax, 05020801 :761112ED 5B pop ebx :761112EE 15030C024C adc eax, 4C020C03 :761112F3 00F4 add ah, dh :761112F5 FF08 dec dword ptr [eax] :761112F7 5B pop ebx :761112F8 1100 adc dword ptr [eax], eax :761112FA 0200 add al, byte ptr [eax] :761112FC 22444000 and al, byte ptr [eax+2*eax] :76111300 000412 add byte ptr [edx+edx], al :76111303 0008 add byte ptr [eax], cl :76111305 001D00400002 add byte ptr [02004000], bl :7611130B 5B pop ebx :7611130C 1507500008 adc eax, 08005007 :76111311 080B or byte ptr [ebx], cl :76111313 4C dec esp :76111314 00F1 add cl, dh :76111316 FF5B11 call far [ebx+11] :76111319 0402 add al, 02 :7611131B 001A add byte ptr [edx], bl :7611131D 07 pop es :7611131E 0C00 or al, 00 :76111320 00000000 BYTE 4 DUP(0) :76111324 080B or byte ptr [ebx], cl :76111326 5C pop esp :76111327 5B pop ebx :76111328 0000000000000000 BYTE 8 DUP(0) :76111330 FFFFFFFF BYTE 4 DUP(0ffh) :76111334 00000000 BYTE 4 DUP(0) :76111338 A4 movsb :76111339 2B11 sub edx, dword ptr [ecx] :7611133B 7600 jbe 7611133D * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611133B(C) | :7611133D 000000 BYTE 3 DUP(0) :76111340 FFFFFFFF BYTE 4 DUP(0ffh) :76111344 00000000 BYTE 4 DUP(0) :76111348 DD BYTE 0ddh :76111349 2C11 sub al, 11 :7611134B 7600 jbe 7611134D * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611134B(C) | :7611134D 000000 BYTE 3 DUP(0) :76111350 FFFFFFFF BYTE 4 DUP(0ffh) :76111354 00000000 BYTE 4 DUP(0) :76111358 F9 stc :76111359 2D11760000 sub eax, 00007611 :7611135E 0000 add byte ptr [eax], al :76111360 FFFFFFFF BYTE 4 DUP(0ffh) :76111364 00000000 BYTE 4 DUP(0) :76111368 242F and al, 2F :7611136A 117600 adc dword ptr [esi+00], esi :7611136D 000000 BYTE 3 DUP(0) :76111370 FFFFFFFF BYTE 4 DUP(0ffh) :76111374 00000000 BYTE 4 DUP(0) :76111378 91 xchg eax,ecx :76111379 3011 xor byte ptr [ecx], dl :7611137B 7600 jbe 7611137D * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611137B(C) | :7611137D 000000 BYTE 3 DUP(0) :76111380 FFFFFFFF BYTE 4 DUP(0ffh) :76111384 00000000 BYTE 4 DUP(0) :76111388 BC31117600 mov esp, 00761131 :7611138D 000000 BYTE 3 DUP(0) :76111390 FFFFFFFF BYTE 4 DUP(0ffh) :76111394 00000000 BYTE 4 DUP(0) :76111398 A932117600 test eax, 00761132 :7611139D 000000 BYTE 3 DUP(0) :761113A0 FFFFFFFF BYTE 4 DUP(0ffh) :761113A4 00000000 BYTE 4 DUP(0) :761113A8 823311 xor byte ptr [ebx], 11 :761113AB 7600 jbe 761113AD * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761113AB(C) | :761113AD 000000 BYTE 3 DUP(0) :761113B0 FFFFFFFF BYTE 4 DUP(0ffh) :761113B4 00000000 BYTE 4 DUP(0) :761113B8 6F outsd :761113B9 3411 xor al, 11 :761113BB 7600 jbe 761113BD * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761113BB(C) | :761113BD 000000 BYTE 3 DUP(0) :761113C0 FFFFFFFF BYTE 4 DUP(0ffh) :761113C4 00000000 BYTE 4 DUP(0) :761113C8 48 dec eax :761113C9 3511760000 xor eax, 00007611 :761113CE 0000 add byte ptr [eax], al :761113D0 FFFFFFFF BYTE 4 DUP(0ffh) :761113D4 00000000 BYTE 4 DUP(0) :761113D8 64 BYTE 064h :761113D9 36117600 adc dword ptr ss:[esi+00], esi :761113DD 000000 BYTE 3 DUP(0) :761113E0 FFFFFFFF BYTE 4 DUP(0ffh) :761113E4 00000000 BYTE 4 DUP(0) :761113E8 A4 movsb :761113E9 37 aaa :761113EA 117600 adc dword ptr [esi+00], esi :761113ED 000000 BYTE 3 DUP(0) :761113F0 FFFFFFFF BYTE 4 DUP(0ffh) :761113F4 00000000 BYTE 4 DUP(0) :761113F8 61 popad :761113F9 3811 cmp byte ptr [ecx], dl :761113FB 7600 jbe 761113FD * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761113FB(C) | :761113FD 000000 BYTE 3 DUP(0) :76111400 FFFFFFFF BYTE 4 DUP(0ffh) :76111404 00000000 BYTE 4 DUP(0) :76111408 FD std :76111409 3811 cmp byte ptr [ecx], dl :7611140B 7653 jbe 76111460 :7611140D 7973 jns 76111482 :7611140F 7465 je 76111476 :76111411 6D insd :76111412 5C pop esp :76111413 52 push edx :76111414 65 BYTE 065h :76111415 7374 jnb 7611148B :76111417 6F outsd :76111418 7265 jb 7611147F :7611141A 5C pop esp :7611141B 53 push ebx :7611141C 744D je 7611146B :7611141E 67722E jb 7611144F :76111421 65 BYTE 065h :76111422 7865 js 76111489 :76111424 00000000 BYTE 4 DUP(0) :76111428 41 inc ecx :76111429 6C insb :7611142A 7761 ja 7611148D :7611142C 7973 jns 761114A1 :7611142E 43 inc ebx :7611142F 6F outsd :76111430 6D insd :76111431 7072 jo 761114A5 :76111433 65 BYTE 065h :76111434 7373 jnb 761114A9 :76111436 0000 add byte ptr [eax], al :76111438 42 inc edx :76111439 726F jb 761114AA :7611143B 61 popad :7611143C 64636173 arpl dword ptr fs:[ecx+73], esp :76111440 7454 je 76111496 :76111442 65 BYTE 065h :76111443 7374 jnb 761114B9 :76111445 4D dec ebp :76111446 65 BYTE 065h :76111447 7373 jnb 761114BC :76111449 61 popad :7611144A 67 BYTE 067h :7611144B 65 BYTE 065h :7611144C 7300 jnb 7611144E * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611144C(C) | :7611144E 0000 add byte ptr [eax], al :76111450 54 push esp :76111451 65 BYTE 065h :76111452 7374 jnb 761114C8 :76111454 4B dec ebx :76111455 65 BYTE 065h :76111456 7973 jns 761114CB :76111458 00000000 BYTE 4 DUP(0) :7611145C 53 push ebx :7611145D 4F dec edi :7611145E 46 inc esi :7611145F 54 push esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611140B(C) | :76111460 57 push edi :76111461 41 inc ecx :76111462 52 push edx :76111463 45 inc ebp :76111464 5C pop esp :76111465 4D dec ebp :76111466 6963726F736F66 imul esp, dword ptr [ebx+72], 666F736F :7611146D 745C je 761114CB :7611146F 57 push edi :76111470 696E646F77735C imul ebp, dword ptr [esi+64], 5C73776F :76111477 43 inc ebx :76111478 7572 jne 761114EC :7611147A 7265 jb 761114E1 :7611147C 6E outsb :7611147D 7456 je 761114D5 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111418(C) | :7611147F 65 BYTE 065h :76111480 7273 jb 761114F5 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611140D(C) | :76111482 696F6E5C537461 imul ebp, dword ptr [edi+6E], 6174535C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111422(C) | :76111489 7465 je 761114F0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111415(C) | :7611148B 4D dec ebp :7611148C 67725C jb 761114EB :7611148F 54 push esp :76111490 65 BYTE 065h :76111491 7374 jnb 76111507 :76111493 4B dec ebx :76111494 65 BYTE 065h :76111495 7973 jns 7611150A :76111497 004D73 add byte ptr [ebp+73], cl :7611149A 675F pop edi :7611149C 54 push esp :7611149D 65 BYTE 065h :7611149E 7374 jnb 76111514 :761114A0 44 inc esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611142C(C) | :761114A1 69736B4D6F6E69 imul esi, dword ptr [ebx+6B], 696E6F4D :761114A8 746F je 76111519 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111439(C) | :761114AA 7200 jb 761114AC * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761114AA(C) | :761114AC 4D dec ebp :761114AD 7367 jnb 76111516 :761114AF 5F pop edi :761114B0 54 push esp :761114B1 65 BYTE 065h :761114B2 7374 jnb 76111528 :761114B4 54 push esp :761114B5 686177534D push 4D537761 :761114BA 0000 add byte ptr [eax], al * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111447(C) | :761114BC 4D dec ebp :761114BD 7367 jnb 76111526 :761114BF 5F pop edi :761114C0 54 push esp :761114C1 65 BYTE 065h :761114C2 7374 jnb 76111538 :761114C4 46 inc esi :761114C5 7265 jb 7611152C :761114C7 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111452(C) | :761114C8 7A65 jpe 7611152F :761114CA 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76111456(C), :7611146D(C) | :761114CB 4D dec ebp :761114CC 00000000 BYTE 4 DUP(0) :761114D0 4D dec ebp :761114D1 7367 jnb 7611153A :761114D3 5F pop edi :761114D4 54 push esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611147D(C) | :761114D5 65 BYTE 065h :761114D6 7374 jnb 7611154C :761114D8 43 inc ebx :761114D9 7572 jne 7611154D :761114DB 7265 jb 76111542 :761114DD 6E outsb :761114DE 7444 je 76111524 :761114E0 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611147A(C) | :761114E1 53 push ebx :761114E2 697A650000004D imul edi, dword ptr [edx+65], 4D000000 :761114E9 7367 jnb 76111552 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611148D(C) | :761114EB 5F pop edi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111478(C) | :761114EC 54 push esp :761114ED 65 BYTE 065h :761114EE 7374 jnb 76111564 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111489(C) | :761114F0 53 push ebx :761114F1 746F je 76111562 :761114F3 7046 jo 7611153B * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111480(C) | :761114F5 49 dec ecx :761114F6 46 inc esi :761114F7 4F dec edi :761114F8 00000000 BYTE 4 DUP(0) :761114FC 4D dec ebp :761114FD 7367 jnb 76111566 :761114FF 5F pop edi :76111500 54 push esp :76111501 65 BYTE 065h :76111502 7374 jnb 76111578 :76111504 53 push ebx :76111505 7461 je 76111568 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111491(C) | :76111507 7274 jb 7611157D :76111509 46 inc esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111495(C) | :7611150A 49 dec ecx :7611150B 46 inc esi :7611150C 4F dec edi :7611150D 000000 BYTE 3 DUP(0) :76111510 4D dec ebp :76111511 7367 jnb 7611157A :76111513 5F pop edi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611149E(C) | :76111514 54 push esp :76111515 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761114AD(C) | :76111516 7374 jnb 7611158C :76111518 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761114A8(C) | :76111519 746F je 7611158A :7611151B 7043 jo 76111560 :7611151D 61 popad :7611151E 626269 bound esp, dword ptr [edx+69] :76111521 6E outsb :76111522 67004D73 add [di+73], cl :76111526 675F pop edi :76111528 54 push esp :76111529 65 BYTE 065h :7611152A 7374 jnb 761115A0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761114C5(C) | :7611152C 53 push ebx :7611152D 7461 je 76111590 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761114C8(C) | :7611152F 7274 jb 761115A5 :76111531 43 inc ebx :76111532 61 popad :76111533 626269 bound esp, dword ptr [edx+69] :76111536 6E outsb :76111537 00 BYTE 000h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761114C2(C) | :76111538 00000000 BYTE 4 DUP(0) :7611153C 43 inc ebx :7611153D 41 inc ecx :7611153E 42 inc edx :7611153F 44 inc esp :76111540 4F dec edi :76111541 4E dec esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761114DB(C) | :76111542 45 inc ebp :76111543 005645 add byte ptr [esi+45], dl :76111546 52 push edx :76111547 53 push ebx :76111548 49 dec ecx :76111549 4F dec edi :7611154A 4E dec esi :7611154B 00534F add byte ptr [ebx+4F], dl :7611154E 46 inc esi :7611154F 54 push esp :76111550 57 push edi :76111551 41 inc ecx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761114E9(C) | :76111552 52 push edx :76111553 45 inc ebp :76111554 5C pop esp :76111555 4D dec ebp :76111556 6963726F736F66 imul esp, dword ptr [ebx+72], 666F736F :7611155D 745C je 761115BB :7611155F 57 push edi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611151B(C) | :76111560 696E646F77735C imul ebp, dword ptr [esi+64], 5C73776F :76111567 43 inc ebx :76111568 7572 jne 761115DC :7611156A 7265 jb 761115D1 :7611156C 6E outsb :7611156D 7456 je 761115C5 :7611156F 65 BYTE 065h :76111570 7273 jb 761115E5 :76111572 696F6E5C537461 imul ebp, dword ptr [edi+6E], 6174535C :76111579 7465 je 761115E0 :7611157B 4D dec ebp :7611157C 67725C jb 761115DB :7611157F 43 inc ebx :76111580 66675C pop sp :76111583 43 inc ebx :76111584 61 popad :76111585 626269 bound esp, dword ptr [edx+69] :76111588 6E outsb :76111589 670000 add [bx+si], al * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111516(C) | :7611158C 53 push ebx :7611158D 4F dec edi :7611158E 46 inc esi :7611158F 54 push esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611152D(C) | :76111590 57 push edi :76111591 41 inc ecx :76111592 52 push edx :76111593 45 inc ebp :76111594 5C pop esp :76111595 4D dec ebp :76111596 6963726F736F66 imul esp, dword ptr [ebx+72], 666F736F :7611159D 745C je 761115FB :7611159F 57 push edi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611152A(C) | :761115A0 696E646F77735C imul ebp, dword ptr [esi+64], 5C73776F :761115A7 43 inc ebx :761115A8 7572 jne 7611161C :761115AA 7265 jb 76111611 :761115AC 6E outsb :761115AD 7456 je 76111605 :761115AF 65 BYTE 065h :761115B0 7273 jb 76111625 :761115B2 696F6E5C537461 imul ebp, dword ptr [edi+6E], 6174535C :761115B9 7465 je 76111620 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611155D(C) | :761115BB 4D dec ebp :761115BC 67725C jb 7611161B :761115BF 43 inc ebx :761115C0 66675C pop sp :761115C3 52 push edx :761115C4 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611156D(C) | :761115C5 7365 jnb 7611162C :761115C7 7276 jb 7611163F :761115C9 65 BYTE 065h :761115CA 64 BYTE 064h :761115CB 44 inc esp :761115CC 69736B53706163 imul esi, dword ptr [ebx+6B], 63617053 :761115D3 65 BYTE 065h :761115D4 00000000 BYTE 4 DUP(0) :761115D8 53 push ebx :761115D9 4F dec edi :761115DA 46 inc esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611157D(C) | :761115DB 54 push esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111568(C) | :761115DC 57 push edi :761115DD 41 inc ecx :761115DE 52 push edx :761115DF 45 inc ebp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111579(C) | :761115E0 5C pop esp :761115E1 4D dec ebp :761115E2 6963726F736F66 imul esp, dword ptr [ebx+72], 666F736F :761115E9 745C je 76111647 :761115EB 57 push edi :761115EC 696E646F77735C imul ebp, dword ptr [esi+64], 5C73776F :761115F3 43 inc ebx :761115F4 7572 jne 76111668 :761115F6 7265 jb 7611165D :761115F8 6E outsb :761115F9 7456 je 76111651 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611159D(C) | :761115FB 65 BYTE 065h :761115FC 7273 jb 76111671 :761115FE 696F6E5C537461 imul ebp, dword ptr [edi+6E], 6174535C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761115AD(C) | :76111605 7465 je 7611166C :76111607 4D dec ebp :76111608 67725C jb 76111667 :7611160B 43 inc ebx :7611160C 66675C pop sp :7611160F 52 push edx :76111610 656753 push ebx :76111613 6E outsb :76111614 61 popad :76111615 7053 jo 7611166A :76111617 686F74496E push 6E49746F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761115A8(C) | :7611161C 7465 je 76111683 :7611161E 7276 jb 76111696 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761115B9(C) | :76111620 61 popad :76111621 6C insb :76111622 0000 add byte ptr [eax], al :76111624 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761115B0(C) | :76111625 4F dec edi :76111626 46 inc esi :76111627 54 push esp :76111628 57 push edi :76111629 41 inc ecx :7611162A 52 push edx :7611162B 45 inc ebp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761115C5(C) | :7611162C 5C pop esp :7611162D 4D dec ebp :7611162E 6963726F736F66 imul esp, dword ptr [ebx+72], 666F736F :76111635 745C je 76111693 :76111637 57 push edi :76111638 696E646F77735C imul ebp, dword ptr [esi+64], 5C73776F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761115C7(C) | :7611163F 43 inc ebx :76111640 7572 jne 761116B4 :76111642 7265 jb 761116A9 :76111644 6E outsb :76111645 7456 je 7611169D * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761115E9(C) | :76111647 65 BYTE 065h :76111648 7273 jb 761116BD :7611164A 696F6E5C537461 imul ebp, dword ptr [edi+6E], 6174535C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761115F9(C) | :76111651 7465 je 761116B8 :76111653 4D dec ebp :76111654 67725C jb 761116B3 :76111657 43 inc ebx :76111658 61 popad :76111659 626269 bound esp, dword ptr [edx+69] :7611165C 6E outsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761115F6(C) | :7611165D 670000 add [bx+si], al :76111660 53 push ebx :76111661 4F dec edi :76111662 46 inc esi :76111663 54 push esp :76111664 57 push edi :76111665 41 inc ecx :76111666 52 push edx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111609(C) | :76111667 45 inc ebp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761115F4(C) | :76111668 5C pop esp :76111669 4D dec ebp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111615(C) | :7611166A 6963726F736F66 imul esp, dword ptr [ebx+72], 666F736F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761115FC(C) | :76111671 745C je 761116CF :76111673 57 push edi :76111674 696E646F77735C imul ebp, dword ptr [esi+64], 5C73776F :7611167B 43 inc ebx :7611167C 7572 jne 761116F0 :7611167E 7265 jb 761116E5 :76111680 6E outsb :76111681 7456 je 761116D9 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611161C(C) | :76111683 65 BYTE 065h :76111684 7273 jb 761116F9 :76111686 696F6E5C537461 imul ebp, dword ptr [edi+6E], 6174535C :7611168D 7465 je 761116F4 :7611168F 4D dec ebp :76111690 67725C jb 761116EF * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111635(C) | :76111693 52 push edx :76111694 65 BYTE 065h :76111695 7365 jnb 761116FC :76111697 7276 jb 7611170F :76111699 65 BYTE 065h :7611169A 64 BYTE 064h :7611169B 44 inc esp :7611169C 69736B53706163 imul esi, dword ptr [ebx+6B], 63617053 :761116A3 65 BYTE 065h :761116A4 00000000 BYTE 4 DUP(0) :761116A8 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111642(C) | :761116A9 4F dec edi :761116AA 46 inc esi :761116AB 54 push esp :761116AC 57 push edi :761116AD 41 inc ecx :761116AE 52 push edx :761116AF 45 inc ebp :761116B0 5C pop esp :761116B1 4D dec ebp :761116B2 6963726F736F66 imul esp, dword ptr [ebx+72], 666F736F :761116B9 745C je 76111717 :761116BB 57 push edi :761116BC 696E646F77735C imul ebp, dword ptr [esi+64], 5C73776F :761116C3 43 inc ebx :761116C4 7572 jne 76111738 :761116C6 7265 jb 7611172D :761116C8 6E outsb :761116C9 7456 je 76111721 :761116CB 65 BYTE 065h :761116CC 7273 jb 76111741 :761116CE 696F6E5C537461 imul ebp, dword ptr [edi+6E], 6174535C :761116D5 7465 je 7611173C :761116D7 4D dec ebp :761116D8 67725C jb 76111737 :761116DB 52 push edx :761116DC 656753 push ebx :761116DF 6E outsb :761116E0 61 popad :761116E1 7053 jo 76111736 :761116E3 686F74496E push 6E49746F :761116E8 7465 je 7611174F :761116EA 7276 jb 76111762 :761116EC 61 popad :761116ED 6C insb :761116EE 0000 add byte ptr [eax], al * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611167C(C) | :761116F0 43 inc ebx :761116F1 6F outsd :761116F2 6D insd :761116F3 7072 jo 76111767 :761116F5 65 BYTE 065h :761116F6 7373 jnb 7611176B :761116F8 696F6E00546F74 imul ebp, dword ptr [edi+6E], 746F5400 :761116FF 61 popad :76111700 6C insb :76111701 46 inc esi :76111702 696C6553697A6550 imul ebp, dword ptr [ebp+53], 50657A69 :7611170A 65 BYTE 065h :7611170B 7243 jb 76111750 :7611170D 61 popad :7611170E 6200 bound eax, dword ptr [eax] :76111710 43 inc ebx :76111711 6865636B49 push 496B6365 :76111716 6E outsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761116B9(C) | :76111717 7465 je 7611177E :76111719 7276 jb 76111791 :7611171B 61 popad :7611171C 6C insb :7611171D 000000 BYTE 3 DUP(0) :76111720 49 dec ecx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761116C9(C) | :76111721 6E outsb :76111722 697469616C576169 imul esi, dword ptr [ecx+2*ebp+61], 6961576C :7611172A 7400 je 7611172C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611172A(C) | :7611172C 43 inc ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761116C6(C) | :7611172D 61 popad :7611172E 626269 bound esp, dword ptr [edx+69] :76111731 6E outsb :76111732 67005374 add [bp+di+74], dl * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761116E1(C) | :76111736 61 popad * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761116D9(C) | :76111737 7475 je 761117AE :76111739 7300 jnb 7611173B * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111739(C) | :7611173B 004D61 add byte ptr [ebp+61], cl :7611173E 7800 js 76111740 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611173E(C) | :76111740 44 inc esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761116CC(C) | :76111741 69736B55736167 imul esi, dword ptr [ebx+6B], 67617355 :76111748 65 BYTE 065h :76111749 000000 BYTE 3 DUP(0) :7611174C 41 inc ecx :7611174D 62736F bound esi, dword ptr [ebx+6F] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611170B(C) | :76111750 6C insb :76111751 7574 jne 761117C7 :76111753 65 BYTE 065h :76111754 56 push esi :76111755 61 popad :76111756 6C insb :76111757 7565 jne 761117BE :76111759 000000 BYTE 3 DUP(0) :7611175C 50 push eax :7611175D 65 BYTE 065h :7611175E 7263 jb 761117C3 :76111760 65 BYTE 065h :76111761 6E outsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761116EA(C) | :76111762 7400 je 76111764 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111762(C) | :76111764 4D dec ebp :76111765 696E0052657365 imul ebp, dword ptr [esi+00], 65736552 :7611176C 7276 jb 761117E4 :7611176E 65 BYTE 065h :7611176F 64 BYTE 064h :76111770 44 inc esp :76111771 69736B53706163 imul esi, dword ptr [ebx+6B], 63617053 :76111778 65 BYTE 065h :76111779 000000 BYTE 3 DUP(0) :7611177C 4E dec esi :7611177D 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111717(C) | :7611177E 7874 js 761117F4 :76111780 00000000 BYTE 4 DUP(0) :76111784 46 inc esi :76111785 69727374000000 imul esi, dword ptr [edx+73], 00000074 :7611178C 52 push edx :7611178D 656753 push ebx :76111790 6E outsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111719(C) | :76111791 61 popad :76111792 7053 jo 761117E7 :76111794 686F74496E push 6E49746F :76111799 7465 je 76111800 :7611179B 7276 jb 76111813 :7611179D 61 popad :7611179E 6C insb :7611179F 00534F add byte ptr [ebx+4F], dl :761117A2 46 inc esi :761117A3 54 push esp :761117A4 57 push edi :761117A5 41 inc ecx :761117A6 52 push edx :761117A7 45 inc ebp :761117A8 5C pop esp :761117A9 4D dec ebp :761117AA 6963726F736F66 imul esp, dword ptr [ebx+72], 666F736F :761117B1 745C je 7611180F :761117B3 57 push edi :761117B4 696E646F77735C imul ebp, dword ptr [esi+64], 5C73776F :761117BB 43 inc ebx :761117BC 7572 jne 76111830 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111757(C) | :761117BE 7265 jb 76111825 :761117C0 6E outsb :761117C1 7456 je 76111819 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611175E(C) | :761117C3 65 BYTE 065h :761117C4 7273 jb 76111839 :761117C6 696F6E5C537461 imul ebp, dword ptr [edi+6E], 6174535C :761117CD 7465 je 76111834 :761117CF 4D dec ebp :761117D0 677200 jb 761117D3 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761117D1(C) | :761117D3 00433A add byte ptr [ebx+3A], al :761117D6 5C pop esp :761117D7 5F pop edi :761117D8 52 push edx :761117D9 45 inc ebp :761117DA 53 push ebx :761117DB 54 push esp :761117DC 4F dec edi :761117DD 52 push edx :761117DE 45 inc ebp :761117DF 5C pop esp :761117E0 4C dec esp :761117E1 4F dec edi :761117E2 47 inc edi :761117E3 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611176C(C) | :761117E4 00000000 BYTE 4 DUP(0) :761117E8 43 inc ebx :761117E9 3A5C5F52 cmp bl, byte ptr [edi+2*ebx+52] :761117ED 45 inc ebp :761117EE 53 push ebx :761117EF 54 push esp :761117F0 4F dec edi :761117F1 52 push edx :761117F2 45 inc ebp :761117F3 5C pop esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611177E(C) | :761117F4 54 push esp :761117F5 45 inc ebp :761117F6 4D dec ebp :761117F7 50 push eax :761117F8 00000000 BYTE 4 DUP(0) :761117FC 43 inc ebx :761117FD 3A5C0043 cmp bl, byte ptr [eax+eax+43] :76111801 3A5C5F52 cmp bl, byte ptr [edi+2*ebx+52] :76111805 45 inc ebp :76111806 53 push ebx :76111807 54 push esp :76111808 4F dec edi :76111809 52 push edx :7611180A 45 inc ebp :7611180B 00433A add byte ptr [ebx+3A], al :7611180E 5C pop esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761117B1(C) | :7611180F 57 push edi :76111810 49 dec ecx :76111811 4E dec esi :76111812 44 inc esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611179B(C) | :76111813 4F dec edi :76111814 57 push edi :76111815 53 push ebx :76111816 0000 add byte ptr [eax], al :76111818 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761117C1(C) | :76111819 4F dec edi :7611181A 46 inc esi :7611181B 54 push esp :7611181C 57 push edi :7611181D 41 inc ecx :7611181E 52 push edx :7611181F 45 inc ebp :76111820 5C pop esp :76111821 4D dec ebp :76111822 6963726F736F66 imul esp, dword ptr [ebx+72], 666F736F :76111829 745C je 76111887 :7611182B 57 push edi :7611182C 696E646F77735C imul ebp, dword ptr [esi+64], 5C73776F :76111833 43 inc ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761117CD(C) | :76111834 7572 jne 761118A8 :76111836 7265 jb 7611189D :76111838 6E outsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761117C4(C) | :76111839 7456 je 76111891 :7611183B 65 BYTE 065h :7611183C 7273 jb 761118B1 :7611183E 696F6E5C457870 imul ebp, dword ptr [edi+6E], 7078455C :76111845 6C insb :76111846 6F outsd :76111847 7265 jb 761118AE :76111849 725C jb 761118A7 :7611184B 53 push ebx :7611184C 68656C6C45 push 456C6C65 :76111851 7865 js 761118B8 :76111853 637574 arpl dword ptr [ebp+74], esi :76111856 65 BYTE 065h :76111857 48 dec eax :76111858 6F outsd :76111859 6F outsd :7611185A 6B730000 imul esi, dword ptr [ebx+00], 00000000 :7611185E 0000 add byte ptr [eax], al :76111860 56 push esi :76111861 7844 js 761118A7 :76111863 4D dec ebp :76111864 6F outsd :76111865 6E outsb :76111866 2E636667 arpl dword ptr cs:[esi+67], esp :7611186A 0000 add byte ptr [eax], al :7611186C 56 push esi :7611186D 7864 js 761118D3 :7611186F 43 inc ebx :76111870 66670000 add [bx+si], al :76111874 4D dec ebp :76111875 6963726F736F66 imul esp, dword ptr [ebx+72], 666F736F :7611187C 7420 je 7611189E :7611187E 50 push eax :7611187F 43 inc ebx :76111880 205374 and byte ptr [ebx+74], dl :76111883 61 popad :76111884 7465 je 761118EB :76111886 204D61 and byte ptr [ebp+61], cl :76111889 6E outsb :7611188A 61 popad :7611188B 67 BYTE 067h :7611188C 65 BYTE 065h :7611188D 7200 jb 7611188F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611188D(C) | :7611188F 005354 add byte ptr [ebx+54], dl :76111892 41 inc ecx :76111893 54 push esp :76111894 45 inc ebp :76111895 4D dec ebp :76111896 47 inc edi :76111897 52 push edx :76111898 50 push eax :76111899 52 push edx :7611189A 4F dec edi :7611189B 43 inc ebx :7611189C 00000000 BYTE 4 DUP(0) :761118A0 5C pop esp :761118A1 53 push ebx :761118A2 7973 jns 76111917 :761118A4 7465 je 7611190B :761118A6 6D insd * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76111849(C), :76111861(C) | :761118A7 5C pop esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111834(C) | :761118A8 52 push edx :761118A9 65 BYTE 065h :761118AA 7374 jnb 76111920 :761118AC 6F outsd :761118AD 7265 jb 76111914 :761118AF 5C pop esp :761118B0 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611183C(C) | :761118B1 7461 je 76111914 :761118B3 7465 je 7611191A :761118B5 4D dec ebp :761118B6 67722E jb 761118E7 :761118B9 65 BYTE 065h :761118BA 7865 js 76111921 :761118BC 00000000 BYTE 4 DUP(0) :761118C0 4F dec edi :761118C1 4F dec edi :761118C2 42 inc edx :761118C3 45 inc ebp :761118C4 49 dec ecx :761118C5 6E outsb :761118C6 50 push eax :761118C7 726F jb 76111938 :761118C9 677265 jb 76111931 :761118CC 7373 jnb 76111941 :761118CE 0000 add byte ptr [eax], al :761118D0 44 inc esp :761118D1 65 BYTE 065h :761118D2 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611186D(C) | :761118D3 61 popad :761118D4 7946 jns 7611191C :761118D6 69727374527374 imul esi, dword ptr [edx+73], 74735274 :761118DD 7074 jo 76111953 :761118DF 004669 add byte ptr [esi+69], al :761118E2 7273 jb 76111957 :761118E4 7452 je 76111938 :761118E6 756E jne 76111956 :761118E8 00000000 BYTE 4 DUP(0) :761118EC 2A5374 sub dl, byte ptr [ebx+74] :761118EF 61 popad :761118F0 7465 je 76111957 :761118F2 4D dec ebp :761118F3 677200 jb 761118F6 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761118F4(C) | :761118F6 0000 add byte ptr [eax], al :761118F8 53 push ebx :761118F9 4F dec edi :761118FA 46 inc esi :761118FB 54 push esp :761118FC 57 push edi :761118FD 41 inc ecx :761118FE 52 push edx :761118FF 45 inc ebp :76111900 5C pop esp :76111901 4D dec ebp :76111902 6963726F736F66 imul esp, dword ptr [ebx+72], 666F736F :76111909 745C je 76111967 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761118A4(C) | :7611190B 57 push edi :7611190C 696E646F77735C imul ebp, dword ptr [esi+64], 5C73776F :76111913 43 inc ebx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761118AD(C), :761118B1(C) | :76111914 7572 jne 76111988 :76111916 7265 jb 7611197D :76111918 6E outsb :76111919 7456 je 76111971 :7611191B 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761118D4(C) | :7611191C 7273 jb 76111991 :7611191E 696F6E5C52756E imul ebp, dword ptr [edi+6E], 6E75525C :76111925 53 push ebx :76111926 65 BYTE 065h :76111927 7276 jb 7611199F :76111929 69636573000000 imul esp, dword ptr [ebx+65], 00000073 :76111930 56 push esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761118CA(C) | :76111931 7844 js 76111977 :76111933 4D dec ebp :76111934 6F outsd :76111935 6E outsb :76111936 2E BYTE 02eh :76111937 64 BYTE 064h * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761118C7(C), :761118E4(C) | :76111938 61 popad :76111939 7400 je 7611193B * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111939(C) | :7611193B 005678 add byte ptr [esi+78], dl :7611193E 64 BYTE 064h :7611193F 44 inc esp :76111940 61 popad * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761118CC(C) | :76111941 7400 je 76111943 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111941(C) | :76111943 002A add byte ptr [edx], ch :76111945 56 push esi :76111946 7844 js 7611198C :76111948 4D dec ebp :76111949 6F outsd :7611194A 6E outsb :7611194B 005C5379 add byte ptr [ebx+2*edx+79], bl :7611194F 7374 jnb 761119C5 :76111951 65 BYTE 065h :76111952 6D insd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761118DD(C) | :76111953 5C pop esp :76111954 56 push esi :76111955 7844 js 7611199B * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761118E2(C), :761118F0(C) | :76111957 4D dec ebp :76111958 6F outsd :76111959 6E outsb :7611195A 2E BYTE 02eh :7611195B 7678 jbe 761119D5 :7611195D 64 BYTE 064h :7611195E 0000 add byte ptr [eax], al :76111960 54 push esp :76111961 65 BYTE 065h :76111962 6D insd :76111963 7044 jo 761119A9 :76111965 6972004C6F6744 imul esi, dword ptr [edx+00], 44676F4C :7611196C 69720000537461 imul esi, dword ptr [edx+00], 61745300 :76111973 7469 je 761119DE :76111975 635678 arpl dword ptr [esi+78], edx :76111978 44 inc esp :76111979 000000 BYTE 3 DUP(0) :7611197C 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111916(C) | :7611197D 7973 jns 761119F2 :7611197F 7465 je 761119E6 :76111981 6D insd :76111982 5C pop esp :76111983 43 inc ebx :76111984 7572 jne 761119F8 :76111986 7265 jb 761119ED * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111914(C) | :76111988 6E outsb :76111989 7443 je 761119CE :7611198B 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111946(C) | :7611198C 6E outsb :7611198D 7472 je 76111A01 :7611198F 6F outsd :76111990 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611191C(C) | :76111991 53 push ebx :76111992 65 BYTE 065h :76111993 745C je 761119F1 :76111995 53 push ebx :76111996 65 BYTE 065h :76111997 7276 jb 76111A0F :76111999 696365735C5678 imul esp, dword ptr [ebx+65], 78565C73 :761119A0 44 inc esp :761119A1 5C pop esp :761119A2 56 push esi :761119A3 7844 js 761119E9 :761119A5 4D dec ebp :761119A6 6F outsd :761119A7 6E outsb :761119A8 00000000 BYTE 4 DUP(0) :761119AC 53 push ebx :761119AD 46 inc esi :761119AE 50 push eax :761119AF 005C5379 add byte ptr [ebx+2*edx+79], bl :761119B3 7374 jnb 76111A29 :761119B5 65 BYTE 065h :761119B6 6D insd :761119B7 5C pop esp :761119B8 52 push edx :761119B9 65 BYTE 065h :761119BA 7374 jnb 76111A30 :761119BC 6F outsd :761119BD 7265 jb 76111A24 :761119BF 5C pop esp :761119C0 44 inc esp :761119C1 61 popad :761119C2 7461 je 76111A25 :761119C4 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611194F(C) | :761119C5 746F je 76111A36 :761119C7 722E jb 761119F7 :761119C9 696E6900000000 imul ebp, dword ptr [esi+69], 00000000 :761119D0 44 inc esp :761119D1 53 push ebx :761119D2 52 push edx :761119D3 4F dec edi :761119D4 4F dec edi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611195B(C) | :761119D5 54 push esp :761119D6 0000 add byte ptr [eax], al :761119D8 44 inc esp :761119D9 53 push ebx :761119DA 49 dec ecx :761119DB 4E dec esi :761119DC 46 inc esi :761119DD 4F dec edi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111973(C) | :761119DE 2E BYTE 02eh :761119DF 44 inc esp :761119E0 41 inc ecx :761119E1 54 push esp :761119E2 0000 add byte ptr [eax], al :761119E4 45 inc ebp :761119E5 58 pop eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611197F(C) | :761119E6 54 push esp :761119E7 52 push edx :761119E8 41 inc ecx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761119A3(C) | :761119E9 43 inc ebx :761119EA 54 push esp :761119EB 004C4F47 add byte ptr [edi+2*ecx+47], cl :761119EF 53 push ebx :761119F0 00000000 BYTE 4 DUP(0) :761119F4 41 inc ecx :761119F5 52 push edx :761119F6 43 inc ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761119C7(C) | :761119F7 48 dec eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111984(C) | :761119F8 49 dec ecx :761119F9 56 push esi :761119FA 45 inc ebp :761119FB 0054454D add byte ptr [ebp+2*eax+4D], dl :761119FF 50 push eax :76111A00 00000000 BYTE 4 DUP(0) :76111A04 5F pop edi :76111A05 52 push edx :76111A06 45 inc ebp :76111A07 53 push ebx :76111A08 54 push esp :76111A09 4F dec edi :76111A0A 52 push edx :76111A0B 45 inc ebp :76111A0C 00000000 BYTE 4 DUP(0) :76111A10 7273 jb 76111A85 :76111A12 7472 je 76111A86 :76111A14 7332 jnb 76111A48 :76111A16 6C insb :76111A17 2E BYTE 02eh :76111A18 64 BYTE 064h :76111A19 61 popad :76111A1A 7400 je 76111A1C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111A1A(C) | :76111A1C 3238 xor bh, byte ptr [eax] :76111A1E 3033 xor byte ptr [ebx], dh :76111A20 00000000 BYTE 4 DUP(0) * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761119BD(C) | :76111A24 323536370000 xor dh, byte ptr [00003736] :76111A2A 0000 add byte ptr [eax], al :76111A2C 4E dec esi :76111A2D 000000 BYTE 3 DUP(0) * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761119BA(C) | :76111A30 59 pop ecx :76111A31 000000 BYTE 3 DUP(0) :76111A34 53 push ebx :76111A35 7973 jns 76111AAA :76111A37 7465 je 76111A9E :76111A39 6D insd :76111A3A 52 push edx :76111A3B 65 BYTE 065h :76111A3C 7374 jnb 76111AB2 :76111A3E 6F outsd :76111A3F 7265 jb 76111AA6 :76111A41 000000 BYTE 3 DUP(0) :76111A44 56 push esi :76111A45 7864 js 76111AAB :76111A47 43 inc ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111A14(C) | :76111A48 64 BYTE 064h :76111A49 50 push eax :76111A4A 61 popad :76111A4B 67 BYTE 067h :76111A4C 65 BYTE 065h :76111A4D 000000 BYTE 3 DUP(0) :76111A50 4D dec ebp :76111A51 6963726F736F66 imul esp, dword ptr [ebx+72], 666F736F :76111A58 7420 je 76111A7A :76111A5A 53 push ebx :76111A5B 7973 jns 76111AD0 :76111A5D 7465 je 76111AC4 :76111A5F 6D insd :76111A60 205265 and byte ptr [edx+65], dl :76111A63 7374 jnb 76111AD9 :76111A65 6F outsd :76111A66 7265 jb 76111ACD :76111A68 205368 and byte ptr [ebx+68], dl :76111A6B 65 BYTE 065h :76111A6C 6C insb :76111A6D 6C insb :76111A6E 204578 and byte ptr [ebp+78], al :76111A71 65637574 arpl dword ptr gs:[ebp+74], esi :76111A75 6520486F and byte ptr gs:[eax+6F], cl :76111A79 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111A58(C) | :76111A7A 6B007B imul eax, dword ptr [eax], 0000007B :76111A7D 636164 arpl dword ptr [ecx+64], esp :76111A80 663431 xor al, 31 :76111A83 6236 bound esi, dword ptr [esi] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111A10(C) | :76111A85 2D66313364 sub eax, 64333166 :76111A8A 2D31316432 sub eax, 32643131 :76111A8F 2D38336166 sub eax, 66613338 :76111A94 2D30303630 sub eax, 30363030 :76111A99 6230 bound esi, dword ptr [eax] :76111A9B 3537636139 xor eax, 39616337 :76111AA0 627D00 bound edi, dword ptr [ebp+00] :76111AA3 005678 add byte ptr [esi+78], dl * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111A3F(C) | :76111AA6 64 BYTE 064h :76111AA7 44 inc esp :76111AA8 6F outsd :76111AA9 4E dec esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111A35(C) | :76111AAA 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111A45(C) | :76111AAB 744F je 76111AFC :76111AAD 7074 jo 76111B23 :76111AAF 696D697A654465 imul ebp, dword ptr [ebp+69], 6544657A :76111AB6 6C insb :76111AB7 65 BYTE 065h :76111AB8 7465 je 76111B1F :76111ABA 0000 add byte ptr [eax], al :76111ABC 737A jnb 76111B38 :76111ABE 49 dec ecx :76111ABF 676E outsb :76111AC1 6F outsd :76111AC2 7265 jb 76111B29 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111A5D(C) | :76111AC4 50 push eax :76111AC5 61 popad :76111AC6 7468 je 76111B30 :76111AC8 7300 jnb 76111ACA * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111AC8(C) | :76111ACA 0000 add byte ptr [eax], al :76111ACC 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111A66(C) | :76111ACD 6F outsd :76111ACE 667477 je 76111B48 :76111AD1 61 popad :76111AD2 7265 jb 76111B39 :76111AD4 5C pop esp :76111AD5 4D dec ebp :76111AD6 697373696E6720 imul esi, dword ptr [ebx+73], 20676E69 :76111ADD 53 push ebx :76111ADE 6F outsd :76111ADF 636B5C arpl dword ptr [ebx+5C], ebp :76111AE2 55 push ebp :76111AE3 6E outsb :76111AE4 64 BYTE 064h :76111AE5 6F outsd :76111AE6 0000 add byte ptr [eax], al :76111AE8 55 push ebp :76111AE9 6E outsb :76111AEA 6B6E6F77 imul ebp, dword ptr [esi+6F], 00000077 :76111AEE 6E outsb :76111AEF 206572 and byte ptr [ebp+72], ah :76111AF2 726F jb 76111B63 :76111AF4 7200 jb 76111AF6 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111AF4(C) | :76111AF6 0000 add byte ptr [eax], al :76111AF8 46 inc esi :76111AF9 61 popad :76111AFA 696C75726520636F imul ebp, dword ptr [ebp+2*esi+72], 6F632065 :76111B02 6D insd :76111B03 7072 jo 76111B77 :76111B05 65 BYTE 065h :76111B06 7373 jnb 76111B7B :76111B08 696E6720646174 imul ebp, dword ptr [esi+67], 74616420 :76111B0F 61 popad :76111B10 00000000 BYTE 4 DUP(0) :76111B14 43 inc ebx :76111B15 6C insb :76111B16 69656E74207265 imul esp, dword ptr [ebp+6E], 65722074 :76111B1D 7175 jno 76111B94 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111AB8(C) | :76111B1F 65 BYTE 065h :76111B20 7374 jnb 76111B96 :76111B22 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111AAD(C) | :76111B23 64206162 and byte ptr fs:[ecx+62], ah :76111B27 6F outsd :76111B28 7274 jb 76111B9E :76111B2A 0000 add byte ptr [eax], al :76111B2C 43 inc ebx :76111B2D 6F outsd :76111B2E 756C jne 76111B9C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111AC6(C) | :76111B30 64206E6F and byte ptr fs:[esi+6F], ch :76111B34 7420 je 76111B56 :76111B36 637265 arpl dword ptr [edx+65], esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111AD2(C) | :76111B39 61 popad :76111B3A 7465 je 76111BA1 :76111B3C 206361 and byte ptr [ebx+61], ah :76111B3F 62696E bound ebp, dword ptr [ecx+6E] :76111B42 65 BYTE 065h :76111B43 7420 je 76111B65 :76111B45 66696C65000000 imul bp, word ptr [ebp], 0000 :76111B4C 55 push ebp :76111B4D 6E outsb :76111B4E 6B6E6F77 imul ebp, dword ptr [esi+6F], 00000077 :76111B52 6E outsb :76111B53 20636F and byte ptr [ebx+6F], ah * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111B34(C) | :76111B56 6D insd :76111B57 7072 jo 76111BCB :76111B59 65 BYTE 065h :76111B5A 7373 jnb 76111BCF :76111B5C 696F6E20747970 imul ebp, dword ptr [edi+6E], 70797420 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111AF2(C) | :76111B63 65 BYTE 065h :76111B64 00000000 BYTE 4 DUP(0) :76111B68 43 inc ebx :76111B69 6F outsd :76111B6A 756C jne 76111BD8 :76111B6C 64206E6F and byte ptr fs:[esi+6F], ch :76111B70 7420 je 76111B92 :76111B72 637265 arpl dword ptr [edx+65], esi :76111B75 61 popad :76111B76 7465 je 76111BDD :76111B78 206120 and byte ptr [ecx+20], ah * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111B06(C) | :76111B7B 7465 je 76111BE2 :76111B7D 6D insd :76111B7E 706F jo 76111BEF :76111B80 7261 jb 76111BE3 :76111B82 7279 jb 76111BFD :76111B84 206669 and byte ptr [esi+69], ah :76111B87 6C insb :76111B88 65 BYTE 065h :76111B89 000000 BYTE 3 DUP(0) :76111B8C 49 dec ecx :76111B8D 6E outsb :76111B8E 7375 jnb 76111C05 :76111B90 66 BYTE 066h :76111B91 66696369656E imul sp, word ptr [ebx+69], 6E65 :76111B97 7420 je 76111BB9 :76111B99 6D insd :76111B9A 65 BYTE 065h :76111B9B 6D insd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111B2E(C) | :76111B9C 6F outsd :76111B9D 7279 jb 76111C18 :76111B9F 20696E and byte ptr [ecx+6E], ch :76111BA2 204643 and byte ptr [esi+43], al :76111BA5 49 dec ecx :76111BA6 0000 add byte ptr [eax], al :76111BA8 46 inc esi :76111BA9 61 popad :76111BAA 696C757265207265 imul ebp, dword ptr [ebp+2*esi+72], 65722065 :76111BB2 61 popad :76111BB3 64696E672066696C imul ebp, dword ptr fs:[esi+67], 6C696620 :76111BBB 6520746F20 and byte ptr gs:[edi+2*ebp+20], dh :76111BC0 626520 bound esp, dword ptr [ebp+20] :76111BC3 7374 jnb 76111C39 :76111BC5 6F outsd :76111BC6 7265 jb 76111C2D :76111BC8 6420696E and byte ptr fs:[ecx+6E], ch :76111BCC 206361 and byte ptr [ebx+61], ah * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111B5A(C) | :76111BCF 62696E bound ebp, dword ptr [ecx+6E] :76111BD2 65 BYTE 065h :76111BD3 7400 je 76111BD5 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111BD3(C) | :76111BD5 000000 BYTE 3 DUP(0) * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111B6A(C) | :76111BD8 46 inc esi :76111BD9 61 popad :76111BDA 696C757265206F70 imul ebp, dword ptr [ebp+2*esi+72], 706F2065 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111B7B(C) | :76111BE2 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111B80(C) | :76111BE3 6E outsb :76111BE4 696E672066696C imul ebp, dword ptr [esi+67], 6C696620 :76111BEB 6520746F20 and byte ptr gs:[edi+2*ebp+20], dh :76111BF0 626520 bound esp, dword ptr [ebp+20] :76111BF3 7374 jnb 76111C69 :76111BF5 6F outsd :76111BF6 7265 jb 76111C5D :76111BF8 6420696E and byte ptr fs:[ecx+6E], ch :76111BFC 206361 and byte ptr [ebx+61], ah :76111BFF 62696E bound ebp, dword ptr [ecx+6E] :76111C02 65 BYTE 065h :76111C03 7400 je 76111C05 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76111B8E(C), :76111C03(C) | :76111C05 000000 BYTE 3 DUP(0) :76111C08 4E dec esi :76111C09 6F outsd :76111C0A 206572 and byte ptr [ebp+72], ah :76111C0D 726F jb 76111C7E :76111C0F 7200 jb 76111C11 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111C0F(C) | :76111C11 000000 BYTE 3 DUP(0) :76111C14 52 push edx :76111C15 656769737465725365 imul esi, gs:[bp+di+74], 65537265 :76111C1E 7276 jb 76111C96 :76111C20 69636550726F63 imul esp, dword ptr [ebx+65], 636F7250 :76111C27 65 BYTE 065h :76111C28 7373 jnb 76111C9D :76111C2A 0000 add byte ptr [eax], al :76111C2C 4B dec ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111BC6(C) | :76111C2D 45 inc ebp :76111C2E 52 push edx :76111C2F 4E dec esi :76111C30 45 inc ebp :76111C31 4C dec esp :76111C32 3332 xor esi, dword ptr [edx] :76111C34 2E BYTE 02eh :76111C35 44 inc esp :76111C36 4C dec esp :76111C37 4C dec esp :76111C38 00000000 BYTE 4 DUP(0) :76111C3C 5C pop esp :76111C3D 41 inc ecx :76111C3E 52 push edx :76111C3F 43 inc ebx :76111C40 48 dec eax :76111C41 49 dec ecx :76111C42 56 push esi :76111C43 45 inc ebp :76111C44 2E BYTE 02eh :76111C45 4C dec esp :76111C46 43 inc ebx :76111C47 4B dec ebx :76111C48 00000000 BYTE 4 DUP(0) :76111C4C 43 inc ebx :76111C4D 68674C6F67 push 676F4C67 :76111C52 48 dec eax :76111C53 64 BYTE 064h :76111C54 7200 jb 76111C56 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111C54(C) | :76111C56 0000 add byte ptr [eax], al :76111C58 5C pop esp :76111C59 4C dec esp :76111C5A 4F dec edi :76111C5B 47 inc edi :76111C5C 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111BF6(C) | :76111C5D 5C pop esp :76111C5E 53 push ebx :76111C5F 7461 je 76111CC2 :76111C61 7473 je 76111CD6 :76111C63 2E BYTE 02eh :76111C64 64 BYTE 064h :76111C65 61 popad :76111C66 7400 je 76111C68 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111C66(C) | :76111C68 5C pop esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111BF3(C) | :76111C69 7769 ja 76111CD4 :76111C6B 6E outsb :76111C6C 696E69742E696E imul ebp, dword ptr [esi+69], 6E692E74 :76111C73 69000000004E imul eax, dword ptr [eax], 4E000000 :76111C79 55 push ebp :76111C7A 4C dec esp :76111C7B 4C dec esp :76111C7C 00000000 BYTE 4 DUP(0) :76111C80 57 push edi :76111C81 696E696E697400 imul ebp, dword ptr [esi+69], 0074696E :76111C88 41 inc ecx :76111C89 000000 BYTE 3 DUP(0) :76111C8C 3A00 cmp al, byte ptr [eax] :76111C8E 0000 add byte ptr [eax], al :76111C90 2000 and byte ptr [eax], al :76111C92 0000 add byte ptr [eax], al :76111C94 5C pop esp :76111C95 7678 jbe 76111D0F :76111C97 64 BYTE 064h :76111C98 6C insb :76111C99 6F outsd :76111C9A 67 BYTE 067h :76111C9B 2E BYTE 02eh :76111C9C 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111C28(C) | :76111C9D 6F outsd :76111C9E 67007200 add [bp+si+00], dh :76111CA2 0000 add byte ptr [eax], al :76111CA4 52 push edx :76111CA5 45 inc ebp :76111CA6 4E dec esi :76111CA7 41 inc ecx :76111CA8 4D dec ebp :76111CA9 45 inc ebp :76111CAA 5F pop edi :76111CAB 46 inc esi :76111CAC 49 dec ecx :76111CAD 4C dec esp :76111CAE 45 inc ebp :76111CAF 0044454C add byte ptr [ebp+2*eax+4C], al :76111CB3 45 inc ebp :76111CB4 54 push esp :76111CB5 45 inc ebp :76111CB6 5F pop edi :76111CB7 44 inc esp :76111CB8 49 dec ecx :76111CB9 52 push edx :76111CBA 0000 add byte ptr [eax], al :76111CBC 44 inc esp :76111CBD 45 inc ebp :76111CBE 4C dec esp :76111CBF 45 inc ebp :76111CC0 54 push esp :76111CC1 45 inc ebp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111C5F(C) | :76111CC2 5F pop edi :76111CC3 46 inc esi :76111CC4 49 dec ecx :76111CC5 4C dec esp :76111CC6 45 inc ebp :76111CC7 005C7769 add byte ptr [edi+2*esi+69], bl :76111CCB 6E outsb :76111CCC 696E69746C6F67 imul ebp, dword ptr [esi+69], 676F6C74 :76111CD3 2E BYTE 02eh * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111C69(C) | :76111CD4 6F outsd :76111CD5 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111C61(C) | :76111CD6 64005C7769 add byte ptr fs:[edi+2*esi+69], bl :76111CDB 6E outsb :76111CDC 696E69742E6C6F imul ebp, dword ptr [esi+69], 6F6C2E74 :76111CE3 00 BYTE 000h :76111CE4 00000000 BYTE 4 DUP(0) :76111CE8 5C pop esp :76111CE9 2E BYTE 02eh :76111CEA 0000 add byte ptr [eax], al :76111CEC 5C pop esp :76111CED 6C insb :76111CEE 61 popad :76111CEF 7374 jnb 76111D65 :76111CF1 7366 jnb 76111D59 :76111CF3 702E jo 76111D23 :76111CF5 62616B bound esp, dword ptr [ecx+6B] :76111CF8 00000000 BYTE 4 DUP(0) :76111CFC 5C pop esp :76111CFD 6C insb :76111CFE 61 popad :76111CFF 7374 jnb 76111D75 :76111D01 7366 jnb 76111D69 :76111D03 702E jo 76111D33 :76111D05 64 BYTE 064h :76111D06 61 popad :76111D07 7400 je 76111D09 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111D07(C) | :76111D09 000000 BYTE 3 DUP(0) :76111D0C 5C pop esp :76111D0D 7678 jbe 76111D87 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111C95(C) | :76111D0F 64 BYTE 064h :76111D10 7366 jnb 76111D78 :76111D12 702E jo 76111D42 :76111D14 62616B bound esp, dword ptr [ecx+6B] :76111D17 005C7678 add byte ptr [esi+2*esi+78], bl :76111D1B 64 BYTE 064h :76111D1C 7366 jnb 76111D84 :76111D1E 702E jo 76111D4E :76111D20 6C insb :76111D21 6F outsd :76111D22 67005C76 add [si+76], bl :76111D26 7864 js 76111D8C :76111D28 6C insb :76111D29 6F outsd :76111D2A 67005C76 add [si+76], bl :76111D2E 7864 js 76111D94 :76111D30 6C insb :76111D31 61 popad :76111D32 7374 jnb 76111DA8 :76111D34 2E BYTE 02eh :76111D35 6C insb :76111D36 6F outsd :76111D37 00 BYTE 000h :76111D38 00000000 BYTE 4 DUP(0) :76111D3C 5C pop esp :76111D3D 53 push ebx :76111D3E 45 inc ebp :76111D3F 51 push ecx :76111D40 2E BYTE 02eh :76111D41 000000 BYTE 3 DUP(0) :76111D44 46 inc esi :76111D45 69727374205275 imul esi, dword ptr [edx+73], 75522074 :76111D4C 6E outsb :76111D4D 206F66 and byte ptr [edi+66], ch :76111D50 205379 and byte ptr [ebx+79], dl :76111D53 7374 jnb 76111DC9 :76111D55 65 BYTE 065h :76111D56 6D insd :76111D57 205265 and byte ptr [edx+65], dl :76111D5A 7374 jnb 76111DD0 :76111D5C 6F outsd :76111D5D 7265 jb 76111DC4 :76111D5F 005769 add byte ptr [edi+69], dl :76111D62 6E outsb :76111D63 64 BYTE 064h :76111D64 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111CEF(C) | :76111D65 7773 ja 76111DDA :76111D67 20426F and byte ptr [edx+6F], al :76111D6A 6F outsd :76111D6B 7400 je 76111D6D * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111D6B(C) | :76111D6D 000000 BYTE 3 DUP(0) :76111D70 57 push edi :76111D71 696E646F777320 imul ebp, dword ptr [esi+64], 2073776F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111D10(C) | :76111D78 53 push ebx :76111D79 687574646F push 6F647475 :76111D7E 776E ja 76111DEE :76111D80 00000000 BYTE 4 DUP(0) * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111D1C(C) | :76111D84 53 push ebx :76111D85 7973 jns 76111DFA * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111D0D(C) | :76111D87 7465 je 76111DEE :76111D89 6D insd :76111D8A 204368 and byte ptr [ebx+68], al :76111D8D 65636B20 arpl dword ptr gs:[ebx+20], ebp :76111D91 50 push eax :76111D92 6F outsd :76111D93 696E7400005C46 imul ebp, dword ptr [esi+74], 465C0000 :76111D9A 49 dec ecx :76111D9B 46 inc esi :76111D9C 4F dec edi :76111D9D 2E BYTE 02eh :76111D9E 4C dec esp :76111D9F 4F dec edi :76111DA0 47 inc edi :76111DA1 000000 BYTE 3 DUP(0) :76111DA4 5C pop esp :76111DA5 52 push edx :76111DA6 45 inc ebp :76111DA7 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111D32(C) | :76111DA8 54 push esp :76111DA9 4F dec edi :76111DAA 52 push edx :76111DAB 45 inc ebp :76111DAC 50 push eax :76111DAD 54 push esp :76111DAE 2E BYTE 02eh :76111DAF 4E dec esi :76111DB0 45 inc ebp :76111DB1 57 push edi :76111DB2 0000 add byte ptr [eax], al :76111DB4 5C pop esp :76111DB5 52 push edx :76111DB6 45 inc ebp :76111DB7 53 push ebx :76111DB8 54 push esp :76111DB9 4F dec edi :76111DBA 52 push edx :76111DBB 45 inc ebp :76111DBC 50 push eax :76111DBD 54 push esp :76111DBE 2E BYTE 02eh :76111DBF 4C dec esp :76111DC0 4F dec edi :76111DC1 47 inc edi :76111DC2 0000 add byte ptr [eax], al * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111D5D(C) | :76111DC4 5C pop esp :76111DC5 52 push edx :76111DC6 45 inc ebp :76111DC7 47 inc edi :76111DC8 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111D53(C) | :76111DC9 4E dec esi :76111DCA 41 inc ecx :76111DCB 50 push eax :76111DCC 53 push ebx :76111DCD 48 dec eax :76111DCE 4F dec edi :76111DCF 54 push esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111D5A(C) | :76111DD0 2E BYTE 02eh :76111DD1 4C dec esp :76111DD2 4F dec edi :76111DD3 47 inc edi :76111DD4 00000000 BYTE 4 DUP(0) :76111DD8 5C pop esp :76111DD9 50 push eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111D65(C) | :76111DDA 726F jb 76111E4B :76111DDC 66696C65730000 imul bp, word ptr [ebp+73], 0000 :76111DE3 005C434C add byte ptr [ebx+2*eax+4C], bl :76111DE7 41 inc ecx :76111DE8 53 push ebx :76111DE9 53 push ebx :76111DEA 45 inc ebp :76111DEB 53 push ebx :76111DEC 2E BYTE 02eh :76111DED 44 inc esp * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76111D7E(C), :76111D87(C) | :76111DEE 41 inc ecx :76111DEF 54 push esp :76111DF0 00000000 BYTE 4 DUP(0) :76111DF4 5C pop esp :76111DF5 53 push ebx :76111DF6 59 pop ecx :76111DF7 53 push ebx :76111DF8 54 push esp :76111DF9 45 inc ebp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111D85(C) | :76111DFA 4D dec ebp :76111DFB 2E BYTE 02eh :76111DFC 44 inc esp :76111DFD 41 inc ecx :76111DFE 54 push esp :76111DFF 005C5553 add byte ptr [ebp+2*edx+53], bl :76111E03 45 inc ebp :76111E04 52 push edx :76111E05 2E BYTE 02eh :76111E06 44 inc esp :76111E07 41 inc ecx :76111E08 54 push esp :76111E09 000000 BYTE 3 DUP(0) :76111E0C 2E BYTE 02eh :76111E0D 000000 BYTE 3 DUP(0) :76111E10 5C pop esp :76111E11 42 inc edx :76111E12 4B dec ebx :76111E13 55 push ebp :76111E14 50 push eax :76111E15 56 push esi :76111E16 58 pop eax :76111E17 44 inc esp :76111E18 4C dec esp :76111E19 41 inc ecx :76111E1A 53 push ebx :76111E1B 54 push esp :76111E1C 4C dec esp :76111E1D 4F dec edi :76111E1E 47 inc edi :76111E1F 005C424B add byte ptr [edx+2*eax+4B], bl :76111E23 55 push ebp :76111E24 50 push eax :76111E25 57 push edi :76111E26 49 dec ecx :76111E27 4E dec esi :76111E28 49 dec ecx :76111E29 4E dec esi :76111E2A 49 dec ecx :76111E2B 54 push esp :76111E2C 4C dec esp :76111E2D 4F dec edi :76111E2E 47 inc edi :76111E2F 005C424B add byte ptr [edx+2*eax+4B], bl :76111E33 55 push ebp :76111E34 50 push eax :76111E35 4C dec esp :76111E36 4F dec edi :76111E37 47 inc edi :76111E38 00000000 BYTE 4 DUP(0) :76111E3C 5C pop esp :76111E3D 42 inc edx :76111E3E 4B dec ebx :76111E3F 55 push ebp :76111E40 50 push eax :76111E41 000000 BYTE 3 DUP(0) :76111E44 52 push edx :76111E45 47 inc edi :76111E46 0000 add byte ptr [eax], al :76111E48 52 push edx :76111E49 47 inc edi :76111E4A 2A2E sub ch, byte ptr [esi] :76111E4C 43 inc ebx :76111E4D 41 inc ecx :76111E4E 42 inc edx :76111E4F 004653 add byte ptr [esi+53], al :76111E52 0000 add byte ptr [eax], al :76111E54 46 inc esi :76111E55 53 push ebx :76111E56 2A2E sub ch, byte ptr [esi] :76111E58 43 inc ebx :76111E59 41 inc ecx :76111E5A 42 inc edx :76111E5B 005F54 add byte ptr [edi+54], bl :76111E5E 4D dec ebp :76111E5F 50 push eax :76111E60 00000000 BYTE 4 DUP(0) :76111E64 43 inc ebx :76111E65 48 dec eax :76111E66 41 inc ecx :76111E67 4E dec esi :76111E68 47 inc edi :76111E69 45 inc ebp :76111E6A 2E BYTE 02eh :76111E6B 4C dec esp :76111E6C 4F dec edi :76111E6D 47 inc edi :76111E6E 0000 add byte ptr [eax], al :76111E70 2E BYTE 02eh :76111E71 41 inc ecx :76111E72 54 push esp :76111E73 46 inc esi :76111E74 00000000 BYTE 4 DUP(0) :76111E78 53 push ebx :76111E79 7461 je 76111EDC :76111E7B 7465 je 76111EE2 :76111E7D 6D insd :76111E7E 677200 jb 76111E81 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111E7F(C) | :76111E81 000000 BYTE 3 DUP(0) :76111E84 4C dec esp :76111E85 6F outsd :76111E86 63616C arpl dword ptr [ecx+6C], esp :76111E89 44 inc esp :76111E8A 69736B00000056 imul esi, dword ptr [ebx+6B], 56000000 :76111E91 58 pop eax :76111E92 44 inc esp :76111E93 4C dec esp :76111E94 4F dec edi :76111E95 47 inc edi :76111E96 2E BYTE 02eh :76111E97 4C dec esp :76111E98 4F dec edi :76111E99 47 inc edi :76111E9A 0000 add byte ptr [eax], al :76111E9C 2E BYTE 02eh :76111E9D 54 push esp :76111E9E 4D dec ebp :76111E9F 50 push eax :76111EA0 00000000 BYTE 4 DUP(0) :76111EA4 52 push edx :76111EA5 65 BYTE 065h :76111EA6 7374 jnb 76111F1C :76111EA8 6F outsd :76111EA9 7265 jb 76111F10 :76111EAB 55 push ebp :76111EAC 6E outsb :76111EAD 696E7374616C6C imul ebp, dword ptr [esi+73], 6C6C6174 :76111EB4 00000000 BYTE 4 DUP(0) :76111EB8 53 push ebx :76111EB9 4F dec edi :76111EBA 46 inc esi :76111EBB 54 push esp :76111EBC 57 push edi :76111EBD 41 inc ecx :76111EBE 52 push edx :76111EBF 45 inc ebp :76111EC0 5C pop esp :76111EC1 4D dec ebp :76111EC2 6963726F736F66 imul esp, dword ptr [ebx+72], 666F736F :76111EC9 745C je 76111F27 :76111ECB 57 push edi :76111ECC 696E646F77735C imul ebp, dword ptr [esi+64], 5C73776F :76111ED3 43 inc ebx :76111ED4 7572 jne 76111F48 :76111ED6 7265 jb 76111F3D :76111ED8 6E outsb :76111ED9 7456 je 76111F31 :76111EDB 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111E79(C) | :76111EDC 7273 jb 76111F51 :76111EDE 696F6E5C52756E imul ebp, dword ptr [edi+6E], 6E75525C :76111EE5 4F dec edi :76111EE6 6E outsb :76111EE7 636500 arpl dword ptr [ebp+00], esp :76111EEA 0000 add byte ptr [eax], al :76111EEC 5C pop esp :76111EED 7379 jnb 76111F68 :76111EEF 7374 jnb 76111F65 :76111EF1 65 BYTE 065h :76111EF2 6D insd :76111EF3 5C pop esp :76111EF4 7678 jbe 76111F6E :76111EF6 64 BYTE 064h :76111EF7 6D insd :76111EF8 6F outsd :76111EF9 6E outsb :76111EFA 2E BYTE 02eh :76111EFB 64 BYTE 064h :76111EFC 61 popad :76111EFD 7400 je 76111EFF * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111EFD(C) | :76111EFF 005C7379 add byte ptr [ebx+2*esi+79], bl :76111F03 7374 jnb 76111F79 :76111F05 65 BYTE 065h :76111F06 6D insd :76111F07 5C pop esp :76111F08 7265 jb 76111F6F :76111F0A 7374 jnb 76111F80 :76111F0C 6F outsd :76111F0D 7265 jb 76111F74 :76111F0F 5C pop esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111EA9(C) | :76111F10 66696C656C6973 imul bp, word ptr [ebp+6C], 7369 :76111F17 742E je 76111F47 :76111F19 786D js 76111F88 :76111F1B 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111EA6(C) | :76111F1C 00000000 BYTE 4 DUP(0) :76111F20 5C pop esp :76111F21 7379 jnb 76111F9C :76111F23 7374 jnb 76111F99 :76111F25 65 BYTE 065h :76111F26 6D insd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111EC9(C) | :76111F27 5C pop esp :76111F28 7265 jb 76111F8F :76111F2A 7374 jnb 76111FA0 :76111F2C 6F outsd :76111F2D 7265 jb 76111F94 :76111F2F 5C pop esp :76111F30 7678 jbe 76111FAA :76111F32 64627569 bound esi, dword ptr fs:[ebp+69] :76111F36 6C insb :76111F37 64 BYTE 064h :76111F38 2E BYTE 02eh :76111F39 65 BYTE 065h :76111F3A 7865 js 76111FA1 :76111F3C 00000000 BYTE 4 DUP(0) :76111F40 5C pop esp :76111F41 7379 jnb 76111FBC :76111F43 7374 jnb 76111FB9 :76111F45 65 BYTE 065h :76111F46 6D insd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F17(C) | :76111F47 5C pop esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111ED4(C) | :76111F48 7265 jb 76111FAF :76111F4A 7374 jnb 76111FC0 :76111F4C 6F outsd :76111F4D 7265 jb 76111FB4 :76111F4F 5C pop esp :76111F50 7574 jne 76111FC6 :76111F52 696C735C636F6E66 imul ebp, dword ptr [ebx+2*esi+5C], 666E6F63 :76111F5A 69726D2E626174 imul esi, dword ptr [edx+6D], 7461622E :76111F61 000000 BYTE 3 DUP(0) :76111F64 7265 jb 76111FCB :76111F66 7374 jnb 76111FDC * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111EED(C) | :76111F68 6F outsd :76111F69 7265 jb 76111FD0 :76111F6B 42 inc edx :76111F6C 56 push esi :76111F6D 54 push esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111EF4(C) | :76111F6E 0000 add byte ptr [eax], al :76111F70 64 BYTE 064h :76111F71 65 BYTE 065h :76111F72 6C insb :76111F73 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F0D(C) | :76111F74 7465 je 76111FDB :76111F76 53 push ebx :76111F77 52 push edx :76111F78 2E626174 bound esp, dword ptr cs:[ecx+74] :76111F7C 00000000 BYTE 4 DUP(0) * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F0A(C) | :76111F80 5C pop esp :76111F81 7379 jnb 76111FFC :76111F83 7374 jnb 76111FF9 :76111F85 65 BYTE 065h :76111F86 6D insd :76111F87 5C pop esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F19(C) | :76111F88 7265 jb 76111FEF :76111F8A 7374 jnb 76112000 :76111F8C 6F outsd :76111F8D 7265 jb 76111FF4 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F28(C) | :76111F8F 005C7465 add byte ptr [esp+2*esi+65], bl :76111F93 6D insd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F2D(C) | :76111F94 705C jo 76111FF2 :76111F96 64 BYTE 064h :76111F97 65 BYTE 065h :76111F98 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F23(C) | :76111F99 65 BYTE 065h :76111F9A 7465 je 76112001 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F21(C) | :76111F9C 53 push ebx :76111F9D 52 push edx :76111F9E 2E626174 bound esp, dword ptr cs:[ecx+74] :76111FA2 0000 add byte ptr [eax], al :76111FA4 43 inc ebx :76111FA5 61 popad :76111FA6 626269 bound esp, dword ptr [edx+69] :76111FA9 6E outsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F30(C) | :76111FAA 6745 inc ebp :76111FAC 6E outsb :76111FAD 64 BYTE 064h :76111FAE 5F pop edi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F48(C) | :76111FAF 45 inc ebp :76111FB0 7665 jbe 76112017 :76111FB2 6E outsb :76111FB3 7400 je 76111FB5 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111FB3(C) | :76111FB5 000000 BYTE 3 DUP(0) :76111FB8 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F43(C) | :76111FB9 7573 jne 7611202E :76111FBB 7065 jo 76112022 :76111FBD 6E outsb :76111FBE 64 BYTE 064h :76111FBF 5F pop edi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F4A(C) | :76111FC0 45 inc ebp :76111FC1 7665 jbe 76112028 :76111FC3 6E outsb :76111FC4 7400 je 76111FC6 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76111F50(C), :76111FC4(C) | :76111FC6 0000 add byte ptr [eax], al :76111FC8 46 inc esi :76111FC9 7265 jb 76112030 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F64(C) | :76111FCB 65 BYTE 065h :76111FCC 7A65 jpe 76112033 :76111FCE 5F pop edi :76111FCF 45 inc ebp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F69(C) | :76111FD0 7665 jbe 76112037 :76111FD2 6E outsb :76111FD3 7400 je 76111FD5 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111FD3(C) | :76111FD5 000000 BYTE 3 DUP(0) :76111FD8 53 push ebx :76111FD9 66705F jo 7611203B * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F66(C) | :76111FDC 50 push eax :76111FDD 65 BYTE 065h :76111FDE 6E outsb :76111FDF 64696E675F457665 imul ebp, dword ptr fs:[esi+67], 6576455F :76111FE7 6E outsb :76111FE8 7400 je 76111FEA * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111FE8(C) | :76111FEA 0000 add byte ptr [eax], al :76111FEC 53 push ebx :76111FED 66705F jo 7611204F :76111FF0 49 dec ecx :76111FF1 6E outsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F94(C) | :76111FF2 69745F4576656E74 imul esi, dword ptr [edi+2*ebx+45], 746E6576 :76111FFA 0000 add byte ptr [eax], al * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111F81(C) | :76111FFC 53 push ebx :76111FFD 796E jns 7611206D :76111FFF 63685F arpl dword ptr [eax+5F], ebp :76112002 45 inc ebp :76112003 7665 jbe 7611206A :76112005 6E outsb :76112006 7400 je 76112008 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112006(C) | :76112008 53 push ebx :76112009 687574446F push 6F447475 :7611200E 776E ja 7611207E :76112010 5F pop edi :76112011 45 inc ebp :76112012 7665 jbe 76112079 :76112014 6E outsb :76112015 7400 je 76112017 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76111FB0(C), :76112015(C) | :76112017 005678 add byte ptr [esi+78], dl :7611201A 64 BYTE 064h :7611201B 41 inc ecx :7611201C 7263 jb 76112081 :7611201E 686976655F push 5F657669 :76112023 45 inc ebp :76112024 7665 jbe 7611208B :76112026 6E outsb :76112027 7400 je 76112029 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112027(C) | :76112029 000000 BYTE 3 DUP(0) :7611202C 41 inc ecx :7611202D 7263 jb 76112092 :7611202F 686976655F push 5F657669 :76112034 45 inc ebp :76112035 7665 jbe 7611209C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111FD0(C) | :76112037 6E outsb :76112038 7400 je 7611203A * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112038(C) | :7611203A 0000 add byte ptr [eax], al :7611203C 53 push ebx :7611203D 4D dec ebp :7611203E 47 inc edi :7611203F 52 push edx :76112040 50 push eax :76112041 726F jb 761120B2 :76112043 635F4D arpl dword ptr [edi+4D], ebx :76112046 7574 jne 761120BC :76112048 65 BYTE 065h :76112049 7800 js 7611204B * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112049(C) | :7611204B 004368 add byte ptr [ebx+68], al :7611204E 61 popad * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111FEE(C) | :7611204F 6E outsb :76112050 67 BYTE 067h :76112051 65 BYTE 065h :76112052 4C dec esp :76112053 6F outsd :76112054 6741 inc ecx :76112056 50 push eax :76112057 49 dec ecx :76112058 5F pop edi :76112059 4D dec ebp :7611205A 7574 jne 761120D0 :7611205C 65 BYTE 065h :7611205D 7800 js 7611205F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611205D(C) | :7611205F 00426F add byte ptr [edx+6F], al :76112062 6F outsd :76112063 7454 je 761120B9 :76112065 696D655F4D7574 imul ebp, dword ptr [ebp+65], 74754D5F :7611206C 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76111FFD(C) | :7611206D 7800 js 7611206F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611206D(C) | :7611206F 005265 add byte ptr [edx+65], dl :76112072 675F pop edi :76112074 4D dec ebp :76112075 7574 jne 761120EB :76112077 65 BYTE 065h :76112078 7800 js 7611207A * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112078(C) | :7611207A 0000 add byte ptr [eax], al :7611207C 53 push ebx :7611207D 4D dec ebp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611200E(C) | :7611207E 49 dec ecx :7611207F 6E outsb :76112080 69745F4D75746578 imul esi, dword ptr [edi+2*ebx+4D], 78657475 :76112088 00000000 BYTE 4 DUP(0) :7611208C 43 inc ebx :7611208D 6F outsd :7611208E 6D insd :7611208F 6D insd :76112090 6974465343686773 imul esi, dword ptr [esi+2*eax+53], 73676843 :76112098 5F pop edi :76112099 4D dec ebp :7611209A 7574 jne 76112110 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112035(C) | :7611209C 65 BYTE 065h :7611209D 7800 js 7611209F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611209D(C) | :7611209F 005348 add byte ptr [ebx+48], dl :761120A2 45 inc ebp :761120A3 58 pop eax :761120A4 5F pop edi :761120A5 4D dec ebp :761120A6 7574 jne 7611211C :761120A8 65 BYTE 065h :761120A9 7800 js 761120AB * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761120A9(C) | :761120AB 005346 add byte ptr [ebx+46], dl :761120AE 50 push eax :761120AF 5F pop edi :761120B0 4D dec ebp :761120B1 7574 jne 76112127 :761120B3 65 BYTE 065h :761120B4 7800 js 761120B6 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761120B4(C) | :761120B6 0000 add byte ptr [eax], al :761120B8 2573256C64 and eax, 646C2573 :761120BD 2E BYTE 02eh :761120BE 4F dec edi :761120BF 55 push ebp :761120C0 54 push esp :761120C1 000000 BYTE 3 DUP(0) :761120C4 2573256C64 and eax, 646C2573 :761120C9 2E BYTE 02eh :761120CA 49 dec ecx :761120CB 4E dec esi :761120CC 00000000 BYTE 4 DUP(0) * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611205A(C) | :761120D0 5C pop esp :761120D1 49 dec ecx :761120D2 6E outsb :761120D3 7665 jbe 7611213A :761120D5 6E outsb :761120D6 746F je 76112147 :761120D8 7279 jb 76112153 :761120DA 2E BYTE 02eh :761120DB 64 BYTE 064h :761120DC 61 popad :761120DD 7400 je 761120DF * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761120DD(C) | :761120DF 005769 add byte ptr [edi+69], dl :761120E2 6E outsb :761120E3 64 BYTE 064h :761120E4 6F outsd :761120E5 7773 ja 7611215A :761120E7 204D69 and byte ptr [ebp+69], cl :761120EA 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112075(C) | :761120EB 6C insb :761120EC 65 BYTE 065h :761120ED 6E outsb :761120EE 6E outsb :761120EF 69756D00002A2E imul esi, dword ptr [ebp+6D], 2E2A0000 :761120F6 2A00 sub al, byte ptr [eax] :761120F8 5C pop esp :761120F9 2A2E sub ch, byte ptr [esi] :761120FB 2A00 sub al, byte ptr [eax] :761120FD 000000 BYTE 3 DUP(0) :76112100 3D0000005C cmp eax, 5C000000 :76112105 5C pop esp :76112106 2E BYTE 02eh :76112107 5C pop esp :76112108 00000000 BYTE 4 DUP(0) :7611210C 5C pop esp :7611210D 000000 BYTE 3 DUP(0) * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611209A(C) | :76112110 5C pop esp :76112111 000000 BYTE 3 DUP(0) :76112114 52 push edx :76112115 65 BYTE 065h :76112116 7374 jnb 7611218C :76112118 6F outsd :76112119 7252 jb 7611216D :7611211B 6300 arpl dword ptr [eax], eax :7611211D 000000 BYTE 3 DUP(0) :76112120 45 inc ebp :76112121 7272 jb 76112195 :76112123 6F outsd :76112124 7220 jb 76112146 :76112126 25783A2043 and eax, 43203A78 :7611212B 61 popad :7611212C 6E outsb :7611212D 6E outsb :7611212E 6F outsd :7611212F 7420 je 76112151 :76112131 667265 jb 76112199 :76112134 65207374 and byte ptr gs:[ebx+74], dh :76112138 7269 jb 761121A3 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761120D3(C) | :7611213A 6E outsb :7611213B 00 BYTE 000h :7611213C 00000000 BYTE 4 DUP(0) :76112140 45 inc ebp :76112141 7272 jb 761121B5 :76112143 6F outsd :76112144 7220 jb 76112166 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112124(C) | :76112146 25783A2043 and eax, 43203A78 :7611214B 61 popad :7611214C 6E outsb :7611214D 6E outsb :7611214E 6F outsd :7611214F 7420 je 76112171 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611212F(C) | :76112151 637265 arpl dword ptr [edx+65], esi :76112154 61 popad :76112155 7465 je 761121BC :76112157 206269 and byte ptr [edx+69], ah * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761120E5(C) | :7611215A 6E outsb :7611215B 64696E6700457272 imul ebp, dword ptr fs:[esi+67], 72724500 :76112163 6F outsd :76112164 7220 jb 76112186 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112144(C) | :76112166 25783A2043 and eax, 43203A78 :7611216B 61 popad :7611216C 6E outsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112119(C) | :7611216D 6E outsb :7611216E 6F outsd :7611216F 7420 je 76112191 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611214F(C) | :76112171 637265 arpl dword ptr [edx+65], esi :76112174 61 popad :76112175 7465 je 761121DC :76112177 206269 and byte ptr [edx+69], ah :7611217A 6E outsb :7611217B 64696E6720737472 imul ebp, dword ptr fs:[esi+67], 72747320 :76112183 696E6700005366 imul ebp, dword ptr [esi+67], 66530000 :7611218A 7049 jo 761121D5 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112116(C) | :7611218C 6E outsb :7611218D 697452504300006E imul esi, dword ptr [edx+2*edx+50], 6E000043 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112121(C) | :76112195 63616C arpl dword ptr [ecx+6C], esp :76112198 7270 jb 7611220A :7611219A 6300 arpl dword ptr [eax], eax :7611219C 7366 jnb 76112204 :7611219E 7072 jo 76112212 :761121A0 7063 jo 76112205 :761121A2 0000 add byte ptr [eax], al :761121A4 45 inc ebp :761121A5 7272 jb 76112219 :761121A7 6F outsd :761121A8 7220 jb 761121CA :761121AA 25783A2043 and eax, 43203A78 :761121AF 61 popad :761121B0 6E outsb :761121B1 6E outsb :761121B2 6F outsd :761121B3 7420 je 761121D5 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112141(C) | :761121B5 667265 jb 7611221D :761121B8 65206269 and byte ptr gs:[edx+69], ah * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112155(C) | :761121BC 6E outsb :761121BD 64696E6700000053 imul ebp, dword ptr fs:[esi+67], 53000000 :761121C5 667052 jo 7611221A :761121C8 50 push eax :761121C9 43 inc ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761121A8(C) | :761121CA 54 push esp :761121CB 65 BYTE 065h :761121CC 726D jb 7611223B :761121CE 0000 add byte ptr [eax], al :761121D0 43 inc ebx :761121D1 61 popad :761121D2 6E outsb :761121D3 6E outsb :761121D4 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:7611218A(C), :761121B3(C) | :761121D5 7420 je 761121F7 :761121D7 7465 je 7611223E :761121D9 726D jb 76112248 :761121DB 205250 and byte ptr [edx+50], dl :761121DE 43 inc ebx :761121DF 004361 add byte ptr [ebx+61], al :761121E2 6E outsb :761121E3 6E outsb :761121E4 6F outsd :761121E5 7420 je 76112207 :761121E7 6C insb :761121E8 6F outsd :761121E9 61 popad :761121EA 64207366 and byte ptr fs:[ebx+66], dh :761121EE 7064 jo 76112254 :761121F0 6C insb :761121F1 6C insb :761121F2 2E BYTE 02eh :761121F3 64 BYTE 064h :761121F4 6C insb :761121F5 6C insb :761121F6 2C20 sub al, 20 :761121F8 65633D256C6400 arpl dword ptr gs:[00646C25], edi :761121FF 004361 add byte ptr [ebx+61], al :76112202 6E outsb :76112203 6E outsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611219C(C) | :76112204 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761121A0(C) | :76112205 7420 je 76112227 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761121E5(C) | :76112207 6C insb :76112208 6F outsd :76112209 61 popad * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112198(C) | :7611220A 64205346 and byte ptr fs:[ebx+46], dl :7611220E 50 push eax :7611220F 43 inc ebx :76112210 6F outsd :76112211 7079 jo 7611228C :76112213 43 inc ebx :76112214 61 popad :76112215 7461 je 76112278 :76112217 6C insb :76112218 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761121A5(C) | :76112219 672C20 sub al, 20 :7611221C 65633D256C6400 arpl dword ptr gs:[00646C25], edi :76112223 005346 add byte ptr [ebx+46], dl :76112226 50 push eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112205(C) | :76112227 43 inc ebx :76112228 6F outsd :76112229 7079 jo 761122A4 :7611222B 43 inc ebx :7611222C 61 popad :7611222D 7461 je 76112290 :7611222F 6C insb :76112230 6F outsd :76112231 670000 add [bx+si], al :76112234 7366 jnb 7611229C :76112236 7064 jo 7611229C :76112238 6C insb :76112239 6C insb :7611223A 2E BYTE 02eh * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761121CC(C) | :7611223B 64 BYTE 064h :7611223C 6C insb :7611223D 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761121D7(C) | :7611223E 0000 add byte ptr [eax], al :76112240 45 inc ebp :76112241 7272 jb 761122B5 :76112243 6F outsd :76112244 7220 jb 76112266 :76112246 25783A2052 and eax, 52203A78 :7611224B 50 push eax :7611224C 43 inc ebx :7611224D 207275 and byte ptr [edx+75], dh :76112250 6E outsb :76112251 7469 je 761122BC :76112253 6D insd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761121EE(C) | :76112254 65207265 and byte ptr gs:[edx+65], dh :76112258 706F jo 761122C9 :7611225A 7274 jb 761122D0 :7611225C 65 BYTE 065h :7611225D 64206578 and byte ptr fs:[ebp+78], ah :76112261 636570 arpl dword ptr [ebp+70], esp :76112264 7469 je 761122CF * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112244(C) | :76112266 6F outsd :76112267 6E outsb :76112268 00000000 BYTE 4 DUP(0) :7611226C 43 inc ebx :7611226D 61 popad :7611226E 6E outsb :7611226F 6E outsb :76112270 6F outsd :76112271 7420 je 76112293 :76112273 696E6974205250 imul ebp, dword ptr [esi+69], 50522074 :7611227A 43 inc ebx :7611227B 004E55 add byte ptr [esi+55], cl :7611227E 4C dec esp :7611227F 4C dec esp :76112280 206361 and byte ptr [ebx+61], ah :76112283 7461 je 761122E6 :76112285 6C insb :76112286 6F outsd :76112287 67206E61 and [bp+61], ch :7611228B 6D insd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112211(C) | :7611228C 65 BYTE 065h :7611228D 000000 BYTE 3 DUP(0) * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611222D(C) | :76112290 53 push ebx :76112291 667049 jo 761122DD :76112294 6E outsb :76112295 7374 jnb 7611230B :76112297 61 popad :76112298 6C insb :76112299 6C insb :7611229A 43 inc ebx :7611229B 61 popad * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76112234(C), :76112236(C) | :7611229C 7461 je 761122FF :7611229E 6C insb :7611229F 6F outsd :761122A0 00 BYTE 000h :761122A1 00000000000000 BYTE 7 DUP(0) :761122A8 FFFFFFFF BYTE 4 DUP(0ffh) :761122AC 583B1176 DWORD 76113B58 :761122B0 663B1176 DWORD 76113B66 :761122B4 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112241(C) | :761122B5 667044 jo 761122FC :761122B8 65 BYTE 065h :761122B9 6C insb :761122BA 65 BYTE 065h :761122BB 7465 je 76112322 :761122BD 43 inc ebx :761122BE 61 popad :761122BF 7461 je 76112322 :761122C1 6C insb :761122C2 6F outsd :761122C3 00 BYTE 000h :761122C4 00000000 BYTE 4 DUP(0) :761122C8 FFFFFFFF BYTE 4 DUP(0ffh) :761122CC 793D1176 DWORD 76113D79 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611225A(C) | :761122D0 873D1176 DWORD 76113D87 :761122D4 46 inc esi :761122D5 61 popad :761122D6 696C656420746F20 imul ebp, dword ptr [ebp+64], 206F7420 :761122DE 636F6E arpl dword ptr [edi+6E], ebp :761122E1 7665 jbe 76112348 :761122E3 7274 jb 76112359 :761122E5 20255320746F and byte ptr [6F742053], ah :761122EB 20414E and byte ptr [ecx+4E], al :761122EE 53 push ebx :761122EF 49 dec ecx :761122F0 2C20 sub al, 20 :761122F2 65 BYTE 065h :761122F3 7272 jb 76112367 :761122F5 6F outsd :761122F6 7220 jb 76112318 :761122F8 256C64004E and eax, 4E00646C :761122FD 55 push ebp :761122FE 4C dec esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611229C(C) | :761122FF 4C dec esp :76112300 206669 and byte ptr [esi+69], ah :76112303 6C insb :76112304 65206E61 and byte ptr gs:[esi+61], ch * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761122B3(C) | :76112308 6D insd :76112309 65 BYTE 065h :7611230A 0000 add byte ptr [eax], al :7611230C 53 push ebx :7611230D 667049 jo 76112359 :76112310 7346 jnb 76112358 :76112312 696C6550726F7465 imul ebp, dword ptr [ebp+50], 65746F72 :7611231A 63746564 arpl dword ptr [ebp+64], esi :7611231E 0000 add byte ptr [eax], al :76112320 FFFFFFFF BYTE 4 DUP(0ffh) :76112324 793F1176 DWORD 76113F79 :76112328 8A3F1176 DWORD 76113F8A :7611232C 4E dec esi :7611232D 55 push ebp :7611232E 4C dec esp :7611232F 4C dec esp :76112330 206669 and byte ptr [esi+69], ah :76112333 6C insb :76112334 6520646174 and byte ptr gs:[ecx+74], ah :76112339 61 popad :7611233A 0000 add byte ptr [eax], al :7611233C 53 push ebx :7611233D 66634765 arpl word ptr [edi+65], ax :76112341 744E je 76112391 :76112343 65 BYTE 065h :76112344 7874 js 761123BA :76112346 50 push eax :76112347 726F jb 761123B8 :76112349 7465 je 761123B0 :7611234B 63746564 arpl dword ptr [ebp+64], esi :7611234F 46 inc esi :76112350 696C650000000000 imul ebp, dword ptr [ebp], 00000000 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112310(C) | :76112358 FFFFFFFF BYTE 4 DUP(0ffh) :7611235C 03411176 DWORD 76114103 :76112360 11411176 DWORD 76114111 :76112364 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112324(C) | :76112365 667056 jo 761123BE :76112368 65 BYTE 065h :76112369 7269 jb 761123D4 :7611236B 667946 jns 761123B4 :7611236E 696C650000000000 imul ebp, dword ptr [ebp], 00000000 :76112376 0000 add byte ptr [eax], al :76112378 FFFFFFFF BYTE 4 DUP(0ffh) :7611237C 3A421176 DWORD 7611423A :76112380 48421176 DWORD 76114248 :76112384 44 inc esp :76112385 697361626C6553 imul esi, dword ptr [ebx+61], 53656C62 :7611238C 46 inc esi :7611238D 50 push eax :7611238E 0000 add byte ptr [eax], al :76112390 FFFFFFFF BYTE 4 DUP(0ffh) :76112394 65431176 DWORD 76114365 :76112398 73431176 DWORD 76114373 :7611239C 47 inc edi :7611239D 65 BYTE 065h :7611239E 7453 je 761123F3 :761123A0 7461 je 76112403 :761123A2 7465 je 76112409 :761123A4 4D dec ebp :761123A5 677244 jb 761123EC :761123A8 69736B4D617800 imul esi, dword ptr [ebx+6B], 0078614D :761123AF 00FF add bh, bh :761123B1 FFFFFF BYTE 3 DUP(0ffh) * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611236C(C) | :761123B4 03451176 DWORD 76114503 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112347(C) | :761123B8 11451176 DWORD 76114511 :761123BC 53 push ebx :761123BD 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112366(C) | :761123BE 7453 je 76112413 :761123C0 7461 je 76112423 :761123C2 7465 je 76112429 :761123C4 4D dec ebp :761123C5 677244 jb 7611240C :761123C8 69736B4D617800 imul esi, dword ptr [ebx+6B], 0078614D :761123CF 00FF add bh, bh :761123D1 FFFFFF BYTE 3 DUP(0ffh) * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112369(C) | :761123D4 99461176 DWORD 76114699 :761123D8 A7461176 DWORD 761146A7 :761123DC 43 inc ebx :761123DD 61 popad :761123DE 6E outsb :761123DF 6E outsb :761123E0 6F outsd :761123E1 7420 je 76112403 :761123E3 7365 jnb 7611244A :761123E5 7420 je 76112407 :761123E7 7265 jb 7611244E :761123E9 676B657920 imul esp, [di+79], 00000020 :761123EE 7661 jbe 76112451 :761123F0 6C insb :761123F1 7565 jne 76112458 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611239E(C) | :761123F3 2C20 sub al, 20 :761123F5 65633D256C6400 arpl dword ptr gs:[00646C25], edi :761123FC 43 inc ebx :761123FD 61 popad :761123FE 6E outsb :761123FF 6E outsb :76112400 6F outsd :76112401 7420 je 76112423 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761123A0(C), :761123E1(C) | :76112403 6F outsd :76112404 7065 jo 7611246B :76112406 6E outsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761123E5(C) | :76112407 207265 and byte ptr [edx+65], dh :7611240A 676B65792C imul esp, [di+79], 0000002C :7611240F 206563 and byte ptr [ebp+63], ah :76112412 3D256C6400 cmp eax, 00646C25 :76112417 005275 add byte ptr [edx+75], dl :7611241A 6E outsb :7611241B 44 inc esp :7611241C 697361626C6553 imul esi, dword ptr [ebx+61], 53656C62 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761123C0(C), :76112401(C) | :76112423 52 push edx :76112424 00000000 BYTE 4 DUP(0) :76112428 49 dec ecx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761123C2(C) | :76112429 7353 jnb 7611247E :7611242B 52 push edx :7611242C 45 inc ebp :7611242D 6E outsb :7611242E 61 popad :7611242F 626C6564 bound ebp, dword ptr [ebp+64] :76112433 0000000000 BYTE 5 DUP(0) :76112438 FFFFFFFF BYTE 4 DUP(0ffh) :7611243C 15491176 DWORD 76114915 :76112440 23491176 DWORD 76114923 :76112444 44 inc esp :76112445 697361626C6553 imul esi, dword ptr [ebx+61], 53656C62 :7611244C 52 push edx :7611244D 000000 BYTE 3 DUP(0) :76112450 FFFFFFFF BYTE 4 DUP(0ffh) :76112454 4B4A1176 DWORD 76114A4B * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761123F1(C) | :76112458 594A1176 DWORD 76114A59 :7611245C 53 push ebx :7611245D 52 push edx :7611245E 55 push ebp :7611245F 7064 jo 761124C5 :76112461 61 popad :76112462 7465 je 761124C9 :76112464 4D dec ebp :76112465 6F outsd :76112466 6E outsb :76112467 69746F7265644C69 imul esi, dword ptr [edi+2*ebp+72], 694C6465 :7611246F 7374 jnb 761124E5 :76112471 00000000000000 BYTE 7 DUP(0) :76112478 FFFFFFFF BYTE 4 DUP(0ffh) :7611247C 794B1176 DWORD 76114B79 :76112480 874B1176 DWORD 76114B87 :76112484 53 push ebx :76112485 52 push edx :76112486 20646973 and byte ptr [ecx+2*ebp+73], ah :7611248A 61 popad :7611248B 626C6564 bound ebp, dword ptr [ebp+64] :7611248F 2E BYTE 02eh :76112490 00000000 BYTE 4 DUP(0) :76112494 53 push ebx :76112495 52 push edx :76112496 53 push ebx :76112497 65 BYTE 065h :76112498 7452 je 761124EC :7611249A 65 BYTE 065h :7611249B 7374 jnb 76112511 :7611249D 6F outsd :7611249E 7265 jb 76112505 :761124A0 50 push eax :761124A1 6F outsd :761124A2 696E74000000FF imul ebp, dword ptr [esi+74], FF000000 :761124A9 FFFFFF BYTE 3 DUP(0ffh) :761124AC 154D1176 DWORD 76114D15 :761124B0 234D1176 DWORD 76114D23 :761124B4 44 inc esp :761124B5 697361626C6546 imul esi, dword ptr [ebx+61], 46656C62 :761124BC 49 dec ecx :761124BD 46 inc esi :761124BE 4F dec edi :761124BF 00FF add bh, bh :761124C1 FFFFFF BYTE 3 DUP(0ffh) :761124C4 3B4E1176 DWORD 76114E3B :761124C8 494E1176 DWORD 76114E49 :761124CC 45 inc ebp :761124CD 6E outsb :761124CE 61 popad :761124CF 626C6546 bound ebp, dword ptr [ebp+46] :761124D3 49 dec ecx :761124D4 46 inc esi :761124D5 4F dec edi :761124D6 0000 add byte ptr [eax], al :761124D8 FFFFFFFF BYTE 4 DUP(0ffh) :761124DC 5E4F1176 DWORD 76114F5E :761124E0 6C4F1176 DWORD 76114F6C :761124E4 45 inc ebp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611246F(C) | :761124E5 7272 jb 76112559 :761124E7 6F outsd :761124E8 7220 jb 7611250A :761124EA 61 popad :761124EB 7263 jb 76112550 :761124ED 686976696E push 6E697669 :761124F2 67206669 and [bp+69], ah :761124F6 6C insb :761124F7 65206563 and byte ptr gs:[ebp+63], ah :761124FB 3D25640000 cmp eax, 00006425 :76112500 43 inc ebx :76112501 61 popad :76112502 7461 je 76112565 :76112504 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611249E(C) | :76112505 6F outsd :76112506 672025 and [di], ah :76112509 7320 jnb 7611252B :7611250B 64 BYTE 064h :7611250C 6F outsd :7611250D 65 BYTE 065h :7611250E 7320 jnb 76112530 :76112510 6E outsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611249B(C) | :76112511 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761124C7(C) | :76112512 7420 je 76112534 :76112514 65 BYTE 065h :76112515 7869 js 76112580 :76112517 7374 jnb 7611258D :76112519 000000 BYTE 3 DUP(0) :7611251C 45 inc ebp :7611251D 7272 jb 76112591 :7611251F 6F outsd :76112520 7220 jb 76112542 :76112522 67 BYTE 067h :76112523 65 BYTE 065h :76112524 7474 je 7611259A :76112526 696E6720746865 imul ebp, dword ptr [esi+67], 65687420 :7611252D 206675 and byte ptr [esi+75], ah * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611250E(C) | :76112530 6C insb :76112531 6C insb :76112532 206361 and byte ptr [ebx+61], ah :76112535 7461 je 76112598 :76112537 6C insb :76112538 6F outsd :76112539 67207061 and [bx+si+61], dh :7611253D 7468 je 761125A7 :7611253F 2E BYTE 02eh :76112540 00000000 BYTE 4 DUP(0) :76112544 45 inc ebp :76112545 7272 jb 761125B9 :76112547 6F outsd :76112548 7220 jb 7611256A :7611254A 696E697469616C imul ebp, dword ptr [esi+69], 6C616974 :76112551 697A696E672063 imul edi, dword ptr [edx+69], 6320676E :76112558 61 popad * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761124E5(C) | :76112559 7461 je 761125BC :7611255B 6C insb :7611255C 6F outsd :7611255D 67207574 and [di+74], dh :76112561 696C697469657300 imul ebp, dword ptr [ecx+2*ebp+74], 00736569 :76112569 000000 BYTE 3 DUP(0) :7611256C 53 push ebx :7611256D 667044 jo 761125B4 :76112570 7570 jne 761125E2 :76112572 6C insb :76112573 69636174654361 imul esp, dword ptr [ebx+61], 61436574 :7611257A 7461 je 761125DD :7611257C 6C insb :7611257D 6F outsd :7611257E 67004E75 add [bp+75], cl :76112582 6C insb :76112583 6C insb :76112584 204361 and byte ptr [ebx+61], al :76112587 7420 je 761125A9 :76112589 66696C656E616D imul bp, word ptr [ebp+6E], 6D61 :76112590 65206F72 and byte ptr gs:[edi+72], ch :76112594 206275 and byte ptr [edx+75], ah :76112597 66 BYTE 066h :76112598 66 BYTE 066h :76112599 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112524(C) | :7611259A 7220 jb 761125BC :7611259C 7369 jnb 76112607 :7611259E 7A65 jpe 76112605 :761125A0 20706F and byte ptr [eax+6F], dh :761125A3 696E7465720000 imul ebp, dword ptr [esi+74], 00007265 :761125AA 0000 add byte ptr [eax], al :761125AC 45 inc ebp :761125AD 7272 jb 76112621 :761125AF 6F outsd :761125B0 7220 jb 761125D2 :761125B2 7265 jb 76112619 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611256E(C) | :761125B4 61 popad :761125B5 64696E6720646570 imul ebp, dword ptr fs:[esi+67], 70656420 :761125BD 65 BYTE 065h :761125BE 6E outsb :761125BF 64 BYTE 064h :761125C0 65 BYTE 065h :761125C1 6E outsb :761125C2 637920 arpl dword ptr [ecx+20], edi :761125C5 7661 jbe 76112628 :761125C7 6C insb :761125C8 7565 jne 7611262F :761125CA 2C20 sub al, 20 :761125CC 656320 arpl dword ptr gs:[eax], esp :761125CF 256C640000 and eax, 0000646C :761125D4 49 dec ecx :761125D5 6E outsb :761125D6 7375 jnb 7611264D :761125D8 66 BYTE 066h :761125D9 66696369656E imul sp, word ptr [ebx+69], 6E65 :761125DF 7420 je 76112601 :761125E1 64 BYTE 064h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112570(C) | :761125E2 65 BYTE 065h :761125E3 7065 jo 7611264A :761125E5 6E outsb :761125E6 64 BYTE 064h :761125E7 65 BYTE 065h :761125E8 6E outsb :761125E9 637920 arpl dword ptr [ecx+20], edi :761125EC 627566 bound esi, dword ptr [ebp+66] :761125EF 66 BYTE 066h :761125F0 65 BYTE 065h :761125F1 7200 jb 761125F3 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761125F1(C) | :761125F3 00476F add byte ptr [edi+6F], al :761125F6 7420 je 76112618 :761125F8 64 BYTE 064h :761125F9 65 BYTE 065h :761125FA 7065 jo 76112661 :761125FC 6E outsb :761125FD 64 BYTE 064h :761125FE 65 BYTE 065h :761125FF 6E outsb :76112600 7420 je 76112622 :76112602 636174 arpl dword ptr [ecx+74], esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611259E(C) | :76112605 61 popad :76112606 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611259C(C) | :76112607 6F outsd :76112608 67202D and [di], ch :7611260B 202573000043 and byte ptr [43000073], ah :76112611 61 popad :76112612 6E outsb :76112613 6E outsb :76112614 6F outsd :76112615 7420 je 76112637 :76112617 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761125F6(C) | :76112618 7065 jo 7611267F :7611261A 6E outsb :7611261B 207265 and byte ptr [edx+65], dh :7611261E 676B657920 imul esp, [di+79], 00000020 :76112623 2573000000 and eax, 00000073 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761125C5(C) | :76112628 25735C2573 and eax, 73255C73 :7611262D 000000 BYTE 3 DUP(0) :76112630 53 push ebx :76112631 6F outsd :76112632 667477 je 761126AC :76112635 61 popad :76112636 7265 jb 7611269D :76112638 5C pop esp :76112639 4D dec ebp :7611263A 6963726F736F66 imul esp, dword ptr [ebx+72], 666F736F :76112641 745C je 7611269F :76112643 57 push edi :76112644 696E646F77735C imul ebp, dword ptr [esi+64], 5C73776F :7611264B 43 inc ebx :7611264C 7572 jne 761126C0 :7611264E 7265 jb 761126B5 :76112650 6E outsb :76112651 7456 je 761126A9 :76112653 65 BYTE 065h :76112654 7273 jb 761126C9 :76112656 696F6E5C537973 imul ebp, dword ptr [edi+6E], 7379535C :7611265D 7465 je 761126C4 :7611265F 6D insd :76112660 46 inc esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761125FA(C) | :76112661 696C6550726F7465 imul ebp, dword ptr [ebp+50], 65746F72 :76112669 6374696F arpl dword ptr [ecx+2*ebp+6F], esi :7611266D 6E outsb :7611266E 5C pop esp :7611266F 43 inc ebx :76112670 61 popad :76112671 7444 je 761126B7 :76112673 65 BYTE 065h :76112674 7065 jo 761126DB :76112676 6E outsb :76112677 64 BYTE 064h :76112678 00000000 BYTE 4 DUP(0) :7611267C 43 inc ebx :7611267D 61 popad :7611267E 7420 je 761126A0 :76112680 66696C65202573 imul bp, word ptr [ebp+20], 7325 :76112687 206E6F and byte ptr [esi+6F], ch :7611268A 7420 je 761126AC :7611268C 7072 jo 76112700 :7611268E 65 BYTE 065h :7611268F 7365 jnb 761126F6 :76112691 6E outsb :76112692 7420 je 761126B4 :76112694 696E2043727970 imul ebp, dword ptr [esi+20], 70797243 :7611269B 746F je 7611270C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112636(C) | :7611269D 000000 BYTE 3 DUP(0) * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611267E(C) | :761126A0 45 inc ebp :761126A1 7272 jb 76112715 :761126A3 6F outsd :761126A4 7220 jb 761126C6 :761126A6 67 BYTE 067h :761126A7 65 BYTE 065h :761126A8 7474 je 7611271E :761126AA 696E6720636174 imul ebp, dword ptr [esi+67], 74616320 :761126B1 61 popad :761126B2 6C insb :761126B3 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112692(C) | :761126B4 67207061 and [bx+si+61], dh :761126B8 7468 je 76112722 :761126BA 0000 add byte ptr [eax], al :761126BC 53 push ebx :761126BD 667051 jo 76112711 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611264C(C) | :761126C0 7565 jne 76112727 :761126C2 7279 jb 7611273D * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611265D(C) | :761126C4 43 inc ebx :761126C5 61 popad * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761126A4(C) | :761126C6 7461 je 76112729 :761126C8 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112654(C) | :761126C9 6F outsd :761126CA 67004361 add [bp+di+61], al :761126CE 6E outsb :761126CF 6E outsb :761126D0 6F outsd :761126D1 7420 je 761126F3 :761126D3 6F outsd :761126D4 7065 jo 7611273B :761126D6 6E outsb :761126D7 205678 and byte ptr [esi+78], dl :761126DA 64 BYTE 064h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112674(C) | :761126DB 4D dec ebp :761126DC 6F outsd :761126DD 6E outsb :761126DE 207265 and byte ptr [edx+65], dh :761126E1 676B657900 imul esp, [di+79], 00000000 :761126E6 0000 add byte ptr [eax], al :761126E8 257325735C and eax, 5C732573 :761126ED 2573000000 and eax, 00000073 :761126F2 0000 add byte ptr [eax], al :761126F4 7C00 jl 761126F6 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:7611268F(C), :761126F4(C) | :761126F6 0000 add byte ptr [eax], al :761126F8 43 inc ebx :761126F9 61 popad :761126FA 6E outsb :761126FB 6E outsb :761126FC 6F outsd :761126FD 7420 je 7611271F :761126FF 67 BYTE 067h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611268C(C) | :76112700 65 BYTE 065h :76112701 7420 je 76112723 :76112703 64 BYTE 064h :76112704 7269 jb 7611276F :76112706 7665 jbe 7611276D :76112708 206672 and byte ptr [esi+72], ah :7611270B 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611269B(C) | :7611270C 6D insd :7611270D 207769 and byte ptr [edi+69], dh :76112710 6E outsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761126BE(C) | :76112711 6469720000000043 imul esi, dword ptr fs:[edx+00], 43000000 :76112719 61 popad :7611271A 6E outsb :7611271B 6E outsb :7611271C 6F outsd :7611271D 7420 je 7611273F :7611271F 67 BYTE 067h :76112720 65 BYTE 065h :76112721 7420 je 76112743 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112701(C) | :76112723 7769 ja 7611278E :76112725 6E outsb :76112726 6469720000004361 imul esi, dword ptr fs:[edx+00], 61430000 :7611272E 6E outsb :7611272F 6E outsb :76112730 6F outsd :76112731 7420 je 76112753 :76112733 67 BYTE 067h :76112734 65 BYTE 065h :76112735 7420 je 76112757 :76112737 65 BYTE 065h :76112738 7863 js 7611279D :7611273A 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761126D4(C) | :7611273B 7573 jne 761127B0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761126C2(C) | :7611273D 696F6E206C6973 imul ebp, dword ptr [edi+6E], 73696C20 :76112744 7420 je 76112766 :76112746 7661 jbe 761127A9 :76112748 6C insb :76112749 7565 jne 761127B0 :7611274B 004361 add byte ptr [ebx+61], al :7611274E 6E outsb :7611274F 6E outsb :76112750 6F outsd :76112751 7420 je 76112773 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112731(C) | :76112753 61 popad :76112754 6C insb :76112755 6C insb :76112756 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112735(C) | :76112757 636174 arpl dword ptr [ecx+74], esp :7611275A 65206D65 and byte ptr gs:[ebp+65], ch :7611275E 6D insd :7611275F 20666F and byte ptr [esi+6F], ah :76112762 7220 jb 76112784 :76112764 65 BYTE 065h :76112765 7863 js 761127CA :76112767 6C insb :76112768 7573 jne 761127DD :7611276A 696F6E206C6973 imul ebp, dword ptr [edi+6E], 73696C20 :76112771 7400 je 76112773 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76112751(C), :76112771(C) | :76112773 004361 add byte ptr [ebx+61], al :76112776 6E outsb :76112777 6E outsb :76112778 6F outsd :76112779 7420 je 7611279B :7611277B 67 BYTE 067h :7611277C 65 BYTE 065h :7611277D 7420 je 7611279F :7611277F 65 BYTE 065h :76112780 7863 js 761127E5 :76112782 6C insb :76112783 7573 jne 761127F8 :76112785 696F6E206C6973 imul ebp, dword ptr [edi+6E], 73696C20 :7611278C 7420 je 761127AE * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112723(C) | :7611278E 7369 jnb 761127F9 :76112790 7A65 jpe 761127F7 :76112792 0000 add byte ptr [eax], al :76112794 55 push ebp :76112795 6E outsb :76112796 64 BYTE 064h :76112797 6F outsd :76112798 65 BYTE 065h :76112799 7220 jb 761127BB * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112779(C) | :7611279B 64 BYTE 064h :7611279C 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112738(C) | :7611279D 65 BYTE 065h :7611279E 7320 jnb 761127C0 :761127A0 6E outsb :761127A1 6F outsd :761127A2 7420 je 761127C4 :761127A4 65 BYTE 065h :761127A5 7869 js 76112810 :761127A7 7374 jnb 7611281D * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112746(C) | :761127A9 000000 BYTE 3 DUP(0) :761127AC 53 push ebx :761127AD 52 push edx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611278C(C) | :761127AE 44 inc esp :761127AF 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:7611273B(C), :76112749(C) | :761127B0 7465 je 76112817 :761127B2 6374556E arpl dword ptr [ebp+2*edx+6E], esi :761127B6 64 BYTE 064h :761127B7 6F outsd :761127B8 65 BYTE 065h :761127B9 7200 jb 761127BB * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76112799(C), :761127B9(C) | :761127BB 004669 add byte ptr [esi+69], al :761127BE 6C insb :761127BF 652020 and byte ptr gs:[eax], ah :761127C2 65 BYTE 065h :761127C3 7869 js 7611282E :761127C5 7374 jnb 7611283B :761127C7 7300 jnb 761127C9 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761127C7(C) | :761127C9 000000 BYTE 3 DUP(0) :761127CC 49 dec ecx :761127CD 7420 je 761127EF :761127CF 69732061204469 imul esi, dword ptr [ebx+20], 69442061 :761127D6 7265 jb 7611283D :761127D8 63746F72 arpl dword ptr [edi+2*ebp+72], esi :761127DC 7920 jns 761127FE :761127DE 0000 add byte ptr [eax], al :761127E0 47 inc edi :761127E1 65 BYTE 065h :761127E2 7446 je 7611282A :761127E4 696C654174747269 imul ebp, dword ptr [ebp+41], 69727474 :761127EC 627574 bound esi, dword ptr [ebp+74] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761127CD(C) | :761127EF 65 BYTE 065h :761127F0 7320 jnb 76112812 :761127F2 6661 popa :761127F4 696C656420307825 imul ebp, dword ptr [ebp+64], 25783020 :761127FC 7800 js 761127FE :761127FE 0000 add byte ptr [eax], al :76112800 43 inc ebx :76112801 6865636B69 push 696B6365 :76112806 6E outsb :76112807 6720666F and [bp+6F], ah :7611280B 7220 jb 7611282D :7611280D 257300446F and eax, 6F440073 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761127F0(C) | :76112812 65 BYTE 065h :76112813 7346 jnb 7611285B :76112815 696C654578697374 imul ebp, dword ptr [ebp+45], 74736978 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761127A7(C) | :7611281D 000000 BYTE 3 DUP(0) :76112820 44 inc esp :76112821 69726563746F72 imul esi, dword ptr [edx+65], 726F7463 :76112828 7920 jns 7611284A * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761127E2(C) | :7611282A 64 BYTE 064h :7611282B 6F outsd :7611282C 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611280B(C) | :7611282D 7320 jnb 7611284F :7611282F 6E outsb :76112830 6F outsd :76112831 7420 je 76112853 :76112833 65 BYTE 065h :76112834 7869 js 7611289F :76112836 7374 jnb 761128AC :76112838 00000000 BYTE 4 DUP(0) :7611283C 44 inc esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761127D6(C) | :7611283D 69726563746F72 imul esi, dword ptr [edx+65], 726F7463 :76112844 7920 jns 76112866 :76112846 65 BYTE 065h :76112847 7869 js 761128B2 :76112849 7374 jnb 761128BF :7611284B 7320 jnb 7611286D :7611284D 000000 BYTE 3 DUP(0) :76112850 204368 and byte ptr [ebx+68], al * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112831(C) | :76112853 65636B69 arpl dword ptr gs:[ebx+69], ebp :76112857 6E outsb :76112858 6720666F and [bp+6F], ah :7611285C 7220 jb 7611287E :7611285E 2573000000 and eax, 00000073 :76112863 00446F65 add byte ptr [edi+2*ebp+65], al :76112867 7344 jnb 761128AD :76112869 69724578697374 imul esi, dword ptr [edx+45], 74736978 :76112870 00000000 BYTE 4 DUP(0) :76112874 4D dec ebp :76112875 756C jne 761128E3 :76112877 7469 je 761128E2 :76112879 42 inc edx :7611287A 7974 jns 761128F0 :7611287C 65 BYTE 065h :7611287D 54 push esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611285C(C) | :7611287E 6F outsd :7611287F 57 push edi :76112880 6964654368617228 imul esp, dword ptr [ebp+43], 28726168 :76112888 2029 and byte ptr [ecx], ch :7611288A 206661 and byte ptr [esi+61], ah :7611288D 696C65642D202065 imul ebp, dword ptr [ebp+64], 6520202D :76112895 632D2D256400 arpl dword ptr [0064252D], ebp :7611289B 004358 add byte ptr [ebx+58], al :7611289E 4D dec ebp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112834(C) | :7611289F 4C dec esp :761128A0 46 inc esi :761128A1 696C654C69737450 imul ebp, dword ptr [ebp+4C], 50747369 :761128A9 61 popad :761128AA 7273 jb 7611291F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112836(C) | :761128AC 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112867(C) | :761128AD 723A jb 761128E9 :761128AF 3A4765 cmp al, byte ptr [edi+65] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112847(C) | :761128B2 7446 je 761128FA :761128B4 69656C64000000 imul esp, dword ptr [ebp+6C], 00000064 :761128BB 004572 add byte ptr [ebp+72], al :761128BE 726F jb 7611292F :761128C0 7220 jb 761128E2 :761128C2 67 BYTE 067h :761128C3 65 BYTE 065h :761128C4 7474 je 7611293A :761128C6 696E6720636F64 imul ebp, dword ptr [esi+67], 646F6320 :761128CD 65207061 and byte ptr gs:[eax+61], dh :761128D1 67 BYTE 067h :761128D2 65 BYTE 065h :761128D3 2E BYTE 02eh :761128D4 00000000 BYTE 4 DUP(0) :761128D8 45 inc ebp :761128D9 7272 jb 7611294D :761128DB 6F outsd :761128DC 7220 jb 761128FE :761128DE 7175 jno 76112955 :761128E0 65 BYTE 065h :761128E1 7279 jb 7611295C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112875(C) | :761128E3 696E6720636F64 imul ebp, dword ptr [esi+67], 646F6320 :761128EA 65206C6F63 and byte ptr gs:[edi+2*ebp+63], ch :761128EF 61 popad * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611287A(C) | :761128F0 6C insb :761128F1 65 BYTE 065h :761128F2 2E004765 add byte ptr cs:[edi+65], al :761128F6 7443 je 7611293B :761128F8 7572 jne 7611296C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761128B2(C) | :761128FA 7265 jb 76112961 :761128FC 6E outsb :761128FD 7443 je 76112942 :761128FF 6F outsd :76112900 64 BYTE 064h :76112901 65 BYTE 065h :76112902 50 push eax :76112903 61 popad :76112904 67 BYTE 067h :76112905 65 BYTE 065h :76112906 0000 add byte ptr [eax], al :76112908 312E xor dword ptr [esi], ebp :7611290A 332E xor ebp, dword ptr [esi] :7611290C 36 BYTE 036h :7611290D 2E312E xor dword ptr cs:[esi], ebp :76112910 342E xor al, 2E :76112912 312E xor dword ptr [esi], ebp :76112914 3331 xor esi, dword ptr [ecx] :76112916 312E xor dword ptr [esi], ebp :76112918 3130 xor dword ptr [eax], esi :7611291A 2E332E xor ebp, dword ptr cs:[esi] :7611291D 36 BYTE 036h :7611291E 0000 add byte ptr [eax], al :76112920 45 inc ebp :76112921 7272 jb 76112995 :76112923 6F outsd :76112924 7220 jb 76112946 :76112926 64 BYTE 064h :76112927 7570 jne 76112999 :76112929 6C insb :7611292A 69636174696E67 imul esp, dword ptr [ebx+61], 676E6974 :76112931 206361 and byte ptr [ebx+61], ah :76112934 7461 je 76112997 :76112936 6C insb :76112937 6F outsd :76112938 6720726F and [bp+si+6F], dh :7611293C 6F outsd :7611293D 7420 je 7611295F :7611293F 7061 jo 761129A2 :76112941 7468 je 761129AB :76112943 004343 add byte ptr [ebx+43], al * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112924(C) | :76112946 61 popad :76112947 7455 je 7611299E :76112949 7469 je 761129B4 :7611294B 6C insb :7611294C 733A jnb 76112988 :7611294E 3A496E cmp cl, byte ptr [ecx+6E] :76112951 6974282900000041 imul esi, dword ptr [eax+ebp+29], 41000000 :76112959 6C insb :7611295A 7465 je 761129C1 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761128E1(C) | :7611295C 726E jb 761129CC :7611295E 61 popad * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611293D(C) | :7611295F 7465 je 761129C6 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761128FA(C) | :76112961 206361 and byte ptr [ebx+61], ah :76112964 7420 je 76112986 :76112966 6469726563746F72 imul esi, dword ptr fs:[edx+65], 726F7463 :7611296E 7920 jns 76112990 :76112970 6E outsb :76112971 6F outsd :76112972 6E outsb :76112973 2D65786973 sub eax, 73697865 :76112978 7461 je 761129DB :7611297A 6E outsb :7611297B 742E je 761129AB :7611297D 000000 BYTE 3 DUP(0) :76112980 43 inc ebx :76112981 41 inc ecx :76112982 54 push esp :76112983 41 inc ecx :76112984 4C dec esp :76112985 4F dec edi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112964(C) | :76112986 47 inc edi :76112987 20646972 and byte ptr [ecx+2*ebp+72], ah :7611298B 6563746F72 arpl dword ptr gs:[edi+2*ebp+72], esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611296E(C) | :76112990 7920 jns 761129B2 :76112992 6E outsb :76112993 6F outsd :76112994 7420 je 761129B6 :76112996 666F outsw :76112998 756E jne 76112A08 :7611299A 64 BYTE 064h :7611299B 2D2D206368 sub eax, 6863202D :761129A0 65636B69 arpl dword ptr gs:[ebx+69], ebp :761129A4 6E outsb :761129A5 6720433A and [bp+di+3A], al :761129A9 5C pop esp :761129AA 7769 ja 76112A15 :761129AC 6E outsb :761129AD 64 BYTE 064h :761129AE 6F outsd :761129AF 7773 ja 76112A24 :761129B1 5C pop esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112990(C) | :761129B2 636174 arpl dword ptr [ecx+74], esp :761129B5 726F jb 76112A26 :761129B7 6F outsd :761129B8 7420 je 761129DA :761129BA 2E BYTE 02eh :761129BB 2E BYTE 02eh :761129BC 00000000 BYTE 4 DUP(0) :761129C0 25735C2573 and eax, 73255C73 :761129C5 5C pop esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611295F(C) | :761129C6 2573000000 and eax, 00000073 :761129CB 004361 add byte ptr [ebx+61], al :761129CE 7452 je 76112A22 :761129D0 6F outsd :761129D1 6F outsd :761129D2 7400 je 761129D4 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761129D2(C) | :761129D4 7B46 jpo 76112A1C :761129D6 37 aaa :761129D7 3530453643 xor eax, 43364530 :761129DC 332D33384545 xor ebp, dword ptr [45453833] :761129E2 2D31314431 sub eax, 31443131 :761129E7 2D38354535 sub eax, 35453538 :761129EC 2D30304330 sub eax, 30433030 :761129F1 3446 xor al, 46 :761129F3 43 inc ebx :761129F4 3239 xor bh, byte ptr [ecx] :761129F6 3545457D00 xor eax, 007D4545 :761129FB 004572 add byte ptr [ebp+72], al :761129FE 726F jb 76112A6F :76112A00 7220 jb 76112A22 :76112A02 67 BYTE 067h :76112A03 65 BYTE 065h :76112A04 7474 je 76112A7A :76112A06 696E6720746865 imul ebp, dword ptr [esi+67], 65687420 :76112A0D 207379 and byte ptr [ebx+79], dh :76112A10 7374 jnb 76112A86 :76112A12 65 BYTE 065h :76112A13 6D insd :76112A14 20646972 and byte ptr [ecx+2*ebp+72], ah :76112A18 6563746F72 arpl dword ptr gs:[edi+2*ebp+72], esi :76112A1D 7900 jns 76112A1F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112A1D(C) | :76112A1F 004275 add byte ptr [edx+75], al * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761129CE(C), :76112A00(C) | :76112A22 66 BYTE 066h :76112A23 66 BYTE 066h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761129AF(C) | :76112A24 65 BYTE 065h :76112A25 7220 jb 76112A47 :76112A27 746F je 76112A98 :76112A29 6F outsd :76112A2A 20736D and byte ptr [ebx+6D], dh :76112A2D 61 popad :76112A2E 6C insb :76112A2F 6C insb :76112A30 00000000 BYTE 4 DUP(0) :76112A34 55 push ebp :76112A35 6E outsb :76112A36 697469616C697A65 imul esi, dword ptr [ecx+2*ebp+61], 657A696C :76112A3E 64205574 and byte ptr fs:[ebp+74], dl :76112A42 696C697469657300 imul ebp, dword ptr [ecx+2*ebp+74], 00736569 :76112A4A 0000 add byte ptr [eax], al :76112A4C 43 inc ebx :76112A4D 43 inc ebx :76112A4E 61 popad :76112A4F 7455 je 76112AA6 :76112A51 7469 je 76112ABC :76112A53 6C insb :76112A54 733A jnb 76112A90 :76112A56 3A4765 cmp al, byte ptr [edi+65] :76112A59 7446 je 76112AA1 :76112A5B 756C jne 76112AC9 :76112A5D 6C insb :76112A5E 43 inc ebx :76112A5F 61 popad :76112A60 7450 je 76112AB2 :76112A62 61 popad :76112A63 7468 je 76112ACD :76112A65 00000000000000000000 BYTE 10 DUP(0) * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761129FE(C) | :76112A6F 00 BYTE 0 * Referenced by a CALL at Address: |:76113B3B | :76112A70 55 push ebp :76112A71 8BEC mov ebp, esp :76112A73 6AFF push FFFFFFFF :76112A75 6830131176 push 76111330 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112A04(C) | :76112A7A 6810591176 push 76115910 :76112A7F 64A100000000 mov eax, dword ptr fs:[00000000] :76112A85 50 push eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112A10(C) | :76112A86 64892500000000 mov dword ptr fs:[00000000], esp :76112A8D 81EC04010000 sub esp, 00000104 :76112A93 53 push ebx :76112A94 56 push esi :76112A95 57 push edi :76112A96 33C0 xor eax, eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112A27(C) | :76112A98 394508 cmp dword ptr [ebp+08], eax :76112A9B 750B jne 76112AA8 :76112A9D 68F4060000 push 000006F4 * Reference To: RPCRT4.RpcRaiseException, Ord:017Ah | :76112AA2 FF15B8101176 Call dword ptr [761110B8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112A9B(C) | :76112AA8 8945FC mov dword ptr [ebp-04], eax :76112AAB 50 push eax :76112AAC 68A0111176 push 761111A0 :76112AB1 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112AB7 50 push eax :76112AB8 8D85F0FEFFFF lea eax, dword ptr [ebp+FFFFFEF0] :76112ABE 50 push eax * Reference To: RPCRT4.NdrClientInitializeNew, Ord:007Fh | :76112ABF FF1584101176 Call dword ptr [76111084] :76112AC5 8B1DE0791176 mov ebx, dword ptr [761179E0] :76112ACB 895DE4 mov dword ptr [ebp-1C], ebx :76112ACE C78530FFFFFF24000000 mov dword ptr [ebp+FFFFFF30], 00000024 :76112AD8 BFDE121176 mov edi, 761112DE :76112ADD 57 push edi :76112ADE FF7508 push [ebp+08] :76112AE1 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112AE7 50 push eax * Reference To: RPCRT4.NdrConformantStringBufferSize, Ord:008Fh | :76112AE8 FF15C0101176 Call dword ptr [761110C0] :76112AEE BEE0121176 mov esi, 761112E0 :76112AF3 56 push esi :76112AF4 FF750C push [ebp+0C] :76112AF7 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112AFD 50 push eax * Reference To: RPCRT4.NdrPointerBufferSize, Ord:00EBh | :76112AFE FF1598101176 Call dword ptr [76111098] :76112B04 53 push ebx :76112B05 FFB530FFFFFF push dword ptr [ebp+FFFFFF30] :76112B0B 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112B11 50 push eax * Reference To: RPCRT4.NdrGetBuffer, Ord:00C0h | :76112B12 FF158C101176 Call dword ptr [7611108C] :76112B18 57 push edi :76112B19 FF7508 push [ebp+08] :76112B1C 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112B22 50 push eax * Reference To: RPCRT4.NdrConformantStringMarshall, Ord:0090h | :76112B23 FF1588101176 Call dword ptr [76111088] :76112B29 56 push esi :76112B2A FF750C push [ebp+0C] :76112B2D 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112B33 50 push eax * Reference To: RPCRT4.NdrPointerMarshall, Ord:00EDh | :76112B34 FF159C101176 Call dword ptr [7611109C] :76112B3A FFB520FFFFFF push dword ptr [ebp+FFFFFF20] :76112B40 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112B46 50 push eax * Reference To: RPCRT4.NdrSendReceive, Ord:00FDh | :76112B47 FF15C4101176 Call dword ptr [761110C4] :76112B4D 8B85F4FEFFFF mov eax, dword ptr [ebp+FFFFFEF4] :76112B53 25FFFF0000 and eax, 0000FFFF :76112B58 83F810 cmp eax, 00000010 :76112B5B 7412 je 76112B6F :76112B5D 688A121176 push 7611128A :76112B62 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112B68 50 push eax * Reference To: RPCRT4.NdrConvert, Ord:00A4h | :76112B69 FF15C8101176 Call dword ptr [761110C8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112B5B(C) | :76112B6F 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :76112B75 8B00 mov eax, dword ptr [eax] :76112B77 8985ECFEFFFF mov dword ptr [ebp+FFFFFEEC], eax :76112B7D 838520FFFFFF04 add dword ptr [ebp+FFFFFF20], 00000004 :76112B84 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76112B88 E817000000 call 76112BA4 :76112B8D 8B85ECFEFFFF mov eax, dword ptr [ebp+FFFFFEEC] :76112B93 8B4DF0 mov ecx, dword ptr [ebp-10] :76112B96 64890D00000000 mov dword ptr fs:[00000000], ecx :76112B9D 5F pop edi :76112B9E 5E pop esi :76112B9F 5B pop ebx :76112BA0 C9 leave :76112BA1 C20800 ret 0008 * Referenced by a CALL at Address: |:76112B88 | :76112BA4 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112BAA 50 push eax * Reference To: RPCRT4.NdrFreeBuffer, Ord:00B9h | :76112BAB FF15CC101176 Call dword ptr [761110CC] :76112BB1 C3 ret * Referenced by a CALL at Address: |:76113D6D | :76112BB2 55 push ebp :76112BB3 8BEC mov ebp, esp :76112BB5 6AFF push FFFFFFFF :76112BB7 6840131176 push 76111340 :76112BBC 6810591176 push 76115910 :76112BC1 64A100000000 mov eax, dword ptr fs:[00000000] :76112BC7 50 push eax :76112BC8 64892500000000 mov dword ptr fs:[00000000], esp :76112BCF 81EC04010000 sub esp, 00000104 :76112BD5 53 push ebx :76112BD6 56 push esi :76112BD7 57 push edi :76112BD8 837D0800 cmp dword ptr [ebp+08], 00000000 :76112BDC 750B jne 76112BE9 :76112BDE 68F4060000 push 000006F4 * Reference To: RPCRT4.RpcRaiseException, Ord:017Ah | :76112BE3 FF15B8101176 Call dword ptr [761110B8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112BDC(C) | :76112BE9 8365FC00 and dword ptr [ebp-04], 00000000 :76112BED 6A01 push 00000001 :76112BEF 68A0111176 push 761111A0 :76112BF4 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112BFA 50 push eax :76112BFB 8D85F0FEFFFF lea eax, dword ptr [ebp+FFFFFEF0] :76112C01 50 push eax * Reference To: RPCRT4.NdrClientInitializeNew, Ord:007Fh | :76112C02 FF1584101176 Call dword ptr [76111084] :76112C08 8B3DE0791176 mov edi, dword ptr [761179E0] :76112C0E 897DE4 mov dword ptr [ebp-1C], edi :76112C11 C78530FFFFFF17000000 mov dword ptr [ebp+FFFFFF30], 00000017 :76112C1B BEDE121176 mov esi, 761112DE :76112C20 56 push esi :76112C21 FF7508 push [ebp+08] :76112C24 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112C2A 50 push eax * Reference To: RPCRT4.NdrConformantStringBufferSize, Ord:008Fh | :76112C2B FF15C0101176 Call dword ptr [761110C0] :76112C31 57 push edi :76112C32 FFB530FFFFFF push dword ptr [ebp+FFFFFF30] :76112C38 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112C3E 50 push eax * Reference To: RPCRT4.NdrGetBuffer, Ord:00C0h | :76112C3F FF158C101176 Call dword ptr [7611108C] :76112C45 56 push esi :76112C46 FF7508 push [ebp+08] :76112C49 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112C4F 50 push eax * Reference To: RPCRT4.NdrConformantStringMarshall, Ord:0090h | :76112C50 FF1588101176 Call dword ptr [76111088] :76112C56 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :76112C5C 83C003 add eax, 00000003 :76112C5F 24FC and al, FC :76112C61 898520FFFFFF mov dword ptr [ebp+FFFFFF20], eax :76112C67 8B4D0C mov ecx, dword ptr [ebp+0C] :76112C6A 8908 mov dword ptr [eax], ecx :76112C6C 838520FFFFFF04 add dword ptr [ebp+FFFFFF20], 00000004 :76112C73 FFB520FFFFFF push dword ptr [ebp+FFFFFF20] :76112C79 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112C7F 50 push eax * Reference To: RPCRT4.NdrSendReceive, Ord:00FDh | :76112C80 FF15C4101176 Call dword ptr [761110C4] :76112C86 8B85F4FEFFFF mov eax, dword ptr [ebp+FFFFFEF4] :76112C8C 25FFFF0000 and eax, 0000FFFF :76112C91 83F810 cmp eax, 00000010 :76112C94 7412 je 76112CA8 :76112C96 6894121176 push 76111294 :76112C9B 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112CA1 50 push eax * Reference To: RPCRT4.NdrConvert, Ord:00A4h | :76112CA2 FF15C8101176 Call dword ptr [761110C8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112C94(C) | :76112CA8 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :76112CAE 8B00 mov eax, dword ptr [eax] :76112CB0 8985ECFEFFFF mov dword ptr [ebp+FFFFFEEC], eax :76112CB6 838520FFFFFF04 add dword ptr [ebp+FFFFFF20], 00000004 :76112CBD 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76112CC1 E817000000 call 76112CDD :76112CC6 8B85ECFEFFFF mov eax, dword ptr [ebp+FFFFFEEC] :76112CCC 8B4DF0 mov ecx, dword ptr [ebp-10] :76112CCF 64890D00000000 mov dword ptr fs:[00000000], ecx :76112CD6 5F pop edi :76112CD7 5E pop esi :76112CD8 5B pop ebx :76112CD9 C9 leave :76112CDA C20800 ret 0008 * Referenced by a CALL at Address: |:76112CC1 | :76112CDD 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112CE3 50 push eax * Reference To: RPCRT4.NdrFreeBuffer, Ord:00B9h | :76112CE4 FF15CC101176 Call dword ptr [761110CC] :76112CEA C3 ret * Referenced by a CALL at Address: |:76113F5D | :76112CEB 55 push ebp :76112CEC 8BEC mov ebp, esp :76112CEE 6AFF push FFFFFFFF :76112CF0 6850131176 push 76111350 :76112CF5 6810591176 push 76115910 :76112CFA 64A100000000 mov eax, dword ptr fs:[00000000] :76112D00 50 push eax :76112D01 64892500000000 mov dword ptr fs:[00000000], esp :76112D08 81EC04010000 sub esp, 00000104 :76112D0E 53 push ebx :76112D0F 56 push esi :76112D10 57 push edi :76112D11 837D0800 cmp dword ptr [ebp+08], 00000000 :76112D15 750B jne 76112D22 :76112D17 68F4060000 push 000006F4 * Reference To: RPCRT4.RpcRaiseException, Ord:017Ah | :76112D1C FF15B8101176 Call dword ptr [761110B8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112D15(C) | :76112D22 8365FC00 and dword ptr [ebp-04], 00000000 :76112D26 6A02 push 00000002 :76112D28 68A0111176 push 761111A0 :76112D2D 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112D33 50 push eax :76112D34 8D85F0FEFFFF lea eax, dword ptr [ebp+FFFFFEF0] :76112D3A 50 push eax * Reference To: RPCRT4.NdrClientInitializeNew, Ord:007Fh | :76112D3B FF1584101176 Call dword ptr [76111084] :76112D41 8B3DE0791176 mov edi, dword ptr [761179E0] :76112D47 897DE4 mov dword ptr [ebp-1C], edi :76112D4A C78530FFFFFF0C000000 mov dword ptr [ebp+FFFFFF30], 0000000C :76112D54 BEDE121176 mov esi, 761112DE :76112D59 56 push esi :76112D5A FF7508 push [ebp+08] :76112D5D 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112D63 50 push eax * Reference To: RPCRT4.NdrConformantStringBufferSize, Ord:008Fh | :76112D64 FF15C0101176 Call dword ptr [761110C0] :76112D6A 57 push edi :76112D6B FFB530FFFFFF push dword ptr [ebp+FFFFFF30] :76112D71 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112D77 50 push eax * Reference To: RPCRT4.NdrGetBuffer, Ord:00C0h | :76112D78 FF158C101176 Call dword ptr [7611108C] :76112D7E 56 push esi :76112D7F FF7508 push [ebp+08] :76112D82 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112D88 50 push eax * Reference To: RPCRT4.NdrConformantStringMarshall, Ord:0090h | :76112D89 FF1588101176 Call dword ptr [76111088] :76112D8F FFB520FFFFFF push dword ptr [ebp+FFFFFF20] :76112D95 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112D9B 50 push eax * Reference To: RPCRT4.NdrSendReceive, Ord:00FDh | :76112D9C FF15C4101176 Call dword ptr [761110C4] :76112DA2 8B85F4FEFFFF mov eax, dword ptr [ebp+FFFFFEF4] :76112DA8 25FFFF0000 and eax, 0000FFFF :76112DAD 83F810 cmp eax, 00000010 :76112DB0 7412 je 76112DC4 :76112DB2 689C121176 push 7611129C :76112DB7 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112DBD 50 push eax * Reference To: RPCRT4.NdrConvert, Ord:00A4h | :76112DBE FF15C8101176 Call dword ptr [761110C8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112DB0(C) | :76112DC4 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :76112DCA 8B00 mov eax, dword ptr [eax] :76112DCC 8985ECFEFFFF mov dword ptr [ebp+FFFFFEEC], eax :76112DD2 838520FFFFFF04 add dword ptr [ebp+FFFFFF20], 00000004 :76112DD9 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76112DDD E817000000 call 76112DF9 :76112DE2 8B85ECFEFFFF mov eax, dword ptr [ebp+FFFFFEEC] :76112DE8 8B4DF0 mov ecx, dword ptr [ebp-10] :76112DEB 64890D00000000 mov dword ptr fs:[00000000], ecx :76112DF2 5F pop edi :76112DF3 5E pop esi :76112DF4 5B pop ebx :76112DF5 C9 leave :76112DF6 C20400 ret 0004 * Referenced by a CALL at Address: |:76112DDD | :76112DF9 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112DFF 50 push eax * Reference To: RPCRT4.NdrFreeBuffer, Ord:00B9h | :76112E00 FF15CC101176 Call dword ptr [761110CC] :76112E06 C3 ret * Referenced by a CALL at Address: |:761140ED | :76112E07 55 push ebp :76112E08 8BEC mov ebp, esp :76112E0A 6AFF push FFFFFFFF :76112E0C 6860131176 push 76111360 :76112E11 6810591176 push 76115910 :76112E16 64A100000000 mov eax, dword ptr fs:[00000000] :76112E1C 50 push eax :76112E1D 64892500000000 mov dword ptr fs:[00000000], esp :76112E24 81EC04010000 sub esp, 00000104 :76112E2A 53 push ebx :76112E2B 56 push esi :76112E2C 57 push edi :76112E2D 33DB xor ebx, ebx :76112E2F 395D08 cmp dword ptr [ebp+08], ebx :76112E32 750B jne 76112E3F :76112E34 68F4060000 push 000006F4 * Reference To: RPCRT4.RpcRaiseException, Ord:017Ah | :76112E39 FF15B8101176 Call dword ptr [761110B8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112E32(C) | :76112E3F 895DFC mov dword ptr [ebp-04], ebx :76112E42 6A03 push 00000003 :76112E44 68A0111176 push 761111A0 :76112E49 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112E4F 50 push eax :76112E50 8D85F0FEFFFF lea eax, dword ptr [ebp+FFFFFEF0] :76112E56 50 push eax * Reference To: RPCRT4.NdrClientInitializeNew, Ord:007Fh | :76112E57 FF1584101176 Call dword ptr [76111084] :76112E5D 8B3DE0791176 mov edi, dword ptr [761179E0] :76112E63 897DE4 mov dword ptr [ebp-1C], edi :76112E66 899D30FFFFFF mov dword ptr [ebp+FFFFFF30], ebx :76112E6C BEEE121176 mov esi, 761112EE :76112E71 56 push esi :76112E72 FF7508 push [ebp+08] :76112E75 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112E7B 50 push eax * Reference To: RPCRT4.NdrSimpleStructBufferSize, Ord:010Bh | :76112E7C FF15AC101176 Call dword ptr [761110AC] :76112E82 57 push edi :76112E83 FFB530FFFFFF push dword ptr [ebp+FFFFFF30] :76112E89 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112E8F 50 push eax * Reference To: RPCRT4.NdrGetBuffer, Ord:00C0h | :76112E90 FF158C101176 Call dword ptr [7611108C] :76112E96 56 push esi :76112E97 FF7508 push [ebp+08] :76112E9A 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112EA0 50 push eax * Reference To: RPCRT4.NdrSimpleStructMarshall, Ord:010Dh | :76112EA1 FF15B0101176 Call dword ptr [761110B0] :76112EA7 FFB520FFFFFF push dword ptr [ebp+FFFFFF20] :76112EAD 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112EB3 50 push eax * Reference To: RPCRT4.NdrSendReceive, Ord:00FDh | :76112EB4 FF15C4101176 Call dword ptr [761110C4] :76112EBA 8B85F4FEFFFF mov eax, dword ptr [ebp+FFFFFEF4] :76112EC0 25FFFF0000 and eax, 0000FFFF :76112EC5 83F810 cmp eax, 00000010 :76112EC8 7412 je 76112EDC :76112ECA 68A2121176 push 761112A2 :76112ECF 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112ED5 50 push eax * Reference To: RPCRT4.NdrConvert, Ord:00A4h | :76112ED6 FF15C8101176 Call dword ptr [761110C8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112EC8(C) | :76112EDC 53 push ebx :76112EDD 56 push esi :76112EDE 8D4508 lea eax, dword ptr [ebp+08] :76112EE1 50 push eax :76112EE2 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112EE8 50 push eax * Reference To: RPCRT4.NdrSimpleStructUnmarshall, Ord:010Fh | :76112EE9 FF15B4101176 Call dword ptr [761110B4] :76112EEF 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :76112EF5 8B00 mov eax, dword ptr [eax] :76112EF7 8985ECFEFFFF mov dword ptr [ebp+FFFFFEEC], eax :76112EFD 838520FFFFFF04 add dword ptr [ebp+FFFFFF20], 00000004 :76112F04 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76112F08 E817000000 call 76112F24 :76112F0D 8B85ECFEFFFF mov eax, dword ptr [ebp+FFFFFEEC] :76112F13 8B4DF0 mov ecx, dword ptr [ebp-10] :76112F16 64890D00000000 mov dword ptr fs:[00000000], ecx :76112F1D 5F pop edi :76112F1E 5E pop esi :76112F1F 5B pop ebx :76112F20 C9 leave :76112F21 C20400 ret 0004 * Referenced by a CALL at Address: |:76112F08 | :76112F24 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112F2A 50 push eax * Reference To: RPCRT4.NdrFreeBuffer, Ord:00B9h | :76112F2B FF15CC101176 Call dword ptr [761110CC] :76112F31 C3 ret * Referenced by a CALL at Address: |:7611422E | :76112F32 55 push ebp :76112F33 8BEC mov ebp, esp :76112F35 6AFF push FFFFFFFF :76112F37 6870131176 push 76111370 :76112F3C 6810591176 push 76115910 :76112F41 64A100000000 mov eax, dword ptr fs:[00000000] :76112F47 50 push eax :76112F48 64892500000000 mov dword ptr fs:[00000000], esp :76112F4F 81EC04010000 sub esp, 00000104 :76112F55 53 push ebx :76112F56 56 push esi :76112F57 57 push edi :76112F58 33DB xor ebx, ebx :76112F5A 395D08 cmp dword ptr [ebp+08], ebx :76112F5D 750B jne 76112F6A :76112F5F 68F4060000 push 000006F4 * Reference To: RPCRT4.RpcRaiseException, Ord:017Ah | :76112F64 FF15B8101176 Call dword ptr [761110B8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112F5D(C) | :76112F6A 395D0C cmp dword ptr [ebp+0C], ebx :76112F6D 750B jne 76112F7A :76112F6F 68F4060000 push 000006F4 * Reference To: RPCRT4.RpcRaiseException, Ord:017Ah | :76112F74 FF15B8101176 Call dword ptr [761110B8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76112F6D(C) | :76112F7A 895DFC mov dword ptr [ebp-04], ebx :76112F7D 6A04 push 00000004 :76112F7F 68A0111176 push 761111A0 :76112F84 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112F8A 50 push eax :76112F8B 8D85F0FEFFFF lea eax, dword ptr [ebp+FFFFFEF0] :76112F91 50 push eax * Reference To: RPCRT4.NdrClientInitializeNew, Ord:007Fh | :76112F92 FF1584101176 Call dword ptr [76111084] :76112F98 8B3DE0791176 mov edi, dword ptr [761179E0] :76112F9E 897DE4 mov dword ptr [ebp-1C], edi :76112FA1 C78530FFFFFF17000000 mov dword ptr [ebp+FFFFFF30], 00000017 :76112FAB BEDE121176 mov esi, 761112DE :76112FB0 56 push esi :76112FB1 FF7508 push [ebp+08] :76112FB4 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112FBA 50 push eax * Reference To: RPCRT4.NdrConformantStringBufferSize, Ord:008Fh | :76112FBB FF15C0101176 Call dword ptr [761110C0] :76112FC1 57 push edi :76112FC2 FFB530FFFFFF push dword ptr [ebp+FFFFFF30] :76112FC8 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112FCE 50 push eax * Reference To: RPCRT4.NdrGetBuffer, Ord:00C0h | :76112FCF FF158C101176 Call dword ptr [7611108C] :76112FD5 56 push esi :76112FD6 FF7508 push [ebp+08] :76112FD9 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76112FDF 50 push eax * Reference To: RPCRT4.NdrConformantStringMarshall, Ord:0090h | :76112FE0 FF1588101176 Call dword ptr [76111088] :76112FE6 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :76112FEC 83C003 add eax, 00000003 :76112FEF 24FC and al, FC :76112FF1 898520FFFFFF mov dword ptr [ebp+FFFFFF20], eax :76112FF7 8B4D10 mov ecx, dword ptr [ebp+10] :76112FFA 8908 mov dword ptr [eax], ecx :76112FFC 838520FFFFFF04 add dword ptr [ebp+FFFFFF20], 00000004 :76113003 FFB520FFFFFF push dword ptr [ebp+FFFFFF20] :76113009 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :7611300F 50 push eax * Reference To: RPCRT4.NdrSendReceive, Ord:00FDh | :76113010 FF15C4101176 Call dword ptr [761110C4] :76113016 8B85F4FEFFFF mov eax, dword ptr [ebp+FFFFFEF4] :7611301C 25FFFF0000 and eax, 0000FFFF :76113021 83F810 cmp eax, 00000010 :76113024 7412 je 76113038 :76113026 68A8121176 push 761112A8 :7611302B 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113031 50 push eax * Reference To: RPCRT4.NdrConvert, Ord:00A4h | :76113032 FF15C8101176 Call dword ptr [761110C8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113024(C) | :76113038 53 push ebx * Possible StringData Ref from Code Obj ->""D@" | :76113039 68FC121176 push 761112FC :7611303E 8D450C lea eax, dword ptr [ebp+0C] :76113041 50 push eax :76113042 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113048 50 push eax * Reference To: RPCRT4.NdrConformantStringUnmarshall, Ord:0092h | :76113049 FF15A8101176 Call dword ptr [761110A8] :7611304F 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :76113055 83C003 add eax, 00000003 :76113058 24FC and al, FC :7611305A 898520FFFFFF mov dword ptr [ebp+FFFFFF20], eax :76113060 8B08 mov ecx, dword ptr [eax] :76113062 898DECFEFFFF mov dword ptr [ebp+FFFFFEEC], ecx :76113068 83C004 add eax, 00000004 :7611306B 898520FFFFFF mov dword ptr [ebp+FFFFFF20], eax :76113071 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76113075 E817000000 call 76113091 :7611307A 8B85ECFEFFFF mov eax, dword ptr [ebp+FFFFFEEC] :76113080 8B4DF0 mov ecx, dword ptr [ebp-10] :76113083 64890D00000000 mov dword ptr fs:[00000000], ecx :7611308A 5F pop edi :7611308B 5E pop esi :7611308C 5B pop ebx :7611308D C9 leave :7611308E C20C00 ret 000C * Referenced by a CALL at Address: |:76113075 | :76113091 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113097 50 push eax * Reference To: RPCRT4.NdrFreeBuffer, Ord:00B9h | :76113098 FF15CC101176 Call dword ptr [761110CC] :7611309E C3 ret * Referenced by a CALL at Address: |:76114359 | :7611309F 55 push ebp :761130A0 8BEC mov ebp, esp :761130A2 6AFF push FFFFFFFF :761130A4 6880131176 push 76111380 :761130A9 6810591176 push 76115910 :761130AE 64A100000000 mov eax, dword ptr fs:[00000000] :761130B4 50 push eax :761130B5 64892500000000 mov dword ptr fs:[00000000], esp :761130BC 81EC04010000 sub esp, 00000104 :761130C2 53 push ebx :761130C3 56 push esi :761130C4 57 push edi :761130C5 33C0 xor eax, eax :761130C7 39450C cmp dword ptr [ebp+0C], eax :761130CA 750B jne 761130D7 :761130CC 68F4060000 push 000006F4 * Reference To: RPCRT4.RpcRaiseException, Ord:017Ah | :761130D1 FF15B8101176 Call dword ptr [761110B8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761130CA(C) | :761130D7 8945FC mov dword ptr [ebp-04], eax :761130DA 50 push eax :761130DB 6838121176 push 76111238 :761130E0 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761130E6 50 push eax :761130E7 8D85F0FEFFFF lea eax, dword ptr [ebp+FFFFFEF0] :761130ED 50 push eax * Reference To: RPCRT4.NdrClientInitializeNew, Ord:007Fh | :761130EE FF1584101176 Call dword ptr [76111084] :761130F4 8B3DE4791176 mov edi, dword ptr [761179E4] :761130FA 897DE4 mov dword ptr [ebp-1C], edi :761130FD 6A10 push 00000010 :761130FF 5B pop ebx :76113100 899D30FFFFFF mov dword ptr [ebp+FFFFFF30], ebx :76113106 BEDE121176 mov esi, 761112DE :7611310B 56 push esi :7611310C FF750C push [ebp+0C] :7611310F 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113115 50 push eax * Reference To: RPCRT4.NdrConformantStringBufferSize, Ord:008Fh | :76113116 FF15C0101176 Call dword ptr [761110C0] :7611311C 57 push edi :7611311D FFB530FFFFFF push dword ptr [ebp+FFFFFF30] :76113123 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113129 50 push eax * Reference To: RPCRT4.NdrGetBuffer, Ord:00C0h | :7611312A FF158C101176 Call dword ptr [7611108C] :76113130 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :76113136 8B4D08 mov ecx, dword ptr [ebp+08] :76113139 8908 mov dword ptr [eax], ecx :7611313B 838520FFFFFF04 add dword ptr [ebp+FFFFFF20], 00000004 :76113142 56 push esi :76113143 FF750C push [ebp+0C] :76113146 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :7611314C 50 push eax * Reference To: RPCRT4.NdrConformantStringMarshall, Ord:0090h | :7611314D FF1588101176 Call dword ptr [76111088] :76113153 FFB520FFFFFF push dword ptr [ebp+FFFFFF20] :76113159 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :7611315F 50 push eax * Reference To: RPCRT4.NdrSendReceive, Ord:00FDh | :76113160 FF15C4101176 Call dword ptr [761110C4] :76113166 8B85F4FEFFFF mov eax, dword ptr [ebp+FFFFFEF4] :7611316C 25FFFF0000 and eax, 0000FFFF :76113171 3BC3 cmp eax, ebx :76113173 7412 je 76113187 :76113175 68B4121176 push 761112B4 :7611317A 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113180 50 push eax * Reference To: RPCRT4.NdrConvert, Ord:00A4h | :76113181 FF15C8101176 Call dword ptr [761110C8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113173(C) | :76113187 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :7611318D 8B00 mov eax, dword ptr [eax] :7611318F 8985ECFEFFFF mov dword ptr [ebp+FFFFFEEC], eax :76113195 838520FFFFFF04 add dword ptr [ebp+FFFFFF20], 00000004 :7611319C 834DFCFF or dword ptr [ebp-04], FFFFFFFF :761131A0 E817000000 call 761131BC :761131A5 8B85ECFEFFFF mov eax, dword ptr [ebp+FFFFFEEC] :761131AB 8B4DF0 mov ecx, dword ptr [ebp-10] :761131AE 64890D00000000 mov dword ptr fs:[00000000], ecx :761131B5 5F pop edi :761131B6 5E pop esi :761131B7 5B pop ebx :761131B8 C9 leave :761131B9 C20800 ret 0008 * Referenced by a CALL at Address: |:761131A0 | :761131BC 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761131C2 50 push eax * Reference To: RPCRT4.NdrFreeBuffer, Ord:00B9h | :761131C3 FF15CC101176 Call dword ptr [761110CC] :761131C9 C3 ret * Referenced by a CALL at Address: |:76114A3F | :761131CA 55 push ebp :761131CB 8BEC mov ebp, esp :761131CD 6AFF push FFFFFFFF :761131CF 6890131176 push 76111390 :761131D4 6810591176 push 76115910 :761131D9 64A100000000 mov eax, dword ptr fs:[00000000] :761131DF 50 push eax :761131E0 64892500000000 mov dword ptr fs:[00000000], esp :761131E7 81EC04010000 sub esp, 00000104 :761131ED 53 push ebx :761131EE 56 push esi :761131EF 57 push edi :761131F0 8365FC00 and dword ptr [ebp-04], 00000000 :761131F4 6A01 push 00000001 :761131F6 6838121176 push 76111238 :761131FB 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113201 50 push eax :76113202 8D85F0FEFFFF lea eax, dword ptr [ebp+FFFFFEF0] :76113208 50 push eax * Reference To: RPCRT4.NdrClientInitializeNew, Ord:007Fh | :76113209 FF1584101176 Call dword ptr [76111084] :7611320F A1E4791176 mov eax, dword ptr [761179E4] :76113214 8945E4 mov dword ptr [ebp-1C], eax :76113217 6A04 push 00000004 :76113219 5E pop esi :7611321A 89B530FFFFFF mov dword ptr [ebp+FFFFFF30], esi :76113220 50 push eax :76113221 56 push esi :76113222 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113228 50 push eax * Reference To: RPCRT4.NdrGetBuffer, Ord:00C0h | :76113229 FF158C101176 Call dword ptr [7611108C] :7611322F 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :76113235 8B4D08 mov ecx, dword ptr [ebp+08] :76113238 8908 mov dword ptr [eax], ecx :7611323A 01B520FFFFFF add dword ptr [ebp+FFFFFF20], esi :76113240 FFB520FFFFFF push dword ptr [ebp+FFFFFF20] :76113246 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :7611324C 50 push eax * Reference To: RPCRT4.NdrSendReceive, Ord:00FDh | :7611324D FF15C4101176 Call dword ptr [761110C4] :76113253 8B85F4FEFFFF mov eax, dword ptr [ebp+FFFFFEF4] :76113259 25FFFF0000 and eax, 0000FFFF :7611325E 83F810 cmp eax, 00000010 :76113261 7412 je 76113275 :76113263 68BC121176 push 761112BC :76113268 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :7611326E 50 push eax * Reference To: RPCRT4.NdrConvert, Ord:00A4h | :7611326F FF15C8101176 Call dword ptr [761110C8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113261(C) | :76113275 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :7611327B 8B00 mov eax, dword ptr [eax] :7611327D 8985ECFEFFFF mov dword ptr [ebp+FFFFFEEC], eax :76113283 01B520FFFFFF add dword ptr [ebp+FFFFFF20], esi :76113289 834DFCFF or dword ptr [ebp-04], FFFFFFFF :7611328D E817000000 call 761132A9 :76113292 8B85ECFEFFFF mov eax, dword ptr [ebp+FFFFFEEC] :76113298 8B4DF0 mov ecx, dword ptr [ebp-10] :7611329B 64890D00000000 mov dword ptr fs:[00000000], ecx :761132A2 5F pop edi :761132A3 5E pop esi :761132A4 5B pop ebx :761132A5 C9 leave :761132A6 C20400 ret 0004 * Referenced by a CALL at Address: |:7611328D | :761132A9 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761132AF 50 push eax * Reference To: RPCRT4.NdrFreeBuffer, Ord:00B9h | :761132B0 FF15CC101176 Call dword ptr [761110CC] :761132B6 C3 ret * Referenced by a CALL at Address: |:76114909 | :761132B7 55 push ebp :761132B8 8BEC mov ebp, esp :761132BA 6AFF push FFFFFFFF :761132BC 68A0131176 push 761113A0 :761132C1 6810591176 push 76115910 :761132C6 64A100000000 mov eax, dword ptr fs:[00000000] :761132CC 50 push eax :761132CD 64892500000000 mov dword ptr fs:[00000000], esp :761132D4 81EC04010000 sub esp, 00000104 :761132DA 53 push ebx :761132DB 56 push esi :761132DC 57 push edi :761132DD 33F6 xor esi, esi :761132DF 8975FC mov dword ptr [ebp-04], esi :761132E2 6A02 push 00000002 :761132E4 6838121176 push 76111238 :761132E9 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761132EF 50 push eax :761132F0 8D85F0FEFFFF lea eax, dword ptr [ebp+FFFFFEF0] :761132F6 50 push eax * Reference To: RPCRT4.NdrClientInitializeNew, Ord:007Fh | :761132F7 FF1584101176 Call dword ptr [76111084] :761132FD A1E4791176 mov eax, dword ptr [761179E4] :76113302 8945E4 mov dword ptr [ebp-1C], eax :76113305 89B530FFFFFF mov dword ptr [ebp+FFFFFF30], esi :7611330B 50 push eax :7611330C 56 push esi :7611330D 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113313 50 push eax * Reference To: RPCRT4.NdrGetBuffer, Ord:00C0h | :76113314 FF158C101176 Call dword ptr [7611108C] :7611331A FFB520FFFFFF push dword ptr [ebp+FFFFFF20] :76113320 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113326 50 push eax * Reference To: RPCRT4.NdrSendReceive, Ord:00FDh | :76113327 FF15C4101176 Call dword ptr [761110C4] :7611332D 8B85F4FEFFFF mov eax, dword ptr [ebp+FFFFFEF4] :76113333 25FFFF0000 and eax, 0000FFFF :76113338 83F810 cmp eax, 00000010 :7611333B 7412 je 7611334F :7611333D 68C0121176 push 761112C0 :76113342 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113348 50 push eax * Reference To: RPCRT4.NdrConvert, Ord:00A4h | :76113349 FF15C8101176 Call dword ptr [761110C8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611333B(C) | :7611334F 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :76113355 8B00 mov eax, dword ptr [eax] :76113357 8985ECFEFFFF mov dword ptr [ebp+FFFFFEEC], eax :7611335D 838520FFFFFF04 add dword ptr [ebp+FFFFFF20], 00000004 :76113364 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76113368 E815000000 call 76113382 :7611336D 8B85ECFEFFFF mov eax, dword ptr [ebp+FFFFFEEC] :76113373 8B4DF0 mov ecx, dword ptr [ebp-10] :76113376 64890D00000000 mov dword ptr fs:[00000000], ecx :7611337D 5F pop edi :7611337E 5E pop esi :7611337F 5B pop ebx :76113380 C9 leave :76113381 C3 ret * Referenced by a CALL at Address: |:76113368 | :76113382 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113388 50 push eax * Reference To: RPCRT4.NdrFreeBuffer, Ord:00B9h | :76113389 FF15CC101176 Call dword ptr [761110CC] :7611338F C3 ret * Referenced by a CALL at Address: |:7611468D | :76113390 55 push ebp :76113391 8BEC mov ebp, esp :76113393 6AFF push FFFFFFFF :76113395 68B0131176 push 761113B0 :7611339A 6810591176 push 76115910 :7611339F 64A100000000 mov eax, dword ptr fs:[00000000] :761133A5 50 push eax :761133A6 64892500000000 mov dword ptr fs:[00000000], esp :761133AD 81EC04010000 sub esp, 00000104 :761133B3 53 push ebx :761133B4 56 push esi :761133B5 57 push edi :761133B6 8365FC00 and dword ptr [ebp-04], 00000000 :761133BA 6A03 push 00000003 :761133BC 6838121176 push 76111238 :761133C1 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761133C7 50 push eax :761133C8 8D85F0FEFFFF lea eax, dword ptr [ebp+FFFFFEF0] :761133CE 50 push eax * Reference To: RPCRT4.NdrClientInitializeNew, Ord:007Fh | :761133CF FF1584101176 Call dword ptr [76111084] :761133D5 A1E4791176 mov eax, dword ptr [761179E4] :761133DA 8945E4 mov dword ptr [ebp-1C], eax :761133DD 6A04 push 00000004 :761133DF 5E pop esi :761133E0 89B530FFFFFF mov dword ptr [ebp+FFFFFF30], esi :761133E6 50 push eax :761133E7 56 push esi :761133E8 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761133EE 50 push eax * Reference To: RPCRT4.NdrGetBuffer, Ord:00C0h | :761133EF FF158C101176 Call dword ptr [7611108C] :761133F5 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :761133FB 8B4D08 mov ecx, dword ptr [ebp+08] :761133FE 8908 mov dword ptr [eax], ecx :76113400 01B520FFFFFF add dword ptr [ebp+FFFFFF20], esi :76113406 FFB520FFFFFF push dword ptr [ebp+FFFFFF20] :7611340C 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113412 50 push eax * Reference To: RPCRT4.NdrSendReceive, Ord:00FDh | :76113413 FF15C4101176 Call dword ptr [761110C4] :76113419 8B85F4FEFFFF mov eax, dword ptr [ebp+FFFFFEF4] :7611341F 25FFFF0000 and eax, 0000FFFF :76113424 83F810 cmp eax, 00000010 :76113427 7412 je 7611343B :76113429 68BC121176 push 761112BC :7611342E 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113434 50 push eax * Reference To: RPCRT4.NdrConvert, Ord:00A4h | :76113435 FF15C8101176 Call dword ptr [761110C8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113427(C) | :7611343B 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :76113441 8B00 mov eax, dword ptr [eax] :76113443 8985ECFEFFFF mov dword ptr [ebp+FFFFFEEC], eax :76113449 01B520FFFFFF add dword ptr [ebp+FFFFFF20], esi :7611344F 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76113453 E817000000 call 7611346F :76113458 8B85ECFEFFFF mov eax, dword ptr [ebp+FFFFFEEC] :7611345E 8B4DF0 mov ecx, dword ptr [ebp-10] :76113461 64890D00000000 mov dword ptr fs:[00000000], ecx :76113468 5F pop edi :76113469 5E pop esi :7611346A 5B pop ebx :7611346B C9 leave :7611346C C20400 ret 0004 * Referenced by a CALL at Address: |:76113453 | :7611346F 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113475 50 push eax * Reference To: RPCRT4.NdrFreeBuffer, Ord:00B9h | :76113476 FF15CC101176 Call dword ptr [761110CC] :7611347C C3 ret * Referenced by a CALL at Address: |:761144F7 | :7611347D 55 push ebp :7611347E 8BEC mov ebp, esp :76113480 6AFF push FFFFFFFF :76113482 68C0131176 push 761113C0 :76113487 6810591176 push 76115910 :7611348C 64A100000000 mov eax, dword ptr fs:[00000000] :76113492 50 push eax :76113493 64892500000000 mov dword ptr fs:[00000000], esp :7611349A 81EC04010000 sub esp, 00000104 :761134A0 53 push ebx :761134A1 56 push esi :761134A2 57 push edi :761134A3 33F6 xor esi, esi :761134A5 8975FC mov dword ptr [ebp-04], esi :761134A8 6A04 push 00000004 :761134AA 6838121176 push 76111238 :761134AF 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761134B5 50 push eax :761134B6 8D85F0FEFFFF lea eax, dword ptr [ebp+FFFFFEF0] :761134BC 50 push eax * Reference To: RPCRT4.NdrClientInitializeNew, Ord:007Fh | :761134BD FF1584101176 Call dword ptr [76111084] :761134C3 A1E4791176 mov eax, dword ptr [761179E4] :761134C8 8945E4 mov dword ptr [ebp-1C], eax :761134CB 89B530FFFFFF mov dword ptr [ebp+FFFFFF30], esi :761134D1 50 push eax :761134D2 56 push esi :761134D3 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761134D9 50 push eax * Reference To: RPCRT4.NdrGetBuffer, Ord:00C0h | :761134DA FF158C101176 Call dword ptr [7611108C] :761134E0 FFB520FFFFFF push dword ptr [ebp+FFFFFF20] :761134E6 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761134EC 50 push eax * Reference To: RPCRT4.NdrSendReceive, Ord:00FDh | :761134ED FF15C4101176 Call dword ptr [761110C4] :761134F3 8B85F4FEFFFF mov eax, dword ptr [ebp+FFFFFEF4] :761134F9 25FFFF0000 and eax, 0000FFFF :761134FE 83F810 cmp eax, 00000010 :76113501 7412 je 76113515 :76113503 68C0121176 push 761112C0 :76113508 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :7611350E 50 push eax * Reference To: RPCRT4.NdrConvert, Ord:00A4h | :7611350F FF15C8101176 Call dword ptr [761110C8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113501(C) | :76113515 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :7611351B 8B00 mov eax, dword ptr [eax] :7611351D 8985ECFEFFFF mov dword ptr [ebp+FFFFFEEC], eax :76113523 838520FFFFFF04 add dword ptr [ebp+FFFFFF20], 00000004 :7611352A 834DFCFF or dword ptr [ebp-04], FFFFFFFF :7611352E E815000000 call 76113548 :76113533 8B85ECFEFFFF mov eax, dword ptr [ebp+FFFFFEEC] :76113539 8B4DF0 mov ecx, dword ptr [ebp-10] :7611353C 64890D00000000 mov dword ptr fs:[00000000], ecx :76113543 5F pop edi :76113544 5E pop esi :76113545 5B pop ebx :76113546 C9 leave :76113547 C3 ret * Referenced by a CALL at Address: |:7611352E | :76113548 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :7611354E 50 push eax * Reference To: RPCRT4.NdrFreeBuffer, Ord:00B9h | :7611354F FF15CC101176 Call dword ptr [761110CC] :76113555 C3 ret * Referenced by a CALL at Address: |:76114B6D | :76113556 55 push ebp :76113557 8BEC mov ebp, esp :76113559 6AFF push FFFFFFFF :7611355B 68D0131176 push 761113D0 :76113560 6810591176 push 76115910 :76113565 64A100000000 mov eax, dword ptr fs:[00000000] :7611356B 50 push eax :7611356C 64892500000000 mov dword ptr fs:[00000000], esp :76113573 81EC04010000 sub esp, 00000104 :76113579 53 push ebx :7611357A 56 push esi :7611357B 57 push edi :7611357C 837D0800 cmp dword ptr [ebp+08], 00000000 :76113580 750B jne 7611358D :76113582 68F4060000 push 000006F4 * Reference To: RPCRT4.RpcRaiseException, Ord:017Ah | :76113587 FF15B8101176 Call dword ptr [761110B8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113580(C) | :7611358D 8365FC00 and dword ptr [ebp-04], 00000000 :76113591 6A05 push 00000005 :76113593 6838121176 push 76111238 :76113598 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :7611359E 50 push eax :7611359F 8D85F0FEFFFF lea eax, dword ptr [ebp+FFFFFEF0] :761135A5 50 push eax * Reference To: RPCRT4.NdrClientInitializeNew, Ord:007Fh | :761135A6 FF1584101176 Call dword ptr [76111084] :761135AC 8B3DE4791176 mov edi, dword ptr [761179E4] :761135B2 897DE4 mov dword ptr [ebp-1C], edi :761135B5 C78530FFFFFF0C000000 mov dword ptr [ebp+FFFFFF30], 0000000C :761135BF BEDE121176 mov esi, 761112DE :761135C4 56 push esi :761135C5 FF7508 push [ebp+08] :761135C8 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761135CE 50 push eax * Reference To: RPCRT4.NdrConformantStringBufferSize, Ord:008Fh | :761135CF FF15C0101176 Call dword ptr [761110C0] :761135D5 57 push edi :761135D6 FFB530FFFFFF push dword ptr [ebp+FFFFFF30] :761135DC 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761135E2 50 push eax * Reference To: RPCRT4.NdrGetBuffer, Ord:00C0h | :761135E3 FF158C101176 Call dword ptr [7611108C] :761135E9 56 push esi :761135EA FF7508 push [ebp+08] :761135ED 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761135F3 50 push eax * Reference To: RPCRT4.NdrConformantStringMarshall, Ord:0090h | :761135F4 FF1588101176 Call dword ptr [76111088] :761135FA FFB520FFFFFF push dword ptr [ebp+FFFFFF20] :76113600 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113606 50 push eax * Reference To: RPCRT4.NdrSendReceive, Ord:00FDh | :76113607 FF15C4101176 Call dword ptr [761110C4] :7611360D 8B85F4FEFFFF mov eax, dword ptr [ebp+FFFFFEF4] :76113613 25FFFF0000 and eax, 0000FFFF :76113618 83F810 cmp eax, 00000010 :7611361B 7412 je 7611362F :7611361D 689C121176 push 7611129C :76113622 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113628 50 push eax * Reference To: RPCRT4.NdrConvert, Ord:00A4h | :76113629 FF15C8101176 Call dword ptr [761110C8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611361B(C) | :7611362F 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :76113635 8B00 mov eax, dword ptr [eax] :76113637 8985ECFEFFFF mov dword ptr [ebp+FFFFFEEC], eax :7611363D 838520FFFFFF04 add dword ptr [ebp+FFFFFF20], 00000004 :76113644 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76113648 E817000000 call 76113664 :7611364D 8B85ECFEFFFF mov eax, dword ptr [ebp+FFFFFEEC] :76113653 8B4DF0 mov ecx, dword ptr [ebp-10] :76113656 64890D00000000 mov dword ptr fs:[00000000], ecx :7611365D 5F pop edi :7611365E 5E pop esi :7611365F 5B pop ebx :76113660 C9 leave :76113661 C20400 ret 0004 * Referenced by a CALL at Address: |:76113648 | :76113664 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :7611366A 50 push eax * Reference To: RPCRT4.NdrFreeBuffer, Ord:00B9h | :7611366B FF15CC101176 Call dword ptr [761110CC] :76113671 C3 ret * Referenced by a CALL at Address: |:76114D0B | :76113672 55 push ebp :76113673 8BEC mov ebp, esp :76113675 6AFF push FFFFFFFF :76113677 68E0131176 push 761113E0 :7611367C 6810591176 push 76115910 :76113681 64A100000000 mov eax, dword ptr fs:[00000000] :76113687 50 push eax :76113688 64892500000000 mov dword ptr fs:[00000000], esp :7611368F 81EC04010000 sub esp, 00000104 :76113695 53 push ebx :76113696 56 push esi :76113697 57 push edi :76113698 33DB xor ebx, ebx :7611369A 395D0C cmp dword ptr [ebp+0C], ebx :7611369D 750B jne 761136AA :7611369F 68F4060000 push 000006F4 * Reference To: RPCRT4.RpcRaiseException, Ord:017Ah | :761136A4 FF15B8101176 Call dword ptr [761110B8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611369D(C) | :761136AA 895DFC mov dword ptr [ebp-04], ebx :761136AD 6A06 push 00000006 :761136AF 6838121176 push 76111238 :761136B4 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761136BA 50 push eax :761136BB 8D85F0FEFFFF lea eax, dword ptr [ebp+FFFFFEF0] :761136C1 50 push eax * Reference To: RPCRT4.NdrClientInitializeNew, Ord:007Fh | :761136C2 FF1584101176 Call dword ptr [76111084] :761136C8 8B3DE4791176 mov edi, dword ptr [761179E4] :761136CE 897DE4 mov dword ptr [ebp-1C], edi :761136D1 C78530FFFFFF08000000 mov dword ptr [ebp+FFFFFF30], 00000008 :761136DB BE02131176 mov esi, 76111302 :761136E0 56 push esi :761136E1 FF7508 push [ebp+08] :761136E4 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761136EA 50 push eax * Reference To: RPCRT4.NdrPointerBufferSize, Ord:00EBh | :761136EB FF1598101176 Call dword ptr [76111098] :761136F1 57 push edi :761136F2 FFB530FFFFFF push dword ptr [ebp+FFFFFF30] :761136F8 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761136FE 50 push eax * Reference To: RPCRT4.NdrGetBuffer, Ord:00C0h | :761136FF FF158C101176 Call dword ptr [7611108C] :76113705 56 push esi :76113706 FF7508 push [ebp+08] :76113709 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :7611370F 50 push eax * Reference To: RPCRT4.NdrPointerMarshall, Ord:00EDh | :76113710 FF159C101176 Call dword ptr [7611109C] :76113716 FFB520FFFFFF push dword ptr [ebp+FFFFFF20] :7611371C 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113722 50 push eax * Reference To: RPCRT4.NdrSendReceive, Ord:00FDh | :76113723 FF15C4101176 Call dword ptr [761110C4] :76113729 8B85F4FEFFFF mov eax, dword ptr [ebp+FFFFFEF4] :7611372F 25FFFF0000 and eax, 0000FFFF :76113734 83F810 cmp eax, 00000010 :76113737 7412 je 7611374B :76113739 68C2121176 push 761112C2 :7611373E 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113744 50 push eax * Reference To: RPCRT4.NdrConvert, Ord:00A4h | :76113745 FF15C8101176 Call dword ptr [761110C8] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113737(C) | :7611374B 53 push ebx :7611374C 681C131176 push 7611131C :76113751 8D450C lea eax, dword ptr [ebp+0C] :76113754 50 push eax :76113755 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :7611375B 50 push eax * Reference To: RPCRT4.NdrComplexStructUnmarshall, Ord:0089h | :7611375C FF15A4101176 Call dword ptr [761110A4] :76113762 8B8520FFFFFF mov eax, dword ptr [ebp+FFFFFF20] :76113768 83C003 add eax, 00000003 :7611376B 24FC and al, FC :7611376D 898520FFFFFF mov dword ptr [ebp+FFFFFF20], eax :76113773 8B08 mov ecx, dword ptr [eax] :76113775 898DECFEFFFF mov dword ptr [ebp+FFFFFEEC], ecx :7611377B 83C004 add eax, 00000004 :7611377E 898520FFFFFF mov dword ptr [ebp+FFFFFF20], eax :76113784 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76113788 E817000000 call 761137A4 :7611378D 8B85ECFEFFFF mov eax, dword ptr [ebp+FFFFFEEC] :76113793 8B4DF0 mov ecx, dword ptr [ebp-10] :76113796 64890D00000000 mov dword ptr fs:[00000000], ecx :7611379D 5F pop edi :7611379E 5E pop esi :7611379F 5B pop ebx :761137A0 C9 leave :761137A1 C20800 ret 0008 * Referenced by a CALL at Address: |:76113788 | :761137A4 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761137AA 50 push eax * Reference To: RPCRT4.NdrFreeBuffer, Ord:00B9h | :761137AB FF15CC101176 Call dword ptr [761110CC] :761137B1 C3 ret * Referenced by a CALL at Address: |:76114E34 | :761137B2 55 push ebp :761137B3 8BEC mov ebp, esp :761137B5 6AFF push FFFFFFFF :761137B7 68F0131176 push 761113F0 :761137BC 6810591176 push 76115910 :761137C1 64A100000000 mov eax, dword ptr fs:[00000000] :761137C7 50 push eax :761137C8 64892500000000 mov dword ptr fs:[00000000], esp :761137CF 81EC00010000 sub esp, 00000100 :761137D5 53 push ebx :761137D6 56 push esi :761137D7 57 push edi :761137D8 8365FC00 and dword ptr [ebp-04], 00000000 :761137DC 6A07 push 00000007 :761137DE 6838121176 push 76111238 :761137E3 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761137E9 50 push eax :761137EA 8D85F0FEFFFF lea eax, dword ptr [ebp+FFFFFEF0] :761137F0 50 push eax * Reference To: RPCRT4.NdrClientInitializeNew, Ord:007Fh | :761137F1 FF1584101176 Call dword ptr [76111084] :761137F7 A1E4791176 mov eax, dword ptr [761179E4] :761137FC 8945E4 mov dword ptr [ebp-1C], eax :761137FF 6A08 push 00000008 :76113801 5E pop esi :76113802 89B530FFFFFF mov dword ptr [ebp+FFFFFF30], esi :76113808 50 push eax :76113809 56 push esi :7611380A 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113810 50 push eax * Reference To: RPCRT4.NdrGetBuffer, Ord:00C0h | :76113811 FF158C101176 Call dword ptr [7611108C] :76113817 8B4508 mov eax, dword ptr [ebp+08] :7611381A 8B8D20FFFFFF mov ecx, dword ptr [ebp+FFFFFF20] :76113820 8901 mov dword ptr [ecx], eax :76113822 8B450C mov eax, dword ptr [ebp+0C] :76113825 8B8D20FFFFFF mov ecx, dword ptr [ebp+FFFFFF20] :7611382B 894104 mov dword ptr [ecx+04], eax :7611382E 01B520FFFFFF add dword ptr [ebp+FFFFFF20], esi :76113834 FFB520FFFFFF push dword ptr [ebp+FFFFFF20] :7611383A 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113840 50 push eax * Reference To: RPCRT4.NdrSendReceive, Ord:00FDh | :76113841 FF15C4101176 Call dword ptr [761110C4] :76113847 834DFCFF or dword ptr [ebp-04], FFFFFFFF :7611384B E811000000 call 76113861 :76113850 8B4DF0 mov ecx, dword ptr [ebp-10] :76113853 64890D00000000 mov dword ptr fs:[00000000], ecx :7611385A 5F pop edi :7611385B 5E pop esi :7611385C 5B pop ebx :7611385D C9 leave :7611385E C20800 ret 0008 * Referenced by a CALL at Address: |:7611384B | :76113861 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113867 50 push eax * Reference To: RPCRT4.NdrFreeBuffer, Ord:00B9h | :76113868 FF15CC101176 Call dword ptr [761110CC] :7611386E C3 ret * Referenced by a CALL at Address: |:76114F57 | :7611386F 55 push ebp :76113870 8BEC mov ebp, esp :76113872 6AFF push FFFFFFFF :76113874 6800141176 push 76111400 :76113879 6810591176 push 76115910 :7611387E 64A100000000 mov eax, dword ptr fs:[00000000] :76113884 50 push eax :76113885 64892500000000 mov dword ptr fs:[00000000], esp :7611388C 81EC00010000 sub esp, 00000100 :76113892 53 push ebx :76113893 56 push esi :76113894 57 push edi :76113895 33F6 xor esi, esi :76113897 8975FC mov dword ptr [ebp-04], esi :7611389A 6A08 push 00000008 :7611389C 6838121176 push 76111238 :761138A1 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761138A7 50 push eax :761138A8 8D85F0FEFFFF lea eax, dword ptr [ebp+FFFFFEF0] :761138AE 50 push eax * Reference To: RPCRT4.NdrClientInitializeNew, Ord:007Fh | :761138AF FF1584101176 Call dword ptr [76111084] :761138B5 A1E4791176 mov eax, dword ptr [761179E4] :761138BA 8945E4 mov dword ptr [ebp-1C], eax :761138BD 89B530FFFFFF mov dword ptr [ebp+FFFFFF30], esi :761138C3 50 push eax :761138C4 56 push esi :761138C5 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761138CB 50 push eax * Reference To: RPCRT4.NdrGetBuffer, Ord:00C0h | :761138CC FF158C101176 Call dword ptr [7611108C] :761138D2 FFB520FFFFFF push dword ptr [ebp+FFFFFF20] :761138D8 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :761138DE 50 push eax * Reference To: RPCRT4.NdrSendReceive, Ord:00FDh | :761138DF FF15C4101176 Call dword ptr [761110C4] :761138E5 834DFCFF or dword ptr [ebp-04], FFFFFFFF :761138E9 E80F000000 call 761138FD :761138EE 8B4DF0 mov ecx, dword ptr [ebp-10] :761138F1 64890D00000000 mov dword ptr fs:[00000000], ecx :761138F8 5F pop edi :761138F9 5E pop esi :761138FA 5B pop ebx :761138FB C9 leave :761138FC C3 ret * Referenced by a CALL at Address: |:761138E9 | :761138FD 8D851CFFFFFF lea eax, dword ptr [ebp+FFFFFF1C] :76113903 50 push eax * Reference To: RPCRT4.NdrFreeBuffer, Ord:00B9h | :76113904 FF15CC101176 Call dword ptr [761110CC] :7611390A C3 ret //******************** Program Entry Point ******** :7611390B 6A01 push 00000001 :7611390D 58 pop eax :7611390E C20C00 ret 000C * Referenced by a CALL at Addresses: |:76113AF1 , :76113D24 , :76113E9F , :761140A6 , :761141E1 |:7611430F , :761144B3 , :76114646 , :761148C5 , :761149F8 |:76114B26 , :76114CC4 , :76114DEA , :76114F13 | :76113911 51 push ecx :76113912 51 push ecx :76113913 53 push ebx :76113914 55 push ebp :76113915 56 push esi :76113916 57 push edi :76113917 8D442410 lea eax, dword ptr [esp+10] :7611391B 33FF xor edi, edi :7611391D 50 push eax :7611391E 57 push edi * Possible StringData Ref from Code Obj ->"sfprpc" | :7611391F 689C211176 push 7611219C :76113924 57 push edi * Possible StringData Ref from Code Obj ->"ncalrpc" | :76113925 6894211176 push 76112194 :7611392A 57 push edi :7611392B 897C2428 mov dword ptr [esp+28], edi :7611392F C744242C01000000 mov [esp+2C], 00000001 * Reference To: RPCRT4.RpcStringBindingComposeA, Ord:01B0h | :76113937 FF1594101176 Call dword ptr [76111094] :7611393D 8BF0 mov esi, eax :7611393F 3BF7 cmp esi, edi :76113941 743E je 76113981 :76113943 A1E4101176 mov eax, dword ptr [761110E4] :76113948 F60002 test byte ptr [eax], 02 :7611394B 742B je 76113978 :7611394D 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpInitRPC" | :7611394F 6888211176 push 76112188 :76113954 6A5C push 0000005C :76113956 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :7611395B FF15EC101176 Call dword ptr [761110EC] :76113961 85C0 test eax, eax :76113963 7413 je 76113978 :76113965 56 push esi * Possible StringData Ref from Code Obj ->"Error %x: Cannot create binding " ->"string" | :76113966 6860211176 push 76112160 :7611396B 6801020000 push 00000201 :76113970 E8A5000000 call 76113A1A :76113975 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:7611394B(C), :76113963(C) | :76113978 897C2414 mov dword ptr [esp+14], edi :7611397C E98C000000 jmp 76113A0D * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113941(C) | :76113981 FF74241C push [esp+1C] :76113985 FF742414 push [esp+14] * Reference To: RPCRT4.RpcBindingFromStringBindingA, Ord:0133h | :76113989 FF15BC101176 Call dword ptr [761110BC] :7611398F 8BF0 mov esi, eax * Possible StringData Ref from Code Obj ->"SfpInitRPC" | :76113991 BD88211176 mov ebp, 76112188 :76113996 3BF7 cmp esi, edi * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113998 8B3DEC101176 mov edi, dword ptr [761110EC] :7611399E BBF0721176 mov ebx, 761172F0 :761139A3 742E je 761139D3 :761139A5 A1E4101176 mov eax, dword ptr [761110E4] :761139AA F60002 test byte ptr [eax], 02 :761139AD 741F je 761139CE :761139AF 6A02 push 00000002 :761139B1 55 push ebp :761139B2 6A66 push 00000066 :761139B4 53 push ebx :761139B5 FFD7 call edi :761139B7 85C0 test eax, eax :761139B9 7413 je 761139CE :761139BB 56 push esi * Possible StringData Ref from Code Obj ->"Error %x: Cannot create binding" | :761139BC 6840211176 push 76112140 :761139C1 6801020000 push 00000201 :761139C6 E84F000000 call 76113A1A :761139CB 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761139AD(C), :761139B9(C) | :761139CE 8364241400 and dword ptr [esp+14], 00000000 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761139A3(C) | :761139D3 8D442410 lea eax, dword ptr [esp+10] :761139D7 50 push eax * Reference To: RPCRT4.RpcStringFreeA, Ord:01B4h | :761139D8 FF15A0101176 Call dword ptr [761110A0] :761139DE 8BF0 mov esi, eax :761139E0 85F6 test esi, esi :761139E2 7429 je 76113A0D :761139E4 A1E4101176 mov eax, dword ptr [761110E4] :761139E9 F60002 test byte ptr [eax], 02 :761139EC 741F je 76113A0D :761139EE 6A02 push 00000002 :761139F0 55 push ebp :761139F1 6A6E push 0000006E :761139F3 53 push ebx :761139F4 FFD7 call edi :761139F6 85C0 test eax, eax :761139F8 7413 je 76113A0D :761139FA 56 push esi * Possible StringData Ref from Code Obj ->"Error %x: Cannot free string" | :761139FB 6820211176 push 76112120 :76113A00 6801020000 push 00000201 :76113A05 E810000000 call 76113A1A :76113A0A 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:7611397C(U), :761139E2(C), :761139EC(C), :761139F8(C) | :76113A0D 8B442414 mov eax, dword ptr [esp+14] :76113A11 5F pop edi :76113A12 5E pop esi :76113A13 5D pop ebp :76113A14 5B pop ebx :76113A15 59 pop ecx :76113A16 59 pop ecx :76113A17 C20400 ret 0004 * Referenced by a CALL at Addresses: |:76113970 , :761139C6 , :76113A05 , :76113A6F , :76113ADD |:76113B9D , :76113C0A , :76113C50 , :76113C96 , :76113D10 |:76113DC1 , :76113E0A , :76113F46 , :76113FC6 , :7611400F |:76114148 , :76114191 , :7611427F , :761142C8 , :761143AD |:761143F6 , :7611454B , :76114594 , :761146E1 , :7611472A |:76114863 , :7611495D , :761149A6 , :76114A93 , :76114ADC |:76114BC1 , :76114C0A , :76114C9F , :76114D58 , :76114DA1 |:76114E80 , :76114EC9 , :76114FA3 , :76114FEC , :76115150 |:761151B0 , :761152D3 , :7611531F , :761153A6 , :7611542B |:76115468 , :7611551D , :7611557A , :76115617 , :76115676 |:7611570B , :761158B7 , :76115985 , :761159CB , :761159FA |:76115A21 , :76115A6E , :76115AAD , :76115ADC , :76115B04 |:76115BAE , :76115CC7 , :76115E40 , :76115F15 , :76115F83 |:76115FE6 | :76113A1A 8D44240C lea eax, dword ptr [esp+0C] :76113A1E 50 push eax :76113A1F FF74240C push [esp+0C] :76113A23 FF74240C push [esp+0C] * Reference To: atrace._AsyncStringTrace@12, Ord:0001h | :76113A27 FF15E8101176 Call dword ptr [761110E8] :76113A2D C3 ret * Referenced by a CALL at Addresses: |:76113C66 , :76113DD2 , :76113FD7 , :76114159 , :76114290 |:761143BE , :7611455C , :761146F2 , :7611496E , :76114AA4 |:76114BD2 , :76114D69 , :76114E91 , :76114FB4 | :76113A2E 56 push esi :76113A2F FF742408 push [esp+08] * Reference To: RPCRT4.RpcBindingFree, Ord:0132h | :76113A33 FF1590101176 Call dword ptr [76111090] :76113A39 8BF0 mov esi, eax :76113A3B 85F6 test esi, esi :76113A3D 7438 je 76113A77 :76113A3F A1E4101176 mov eax, dword ptr [761110E4] :76113A44 F60002 test byte ptr [eax], 02 :76113A47 742E je 76113A77 :76113A49 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpRPCTerm" | :76113A4B 68C4211176 push 761121C4 :76113A50 6886000000 push 00000086 :76113A55 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113A5A FF15EC101176 Call dword ptr [761110EC] :76113A60 85C0 test eax, eax :76113A62 7413 je 76113A77 :76113A64 56 push esi * Possible StringData Ref from Code Obj ->"Error %x: Cannot free binding" | :76113A65 68A4211176 push 761121A4 :76113A6A 6801020000 push 00000201 :76113A6F E8A6FFFFFF call 76113A1A :76113A74 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76113A3D(C), :76113A47(C), :76113A62(C) | :76113A77 33C0 xor eax, eax :76113A79 85F6 test esi, esi :76113A7B 0F94C0 sete al :76113A7E 5E pop esi :76113A7F C20400 ret 0004 Exported fn(): Ordinal:0008 - Ord:0008h :76113A82 55 push ebp :76113A83 8BEC mov ebp, esp :76113A85 6AFF push FFFFFFFF :76113A87 68A8221176 push 761122A8 :76113A8C 6810591176 push 76115910 :76113A91 64A100000000 mov eax, dword ptr fs:[00000000] :76113A97 50 push eax :76113A98 64892500000000 mov dword ptr fs:[00000000], esp :76113A9F 83EC1C sub esp, 0000001C :76113AA2 53 push ebx :76113AA3 56 push esi :76113AA4 57 push edi :76113AA5 8965E8 mov dword ptr [ebp-18], esp :76113AA8 837D0800 cmp dword ptr [ebp+08], 00000000 :76113AAC 753E jne 76113AEC :76113AAE A1E4101176 mov eax, dword ptr [761110E4] :76113AB3 F60002 test byte ptr [eax], 02 :76113AB6 742C je 76113AE4 :76113AB8 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpInstallCatalog" | :76113ABA 6890221176 push 76112290 :76113ABF 689E000000 push 0000009E :76113AC4 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113AC9 FF15EC101176 Call dword ptr [761110EC] :76113ACF 85C0 test eax, eax :76113AD1 7411 je 76113AE4 * Possible StringData Ref from Code Obj ->"NULL catalog name" | :76113AD3 687C221176 push 7611227C :76113AD8 6801020000 push 00000201 :76113ADD E838FFFFFF call 76113A1A :76113AE2 59 pop ecx :76113AE3 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76113AB6(C), :76113AD1(C) | :76113AE4 6A57 push 00000057 :76113AE6 5B pop ebx :76113AE7 E9B6010000 jmp 76113CA2 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113AAC(C) | :76113AEC 68E0791176 push 761179E0 :76113AF1 E81BFEFFFF call 76113911 :76113AF6 85C0 test eax, eax :76113AF8 7537 jne 76113B31 :76113AFA A1E4101176 mov eax, dword ptr [761110E4] :76113AFF F60002 test byte ptr [eax], 02 :76113B02 0F8495010000 je 76113C9D :76113B08 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpInstallCatalog" | :76113B0A 6890221176 push 76112290 :76113B0F 68A6000000 push 000000A6 :76113B14 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113B19 FF15EC101176 Call dword ptr [761110EC] :76113B1F 85C0 test eax, eax :76113B21 0F8476010000 je 76113C9D * Possible StringData Ref from Code Obj ->"Cannot init RPC" | :76113B27 686C221176 push 7611226C :76113B2C E960010000 jmp 76113C91 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113AF8(C) | :76113B31 8365FC00 and dword ptr [ebp-04], 00000000 :76113B35 FF750C push [ebp+0C] :76113B38 FF7508 push [ebp+08] :76113B3B E830EFFFFF call 76112A70 :76113B40 8BD8 mov ebx, eax :76113B42 895DE0 mov dword ptr [ebp-20], ebx :76113B45 834DFCFF or dword ptr [ebp-04], FFFFFFFF * Possible StringData Ref from Code Obj ->"SfpInstallCatalog" | :76113B49 BF90221176 mov edi, 76112290 :76113B4E BEF0721176 mov esi, 761172F0 :76113B53 E909010000 jmp 76113C61 :76113B58 8B45EC mov eax, dword ptr [ebp-14] :76113B5B 8B00 mov eax, dword ptr [eax] :76113B5D 8B00 mov eax, dword ptr [eax] :76113B5F 8945D4 mov dword ptr [ebp-2C], eax :76113B62 6A01 push 00000001 :76113B64 58 pop eax :76113B65 C3 ret :76113B66 8B65E8 mov esp, dword ptr [ebp-18] :76113B69 A1E4101176 mov eax, dword ptr [761110E4] :76113B6E F60002 test byte ptr [eax], 02 :76113B71 7434 je 76113BA7 :76113B73 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpInstallCatalog" | :76113B75 BF90221176 mov edi, 76112290 :76113B7A 57 push edi :76113B7B 68B4000000 push 000000B4 :76113B80 BEF0721176 mov esi, 761172F0 :76113B85 56 push esi * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113B86 FF15EC101176 Call dword ptr [761110EC] :76113B8C 85C0 test eax, eax :76113B8E 7421 je 76113BB1 :76113B90 FF75D4 push [ebp-2C] * Possible StringData Ref from Code Obj ->"Error %x: RPC runtime reported " ->"exception" | :76113B93 6840221176 push 76112240 :76113B98 6801020000 push 00000201 :76113B9D E878FEFFFF call 76113A1A :76113BA2 83C40C add esp, 0000000C :76113BA5 EB0A jmp 76113BB1 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113B71(C) | * Possible StringData Ref from Code Obj ->"SfpInstallCatalog" | :76113BA7 BF90221176 mov edi, 76112290 :76113BAC BEF0721176 mov esi, 761172F0 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76113B8E(C), :76113BA5(U) | * Possible StringData Ref from Code Obj ->"sfpdll.dll" | :76113BB1 6834221176 push 76112234 * Reference To: KERNEL32.LoadLibraryA, Ord:01DFh | :76113BB6 FF1544101176 Call dword ptr [76111044] :76113BBC 8945DC mov dword ptr [ebp-24], eax :76113BBF 85C0 test eax, eax :76113BC1 745F je 76113C22 * Possible StringData Ref from Code Obj ->"SFPCopyCatalog" | :76113BC3 6824221176 push 76112224 :76113BC8 50 push eax * Reference To: KERNEL32.GetProcAddress, Ord:0153h | :76113BC9 FF1548101176 Call dword ptr [76111048] :76113BCF 85C0 test eax, eax :76113BD1 7409 je 76113BDC :76113BD3 FF7508 push [ebp+08] :76113BD6 FFD0 call eax :76113BD8 8BD8 mov ebx, eax :76113BDA EB3B jmp 76113C17 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113BD1(C) | :76113BDC A1E4101176 mov eax, dword ptr [761110E4] :76113BE1 F60002 test byte ptr [eax], 02 :76113BE4 742C je 76113C12 :76113BE6 6A02 push 00000002 :76113BE8 57 push edi :76113BE9 68C2000000 push 000000C2 :76113BEE 56 push esi * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113BEF FF15EC101176 Call dword ptr [761110EC] :76113BF5 85C0 test eax, eax :76113BF7 7419 je 76113C12 * Reference To: KERNEL32.GetLastError, Ord:012Dh | :76113BF9 FF154C101176 Call dword ptr [7611104C] :76113BFF 50 push eax * Possible StringData Ref from Code Obj ->"Cannot load SFPCopyCatalog, ec=%ld" | :76113C00 6800221176 push 76112200 :76113C05 6801020000 push 00000201 :76113C0A E80BFEFFFF call 76113A1A :76113C0F 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76113BE4(C), :76113BF7(C) | :76113C12 BB4F050000 mov ebx, 0000054F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113BDA(U) | :76113C17 FF75DC push [ebp-24] * Reference To: KERNEL32.FreeLibrary, Ord:00C3h | :76113C1A FF155C101176 Call dword ptr [7611105C] :76113C20 EB3B jmp 76113C5D * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113BC1(C) | :76113C22 A1E4101176 mov eax, dword ptr [761110E4] :76113C27 F60002 test byte ptr [eax], 02 :76113C2A 742C je 76113C58 :76113C2C 6A02 push 00000002 :76113C2E 57 push edi :76113C2F 68CA000000 push 000000CA :76113C34 56 push esi * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113C35 FF15EC101176 Call dword ptr [761110EC] :76113C3B 85C0 test eax, eax :76113C3D 7419 je 76113C58 * Reference To: KERNEL32.GetLastError, Ord:012Dh | :76113C3F FF154C101176 Call dword ptr [7611104C] :76113C45 50 push eax * Possible StringData Ref from Code Obj ->"Cannot load sfpdll.dll, ec=%ld" | :76113C46 68E0211176 push 761121E0 :76113C4B 6801020000 push 00000201 :76113C50 E8C5FDFFFF call 76113A1A :76113C55 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76113C2A(C), :76113C3D(C) | :76113C58 BB4F050000 mov ebx, 0000054F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113C20(U) | :76113C5D 834DFCFF or dword ptr [ebp-04], FFFFFFFF * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113B53(U) | :76113C61 68E0791176 push 761179E0 :76113C66 E8C3FDFFFF call 76113A2E :76113C6B 85C0 test eax, eax :76113C6D 7533 jne 76113CA2 :76113C6F A1E4101176 mov eax, dword ptr [761110E4] :76113C74 F60002 test byte ptr [eax], 02 :76113C77 7424 je 76113C9D :76113C79 6A02 push 00000002 :76113C7B 57 push edi :76113C7C 68D4000000 push 000000D4 :76113C81 56 push esi * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113C82 FF15EC101176 Call dword ptr [761110EC] :76113C88 85C0 test eax, eax :76113C8A 7411 je 76113C9D * Possible StringData Ref from Code Obj ->"Cannot term RPC" | :76113C8C 68D0211176 push 761121D0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113B2C(U) | :76113C91 6801020000 push 00000201 :76113C96 E87FFDFFFF call 76113A1A :76113C9B 59 pop ecx :76113C9C 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76113B02(C), :76113B21(C), :76113C77(C), :76113C8A(C) | :76113C9D BB4F050000 mov ebx, 0000054F * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76113AE7(U), :76113C6D(C) | :76113CA2 8BC3 mov eax, ebx :76113CA4 8B4DF0 mov ecx, dword ptr [ebp-10] :76113CA7 64890D00000000 mov dword ptr fs:[00000000], ecx :76113CAE 5F pop edi :76113CAF 5E pop esi :76113CB0 5B pop ebx :76113CB1 C9 leave :76113CB2 C20800 ret 0008 Exported fn(): Ordinal:0009 - Ord:0009h :76113CB5 55 push ebp :76113CB6 8BEC mov ebp, esp :76113CB8 6AFF push FFFFFFFF :76113CBA 68C8221176 push 761122C8 :76113CBF 6810591176 push 76115910 :76113CC4 64A100000000 mov eax, dword ptr fs:[00000000] :76113CCA 50 push eax :76113CCB 64892500000000 mov dword ptr fs:[00000000], esp :76113CD2 83EC14 sub esp, 00000014 :76113CD5 53 push ebx :76113CD6 56 push esi :76113CD7 57 push edi :76113CD8 8965E8 mov dword ptr [ebp-18], esp :76113CDB 837D0800 cmp dword ptr [ebp+08], 00000000 :76113CDF 753E jne 76113D1F :76113CE1 A1E4101176 mov eax, dword ptr [761110E4] :76113CE6 F60002 test byte ptr [eax], 02 :76113CE9 742C je 76113D17 :76113CEB 6A02 push 00000002 :76113CED 68B4221176 push 761122B4 :76113CF2 68EB000000 push 000000EB :76113CF7 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113CFC FF15EC101176 Call dword ptr [761110EC] :76113D02 85C0 test eax, eax :76113D04 7411 je 76113D17 * Possible StringData Ref from Code Obj ->"NULL catalog name" | :76113D06 687C221176 push 7611227C :76113D0B 6801020000 push 00000201 :76113D10 E805FDFFFF call 76113A1A :76113D15 59 pop ecx :76113D16 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76113CE9(C), :76113D04(C) | :76113D17 6A57 push 00000057 :76113D19 5E pop esi :76113D1A E9F7000000 jmp 76113E16 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113CDF(C) | :76113D1F 68E0791176 push 761179E0 :76113D24 E8E8FBFFFF call 76113911 :76113D29 85C0 test eax, eax :76113D2B 7537 jne 76113D64 :76113D2D A1E4101176 mov eax, dword ptr [761110E4] :76113D32 F60002 test byte ptr [eax], 02 :76113D35 0F84D6000000 je 76113E11 :76113D3B 6A02 push 00000002 :76113D3D 68B4221176 push 761122B4 :76113D42 68F3000000 push 000000F3 :76113D47 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113D4C FF15EC101176 Call dword ptr [761110EC] :76113D52 85C0 test eax, eax :76113D54 0F84B7000000 je 76113E11 * Possible StringData Ref from Code Obj ->"Cannot init RPC" | :76113D5A 686C221176 push 7611226C :76113D5F E9A1000000 jmp 76113E05 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113D2B(C) | :76113D64 8365FC00 and dword ptr [ebp-04], 00000000 :76113D68 6A01 push 00000001 :76113D6A FF7508 push [ebp+08] :76113D6D E840EEFFFF call 76112BB2 :76113D72 8BF0 mov esi, eax :76113D74 8975E4 mov dword ptr [ebp-1C], esi :76113D77 EB50 jmp 76113DC9 :76113D79 8B45EC mov eax, dword ptr [ebp-14] :76113D7C 8B00 mov eax, dword ptr [eax] :76113D7E 8B00 mov eax, dword ptr [eax] :76113D80 8945DC mov dword ptr [ebp-24], eax :76113D83 6A01 push 00000001 :76113D85 58 pop eax :76113D86 C3 ret :76113D87 8B65E8 mov esp, dword ptr [ebp-18] :76113D8A BE4F050000 mov esi, 0000054F :76113D8F A1E4101176 mov eax, dword ptr [761110E4] :76113D94 F60002 test byte ptr [eax], 02 :76113D97 7430 je 76113DC9 :76113D99 6A02 push 00000002 :76113D9B 68B4221176 push 761122B4 :76113DA0 6801010000 push 00000101 :76113DA5 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113DAA FF15EC101176 Call dword ptr [761110EC] :76113DB0 85C0 test eax, eax :76113DB2 7415 je 76113DC9 :76113DB4 FF75DC push [ebp-24] * Possible StringData Ref from Code Obj ->"Error %x: RPC runtime reported " ->"exception" | :76113DB7 6840221176 push 76112240 :76113DBC 6801020000 push 00000201 :76113DC1 E854FCFFFF call 76113A1A :76113DC6 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76113D77(U), :76113D97(C), :76113DB2(C) | :76113DC9 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76113DCD 68E0791176 push 761179E0 :76113DD2 E857FCFFFF call 76113A2E :76113DD7 85C0 test eax, eax :76113DD9 753B jne 76113E16 :76113DDB A1E4101176 mov eax, dword ptr [761110E4] :76113DE0 F60002 test byte ptr [eax], 02 :76113DE3 742C je 76113E11 :76113DE5 6A02 push 00000002 :76113DE7 68B4221176 push 761122B4 :76113DEC 6809010000 push 00000109 :76113DF1 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113DF6 FF15EC101176 Call dword ptr [761110EC] :76113DFC 85C0 test eax, eax :76113DFE 7411 je 76113E11 * Possible StringData Ref from Code Obj ->"Cannot term RPC" | :76113E00 68D0211176 push 761121D0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113D5F(U) | :76113E05 6801020000 push 00000201 :76113E0A E80BFCFFFF call 76113A1A :76113E0F 59 pop ecx :76113E10 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76113D35(C), :76113D54(C), :76113DE3(C), :76113DFE(C) | :76113E11 BE4F050000 mov esi, 0000054F * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76113D1A(U), :76113DD9(C) | :76113E16 8BC6 mov eax, esi :76113E18 8B4DF0 mov ecx, dword ptr [ebp-10] :76113E1B 64890D00000000 mov dword ptr fs:[00000000], ecx :76113E22 5F pop edi :76113E23 5E pop esi :76113E24 5B pop ebx :76113E25 C9 leave :76113E26 C20400 ret 0004 Exported fn(): SfcIsFileProtected - Ord:0017h :76113E29 55 push ebp :76113E2A 8BEC mov ebp, esp :76113E2C 6AFF push FFFFFFFF :76113E2E 6820231176 push 76112320 :76113E33 6810591176 push 76115910 :76113E38 64A100000000 mov eax, dword ptr fs:[00000000] :76113E3E 50 push eax :76113E3F 64892500000000 mov dword ptr fs:[00000000], esp :76113E46 81EC20010000 sub esp, 00000120 :76113E4C 53 push ebx :76113E4D 56 push esi :76113E4E 57 push edi :76113E4F 8965E8 mov dword ptr [ebp-18], esp :76113E52 C785DCFEFFFF4F050000 mov dword ptr [ebp+FFFFFEDC], 0000054F :76113E5C 33FF xor edi, edi :76113E5E 397D0C cmp dword ptr [ebp+0C], edi :76113E61 7537 jne 76113E9A :76113E63 A1E4101176 mov eax, dword ptr [761110E4] :76113E68 F60002 test byte ptr [eax], 02 :76113E6B 0F84A5010000 je 76114016 :76113E71 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpIsFileProtected" | :76113E73 680C231176 push 7611230C :76113E78 6824010000 push 00000124 :76113E7D 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113E82 FF15EC101176 Call dword ptr [761110EC] :76113E88 85C0 test eax, eax :76113E8A 0F8486010000 je 76114016 * Possible StringData Ref from Code Obj ->"NULL file name" | :76113E90 68FC221176 push 761122FC :76113E95 E970010000 jmp 7611400A * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113E61(C) | :76113E9A 68E0791176 push 761179E0 :76113E9F E86DFAFFFF call 76113911 :76113EA4 85C0 test eax, eax :76113EA6 7537 jne 76113EDF :76113EA8 A1E4101176 mov eax, dword ptr [761110E4] :76113EAD F60002 test byte ptr [eax], 02 :76113EB0 0F8460010000 je 76114016 :76113EB6 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpIsFileProtected" | :76113EB8 680C231176 push 7611230C :76113EBD 682D010000 push 0000012D :76113EC2 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113EC7 FF15EC101176 Call dword ptr [761110EC] :76113ECD 85C0 test eax, eax :76113ECF 0F8441010000 je 76114016 * Possible StringData Ref from Code Obj ->"Cannot init RPC" | :76113ED5 686C221176 push 7611226C :76113EDA E92B010000 jmp 7611400A * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113EA6(C) | :76113EDF 57 push edi :76113EE0 57 push edi :76113EE1 6804010000 push 00000104 :76113EE6 8D85E4FEFFFF lea eax, dword ptr [ebp+FFFFFEE4] :76113EEC 50 push eax :76113EED 6AFF push FFFFFFFF :76113EEF FF750C push [ebp+0C] :76113EF2 57 push edi :76113EF3 E86A1D0000 call 76115C62 :76113EF8 50 push eax * Reference To: KERNEL32.WideCharToMultiByte, Ord:0301h | :76113EF9 FF1550101176 Call dword ptr [76111050] :76113EFF 85C0 test eax, eax :76113F01 7550 jne 76113F53 * Reference To: KERNEL32.GetLastError, Ord:012Dh | :76113F03 FF154C101176 Call dword ptr [7611104C] :76113F09 8BF0 mov esi, eax :76113F0B A1E4101176 mov eax, dword ptr [761110E4] :76113F10 F60002 test byte ptr [eax], 02 :76113F13 0F84FD000000 je 76114016 :76113F19 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpIsFileProtected" | :76113F1B 680C231176 push 7611230C :76113F20 683F010000 push 0000013F :76113F25 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113F2A FF15EC101176 Call dword ptr [761110EC] :76113F30 85C0 test eax, eax :76113F32 0F84DE000000 je 76114016 :76113F38 56 push esi :76113F39 FF750C push [ebp+0C] :76113F3C 68D4221176 push 761122D4 :76113F41 6801020000 push 00000201 :76113F46 E8CFFAFFFF call 76113A1A :76113F4B 83C410 add esp, 00000010 :76113F4E E9C3000000 jmp 76114016 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113F01(C) | :76113F53 897DFC mov dword ptr [ebp-04], edi :76113F56 8D85E4FEFFFF lea eax, dword ptr [ebp+FFFFFEE4] :76113F5C 50 push eax :76113F5D E889EDFFFF call 76112CEB :76113F62 8985DCFEFFFF mov dword ptr [ebp+FFFFFEDC], eax :76113F68 33C9 xor ecx, ecx :76113F6A 3BC7 cmp eax, edi :76113F6C 0F94C1 sete cl :76113F6F 8BF1 mov esi, ecx :76113F71 89B5E0FEFFFF mov dword ptr [ebp+FFFFFEE0], esi :76113F77 EB55 jmp 76113FCE :76113F79 8B45EC mov eax, dword ptr [ebp-14] :76113F7C 8B00 mov eax, dword ptr [eax] :76113F7E 8B00 mov eax, dword ptr [eax] :76113F80 8985D0FEFFFF mov dword ptr [ebp+FFFFFED0], eax :76113F86 6A01 push 00000001 :76113F88 58 pop eax :76113F89 C3 ret :76113F8A 8B65E8 mov esp, dword ptr [ebp-18] :76113F8D 33FF xor edi, edi :76113F8F 33F6 xor esi, esi :76113F91 A1E4101176 mov eax, dword ptr [761110E4] :76113F96 F60002 test byte ptr [eax], 02 :76113F99 7433 je 76113FCE :76113F9B 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpIsFileProtected" | :76113F9D 680C231176 push 7611230C :76113FA2 6850010000 push 00000150 :76113FA7 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113FAC FF15EC101176 Call dword ptr [761110EC] :76113FB2 85C0 test eax, eax :76113FB4 7418 je 76113FCE :76113FB6 FFB5D0FEFFFF push dword ptr [ebp+FFFFFED0] * Possible StringData Ref from Code Obj ->"Error %x: RPC runtime reported " ->"exception" | :76113FBC 6840221176 push 76112240 :76113FC1 6801020000 push 00000201 :76113FC6 E84FFAFFFF call 76113A1A :76113FCB 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76113F77(U), :76113F99(C), :76113FB4(C) | :76113FCE 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76113FD2 68E0791176 push 761179E0 :76113FD7 E852FAFFFF call 76113A2E :76113FDC 85C0 test eax, eax :76113FDE 7538 jne 76114018 :76113FE0 A1E4101176 mov eax, dword ptr [761110E4] :76113FE5 F60002 test byte ptr [eax], 02 :76113FE8 742C je 76114016 :76113FEA 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpIsFileProtected" | :76113FEC 680C231176 push 7611230C :76113FF1 6858010000 push 00000158 :76113FF6 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76113FFB FF15EC101176 Call dword ptr [761110EC] :76114001 85C0 test eax, eax :76114003 7411 je 76114016 * Possible StringData Ref from Code Obj ->"Cannot term RPC" | :76114005 68D0211176 push 761121D0 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76113E95(U), :76113EDA(U) | :7611400A 6801020000 push 00000201 :7611400F E806FAFFFF call 76113A1A :76114014 59 pop ecx :76114015 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76113E6B(C), :76113E8A(C), :76113EB0(C), :76113ECF(C), :76113F13(C) |:76113F32(C), :76113F4E(U), :76113FE8(C), :76114003(C) | :76114016 33F6 xor esi, esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76113FDE(C) | :76114018 FFB5DCFEFFFF push dword ptr [ebp+FFFFFEDC] * Reference To: KERNEL32.SetLastError, Ord:029Ch | :7611401E FF1518101176 Call dword ptr [76111018] :76114024 8BC6 mov eax, esi :76114026 8B4DF0 mov ecx, dword ptr [ebp-10] :76114029 64890D00000000 mov dword ptr fs:[00000000], ecx :76114030 5F pop edi :76114031 5E pop esi :76114032 5B pop ebx :76114033 C9 leave :76114034 C20800 ret 0008 Exported fn(): SfcGetNextProtectedFile - Ord:0016h :76114037 55 push ebp :76114038 8BEC mov ebp, esp :7611403A 6AFF push FFFFFFFF :7611403C 6858231176 push 76112358 :76114041 6810591176 push 76115910 :76114046 64A100000000 mov eax, dword ptr fs:[00000000] :7611404C 50 push eax :7611404D 64892500000000 mov dword ptr fs:[00000000], esp :76114054 83EC18 sub esp, 00000018 :76114057 53 push ebx :76114058 56 push esi :76114059 57 push edi :7611405A 8965E8 mov dword ptr [ebp-18], esp :7611405D C745E04F050000 mov [ebp-20], 0000054F :76114064 837D0C00 cmp dword ptr [ebp+0C], 00000000 :76114068 7537 jne 761140A1 :7611406A A1E4101176 mov eax, dword ptr [761110E4] :7611406F F60002 test byte ptr [eax], 02 :76114072 0F8420010000 je 76114198 :76114078 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfcGetNextProtectedFile" | :7611407A 683C231176 push 7611233C :7611407F 6875010000 push 00000175 :76114084 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114089 FF15EC101176 Call dword ptr [761110EC] :7611408F 85C0 test eax, eax :76114091 0F8401010000 je 76114198 :76114097 682C231176 push 7611232C :7611409C E9EB000000 jmp 7611418C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114068(C) | :761140A1 68E0791176 push 761179E0 :761140A6 E866F8FFFF call 76113911 :761140AB 85C0 test eax, eax :761140AD 7537 jne 761140E6 :761140AF A1E4101176 mov eax, dword ptr [761110E4] :761140B4 F60002 test byte ptr [eax], 02 :761140B7 0F84DB000000 je 76114198 :761140BD 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfcGetNextProtectedFile" | :761140BF 683C231176 push 7611233C :761140C4 687E010000 push 0000017E :761140C9 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :761140CE FF15EC101176 Call dword ptr [761110EC] :761140D4 85C0 test eax, eax :761140D6 0F84BC000000 je 76114198 * Possible StringData Ref from Code Obj ->"Cannot init RPC" | :761140DC 686C221176 push 7611226C :761140E1 E9A6000000 jmp 7611418C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761140AD(C) | :761140E6 8365FC00 and dword ptr [ebp-04], 00000000 :761140EA FF750C push [ebp+0C] :761140ED E815EDFFFF call 76112E07 :761140F2 8945E0 mov dword ptr [ebp-20], eax :761140F5 33C9 xor ecx, ecx :761140F7 85C0 test eax, eax :761140F9 0F94C1 sete cl :761140FC 8BF1 mov esi, ecx :761140FE 8975E4 mov dword ptr [ebp-1C], esi :76114101 EB4D jmp 76114150 :76114103 8B45EC mov eax, dword ptr [ebp-14] :76114106 8B00 mov eax, dword ptr [eax] :76114108 8B00 mov eax, dword ptr [eax] :7611410A 8945D8 mov dword ptr [ebp-28], eax :7611410D 6A01 push 00000001 :7611410F 58 pop eax :76114110 C3 ret :76114111 8B65E8 mov esp, dword ptr [ebp-18] :76114114 33F6 xor esi, esi :76114116 A1E4101176 mov eax, dword ptr [761110E4] :7611411B F60002 test byte ptr [eax], 02 :7611411E 7430 je 76114150 :76114120 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfcGetNextProtectedFile" | :76114122 683C231176 push 7611233C :76114127 688D010000 push 0000018D :7611412C 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114131 FF15EC101176 Call dword ptr [761110EC] :76114137 85C0 test eax, eax :76114139 7415 je 76114150 :7611413B FF75D8 push [ebp-28] * Possible StringData Ref from Code Obj ->"Error %x: RPC runtime reported " ->"exception" | :7611413E 6840221176 push 76112240 :76114143 6801020000 push 00000201 :76114148 E8CDF8FFFF call 76113A1A :7611414D 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114101(U), :7611411E(C), :76114139(C) | :76114150 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76114154 68E0791176 push 761179E0 :76114159 E8D0F8FFFF call 76113A2E :7611415E 85C0 test eax, eax :76114160 7538 jne 7611419A :76114162 A1E4101176 mov eax, dword ptr [761110E4] :76114167 F60002 test byte ptr [eax], 02 :7611416A 742C je 76114198 :7611416C 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfcGetNextProtectedFile" | :7611416E 683C231176 push 7611233C :76114173 6895010000 push 00000195 :76114178 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :7611417D FF15EC101176 Call dword ptr [761110EC] :76114183 85C0 test eax, eax :76114185 7411 je 76114198 * Possible StringData Ref from Code Obj ->"Cannot term RPC" | :76114187 68D0211176 push 761121D0 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:7611409C(U), :761140E1(U) | :7611418C 6801020000 push 00000201 :76114191 E884F8FFFF call 76113A1A :76114196 59 pop ecx :76114197 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114072(C), :76114091(C), :761140B7(C), :761140D6(C), :7611416A(C) |:76114185(C) | :76114198 33F6 xor esi, esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114160(C) | :7611419A FF75E0 push [ebp-20] * Reference To: KERNEL32.SetLastError, Ord:029Ch | :7611419D FF1518101176 Call dword ptr [76111018] :761141A3 8BC6 mov eax, esi :761141A5 8B4DF0 mov ecx, dword ptr [ebp-10] :761141A8 64890D00000000 mov dword ptr fs:[00000000], ecx :761141AF 5F pop edi :761141B0 5E pop esi :761141B1 5B pop ebx :761141B2 C9 leave :761141B3 C20800 ret 0008 Exported fn(): SfpVerifyFile - Ord:001Ah :761141B6 55 push ebp :761141B7 8BEC mov ebp, esp :761141B9 6AFF push FFFFFFFF :761141BB 6878231176 push 76112378 :761141C0 6810591176 push 76115910 :761141C5 64A100000000 mov eax, dword ptr fs:[00000000] :761141CB 50 push eax :761141CC 64892500000000 mov dword ptr fs:[00000000], esp :761141D3 83EC14 sub esp, 00000014 :761141D6 53 push ebx :761141D7 56 push esi :761141D8 57 push edi :761141D9 8965E8 mov dword ptr [ebp-18], esp :761141DC 68E0791176 push 761179E0 :761141E1 E82BF7FFFF call 76113911 :761141E6 85C0 test eax, eax :761141E8 7537 jne 76114221 :761141EA A1E4101176 mov eax, dword ptr [761110E4] :761141EF F60002 test byte ptr [eax], 02 :761141F2 0F84D7000000 je 761142CF :761141F8 6A02 push 00000002 :761141FA 6864231176 push 76112364 :761141FF 68AF010000 push 000001AF :76114204 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114209 FF15EC101176 Call dword ptr [761110EC] :7611420F 85C0 test eax, eax :76114211 0F84B8000000 je 761142CF * Possible StringData Ref from Code Obj ->"Cannot init RPC" | :76114217 686C221176 push 7611226C :7611421C E9A2000000 jmp 761142C3 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761141E8(C) | :76114221 8365FC00 and dword ptr [ebp-04], 00000000 :76114225 FF7510 push [ebp+10] :76114228 FF750C push [ebp+0C] :7611422B FF7508 push [ebp+08] :7611422E E8FFECFFFF call 76112F32 :76114233 8BF0 mov esi, eax :76114235 8975E4 mov dword ptr [ebp-1C], esi :76114238 EB4D jmp 76114287 :7611423A 8B45EC mov eax, dword ptr [ebp-14] :7611423D 8B00 mov eax, dword ptr [eax] :7611423F 8B00 mov eax, dword ptr [eax] :76114241 8945DC mov dword ptr [ebp-24], eax :76114244 6A01 push 00000001 :76114246 58 pop eax :76114247 C3 ret :76114248 8B65E8 mov esp, dword ptr [ebp-18] :7611424B 33F6 xor esi, esi :7611424D A1E4101176 mov eax, dword ptr [761110E4] :76114252 F60002 test byte ptr [eax], 02 :76114255 7430 je 76114287 :76114257 6A02 push 00000002 :76114259 6864231176 push 76112364 :7611425E 68BC010000 push 000001BC :76114263 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114268 FF15EC101176 Call dword ptr [761110EC] :7611426E 85C0 test eax, eax :76114270 7415 je 76114287 :76114272 FF75DC push [ebp-24] * Possible StringData Ref from Code Obj ->"Error %x: RPC runtime reported " ->"exception" | :76114275 6840221176 push 76112240 :7611427A 6801020000 push 00000201 :7611427F E896F7FFFF call 76113A1A :76114284 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114238(U), :76114255(C), :76114270(C) | :76114287 834DFCFF or dword ptr [ebp-04], FFFFFFFF :7611428B 68E0791176 push 761179E0 :76114290 E899F7FFFF call 76113A2E :76114295 85C0 test eax, eax :76114297 7538 jne 761142D1 :76114299 A1E4101176 mov eax, dword ptr [761110E4] :7611429E F60002 test byte ptr [eax], 02 :761142A1 742C je 761142CF :761142A3 6A02 push 00000002 :761142A5 6864231176 push 76112364 :761142AA 68C4010000 push 000001C4 :761142AF 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :761142B4 FF15EC101176 Call dword ptr [761110EC] :761142BA 85C0 test eax, eax :761142BC 7411 je 761142CF * Possible StringData Ref from Code Obj ->"Cannot term RPC" | :761142BE 68D0211176 push 761121D0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611421C(U) | :761142C3 6801020000 push 00000201 :761142C8 E84DF7FFFF call 76113A1A :761142CD 59 pop ecx :761142CE 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761141F2(C), :76114211(C), :761142A1(C), :761142BC(C) | :761142CF 33F6 xor esi, esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114297(C) | :761142D1 8BC6 mov eax, esi :761142D3 8B4DF0 mov ecx, dword ptr [ebp-10] :761142D6 64890D00000000 mov dword ptr fs:[00000000], ecx :761142DD 5F pop edi :761142DE 5E pop esi :761142DF 5B pop ebx :761142E0 C9 leave :761142E1 C20C00 ret 000C Exported fn(): DisableSFP - Ord:000Ch :761142E4 55 push ebp :761142E5 8BEC mov ebp, esp :761142E7 6AFF push FFFFFFFF :761142E9 6890231176 push 76112390 :761142EE 6810591176 push 76115910 :761142F3 64A100000000 mov eax, dword ptr fs:[00000000] :761142F9 50 push eax :761142FA 64892500000000 mov dword ptr fs:[00000000], esp :76114301 83EC14 sub esp, 00000014 :76114304 53 push ebx :76114305 56 push esi :76114306 57 push edi :76114307 8965E8 mov dword ptr [ebp-18], esp :7611430A 68E4791176 push 761179E4 :7611430F E8FDF5FFFF call 76113911 :76114314 85C0 test eax, eax :76114316 7537 jne 7611434F :76114318 A1E4101176 mov eax, dword ptr [761110E4] :7611431D F60002 test byte ptr [eax], 02 :76114320 0F84D7000000 je 761143FD :76114326 6A02 push 00000002 :76114328 6884231176 push 76112384 :7611432D 68DD010000 push 000001DD :76114332 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114337 FF15EC101176 Call dword ptr [761110EC] :7611433D 85C0 test eax, eax :7611433F 0F84B8000000 je 761143FD * Possible StringData Ref from Code Obj ->"Cannot init RPC" | :76114345 686C221176 push 7611226C :7611434A E9A2000000 jmp 761143F1 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114316(C) | :7611434F 8365FC00 and dword ptr [ebp-04], 00000000 :76114353 FF750C push [ebp+0C] :76114356 FF7508 push [ebp+08] :76114359 E841EDFFFF call 7611309F :7611435E 8BF0 mov esi, eax :76114360 8975E4 mov dword ptr [ebp-1C], esi :76114363 EB50 jmp 761143B5 :76114365 8B45EC mov eax, dword ptr [ebp-14] :76114368 8B00 mov eax, dword ptr [eax] :7611436A 8B00 mov eax, dword ptr [eax] :7611436C 8945DC mov dword ptr [ebp-24], eax :7611436F 6A01 push 00000001 :76114371 58 pop eax :76114372 C3 ret :76114373 8B65E8 mov esp, dword ptr [ebp-18] :76114376 BE4F050000 mov esi, 0000054F :7611437B A1E4101176 mov eax, dword ptr [761110E4] :76114380 F60002 test byte ptr [eax], 02 :76114383 7430 je 761143B5 :76114385 6A02 push 00000002 :76114387 6884231176 push 76112384 :7611438C 68EA010000 push 000001EA :76114391 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114396 FF15EC101176 Call dword ptr [761110EC] :7611439C 85C0 test eax, eax :7611439E 7415 je 761143B5 :761143A0 FF75DC push [ebp-24] * Possible StringData Ref from Code Obj ->"Error %x: RPC runtime reported " ->"exception" | :761143A3 6840221176 push 76112240 :761143A8 6801020000 push 00000201 :761143AD E868F6FFFF call 76113A1A :761143B2 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114363(U), :76114383(C), :7611439E(C) | :761143B5 834DFCFF or dword ptr [ebp-04], FFFFFFFF :761143B9 68E4791176 push 761179E4 :761143BE E86BF6FFFF call 76113A2E :761143C3 85C0 test eax, eax :761143C5 753B jne 76114402 :761143C7 A1E4101176 mov eax, dword ptr [761110E4] :761143CC F60002 test byte ptr [eax], 02 :761143CF 742C je 761143FD :761143D1 6A02 push 00000002 :761143D3 6884231176 push 76112384 :761143D8 68F2010000 push 000001F2 :761143DD 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :761143E2 FF15EC101176 Call dword ptr [761110EC] :761143E8 85C0 test eax, eax :761143EA 7411 je 761143FD * Possible StringData Ref from Code Obj ->"Cannot term RPC" | :761143EC 68D0211176 push 761121D0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611434A(U) | :761143F1 6801020000 push 00000201 :761143F6 E81FF6FFFF call 76113A1A :761143FB 59 pop ecx :761143FC 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114320(C), :7611433F(C), :761143CF(C), :761143EA(C) | :761143FD BE4F050000 mov esi, 0000054F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761143C5(C) | :76114402 8BC6 mov eax, esi :76114404 8B4DF0 mov ecx, dword ptr [ebp-10] :76114407 64890D00000000 mov dword ptr fs:[00000000], ecx :7611440E 5F pop edi :7611440F 5E pop esi :76114410 5B pop ebx :76114411 C9 leave :76114412 C20800 ret 0008 Exported fn(): GetWindowsDiskFreeSpace - Ord:0010h :76114415 55 push ebp :76114416 8BEC mov ebp, esp :76114418 81EC1C010000 sub esp, 0000011C :7611441E 53 push ebx :7611441F 8D85E4FEFFFF lea eax, dword ptr [ebp+FFFFFEE4] :76114425 33DB xor ebx, ebx :76114427 6804010000 push 00000104 :7611442C 50 push eax :7611442D 895DFC mov dword ptr [ebp-04], ebx :76114430 895DF8 mov dword ptr [ebp-08], ebx :76114433 895DF4 mov dword ptr [ebp-0C], ebx :76114436 895DF0 mov dword ptr [ebp-10], ebx * Reference To: KERNEL32.GetWindowsDirectoryA, Ord:0197h | :76114439 FF1554101176 Call dword ptr [76111054] :7611443F 85C0 test eax, eax :76114441 7504 jne 76114447 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114468(C) | :76114443 33C0 xor eax, eax :76114445 EB31 jmp 76114478 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114441(C) | :76114447 8D45E8 lea eax, dword ptr [ebp-18] :7611444A 889DE6FEFFFF mov byte ptr [ebp+FFFFFEE6], bl :76114450 50 push eax :76114451 8D45F0 lea eax, dword ptr [ebp-10] :76114454 50 push eax :76114455 8D45F8 lea eax, dword ptr [ebp-08] :76114458 50 push eax :76114459 8D85E4FEFFFF lea eax, dword ptr [ebp+FFFFFEE4] :7611445F 50 push eax * Reference To: KERNEL32.GetDiskFreeSpaceExA, Ord:0114h | :76114460 FF1524101176 Call dword ptr [76111024] :76114466 85C0 test eax, eax :76114468 74D9 je 76114443 :7611446A 8B45F8 mov eax, dword ptr [ebp-08] :7611446D 8B4DFC mov ecx, dword ptr [ebp-04] :76114470 C1E814 shr eax, 14 :76114473 C1E10C shl ecx, 0C :76114476 0BC1 or eax, ecx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114445(U) | :76114478 5B pop ebx :76114479 C9 leave :7611447A C3 ret Exported fn(): GetStateMgrDiskMax - Ord:000Fh :7611447B 55 push ebp :7611447C 8BEC mov ebp, esp :7611447E 6AFF push FFFFFFFF :76114480 68B0231176 push 761123B0 :76114485 6810591176 push 76115910 :7611448A 64A100000000 mov eax, dword ptr fs:[00000000] :76114490 50 push eax :76114491 64892500000000 mov dword ptr fs:[00000000], esp :76114498 83EC14 sub esp, 00000014 :7611449B 53 push ebx :7611449C 56 push esi :7611449D 57 push edi :7611449E 8965E8 mov dword ptr [ebp-18], esp :761144A1 E80B010000 call 761145B1 :761144A6 85C0 test eax, eax :761144A8 0F85ED000000 jne 7611459B :761144AE 68E4791176 push 761179E4 :761144B3 E859F4FFFF call 76113911 :761144B8 85C0 test eax, eax :761144BA 7537 jne 761144F3 :761144BC A1E4101176 mov eax, dword ptr [761110E4] :761144C1 F60002 test byte ptr [eax], 02 :761144C4 0F84D1000000 je 7611459B :761144CA 6A02 push 00000002 :761144CC 689C231176 push 7611239C :761144D1 6827020000 push 00000227 :761144D6 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :761144DB FF15EC101176 Call dword ptr [761110EC] :761144E1 85C0 test eax, eax :761144E3 0F84B2000000 je 7611459B * Possible StringData Ref from Code Obj ->"Cannot init RPC" | :761144E9 686C221176 push 7611226C :761144EE E99C000000 jmp 7611458F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761144BA(C) | :761144F3 8365FC00 and dword ptr [ebp-04], 00000000 :761144F7 E881EFFFFF call 7611347D :761144FC 8BF0 mov esi, eax :761144FE 8975E4 mov dword ptr [ebp-1C], esi :76114501 EB50 jmp 76114553 :76114503 8B45EC mov eax, dword ptr [ebp-14] :76114506 8B00 mov eax, dword ptr [eax] :76114508 8B00 mov eax, dword ptr [eax] :7611450A 8945DC mov dword ptr [ebp-24], eax :7611450D 6A01 push 00000001 :7611450F 58 pop eax :76114510 C3 ret :76114511 8B65E8 mov esp, dword ptr [ebp-18] :76114514 BE4F050000 mov esi, 0000054F :76114519 A1E4101176 mov eax, dword ptr [761110E4] :7611451E F60002 test byte ptr [eax], 02 :76114521 7430 je 76114553 :76114523 6A02 push 00000002 :76114525 689C231176 push 7611239C :7611452A 6834020000 push 00000234 :7611452F 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114534 FF15EC101176 Call dword ptr [761110EC] :7611453A 85C0 test eax, eax :7611453C 7415 je 76114553 :7611453E FF75DC push [ebp-24] * Possible StringData Ref from Code Obj ->"Error %x: RPC runtime reported " ->"exception" | :76114541 6840221176 push 76112240 :76114546 6801020000 push 00000201 :7611454B E8CAF4FFFF call 76113A1A :76114550 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114501(U), :76114521(C), :7611453C(C) | :76114553 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76114557 68E4791176 push 761179E4 :7611455C E8CDF4FFFF call 76113A2E :76114561 85C0 test eax, eax :76114563 753B jne 761145A0 :76114565 A1E4101176 mov eax, dword ptr [761110E4] :7611456A F60002 test byte ptr [eax], 02 :7611456D 742C je 7611459B :7611456F 6A02 push 00000002 :76114571 689C231176 push 7611239C :76114576 683C020000 push 0000023C :7611457B 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114580 FF15EC101176 Call dword ptr [761110EC] :76114586 85C0 test eax, eax :76114588 7411 je 7611459B * Possible StringData Ref from Code Obj ->"Cannot term RPC" | :7611458A 68D0211176 push 761121D0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761144EE(U) | :7611458F 6801020000 push 00000201 :76114594 E881F4FFFF call 76113A1A :76114599 59 pop ecx :7611459A 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761144A8(C), :761144C4(C), :761144E3(C), :7611456D(C), :76114588(C) | :7611459B BE4F050000 mov esi, 0000054F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114563(C) | :761145A0 8BC6 mov eax, esi :761145A2 8B4DF0 mov ecx, dword ptr [ebp-10] :761145A5 64890D00000000 mov dword ptr fs:[00000000], ecx :761145AC 5F pop edi :761145AD 5E pop esi :761145AE 5B pop ebx :761145AF C9 leave :761145B0 C3 ret * Referenced by a CALL at Addresses: |:761144A1 , :761148B0 , :76114C67 | :761145B1 55 push ebp :761145B2 8BEC mov ebp, esp :761145B4 83EC14 sub esp, 00000014 :761145B7 56 push esi :761145B8 8D45F8 lea eax, dword ptr [ebp-08] :761145BB 33F6 xor esi, esi :761145BD 50 push eax :761145BE 56 push esi :761145BF 56 push esi :761145C0 FF35FC711176 push dword ptr [761171FC] :761145C6 6802000080 push 80000002 * Reference To: ADVAPI32.RegOpenKeyExA, Ord:019Dh | :761145CB FF1500101176 Call dword ptr [76111000] :761145D1 85C0 test eax, eax :761145D3 7541 jne 76114616 :761145D5 8D45FC lea eax, dword ptr [ebp-04] :761145D8 C745FC09000000 mov [ebp-04], 00000009 :761145DF 50 push eax :761145E0 8D45EC lea eax, dword ptr [ebp-14] :761145E3 50 push eax :761145E4 56 push esi :761145E5 56 push esi :761145E6 FF35C0711176 push dword ptr [761171C0] :761145EC FF75F8 push [ebp-08] * Reference To: ADVAPI32.RegQueryValueExA, Ord:01A7h | :761145EF FF150C101176 Call dword ptr [7611100C] :761145F5 85C0 test eax, eax :761145F7 7514 jne 7611460D :761145F9 3975FC cmp dword ptr [ebp-04], esi :761145FC 760F jbe 7611460D :761145FE 807DEC4E cmp byte ptr [ebp-14], 4E :76114602 7406 je 7611460A :76114604 807DEC6E cmp byte ptr [ebp-14], 6E :76114608 7503 jne 7611460D * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114602(C) | :7611460A 6A01 push 00000001 :7611460C 5E pop esi * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761145F7(C), :761145FC(C), :76114608(C) | :7611460D FF75F8 push [ebp-08] * Reference To: ADVAPI32.RegCloseKey, Ord:0184h | :76114610 FF1510101176 Call dword ptr [76111010] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761145D3(C) | :76114616 8BC6 mov eax, esi :76114618 5E pop esi :76114619 C9 leave :7611461A C3 ret Exported fn(): SetStateMgrDiskMax - Ord:0015h :7611461B 55 push ebp :7611461C 8BEC mov ebp, esp :7611461E 6AFF push FFFFFFFF :76114620 68D0231176 push 761123D0 :76114625 6810591176 push 76115910 :7611462A 64A100000000 mov eax, dword ptr fs:[00000000] :76114630 50 push eax :76114631 64892500000000 mov dword ptr fs:[00000000], esp :76114638 83EC14 sub esp, 00000014 :7611463B 53 push ebx :7611463C 56 push esi :7611463D 57 push edi :7611463E 8965E8 mov dword ptr [ebp-18], esp :76114641 68E4791176 push 761179E4 :76114646 E8C6F2FFFF call 76113911 :7611464B 85C0 test eax, eax :7611464D 7537 jne 76114686 :7611464F A1E4101176 mov eax, dword ptr [761110E4] :76114654 F60002 test byte ptr [eax], 02 :76114657 0F84D4000000 je 76114731 :7611465D 6A02 push 00000002 :7611465F 68BC231176 push 761123BC :76114664 686E020000 push 0000026E :76114669 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :7611466E FF15EC101176 Call dword ptr [761110EC] :76114674 85C0 test eax, eax :76114676 0F84B5000000 je 76114731 * Possible StringData Ref from Code Obj ->"Cannot init RPC" | :7611467C 686C221176 push 7611226C :76114681 E99F000000 jmp 76114725 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611464D(C) | :76114686 8365FC00 and dword ptr [ebp-04], 00000000 :7611468A FF7508 push [ebp+08] :7611468D E8FEECFFFF call 76113390 :76114692 8BF0 mov esi, eax :76114694 8975E4 mov dword ptr [ebp-1C], esi :76114697 EB50 jmp 761146E9 :76114699 8B45EC mov eax, dword ptr [ebp-14] :7611469C 8B00 mov eax, dword ptr [eax] :7611469E 8B00 mov eax, dword ptr [eax] :761146A0 8945DC mov dword ptr [ebp-24], eax :761146A3 6A01 push 00000001 :761146A5 58 pop eax :761146A6 C3 ret :761146A7 8B65E8 mov esp, dword ptr [ebp-18] :761146AA BE4F050000 mov esi, 0000054F :761146AF A1E4101176 mov eax, dword ptr [761110E4] :761146B4 F60002 test byte ptr [eax], 02 :761146B7 7430 je 761146E9 :761146B9 6A02 push 00000002 :761146BB 68BC231176 push 761123BC :761146C0 687B020000 push 0000027B :761146C5 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :761146CA FF15EC101176 Call dword ptr [761110EC] :761146D0 85C0 test eax, eax :761146D2 7415 je 761146E9 :761146D4 FF75DC push [ebp-24] * Possible StringData Ref from Code Obj ->"Error %x: RPC runtime reported " ->"exception" | :761146D7 6840221176 push 76112240 :761146DC 6801020000 push 00000201 :761146E1 E834F3FFFF call 76113A1A :761146E6 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114697(U), :761146B7(C), :761146D2(C) | :761146E9 834DFCFF or dword ptr [ebp-04], FFFFFFFF :761146ED 68E4791176 push 761179E4 :761146F2 E837F3FFFF call 76113A2E :761146F7 85C0 test eax, eax :761146F9 753B jne 76114736 :761146FB A1E4101176 mov eax, dword ptr [761110E4] :76114700 F60002 test byte ptr [eax], 02 :76114703 742C je 76114731 :76114705 6A02 push 00000002 :76114707 68BC231176 push 761123BC :7611470C 6883020000 push 00000283 :76114711 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114716 FF15EC101176 Call dword ptr [761110EC] :7611471C 85C0 test eax, eax :7611471E 7411 je 76114731 * Possible StringData Ref from Code Obj ->"Cannot term RPC" | :76114720 68D0211176 push 761121D0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114681(U) | :76114725 6801020000 push 00000201 :7611472A E8EBF2FFFF call 76113A1A :7611472F 59 pop ecx :76114730 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114657(C), :76114676(C), :76114703(C), :7611471E(C) | :76114731 BE4F050000 mov esi, 0000054F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761146F9(C) | :76114736 8BC6 mov eax, esi :76114738 8B4DF0 mov ecx, dword ptr [ebp-10] :7611473B 64890D00000000 mov dword ptr fs:[00000000], ecx :76114742 5F pop edi :76114743 5E pop esi :76114744 5B pop ebx :76114745 C9 leave :76114746 C20400 ret 0004 Exported fn(): RunDisableSR - Ord:0012h :76114749 55 push ebp :7611474A 8BEC mov ebp, esp :7611474C 51 push ecx :7611474D 51 push ecx :7611474E 53 push ebx :7611474F 56 push esi :76114750 8D45FC lea eax, dword ptr [ebp-04] :76114753 57 push edi :76114754 33DB xor ebx, ebx :76114756 50 push eax :76114757 53 push ebx :76114758 53 push ebx :76114759 FF35FC711176 push dword ptr [761171FC] :7611475F 895DF8 mov dword ptr [ebp-08], ebx :76114762 895DFC mov dword ptr [ebp-04], ebx :76114765 6802000080 push 80000002 * Reference To: ADVAPI32.RegOpenKeyExA, Ord:019Dh | :7611476A FF1500101176 Call dword ptr [76111000] :76114770 85C0 test eax, eax :76114772 743E je 761147B2 :76114774 A1E4101176 mov eax, dword ptr [761110E4] :76114779 F60002 test byte ptr [eax], 02 :7611477C 0F84E9000000 je 7611486B :76114782 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"RunDisableSR" | :76114784 6818241176 push 76112418 :76114789 689D020000 push 0000029D :7611478E 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114793 FF15EC101176 Call dword ptr [761110EC] :76114799 85C0 test eax, eax :7611479B 0F84CA000000 je 7611486B * Reference To: KERNEL32.GetLastError, Ord:012Dh | :761147A1 FF154C101176 Call dword ptr [7611104C] :761147A7 50 push eax * Possible StringData Ref from Code Obj ->"Cannot open regkey, ec=%ld" | :761147A8 68FC231176 push 761123FC :761147AD E9AC000000 jmp 7611485E * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114772(C) | :761147B2 8B0DC8711176 mov ecx, dword ptr [761171C8] :761147B8 395D08 cmp dword ptr [ebp+08], ebx :761147BB A1C4711176 mov eax, dword ptr [761171C4] :761147C0 8BD1 mov edx, ecx :761147C2 7502 jne 761147C6 :761147C4 8BD0 mov edx, eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761147C2(C) | :761147C6 395D08 cmp dword ptr [ebp+08], ebx :761147C9 8BF9 mov edi, ecx :761147CB 7502 jne 761147CF :761147CD 8BF8 mov edi, eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761147CB(C) | * Reference To: KERNEL32.lstrlenA, Ord:0335h | :761147CF 8B3558101176 mov esi, dword ptr [76111058] :761147D5 52 push edx :761147D6 FFD6 call esi :761147D8 40 inc eax :761147D9 50 push eax :761147DA 57 push edi * Reference To: ADVAPI32.RegSetValueExA, Ord:01B2h | :761147DB 8B3D08101176 mov edi, dword ptr [76111008] :761147E1 6A01 push 00000001 :761147E3 53 push ebx :761147E4 FF35C0711176 push dword ptr [761171C0] :761147EA FF75FC push [ebp-04] :761147ED FFD7 call edi :761147EF 85C0 test eax, eax :761147F1 7418 je 7611480B :761147F3 A1E4101176 mov eax, dword ptr [761110E4] :761147F8 F60002 test byte ptr [eax], 02 :761147FB 746E je 7611486B :761147FD 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"RunDisableSR" | :761147FF 6818241176 push 76112418 :76114804 68AB020000 push 000002AB :76114809 EB38 jmp 76114843 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761147F1(C) | :7611480B FF35C4711176 push dword ptr [761171C4] :76114811 FFD6 call esi :76114813 40 inc eax :76114814 50 push eax :76114815 FF35C4711176 push dword ptr [761171C4] :7611481B 6A01 push 00000001 :7611481D 53 push ebx :7611481E FF3524721176 push dword ptr [76117224] :76114824 FF75FC push [ebp-04] :76114827 FFD7 call edi :76114829 85C0 test eax, eax :7611482B 7445 je 76114872 :7611482D A1E4101176 mov eax, dword ptr [761110E4] :76114832 F60002 test byte ptr [eax], 02 :76114835 7434 je 7611486B :76114837 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"RunDisableSR" | :76114839 6818241176 push 76112418 :7611483E 68B8020000 push 000002B8 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114809(U) | :76114843 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114848 FF15EC101176 Call dword ptr [761110EC] :7611484E 85C0 test eax, eax :76114850 7419 je 7611486B * Reference To: KERNEL32.GetLastError, Ord:012Dh | :76114852 FF154C101176 Call dword ptr [7611104C] :76114858 50 push eax :76114859 68DC231176 push 761123DC * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761147AD(U) | :7611485E 6801020000 push 00000201 :76114863 E8B2F1FFFF call 76113A1A :76114868 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:7611477C(C), :7611479B(C), :761147FB(C), :76114835(C), :76114850(C) | :7611486B C745F84F050000 mov [ebp-08], 0000054F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611482B(C) | :76114872 395DFC cmp dword ptr [ebp-04], ebx :76114875 5F pop edi :76114876 5E pop esi :76114877 5B pop ebx :76114878 7409 je 76114883 :7611487A FF75FC push [ebp-04] * Reference To: ADVAPI32.RegCloseKey, Ord:0184h | :7611487D FF1510101176 Call dword ptr [76111010] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114878(C) | :76114883 8B45F8 mov eax, dword ptr [ebp-08] :76114886 C9 leave :76114887 C20400 ret 0004 Exported fn(): IsSREnabled - Ord:0011h :7611488A 55 push ebp :7611488B 8BEC mov ebp, esp :7611488D 6AFF push FFFFFFFF :7611488F 6838241176 push 76112438 :76114894 6810591176 push 76115910 :76114899 64A100000000 mov eax, dword ptr fs:[00000000] :7611489F 50 push eax :761148A0 64892500000000 mov dword ptr fs:[00000000], esp :761148A7 83EC14 sub esp, 00000014 :761148AA 53 push ebx :761148AB 56 push esi :761148AC 57 push edi :761148AD 8965E8 mov dword ptr [ebp-18], esp :761148B0 E8FCFCFFFF call 761145B1 :761148B5 85C0 test eax, eax :761148B7 7407 je 761148C0 :761148B9 33F6 xor esi, esi :761148BB E9F2000000 jmp 761149B2 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761148B7(C) | :761148C0 68E4791176 push 761179E4 :761148C5 E847F0FFFF call 76113911 :761148CA 85C0 test eax, eax :761148CC 7537 jne 76114905 :761148CE A1E4101176 mov eax, dword ptr [761110E4] :761148D3 F60002 test byte ptr [eax], 02 :761148D6 0F84D1000000 je 761149AD :761148DC 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"IsSREnabled" | :761148DE 6828241176 push 76112428 :761148E3 68D8020000 push 000002D8 :761148E8 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :761148ED FF15EC101176 Call dword ptr [761110EC] :761148F3 85C0 test eax, eax :761148F5 0F84B2000000 je 761149AD * Possible StringData Ref from Code Obj ->"Cannot init RPC" | :761148FB 686C221176 push 7611226C :76114900 E99C000000 jmp 761149A1 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761148CC(C) | :76114905 8365FC00 and dword ptr [ebp-04], 00000000 :76114909 E8A9E9FFFF call 761132B7 :7611490E 8BF0 mov esi, eax :76114910 8975E4 mov dword ptr [ebp-1C], esi :76114913 EB50 jmp 76114965 :76114915 8B45EC mov eax, dword ptr [ebp-14] :76114918 8B00 mov eax, dword ptr [eax] :7611491A 8B00 mov eax, dword ptr [eax] :7611491C 8945DC mov dword ptr [ebp-24], eax :7611491F 6A01 push 00000001 :76114921 58 pop eax :76114922 C3 ret :76114923 8B65E8 mov esp, dword ptr [ebp-18] :76114926 BE4F050000 mov esi, 0000054F :7611492B A1E4101176 mov eax, dword ptr [761110E4] :76114930 F60002 test byte ptr [eax], 02 :76114933 7430 je 76114965 :76114935 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"IsSREnabled" | :76114937 6828241176 push 76112428 :7611493C 68E5020000 push 000002E5 :76114941 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114946 FF15EC101176 Call dword ptr [761110EC] :7611494C 85C0 test eax, eax :7611494E 7415 je 76114965 :76114950 FF75DC push [ebp-24] * Possible StringData Ref from Code Obj ->"Error %x: RPC runtime reported " ->"exception" | :76114953 6840221176 push 76112240 :76114958 6801020000 push 00000201 :7611495D E8B8F0FFFF call 76113A1A :76114962 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114913(U), :76114933(C), :7611494E(C) | :76114965 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76114969 68E4791176 push 761179E4 :7611496E E8BBF0FFFF call 76113A2E :76114973 85C0 test eax, eax :76114975 753B jne 761149B2 :76114977 A1E4101176 mov eax, dword ptr [761110E4] :7611497C F60002 test byte ptr [eax], 02 :7611497F 742C je 761149AD :76114981 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"IsSREnabled" | :76114983 6828241176 push 76112428 :76114988 68ED020000 push 000002ED :7611498D 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114992 FF15EC101176 Call dword ptr [761110EC] :76114998 85C0 test eax, eax :7611499A 7411 je 761149AD * Possible StringData Ref from Code Obj ->"Cannot term RPC" | :7611499C 68D0211176 push 761121D0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114900(U) | :761149A1 6801020000 push 00000201 :761149A6 E86FF0FFFF call 76113A1A :761149AB 59 pop ecx :761149AC 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761148D6(C), :761148F5(C), :7611497F(C), :7611499A(C) | :761149AD BE4F050000 mov esi, 0000054F * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761148BB(U), :76114975(C) | :761149B2 81FE4F050000 cmp esi, 0000054F :761149B8 7502 jne 761149BC :761149BA 33F6 xor esi, esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761149B8(C) | :761149BC 8BC6 mov eax, esi :761149BE 8B4DF0 mov ecx, dword ptr [ebp-10] :761149C1 64890D00000000 mov dword ptr fs:[00000000], ecx :761149C8 5F pop edi :761149C9 5E pop esi :761149CA 5B pop ebx :761149CB C9 leave :761149CC C3 ret Exported fn(): DisableSR - Ord:000Dh :761149CD 55 push ebp :761149CE 8BEC mov ebp, esp :761149D0 6AFF push FFFFFFFF :761149D2 6850241176 push 76112450 :761149D7 6810591176 push 76115910 :761149DC 64A100000000 mov eax, dword ptr fs:[00000000] :761149E2 50 push eax :761149E3 64892500000000 mov dword ptr fs:[00000000], esp :761149EA 83EC14 sub esp, 00000014 :761149ED 53 push ebx :761149EE 56 push esi :761149EF 57 push edi :761149F0 8965E8 mov dword ptr [ebp-18], esp :761149F3 68E4791176 push 761179E4 :761149F8 E814EFFFFF call 76113911 :761149FD 85C0 test eax, eax :761149FF 7537 jne 76114A38 :76114A01 A1E4101176 mov eax, dword ptr [761110E4] :76114A06 F60002 test byte ptr [eax], 02 :76114A09 0F84D4000000 je 76114AE3 :76114A0F 6A02 push 00000002 :76114A11 6844241176 push 76112444 :76114A16 6807030000 push 00000307 :76114A1B 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114A20 FF15EC101176 Call dword ptr [761110EC] :76114A26 85C0 test eax, eax :76114A28 0F84B5000000 je 76114AE3 * Possible StringData Ref from Code Obj ->"Cannot init RPC" | :76114A2E 686C221176 push 7611226C :76114A33 E99F000000 jmp 76114AD7 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761149FF(C) | :76114A38 8365FC00 and dword ptr [ebp-04], 00000000 :76114A3C FF7508 push [ebp+08] :76114A3F E886E7FFFF call 761131CA :76114A44 8BF0 mov esi, eax :76114A46 8975E4 mov dword ptr [ebp-1C], esi :76114A49 EB50 jmp 76114A9B :76114A4B 8B45EC mov eax, dword ptr [ebp-14] :76114A4E 8B00 mov eax, dword ptr [eax] :76114A50 8B00 mov eax, dword ptr [eax] :76114A52 8945DC mov dword ptr [ebp-24], eax :76114A55 6A01 push 00000001 :76114A57 58 pop eax :76114A58 C3 ret :76114A59 8B65E8 mov esp, dword ptr [ebp-18] :76114A5C BE4F050000 mov esi, 0000054F :76114A61 A1E4101176 mov eax, dword ptr [761110E4] :76114A66 F60002 test byte ptr [eax], 02 :76114A69 7430 je 76114A9B :76114A6B 6A02 push 00000002 :76114A6D 6844241176 push 76112444 :76114A72 6814030000 push 00000314 :76114A77 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114A7C FF15EC101176 Call dword ptr [761110EC] :76114A82 85C0 test eax, eax :76114A84 7415 je 76114A9B :76114A86 FF75DC push [ebp-24] * Possible StringData Ref from Code Obj ->"Error %x: RPC runtime reported " ->"exception" | :76114A89 6840221176 push 76112240 :76114A8E 6801020000 push 00000201 :76114A93 E882EFFFFF call 76113A1A :76114A98 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114A49(U), :76114A69(C), :76114A84(C) | :76114A9B 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76114A9F 68E4791176 push 761179E4 :76114AA4 E885EFFFFF call 76113A2E :76114AA9 85C0 test eax, eax :76114AAB 753B jne 76114AE8 :76114AAD A1E4101176 mov eax, dword ptr [761110E4] :76114AB2 F60002 test byte ptr [eax], 02 :76114AB5 742C je 76114AE3 :76114AB7 6A02 push 00000002 :76114AB9 6844241176 push 76112444 :76114ABE 681C030000 push 0000031C :76114AC3 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114AC8 FF15EC101176 Call dword ptr [761110EC] :76114ACE 85C0 test eax, eax :76114AD0 7411 je 76114AE3 * Possible StringData Ref from Code Obj ->"Cannot term RPC" | :76114AD2 68D0211176 push 761121D0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114A33(U) | :76114AD7 6801020000 push 00000201 :76114ADC E839EFFFFF call 76113A1A :76114AE1 59 pop ecx :76114AE2 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114A09(C), :76114A28(C), :76114AB5(C), :76114AD0(C) | :76114AE3 BE4F050000 mov esi, 0000054F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114AAB(C) | :76114AE8 8BC6 mov eax, esi :76114AEA 8B4DF0 mov ecx, dword ptr [ebp-10] :76114AED 64890D00000000 mov dword ptr fs:[00000000], ecx :76114AF4 5F pop edi :76114AF5 5E pop esi :76114AF6 5B pop ebx :76114AF7 C9 leave :76114AF8 C20400 ret 0004 Exported fn(): SRUpdateMonitoredList - Ord:0014h :76114AFB 55 push ebp :76114AFC 8BEC mov ebp, esp :76114AFE 6AFF push FFFFFFFF :76114B00 6878241176 push 76112478 :76114B05 6810591176 push 76115910 :76114B0A 64A100000000 mov eax, dword ptr fs:[00000000] :76114B10 50 push eax :76114B11 64892500000000 mov dword ptr fs:[00000000], esp :76114B18 83EC14 sub esp, 00000014 :76114B1B 53 push ebx :76114B1C 56 push esi :76114B1D 57 push edi :76114B1E 8965E8 mov dword ptr [ebp-18], esp :76114B21 68E4791176 push 761179E4 :76114B26 E8E6EDFFFF call 76113911 :76114B2B 85C0 test eax, eax :76114B2D 7537 jne 76114B66 :76114B2F A1E4101176 mov eax, dword ptr [761110E4] :76114B34 F60002 test byte ptr [eax], 02 :76114B37 0F84D4000000 je 76114C11 :76114B3D 6A02 push 00000002 :76114B3F 685C241176 push 7611245C :76114B44 6835030000 push 00000335 :76114B49 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114B4E FF15EC101176 Call dword ptr [761110EC] :76114B54 85C0 test eax, eax :76114B56 0F84B5000000 je 76114C11 * Possible StringData Ref from Code Obj ->"Cannot init RPC" | :76114B5C 686C221176 push 7611226C :76114B61 E99F000000 jmp 76114C05 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114B2D(C) | :76114B66 8365FC00 and dword ptr [ebp-04], 00000000 :76114B6A FF7508 push [ebp+08] :76114B6D E8E4E9FFFF call 76113556 :76114B72 8BF0 mov esi, eax :76114B74 8975E4 mov dword ptr [ebp-1C], esi :76114B77 EB50 jmp 76114BC9 :76114B79 8B45EC mov eax, dword ptr [ebp-14] :76114B7C 8B00 mov eax, dword ptr [eax] :76114B7E 8B00 mov eax, dword ptr [eax] :76114B80 8945DC mov dword ptr [ebp-24], eax :76114B83 6A01 push 00000001 :76114B85 58 pop eax :76114B86 C3 ret :76114B87 8B65E8 mov esp, dword ptr [ebp-18] :76114B8A BE4F050000 mov esi, 0000054F :76114B8F A1E4101176 mov eax, dword ptr [761110E4] :76114B94 F60002 test byte ptr [eax], 02 :76114B97 7430 je 76114BC9 :76114B99 6A02 push 00000002 :76114B9B 685C241176 push 7611245C :76114BA0 6842030000 push 00000342 :76114BA5 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114BAA FF15EC101176 Call dword ptr [761110EC] :76114BB0 85C0 test eax, eax :76114BB2 7415 je 76114BC9 :76114BB4 FF75DC push [ebp-24] * Possible StringData Ref from Code Obj ->"Error %x: RPC runtime reported " ->"exception" | :76114BB7 6840221176 push 76112240 :76114BBC 6801020000 push 00000201 :76114BC1 E854EEFFFF call 76113A1A :76114BC6 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114B77(U), :76114B97(C), :76114BB2(C) | :76114BC9 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76114BCD 68E4791176 push 761179E4 :76114BD2 E857EEFFFF call 76113A2E :76114BD7 85C0 test eax, eax :76114BD9 753B jne 76114C16 :76114BDB A1E4101176 mov eax, dword ptr [761110E4] :76114BE0 F60002 test byte ptr [eax], 02 :76114BE3 742C je 76114C11 :76114BE5 6A02 push 00000002 :76114BE7 685C241176 push 7611245C :76114BEC 684A030000 push 0000034A :76114BF1 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114BF6 FF15EC101176 Call dword ptr [761110EC] :76114BFC 85C0 test eax, eax :76114BFE 7411 je 76114C11 * Possible StringData Ref from Code Obj ->"Cannot term RPC" | :76114C00 68D0211176 push 761121D0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114B61(U) | :76114C05 6801020000 push 00000201 :76114C0A E80BEEFFFF call 76113A1A :76114C0F 59 pop ecx :76114C10 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114B37(C), :76114B56(C), :76114BE3(C), :76114BFE(C) | :76114C11 BE4F050000 mov esi, 0000054F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114BD9(C) | :76114C16 8BC6 mov eax, esi :76114C18 8B4DF0 mov ecx, dword ptr [ebp-10] :76114C1B 64890D00000000 mov dword ptr fs:[00000000], ecx :76114C22 5F pop edi :76114C23 5E pop esi :76114C24 5B pop ebx :76114C25 C9 leave :76114C26 C20400 ret 0004 Exported fn(): SRSetRestorePoint - Ord:0013h :76114C29 55 push ebp :76114C2A 8BEC mov ebp, esp :76114C2C 6AFF push FFFFFFFF :76114C2E 68A8241176 push 761124A8 :76114C33 6810591176 push 76115910 :76114C38 64A100000000 mov eax, dword ptr fs:[00000000] :76114C3E 50 push eax :76114C3F 64892500000000 mov dword ptr fs:[00000000], esp :76114C46 83EC14 sub esp, 00000014 :76114C49 53 push ebx :76114C4A 56 push esi :76114C4B 57 push edi :76114C4C 8965E8 mov dword ptr [ebp-18], esp :76114C4F 33FF xor edi, edi :76114C51 897DE4 mov dword ptr [ebp-1C], edi :76114C54 8B750C mov esi, dword ptr [ebp+0C] :76114C57 3BF7 cmp esi, edi :76114C59 740C je 76114C67 :76114C5B 897E04 mov dword ptr [esi+04], edi :76114C5E 897E08 mov dword ptr [esi+08], edi :76114C61 C7064F050000 mov dword ptr [esi], 0000054F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114C59(C) | :76114C67 E845F9FFFF call 761145B1 :76114C6C 85C0 test eax, eax :76114C6E 744F je 76114CBF :76114C70 A1E4101176 mov eax, dword ptr [761110E4] :76114C75 F60002 test byte ptr [eax], 02 :76114C78 742C je 76114CA6 :76114C7A 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SRSetRestorePoint" | :76114C7C 6894241176 push 76112494 :76114C81 6866030000 push 00000366 :76114C86 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114C8B FF15EC101176 Call dword ptr [761110EC] :76114C91 85C0 test eax, eax :76114C93 7411 je 76114CA6 :76114C95 6884241176 push 76112484 :76114C9A 6801020000 push 00000201 :76114C9F E876EDFFFF call 76113A1A :76114CA4 59 pop ecx :76114CA5 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114C78(C), :76114C93(C) | :76114CA6 3BF7 cmp esi, edi :76114CA8 0F84FA000000 je 76114DA8 :76114CAE 897E04 mov dword ptr [esi+04], edi :76114CB1 897E08 mov dword ptr [esi+08], edi :76114CB4 C70622040000 mov dword ptr [esi], 00000422 :76114CBA E9E9000000 jmp 76114DA8 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114C6E(C) | :76114CBF 68E4791176 push 761179E4 :76114CC4 E848ECFFFF call 76113911 :76114CC9 85C0 test eax, eax :76114CCB 7537 jne 76114D04 :76114CCD A1E4101176 mov eax, dword ptr [761110E4] :76114CD2 F60002 test byte ptr [eax], 02 :76114CD5 0F84CD000000 je 76114DA8 :76114CDB 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SRSetRestorePoint" | :76114CDD 6894241176 push 76112494 :76114CE2 6872030000 push 00000372 :76114CE7 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114CEC FF15EC101176 Call dword ptr [761110EC] :76114CF2 85C0 test eax, eax :76114CF4 0F84AE000000 je 76114DA8 * Possible StringData Ref from Code Obj ->"Cannot init RPC" | :76114CFA 686C221176 push 7611226C :76114CFF E998000000 jmp 76114D9C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114CCB(C) | :76114D04 897DFC mov dword ptr [ebp-04], edi :76114D07 56 push esi :76114D08 FF7508 push [ebp+08] :76114D0B E862E9FFFF call 76113672 :76114D10 8945E4 mov dword ptr [ebp-1C], eax :76114D13 EB4B jmp 76114D60 :76114D15 8B45EC mov eax, dword ptr [ebp-14] :76114D18 8B00 mov eax, dword ptr [eax] :76114D1A 8B00 mov eax, dword ptr [eax] :76114D1C 8945DC mov dword ptr [ebp-24], eax :76114D1F 6A01 push 00000001 :76114D21 58 pop eax :76114D22 C3 ret :76114D23 8B65E8 mov esp, dword ptr [ebp-18] :76114D26 A1E4101176 mov eax, dword ptr [761110E4] :76114D2B F60002 test byte ptr [eax], 02 :76114D2E 7430 je 76114D60 :76114D30 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SRSetRestorePoint" | :76114D32 6894241176 push 76112494 :76114D37 687D030000 push 0000037D :76114D3C 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114D41 FF15EC101176 Call dword ptr [761110EC] :76114D47 85C0 test eax, eax :76114D49 7415 je 76114D60 :76114D4B FF75DC push [ebp-24] * Possible StringData Ref from Code Obj ->"Error %x: RPC runtime reported " ->"exception" | :76114D4E 6840221176 push 76112240 :76114D53 6801020000 push 00000201 :76114D58 E8BDECFFFF call 76113A1A :76114D5D 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114D13(U), :76114D2E(C), :76114D49(C) | :76114D60 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76114D64 68E4791176 push 761179E4 :76114D69 E8C0ECFFFF call 76113A2E :76114D6E 85C0 test eax, eax :76114D70 7536 jne 76114DA8 :76114D72 A1E4101176 mov eax, dword ptr [761110E4] :76114D77 F60002 test byte ptr [eax], 02 :76114D7A 742C je 76114DA8 :76114D7C 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SRSetRestorePoint" | :76114D7E 6894241176 push 76112494 :76114D83 6885030000 push 00000385 :76114D88 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114D8D FF15EC101176 Call dword ptr [761110EC] :76114D93 85C0 test eax, eax :76114D95 7411 je 76114DA8 * Possible StringData Ref from Code Obj ->"Cannot term RPC" | :76114D97 68D0211176 push 761121D0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114CFF(U) | :76114D9C 6801020000 push 00000201 :76114DA1 E874ECFFFF call 76113A1A :76114DA6 59 pop ecx :76114DA7 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114CA8(C), :76114CBA(U), :76114CD5(C), :76114CF4(C), :76114D70(C) |:76114D7A(C), :76114D95(C) | :76114DA8 8B45E4 mov eax, dword ptr [ebp-1C] :76114DAB 8B4DF0 mov ecx, dword ptr [ebp-10] :76114DAE 64890D00000000 mov dword ptr fs:[00000000], ecx :76114DB5 5F pop edi :76114DB6 5E pop esi :76114DB7 5B pop ebx :76114DB8 C9 leave :76114DB9 C20800 ret 0008 Exported fn(): DisableFIFO - Ord:000Bh :76114DBC 55 push ebp :76114DBD 8BEC mov ebp, esp :76114DBF 6AFF push FFFFFFFF :76114DC1 68C0241176 push 761124C0 :76114DC6 6810591176 push 76115910 :76114DCB 64A100000000 mov eax, dword ptr fs:[00000000] :76114DD1 50 push eax :76114DD2 64892500000000 mov dword ptr fs:[00000000], esp :76114DD9 83EC14 sub esp, 00000014 :76114DDC 53 push ebx :76114DDD 56 push esi :76114DDE 57 push edi :76114DDF 8965E8 mov dword ptr [ebp-18], esp :76114DE2 6A01 push 00000001 :76114DE4 5E pop esi :76114DE5 68E4791176 push 761179E4 :76114DEA E822EBFFFF call 76113911 :76114DEF 85C0 test eax, eax :76114DF1 7537 jne 76114E2A :76114DF3 A1E4101176 mov eax, dword ptr [761110E4] :76114DF8 F60002 test byte ptr [eax], 02 :76114DFB 0F84CF000000 je 76114ED0 :76114E01 6A02 push 00000002 :76114E03 68B4241176 push 761124B4 :76114E08 689A030000 push 0000039A :76114E0D 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114E12 FF15EC101176 Call dword ptr [761110EC] :76114E18 85C0 test eax, eax :76114E1A 0F84B0000000 je 76114ED0 * Possible StringData Ref from Code Obj ->"Cannot init RPC" | :76114E20 686C221176 push 7611226C :76114E25 E99A000000 jmp 76114EC4 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114DF1(C) | :76114E2A 8365FC00 and dword ptr [ebp-04], 00000000 :76114E2E FF750C push [ebp+0C] :76114E31 FF7508 push [ebp+08] :76114E34 E879E9FFFF call 761137B2 :76114E39 EB4D jmp 76114E88 :76114E3B 8B45EC mov eax, dword ptr [ebp-14] :76114E3E 8B00 mov eax, dword ptr [eax] :76114E40 8B00 mov eax, dword ptr [eax] :76114E42 8945DC mov dword ptr [ebp-24], eax :76114E45 6A01 push 00000001 :76114E47 58 pop eax :76114E48 C3 ret :76114E49 8B65E8 mov esp, dword ptr [ebp-18] :76114E4C 33F6 xor esi, esi :76114E4E A1E4101176 mov eax, dword ptr [761110E4] :76114E53 F60002 test byte ptr [eax], 02 :76114E56 7430 je 76114E88 :76114E58 6A02 push 00000002 :76114E5A 68B4241176 push 761124B4 :76114E5F 68A7030000 push 000003A7 :76114E64 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114E69 FF15EC101176 Call dword ptr [761110EC] :76114E6F 85C0 test eax, eax :76114E71 7415 je 76114E88 :76114E73 FF75DC push [ebp-24] * Possible StringData Ref from Code Obj ->"Error %x: RPC runtime reported " ->"exception" | :76114E76 6840221176 push 76112240 :76114E7B 6801020000 push 00000201 :76114E80 E895EBFFFF call 76113A1A :76114E85 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114E39(U), :76114E56(C), :76114E71(C) | :76114E88 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76114E8C 68E4791176 push 761179E4 :76114E91 E898EBFFFF call 76113A2E :76114E96 85C0 test eax, eax :76114E98 7538 jne 76114ED2 :76114E9A A1E4101176 mov eax, dword ptr [761110E4] :76114E9F F60002 test byte ptr [eax], 02 :76114EA2 742C je 76114ED0 :76114EA4 6A02 push 00000002 :76114EA6 68B4241176 push 761124B4 :76114EAB 68AF030000 push 000003AF :76114EB0 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114EB5 FF15EC101176 Call dword ptr [761110EC] :76114EBB 85C0 test eax, eax :76114EBD 7411 je 76114ED0 * Possible StringData Ref from Code Obj ->"Cannot term RPC" | :76114EBF 68D0211176 push 761121D0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114E25(U) | :76114EC4 6801020000 push 00000201 :76114EC9 E84CEBFFFF call 76113A1A :76114ECE 59 pop ecx :76114ECF 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114DFB(C), :76114E1A(C), :76114EA2(C), :76114EBD(C) | :76114ED0 33F6 xor esi, esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114E98(C) | :76114ED2 8BC6 mov eax, esi :76114ED4 8B4DF0 mov ecx, dword ptr [ebp-10] :76114ED7 64890D00000000 mov dword ptr fs:[00000000], ecx :76114EDE 5F pop edi :76114EDF 5E pop esi :76114EE0 5B pop ebx :76114EE1 C9 leave :76114EE2 C20800 ret 0008 Exported fn(): EnableFIFO - Ord:000Eh :76114EE5 55 push ebp :76114EE6 8BEC mov ebp, esp :76114EE8 6AFF push FFFFFFFF :76114EEA 68D8241176 push 761124D8 :76114EEF 6810591176 push 76115910 :76114EF4 64A100000000 mov eax, dword ptr fs:[00000000] :76114EFA 50 push eax :76114EFB 64892500000000 mov dword ptr fs:[00000000], esp :76114F02 83EC14 sub esp, 00000014 :76114F05 53 push ebx :76114F06 56 push esi :76114F07 57 push edi :76114F08 8965E8 mov dword ptr [ebp-18], esp :76114F0B 6A01 push 00000001 :76114F0D 5E pop esi :76114F0E 68E4791176 push 761179E4 :76114F13 E8F9E9FFFF call 76113911 :76114F18 85C0 test eax, eax :76114F1A 7537 jne 76114F53 :76114F1C A1E4101176 mov eax, dword ptr [761110E4] :76114F21 F60002 test byte ptr [eax], 02 :76114F24 0F84C9000000 je 76114FF3 :76114F2A 6A02 push 00000002 :76114F2C 68CC241176 push 761124CC :76114F31 68C5030000 push 000003C5 :76114F36 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114F3B FF15EC101176 Call dword ptr [761110EC] :76114F41 85C0 test eax, eax :76114F43 0F84AA000000 je 76114FF3 * Possible StringData Ref from Code Obj ->"Cannot init RPC" | :76114F49 686C221176 push 7611226C :76114F4E E994000000 jmp 76114FE7 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114F1A(C) | :76114F53 8365FC00 and dword ptr [ebp-04], 00000000 :76114F57 E813E9FFFF call 7611386F :76114F5C EB4D jmp 76114FAB :76114F5E 8B45EC mov eax, dword ptr [ebp-14] :76114F61 8B00 mov eax, dword ptr [eax] :76114F63 8B00 mov eax, dword ptr [eax] :76114F65 8945DC mov dword ptr [ebp-24], eax :76114F68 6A01 push 00000001 :76114F6A 58 pop eax :76114F6B C3 ret :76114F6C 8B65E8 mov esp, dword ptr [ebp-18] :76114F6F 33F6 xor esi, esi :76114F71 A1E4101176 mov eax, dword ptr [761110E4] :76114F76 F60002 test byte ptr [eax], 02 :76114F79 7430 je 76114FAB :76114F7B 6A02 push 00000002 :76114F7D 68CC241176 push 761124CC :76114F82 68D2030000 push 000003D2 :76114F87 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114F8C FF15EC101176 Call dword ptr [761110EC] :76114F92 85C0 test eax, eax :76114F94 7415 je 76114FAB :76114F96 FF75DC push [ebp-24] * Possible StringData Ref from Code Obj ->"Error %x: RPC runtime reported " ->"exception" | :76114F99 6840221176 push 76112240 :76114F9E 6801020000 push 00000201 :76114FA3 E872EAFFFF call 76113A1A :76114FA8 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114F5C(U), :76114F79(C), :76114F94(C) | :76114FAB 834DFCFF or dword ptr [ebp-04], FFFFFFFF :76114FAF 68E4791176 push 761179E4 :76114FB4 E875EAFFFF call 76113A2E :76114FB9 85C0 test eax, eax :76114FBB 7538 jne 76114FF5 :76114FBD A1E4101176 mov eax, dword ptr [761110E4] :76114FC2 F60002 test byte ptr [eax], 02 :76114FC5 742C je 76114FF3 :76114FC7 6A02 push 00000002 :76114FC9 68CC241176 push 761124CC :76114FCE 68DA030000 push 000003DA :76114FD3 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76114FD8 FF15EC101176 Call dword ptr [761110EC] :76114FDE 85C0 test eax, eax :76114FE0 7411 je 76114FF3 * Possible StringData Ref from Code Obj ->"Cannot term RPC" | :76114FE2 68D0211176 push 761121D0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114F4E(U) | :76114FE7 6801020000 push 00000201 :76114FEC E829EAFFFF call 76113A1A :76114FF1 59 pop ecx :76114FF2 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76114F24(C), :76114F43(C), :76114FC5(C), :76114FE0(C) | :76114FF3 33F6 xor esi, esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76114FBB(C) | :76114FF5 8BC6 mov eax, esi :76114FF7 8B4DF0 mov ecx, dword ptr [ebp-10] :76114FFA 64890D00000000 mov dword ptr fs:[00000000], ecx :76115001 5F pop edi :76115002 5E pop esi :76115003 5B pop ebx :76115004 C9 leave :76115005 C3 ret Exported fn(): SfpDuplicateCatalog - Ord:0018h :76115006 55 push ebp :76115007 8BEC mov ebp, esp :76115009 81EC08080000 sub esp, 00000808 :7611500F 53 push ebx :76115010 56 push esi :76115011 57 push edi :76115012 8D4DF8 lea ecx, dword ptr [ebp-08] :76115015 E8280D0000 call 76115D42 :7611501A FF750C push [ebp+0C] * Reference To: KERNEL32.lstrcpyA, Ord:032Fh | :7611501D 8B353C101176 mov esi, dword ptr [7611103C] :76115023 8D85F8FBFFFF lea eax, dword ptr [ebp+FFFFFBF8] :76115029 BB4F050000 mov ebx, 0000054F :7611502E 50 push eax :7611502F FFD6 call esi :76115031 8D85F8FBFFFF lea eax, dword ptr [ebp+FFFFFBF8] :76115037 50 push eax * Reference To: KERNEL32.lstrlenA, Ord:0335h | :76115038 FF1558101176 Call dword ptr [76111058] :7611503E 80BC05F7FBFFFF5C cmp byte ptr [ebp+eax-00000409], 5C * Reference To: KERNEL32.lstrcatA, Ord:0326h | :76115046 8B3D20101176 mov edi, dword ptr [76111020] :7611504C 740E je 7611505C :7611504E 8D85F8FBFFFF lea eax, dword ptr [ebp+FFFFFBF8] :76115054 6810211176 push 76112110 :76115059 50 push eax :7611505A FFD7 call edi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611504C(C) | :7611505C FF7508 push [ebp+08] :7611505F 8D85F8FBFFFF lea eax, dword ptr [ebp+FFFFFBF8] :76115065 50 push eax :76115066 FFD7 call edi :76115068 8D4DF8 lea ecx, dword ptr [ebp-08] :7611506B E8F80C0000 call 76115D68 :76115070 85C0 test eax, eax :76115072 7539 jne 761150AD :76115074 A1E4101176 mov eax, dword ptr [761110E4] :76115079 F60002 test byte ptr [eax], 02 :7611507C 0F8436010000 je 761151B8 :76115082 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpDuplicateCatalog" | :76115084 686C251176 push 7611256C :76115089 68FB030000 push 000003FB :7611508E 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76115093 FF15EC101176 Call dword ptr [761110EC] :76115099 85C0 test eax, eax :7611509B 0F8417010000 je 761151B8 :761150A1 6A00 push 00000000 * Possible StringData Ref from Code Obj ->"Error initializing catalog utilities" | :761150A3 6844251176 push 76112544 :761150A8 E9FE000000 jmp 761151AB * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115072(C) | :761150AD FF7508 push [ebp+08] :761150B0 8D85F8F7FFFF lea eax, dword ptr [ebp+FFFFF7F8] :761150B6 50 push eax :761150B7 FFD6 call esi :761150B9 8D85F8F7FFFF lea eax, dword ptr [ebp+FFFFF7F8] :761150BF 6800040000 push 00000400 :761150C4 50 push eax :761150C5 8D4DF8 lea ecx, dword ptr [ebp-08] :761150C8 E8740E0000 call 76115F41 :761150CD 85C0 test eax, eax :761150CF 7539 jne 7611510A :761150D1 A1E4101176 mov eax, dword ptr [761110E4] :761150D6 F60002 test byte ptr [eax], 02 :761150D9 0F84D9000000 je 761151B8 :761150DF 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpDuplicateCatalog" | :761150E1 686C251176 push 7611256C :761150E6 6804040000 push 00000404 :761150EB 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :761150F0 FF15EC101176 Call dword ptr [761110EC] :761150F6 85C0 test eax, eax :761150F8 0F84BA000000 je 761151B8 :761150FE 6A00 push 00000000 * Possible StringData Ref from Code Obj ->"Error getting the full catalog " ->"path." | :76115100 681C251176 push 7611251C :76115105 E9A1000000 jmp 761151AB * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761150CF(C) | :7611510A 8D85F8F7FFFF lea eax, dword ptr [ebp+FFFFF7F8] :76115110 50 push eax :76115111 E833080000 call 76115949 :76115116 85C0 test eax, eax :76115118 7543 jne 7611515D :7611511A A1E4101176 mov eax, dword ptr [761110E4] :7611511F F60002 test byte ptr [eax], 02 :76115122 7434 je 76115158 :76115124 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpDuplicateCatalog" | :76115126 686C251176 push 7611256C :7611512B 680C040000 push 0000040C :76115130 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76115135 FF15EC101176 Call dword ptr [761110EC] :7611513B 85C0 test eax, eax :7611513D 7419 je 76115158 :7611513F 8D85F8F7FFFF lea eax, dword ptr [ebp+FFFFF7F8] :76115145 50 push eax * Possible StringData Ref from Code Obj ->"Catalog %s does not exist" | :76115146 6800251176 push 76112500 :7611514B 6801020000 push 00000201 :76115150 E8C5E8FFFF call 76113A1A :76115155 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115122(C), :7611513D(C) | :76115158 6A02 push 00000002 :7611515A 5B pop ebx :7611515B EB5B jmp 761151B8 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115118(C) | :7611515D 33DB xor ebx, ebx :7611515F 8D85F8FBFFFF lea eax, dword ptr [ebp+FFFFFBF8] :76115165 53 push ebx :76115166 50 push eax :76115167 8D85F8F7FFFF lea eax, dword ptr [ebp+FFFFF7F8] :7611516D 50 push eax * Reference To: KERNEL32.CopyFileA, Ord:002Bh | :7611516E FF151C101176 Call dword ptr [7611101C] :76115174 85C0 test eax, eax :76115176 7540 jne 761151B8 * Reference To: KERNEL32.GetLastError, Ord:012Dh | :76115178 FF154C101176 Call dword ptr [7611104C] :7611517E 8BD8 mov ebx, eax :76115180 A1E4101176 mov eax, dword ptr [761110E4] :76115185 F60002 test byte ptr [eax], 02 :76115188 742E je 761151B8 :7611518A 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpDuplicateCatalog" | :7611518C 686C251176 push 7611256C :76115191 6817040000 push 00000417 :76115196 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :7611519B FF15EC101176 Call dword ptr [761110EC] :761151A1 85C0 test eax, eax :761151A3 7413 je 761151B8 :761151A5 53 push ebx :761151A6 68E4241176 push 761124E4 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761150A8(U), :76115105(U) | :761151AB 6801020000 push 00000201 :761151B0 E865E8FFFF call 76113A1A :761151B5 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:7611507C(C), :7611509B(C), :761150D9(C), :761150F8(C), :7611515B(U) |:76115176(C), :76115188(C), :761151A3(C) | :761151B8 8D4DF8 lea ecx, dword ptr [ebp-08] :761151BB E8950B0000 call 76115D55 :761151C0 5F pop edi :761151C1 8BC3 mov eax, ebx :761151C3 5E pop esi :761151C4 5B pop ebx :761151C5 C9 leave :761151C6 C20800 ret 0008 Exported fn(): SfpQueryCatalog - Ord:0019h :761151C9 55 push ebp :761151CA 8BEC mov ebp, esp :761151CC 81EC2C050000 sub esp, 0000052C :761151D2 834DDCFF or dword ptr [ebp-24], FFFFFFFF :761151D6 53 push ebx :761151D7 56 push esi :761151D8 33F6 xor esi, esi :761151DA 57 push edi :761151DB 8D4DE0 lea ecx, dword ptr [ebp-20] :761151DE C745FC4F050000 mov [ebp-04], 0000054F :761151E5 8975D8 mov dword ptr [ebp-28], esi :761151E8 8975F4 mov dword ptr [ebp-0C], esi :761151EB E8520B0000 call 76115D42 :761151F0 397508 cmp dword ptr [ebp+08], esi :761151F3 8975EC mov dword ptr [ebp-14], esi :761151F6 0F8453030000 je 7611554F :761151FC 8B5D10 mov ebx, dword ptr [ebp+10] :761151FF 3BDE cmp ebx, esi :76115201 0F8448030000 je 7611554F :76115207 8B7D0C mov edi, dword ptr [ebp+0C] :7611520A 3BFE cmp edi, esi :7611520C 7418 je 76115226 :7611520E 8B0B mov ecx, dword ptr [ebx] :76115210 3BCE cmp ecx, esi :76115212 7412 je 76115226 :76115214 8BD1 mov edx, ecx :76115216 33C0 xor eax, eax :76115218 C1E902 shr ecx, 02 :7611521B F3 repz :7611521C AB stosd :7611521D 8BCA mov ecx, edx :7611521F 83E103 and ecx, 00000003 :76115222 F3 repz :76115223 AA stosb :76115224 EB07 jmp 7611522D * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:7611520C(C), :76115212(C) | :76115226 C745EC01000000 mov [ebp-14], 00000001 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115224(U) | :7611522D 8B03 mov eax, dword ptr [ebx] :7611522F 8D4DE0 lea ecx, dword ptr [ebp-20] :76115232 8945E8 mov dword ptr [ebp-18], eax :76115235 8933 mov dword ptr [ebx], esi :76115237 E82C0B0000 call 76115D68 :7611523C 85C0 test eax, eax :7611523E 7534 jne 76115274 :76115240 A1E4101176 mov eax, dword ptr [761110E4] :76115245 F60002 test byte ptr [eax], 02 :76115248 0F84D9020000 je 76115527 :7611524E 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpQueryCatalog" | :76115250 68BC261176 push 761126BC :76115255 6853040000 push 00000453 :7611525A 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :7611525F FF15EC101176 Call dword ptr [761110EC] :76115265 85C0 test eax, eax :76115267 0F84BA020000 je 76115527 * Possible StringData Ref from Code Obj ->"Error initializing catalog utilities" | :7611526D 6844251176 push 76112544 :76115272 EB5A jmp 761152CE * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611523E(C) | :76115274 FF7508 push [ebp+08] :76115277 8D85D4FAFFFF lea eax, dword ptr [ebp+FFFFFAD4] :7611527D 50 push eax * Reference To: KERNEL32.lstrcpyA, Ord:032Fh | :7611527E FF153C101176 Call dword ptr [7611103C] :76115284 8D85D4FAFFFF lea eax, dword ptr [ebp+FFFFFAD4] :7611528A 6800040000 push 00000400 :7611528F 50 push eax :76115290 8D4DE0 lea ecx, dword ptr [ebp-20] :76115293 E8A90C0000 call 76115F41 :76115298 85C0 test eax, eax :7611529A 7543 jne 761152DF :7611529C A1E4101176 mov eax, dword ptr [761110E4] :761152A1 F60002 test byte ptr [eax], 02 :761152A4 0F847D020000 je 76115527 :761152AA 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"SfpQueryCatalog" | :761152AC 68BC261176 push 761126BC :761152B1 685B040000 push 0000045B :761152B6 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :761152BB FF15EC101176 Call dword ptr [761110EC] :761152C1 85C0 test eax, eax :761152C3 0F845E020000 je 76115527 * Possible StringData Ref from Code Obj ->"Error getting catalog path" | :761152C9 68A0261176 push 761126A0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115272(U) | :761152CE 6801020000 push 00000201 :761152D3 E842E7FFFF call 76113A1A :761152D8 59 pop ecx :761152D9 59 pop ecx :761152DA E948020000 jmp 76115527 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611529A(C) | :761152DF 8D85D4FAFFFF lea eax, dword ptr [ebp+FFFFFAD4] :761152E5 50 push eax * Reference To: KERNEL32.GetFileAttributesA, Ord:0120h | :761152E6 FF1540101176 Call dword ptr [76111040] :761152EC 83F8FF cmp eax, FFFFFFFF :761152EF 7542 jne 76115333 :761152F1 A1E4101176 mov eax, dword ptr [761110E4] :761152F6 F60004 test byte ptr [eax], 04 :761152F9 742C je 76115327 :761152FB 6A04 push 00000004 * Possible StringData Ref from Code Obj ->"SfpQueryCatalog" | :761152FD 68BC261176 push 761126BC :76115302 6862040000 push 00000462 :76115307 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :7611530C FF15EC101176 Call dword ptr [761110EC] :76115312 85C0 test eax, eax :76115314 7411 je 76115327 :76115316 FF7508 push [ebp+08] * Possible StringData Ref from Code Obj ->"Cat file %s not present in Crypto" | :76115319 687C261176 push 7611267C :7611531E 56 push esi :7611531F E8F6E6FFFF call 76113A1A :76115324 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761152F9(C), :76115314(C) | :76115327 C745FC02000000 mov [ebp-04], 00000002 :7611532E E9F4010000 jmp 76115527 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761152EF(C) | :76115333 FF7508 push [ebp+08] :76115336 8D85D4FAFFFF lea eax, dword ptr [ebp+FFFFFAD4] * Possible StringData Ref from Code Obj ->"Software\Microsoft\Windows\CurrentVersion\Syst" ->"emFileProtection\CatDepend" | :7611533C 6830261176 push 76112630 * Possible StringData Ref from Code Obj ->"%s\%s" | :76115341 6828261176 push 76112628 :76115346 50 push eax * Reference To: USER32.wsprintfA, Ord:02B3h | :76115347 FF15D4101176 Call dword ptr [761110D4] :7611534D 83C410 add esp, 00000010 :76115350 8D45F4 lea eax, dword ptr [ebp-0C] :76115353 50 push eax :76115354 6819000200 push 00020019 :76115359 8D85D4FAFFFF lea eax, dword ptr [ebp+FFFFFAD4] :7611535F 56 push esi :76115360 50 push eax :76115361 6802000080 push 80000002 * Reference To: ADVAPI32.RegOpenKeyExA, Ord:019Dh | :76115366 FF1500101176 Call dword ptr [76111000] :7611536C 85C0 test eax, eax :7611536E 7446 je 761153B6 :76115370 A1E4101176 mov eax, dword ptr [761110E4] :76115375 F60004 test byte ptr [eax], 04 :76115378 7434 je 761153AE :7611537A 6A04 push 00000004 * Possible StringData Ref from Code Obj ->"SfpQueryCatalog" | :7611537C 68BC261176 push 761126BC :76115381 6871040000 push 00000471 :76115386 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :7611538B FF15EC101176 Call dword ptr [761110EC] :76115391 85C0 test eax, eax :76115393 7419 je 761153AE :76115395 8D85D4FAFFFF lea eax, dword ptr [ebp+FFFFFAD4] :7611539B 50 push eax * Possible StringData Ref from Code Obj ->"Cannot open regkey %s" | :7611539C 6810261176 push 76112610 :761153A1 6801020000 push 00000201 :761153A6 E86FE6FFFF call 76113A1A :761153AB 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115378(C), :76115393(C), :761154D8(C), :761154E1(C) | :761153AE 8975FC mov dword ptr [ebp-04], esi :761153B1 E971010000 jmp 76115527 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611536E(C) | :761153B6 56 push esi :761153B7 56 push esi :761153B8 56 push esi :761153B9 8D45F8 lea eax, dword ptr [ebp-08] :761153BC 56 push esi :761153BD 50 push eax :761153BE 8D85D4FEFFFF lea eax, dword ptr [ebp+FFFFFED4] :761153C4 897508 mov dword ptr [ebp+08], esi :761153C7 50 push eax :761153C8 56 push esi :761153C9 FF75F4 push [ebp-0C] :761153CC C745F804010000 mov [ebp-08], 00000104 * Reference To: ADVAPI32.RegEnumValueA, Ord:0194h | :761153D3 FF1504101176 Call dword ptr [76111004] :761153D9 3D03010000 cmp eax, 00000103 :761153DE 8945F0 mov dword ptr [ebp-10], eax :761153E1 0F84EC000000 je 761154D3 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :761153E7 8B35EC101176 mov esi, dword ptr [761110EC] * Possible StringData Ref from Code Obj ->"SfpQueryCatalog" | :761153ED BBBC261176 mov ebx, 761126BC :761153F2 BFF0721176 mov edi, 761172F0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761154C8(C) | :761153F7 837DF000 cmp dword ptr [ebp-10], 00000000 :761153FB 0F85EF000000 jne 761154F0 :76115401 A1E4101176 mov eax, dword ptr [761110E4] :76115406 F60004 test byte ptr [eax], 04 :76115409 7428 je 76115433 :7611540B 6A04 push 00000004 :7611540D 53 push ebx :7611540E 6889040000 push 00000489 :76115413 57 push edi :76115414 FFD6 call esi :76115416 85C0 test eax, eax :76115418 7419 je 76115433 :7611541A 8D85D4FEFFFF lea eax, dword ptr [ebp+FFFFFED4] :76115420 50 push eax * Possible StringData Ref from Code Obj ->"Got dependent catalog - %s" | :76115421 68F4251176 push 761125F4 :76115426 6801020000 push 00000201 :7611542B E8EAE5FFFF call 76113A1A :76115430 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115409(C), :76115418(C) | :76115433 8B45F8 mov eax, dword ptr [ebp-08] :76115436 8D4801 lea ecx, dword ptr [eax+01] :76115439 8B4510 mov eax, dword ptr [ebp+10] :7611543C 0108 add dword ptr [eax], ecx :7611543E 8B4DE8 mov ecx, dword ptr [ebp-18] :76115441 3908 cmp dword ptr [eax], ecx :76115443 7631 jbe 76115476 :76115445 A1E4101176 mov eax, dword ptr [761110E4] :7611544A F60002 test byte ptr [eax], 02 :7611544D 7420 je 7611546F :7611544F 6A02 push 00000002 :76115451 53 push ebx :76115452 6890040000 push 00000490 :76115457 57 push edi :76115458 FFD6 call esi :7611545A 85C0 test eax, eax :7611545C 7411 je 7611546F * Possible StringData Ref from Code Obj ->"Insufficient dependency buffer" | :7611545E 68D4251176 push 761125D4 :76115463 6801020000 push 00000201 :76115468 E8ADE5FFFF call 76113A1A :7611546D 59 pop ecx :7611546E 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:7611544D(C), :7611545C(C) | :7611546F C745EC01000000 mov [ebp-14], 00000001 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115443(C) | :76115476 837DEC00 cmp dword ptr [ebp-14], 00000000 :7611547A 751D jne 76115499 :7611547C 8D85D4FEFFFF lea eax, dword ptr [ebp+FFFFFED4] :76115482 50 push eax :76115483 FF750C push [ebp+0C] * Reference To: KERNEL32.lstrcpyA, Ord:032Fh | :76115486 FF153C101176 Call dword ptr [7611103C] :7611548C 8B45F8 mov eax, dword ptr [ebp-08] :7611548F 8B4D0C mov ecx, dword ptr [ebp+0C] :76115492 8D440101 lea eax, dword ptr [ecx+eax+01] :76115496 89450C mov dword ptr [ebp+0C], eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611547A(C) | :76115499 33C0 xor eax, eax :7611549B FF4508 inc [ebp+08] :7611549E 50 push eax :7611549F 50 push eax :761154A0 50 push eax :761154A1 50 push eax :761154A2 8D45F8 lea eax, dword ptr [ebp-08] :761154A5 C745F804010000 mov [ebp-08], 00000104 :761154AC 50 push eax :761154AD 8D85D4FEFFFF lea eax, dword ptr [ebp+FFFFFED4] :761154B3 50 push eax :761154B4 FF7508 push [ebp+08] :761154B7 FF75F4 push [ebp-0C] * Reference To: ADVAPI32.RegEnumValueA, Ord:0194h | :761154BA FF1504101176 Call dword ptr [76111004] :761154C0 3D03010000 cmp eax, 00000103 :761154C5 8945F0 mov dword ptr [ebp-10], eax :761154C8 0F8529FFFFFF jne 761153F7 :761154CE 8B5D10 mov ebx, dword ptr [ebp+10] :761154D1 33F6 xor esi, esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761153E1(C) | :761154D3 8B45E8 mov eax, dword ptr [ebp-18] :761154D6 3903 cmp dword ptr [ebx], eax :761154D8 0F86D0FEFFFF jbe 761153AE :761154DE 39750C cmp dword ptr [ebp+0C], esi :761154E1 0F84C7FEFFFF je 761153AE :761154E7 C745FC08000000 mov [ebp-04], 00000008 :761154EE EB37 jmp 76115527 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761153FB(C) | :761154F0 A1E4101176 mov eax, dword ptr [761110E4] :761154F5 C745FC4F050000 mov [ebp-04], 0000054F :761154FC F60002 test byte ptr [eax], 02 :761154FF 7424 je 76115525 :76115501 6A02 push 00000002 :76115503 53 push ebx :76115504 6885040000 push 00000485 :76115509 57 push edi :7611550A FFD6 call esi :7611550C 85C0 test eax, eax :7611550E 7415 je 76115525 :76115510 FF75F0 push [ebp-10] * Possible StringData Ref from Code Obj ->"Error reading dependency value, " ->"ec %ld" | :76115513 68AC251176 push 761125AC :76115518 6801020000 push 00000201 :7611551D E8F8E4FFFF call 76113A1A :76115522 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761154FF(C), :7611550E(C) | :76115525 33F6 xor esi, esi * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115248(C), :76115267(C), :761152A4(C), :761152C3(C), :761152DA(U) |:7611532E(U), :761153B1(U), :761154EE(U), :76115588(U) | :76115527 3975F4 cmp dword ptr [ebp-0C], esi :7611552A 5F pop edi :7611552B 5E pop esi :7611552C 5B pop ebx :7611552D 7409 je 76115538 :7611552F FF75F4 push [ebp-0C] * Reference To: ADVAPI32.RegCloseKey, Ord:0184h | :76115532 FF1510101176 Call dword ptr [76111010] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611552D(C) | :76115538 8D4DE0 lea ecx, dword ptr [ebp-20] :7611553B E815080000 call 76115D55 :76115540 8D4DD8 lea ecx, dword ptr [ebp-28] :76115543 E842000000 call 7611558A :76115548 8B45FC mov eax, dword ptr [ebp-04] :7611554B C9 leave :7611554C C20C00 ret 000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761151F6(C), :76115201(C) | :7611554F A1E4101176 mov eax, dword ptr [761110E4] :76115554 F60001 test byte ptr [eax], 01 :76115557 7428 je 76115581 :76115559 6A01 push 00000001 * Possible StringData Ref from Code Obj ->"SfpQueryCatalog" | :7611555B 68BC261176 push 761126BC :76115560 683C040000 push 0000043C :76115565 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :7611556A FF15EC101176 Call dword ptr [761110EC] :76115570 85C0 test eax, eax :76115572 740D je 76115581 * Possible StringData Ref from Code Obj ->"Null Cat filename or buffer size " ->"pointer" | :76115574 6880251176 push 76112580 :76115579 56 push esi :7611557A E89BE4FFFF call 76113A1A :7611557F 59 pop ecx :76115580 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115557(C), :76115572(C) | :76115581 C745FC57000000 mov [ebp-04], 00000057 :76115588 EB9D jmp 76115527 * Referenced by a CALL at Address: |:76115543 | :7611558A 56 push esi :7611558B 8BF1 mov esi, ecx :7611558D 8B06 mov eax, dword ptr [esi] :7611558F 85C0 test eax, eax :76115591 7409 je 7611559C :76115593 50 push eax :76115594 E893030000 call 7611592C :76115599 832600 and dword ptr [esi], 00000000 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115591(C) | :7611559C 8B4604 mov eax, dword ptr [esi+04] :7611559F 83F8FF cmp eax, FFFFFFFF :761155A2 740A je 761155AE :761155A4 50 push eax * Reference To: WINTRUST.CryptCATClose, Ord:0011h | :761155A5 E8C80A0000 Call 76116072 :761155AA 834E04FF or dword ptr [esi+04], FFFFFFFF * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761155A2(C) | :761155AE 5E pop esi :761155AF C3 ret Exported fn(): SRDetectUndoer - Ord:000Ah :761155B0 81EC18020000 sub esp, 00000218 :761155B6 53 push ebx :761155B7 55 push ebp :761155B8 56 push esi :761155B9 57 push edi :761155BA 8D442410 lea eax, dword ptr [esp+10] :761155BE 33FF xor edi, edi :761155C0 50 push eax :761155C1 57 push edi :761155C2 57 push edi :761155C3 897C2424 mov dword ptr [esp+24], edi :761155C7 FF35A8711176 push dword ptr [761171A8] :761155CD 897C2420 mov dword ptr [esp+20], edi :761155D1 6802000080 push 80000002 * Reference To: ADVAPI32.RegOpenKeyExA, Ord:019Dh | :761155D6 FF1500101176 Call dword ptr [76111000] :761155DC 85C0 test eax, eax :761155DE 7443 je 76115623 :761155E0 A1E4101176 mov eax, dword ptr [761110E4] :761155E5 F60004 test byte ptr [eax], 04 :761155E8 0F84D1020000 je 761158BF :761155EE 6A04 push 00000004 * Possible StringData Ref from Code Obj ->"SRDetectUndoer" | :761155F0 68AC271176 push 761127AC :761155F5 68CF040000 push 000004CF :761155FA 68F0721176 push 761172F0 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :761155FF FF15EC101176 Call dword ptr [761110EC] :76115605 85C0 test eax, eax :76115607 0F84B2020000 je 761158BF * Possible StringData Ref from Code Obj ->"Undoer does not exist" | :7611560D 6894271176 push 76112794 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761156C0(U), :7611574C(U), :7611578A(U), :76115865(U) | :76115612 6801020000 push 00000201 :76115617 E8FEE3FFFF call 76113A1A :7611561C 59 pop ecx :7611561D 59 pop ecx :7611561E E99C020000 jmp 761158BF * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761155DE(C) | :76115623 8D442414 lea eax, dword ptr [esp+14] :76115627 897C2414 mov dword ptr [esp+14], edi :7611562B 50 push eax :7611562C 57 push edi :7611562D 57 push edi :7611562E 57 push edi :7611562F FF35AC711176 push dword ptr [761171AC] :76115635 FF742424 push [esp+24] * Reference To: ADVAPI32.RegQueryValueExA, Ord:01A7h | :76115639 FF150C101176 Call dword ptr [7611100C] * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :7611563F 8B35EC101176 mov esi, dword ptr [761110EC] * Possible StringData Ref from Code Obj ->"SRDetectUndoer" | :76115645 BBAC271176 mov ebx, 761127AC :7611564A 85C0 test eax, eax :7611564C BDF0721176 mov ebp, 761172F0 :76115651 742A je 7611567D :76115653 A1E4101176 mov eax, dword ptr [761110E4] :76115658 F60002 test byte ptr [eax], 02 :7611565B 7420 je 7611567D :7611565D 6A02 push 00000002 :7611565F 53 push ebx :76115660 68DC040000 push 000004DC :76115665 55 push ebp :76115666 FFD6 call esi :76115668 85C0 test eax, eax :7611566A 7411 je 7611567D * Possible StringData Ref from Code Obj ->"Cannot get exclusion list size" | :7611566C 6874271176 push 76112774 :76115671 6801020000 push 00000201 :76115676 E89FE3FFFF call 76113A1A :7611567B 59 pop ecx :7611567C 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115651(C), :7611565B(C), :7611566A(C) | :7611567D 8144241404010000 add dword ptr [esp+14], 00000104 :76115685 FF742414 push [esp+14] * Reference To: MSVCRT.malloc, Ord:028Eh | :76115689 FF157C101176 Call dword ptr [7611107C] :7611568F 59 pop ecx :76115690 8BC8 mov ecx, eax :76115692 3BCF cmp ecx, edi :76115694 894C2418 mov dword ptr [esp+18], ecx :76115698 752B jne 761156C5 :7611569A A1E4101176 mov eax, dword ptr [761110E4] :7611569F F60002 test byte ptr [eax], 02 :761156A2 0F8417020000 je 761158BF :761156A8 6A02 push 00000002 :761156AA 53 push ebx :761156AB 68E4040000 push 000004E4 :761156B0 55 push ebp :761156B1 FFD6 call esi :761156B3 85C0 test eax, eax :761156B5 0F8404020000 je 761158BF * Possible StringData Ref from Code Obj ->"Cannot allocate mem for exclusion " ->"list" | :761156BB 684C271176 push 7611274C :761156C0 E94DFFFFFF jmp 76115612 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115698(C) | :761156C5 33C0 xor eax, eax :761156C7 8BF9 mov edi, ecx :761156C9 AB stosd :761156CA 8D442414 lea eax, dword ptr [esp+14] :761156CE 50 push eax :761156CF 51 push ecx :761156D0 6A00 push 00000000 :761156D2 6A00 push 00000000 :761156D4 FF35AC711176 push dword ptr [761171AC] :761156DA FF742424 push [esp+24] * Reference To: ADVAPI32.RegQueryValueExA, Ord:01A7h | :761156DE FF150C101176 Call dword ptr [7611100C] :761156E4 85C0 test eax, eax :761156E6 742A je 76115712 :761156E8 A1E4101176 mov eax, dword ptr [761110E4] :761156ED F60002 test byte ptr [eax], 02 :761156F0 7420 je 76115712 :761156F2 6A02 push 00000002 :761156F4 53 push ebx :761156F5 68F1040000 push 000004F1 :761156FA 55 push ebp :761156FB FFD6 call esi :761156FD 85C0 test eax, eax :761156FF 7411 je 76115712 * Possible StringData Ref from Code Obj ->"Cannot get exclusion list value" | :76115701 682C271176 push 7611272C :76115706 6801020000 push 00000201 :7611570B E80AE3FFFF call 76113A1A :76115710 59 pop ecx :76115711 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761156E6(C), :761156F0(C), :761156FF(C) | :76115712 8D442420 lea eax, dword ptr [esp+20] :76115716 6804010000 push 00000104 :7611571B 50 push eax * Reference To: KERNEL32.GetWindowsDirectoryA, Ord:0197h | :7611571C FF1554101176 Call dword ptr [76111054] :76115722 85C0 test eax, eax :76115724 752B jne 76115751 :76115726 A1E4101176 mov eax, dword ptr [761110E4] :7611572B F60002 test byte ptr [eax], 02 :7611572E 0F848B010000 je 761158BF :76115734 6A02 push 00000002 :76115736 53 push ebx :76115737 68F7040000 push 000004F7 :7611573C 55 push ebp :7611573D FFD6 call esi :7611573F 85C0 test eax, eax :76115741 0F8478010000 je 761158BF * Possible StringData Ref from Code Obj ->"Cannot get windir" | :76115747 6818271176 push 76112718 :7611574C E9C1FEFFFF jmp 76115612 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115724(C) | :76115751 8D442420 lea eax, dword ptr [esp+20] :76115755 6A5C push 0000005C :76115757 50 push eax * Reference To: MSVCRT.strchr, Ord:02B4h | :76115758 FF1568101176 Call dword ptr [76111068] :7611575E 59 pop ecx :7611575F 85C0 test eax, eax :76115761 59 pop ecx :76115762 752B jne 7611578F :76115764 A1E4101176 mov eax, dword ptr [761110E4] :76115769 F60002 test byte ptr [eax], 02 :7611576C 0F844D010000 je 761158BF :76115772 6A02 push 00000002 :76115774 53 push ebx :76115775 68FE040000 push 000004FE :7611577A 55 push ebp :7611577B FFD6 call esi :7611577D 85C0 test eax, eax :7611577F 0F843A010000 je 761158BF * Possible StringData Ref from Code Obj ->"Cannot get drive from windir" | :76115785 68F8261176 push 761126F8 :7611578A E983FEFFFF jmp 76115612 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115762(C) | :7611578F 8B7C2418 mov edi, dword ptr [esp+18] :76115793 802000 and byte ptr [eax], 00 :76115796 57 push edi * Reference To: KERNEL32.lstrlenA, Ord:0335h | :76115797 FF1558101176 Call dword ptr [76111058] :7611579D 85C0 test eax, eax :7611579F B8F4261176 mov eax, 761126F4 :761157A4 7505 jne 761157AB :761157A6 B8F0261176 mov eax, 761126F0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761157A4(C) | :761157AB FF35D8711176 push dword ptr [761171D8] :761157B1 8D4C2424 lea ecx, dword ptr [esp+24] :761157B5 51 push ecx :761157B6 50 push eax :761157B7 8D842430010000 lea eax, dword ptr [esp+00000130] * Possible StringData Ref from Code Obj ->"%s%s\%s" | :761157BE 68E8261176 push 761126E8 :761157C3 50 push eax * Reference To: USER32.wsprintfA, Ord:02B3h | :761157C4 FF15D4101176 Call dword ptr [761110D4] :761157CA 83C414 add esp, 00000014 :761157CD 8D842424010000 lea eax, dword ptr [esp+00000124] :761157D4 50 push eax :761157D5 57 push edi * Reference To: KERNEL32.lstrcatA, Ord:0326h | :761157D6 FF1520101176 Call dword ptr [76111020] :761157DC 57 push edi * Reference To: KERNEL32.lstrlenA, Ord:0335h | :761157DD FF1558101176 Call dword ptr [76111058] :761157E3 40 inc eax :761157E4 50 push eax :761157E5 57 push edi * Reference To: ADVAPI32.RegSetValueExA, Ord:01B2h | :761157E6 8B3D08101176 mov edi, dword ptr [76111008] :761157EC 6A01 push 00000001 :761157EE 6A00 push 00000000 :761157F0 FF35AC711176 push dword ptr [761171AC] :761157F6 FF742424 push [esp+24] :761157FA FFD7 call edi :761157FC 85C0 test eax, eax :761157FE 741B je 7611581B :76115800 A1E4101176 mov eax, dword ptr [761110E4] :76115805 F60002 test byte ptr [eax], 02 :76115808 0F84B1000000 je 761158BF :7611580E 6A02 push 00000002 :76115810 53 push ebx :76115811 6810050000 push 00000510 :76115816 E984000000 jmp 7611589F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761157FE(C) | :7611581B FF742410 push [esp+10] * Reference To: ADVAPI32.RegCloseKey, Ord:0184h | :7611581F FF1510101176 Call dword ptr [76111010] :76115825 8D4C2410 lea ecx, dword ptr [esp+10] :76115829 33C0 xor eax, eax :7611582B 51 push ecx :7611582C 50 push eax :7611582D 50 push eax :7611582E 8944241C mov dword ptr [esp+1C], eax :76115832 FF35FC711176 push dword ptr [761171FC] :76115838 6802000080 push 80000002 * Reference To: ADVAPI32.RegOpenKeyExA, Ord:019Dh | :7611583D FF1500101176 Call dword ptr [76111000] :76115843 85C0 test eax, eax :76115845 7423 je 7611586A :76115847 A1E4101176 mov eax, dword ptr [761110E4] :7611584C F60002 test byte ptr [eax], 02 :7611584F 746E je 761158BF :76115851 6A02 push 00000002 :76115853 53 push ebx :76115854 681E050000 push 0000051E :76115859 55 push ebp :7611585A FFD6 call esi :7611585C 85C0 test eax, eax :7611585E 745F je 761158BF * Possible StringData Ref from Code Obj ->"Cannot open VxdMon regkey" | :76115860 68CC261176 push 761126CC :76115865 E9A8FDFFFF jmp 76115612 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115845(C) | :7611586A 8D44241C lea eax, dword ptr [esp+1C] :7611586E 6A04 push 00000004 :76115870 50 push eax :76115871 6A04 push 00000004 :76115873 6A00 push 00000000 :76115875 C744242C01000000 mov [esp+2C], 00000001 :7611587D FF35B0711176 push dword ptr [761171B0] :76115883 FF742424 push [esp+24] :76115887 FFD7 call edi :76115889 85C0 test eax, eax :7611588B 7432 je 761158BF :7611588D A1E4101176 mov eax, dword ptr [761110E4] :76115892 F60002 test byte ptr [eax], 02 :76115895 7428 je 761158BF :76115897 6A02 push 00000002 :76115899 53 push ebx :7611589A 682A050000 push 0000052A * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115816(U) | :7611589F 55 push ebp :761158A0 FFD6 call esi :761158A2 85C0 test eax, eax :761158A4 7419 je 761158BF * Reference To: KERNEL32.GetLastError, Ord:012Dh | :761158A6 FF154C101176 Call dword ptr [7611104C] :761158AC 50 push eax :761158AD 68DC231176 push 761123DC :761158B2 6801020000 push 00000201 :761158B7 E85EE1FFFF call 76113A1A :761158BC 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761155E8(C), :76115607(C), :7611561E(U), :761156A2(C), :761156B5(C) |:7611572E(C), :76115741(C), :7611576C(C), :7611577F(C), :76115808(C) |:7611584F(C), :7611585E(C), :7611588B(C), :76115895(C), :761158A4(C) | :761158BF 837C241000 cmp dword ptr [esp+10], 00000000 :761158C4 5F pop edi :761158C5 5E pop esi :761158C6 5D pop ebp :761158C7 5B pop ebx :761158C8 740A je 761158D4 :761158CA FF742400 push [esp] * Reference To: ADVAPI32.RegCloseKey, Ord:0184h | :761158CE FF1510101176 Call dword ptr [76111010] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761158C8(C) | :761158D4 837C240800 cmp dword ptr [esp+08], 00000000 :761158D9 740B je 761158E6 :761158DB FF742408 push [esp+08] * Reference To: MSVCRT.free, Ord:025Bh | :761158DF FF1578101176 Call dword ptr [76111078] :761158E5 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761158D9(C) | :761158E6 81C418020000 add esp, 00000218 :761158EC C21000 ret 0010 :761158EF FF742404 push [esp+04] :761158F3 E81E000000 call 76115916 :761158F8 C20400 ret 0004 :761158FB 837C240400 cmp dword ptr [esp+04], 00000000 :76115900 7409 je 7611590B :76115902 FF742404 push [esp+04] :76115906 E821000000 call 7611592C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115900(C) | :7611590B C20400 ret 0004 :7611590E CC int 03 :7611590F CC int 03 * Reference To: MSVCRT._except_handler3, Ord:00C7h | :76115910 FF2570101176 Jmp dword ptr [76111070] * Referenced by a CALL at Address: |:761158F3 | :76115916 FF742404 push [esp+04] :7611591A 6A08 push 00000008 * Reference To: KERNEL32.GetProcessHeap, Ord:0155h | :7611591C FF1534101176 Call dword ptr [76111034] :76115922 50 push eax * Reference To: KERNEL32.HeapAlloc, Ord:01B4h | :76115923 FF1538101176 Call dword ptr [76111038] :76115929 C20400 ret 0004 * Referenced by a CALL at Addresses: |:76115594 , :76115906 | :7611592C 837C240400 cmp dword ptr [esp+04], 00000000 :76115931 7413 je 76115946 :76115933 FF742404 push [esp+04] :76115937 6A00 push 00000000 * Reference To: KERNEL32.GetProcessHeap, Ord:0155h | :76115939 FF1534101176 Call dword ptr [76111034] :7611593F 50 push eax * Reference To: KERNEL32.HeapFree, Ord:01BAh | :76115940 FF1530101176 Call dword ptr [76111030] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115931(C) | :76115946 C20400 ret 0004 * Referenced by a CALL at Address: |:76115111 | :76115949 A1E4101176 mov eax, dword ptr [761110E4] :7611594E 53 push ebx :7611594F 55 push ebp :76115950 56 push esi * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76115951 8B35EC101176 mov esi, dword ptr [761110EC] :76115957 57 push edi :76115958 6A04 push 00000004 * Possible StringData Ref from Code Obj ->"DoesFileExist" | :7611595A BD10281176 mov ebp, 76112810 :7611595F 5B pop ebx :76115960 BF08761176 mov edi, 76117608 :76115965 8418 test byte ptr [eax], bl :76115967 7424 je 7611598D :76115969 53 push ebx :7611596A 55 push ebp :7611596B 6892000000 push 00000092 :76115970 57 push edi :76115971 FFD6 call esi :76115973 85C0 test eax, eax :76115975 7416 je 7611598D :76115977 FF742414 push [esp+14] * Possible StringData Ref from Code Obj ->"Checking for %s" | :7611597B 6800281176 push 76112800 :76115980 6807030000 push 00000307 :76115985 E890E0FFFF call 76113A1A :7611598A 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115967(C), :76115975(C) | :7611598D FF742414 push [esp+14] * Reference To: KERNEL32.GetFileAttributesA, Ord:0120h | :76115991 FF1540101176 Call dword ptr [76111040] :76115997 83F8FF cmp eax, FFFFFFFF :7611599A 7539 jne 761159D5 * Reference To: KERNEL32.GetLastError, Ord:012Dh | :7611599C FF154C101176 Call dword ptr [7611104C] :761159A2 89442414 mov dword ptr [esp+14], eax :761159A6 A1E4101176 mov eax, dword ptr [761110E4] :761159AB 8418 test byte ptr [eax], bl :761159AD 7452 je 76115A01 :761159AF 53 push ebx :761159B0 55 push ebp :761159B1 6899000000 push 00000099 :761159B6 57 push edi :761159B7 FFD6 call esi :761159B9 85C0 test eax, eax :761159BB 7444 je 76115A01 :761159BD FF742414 push [esp+14] * Possible StringData Ref from Code Obj ->"GetFileAttributes failed 0x%x" | :761159C1 68E0271176 push 761127E0 :761159C6 6807030000 push 00000307 :761159CB E84AE0FFFF call 76113A1A :761159D0 83C40C add esp, 0000000C :761159D3 EB2C jmp 76115A01 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611599A(C) | :761159D5 A810 test al, 10 :761159D7 A1E4101176 mov eax, dword ptr [761110E4] :761159DC 7427 je 76115A05 :761159DE 8418 test byte ptr [eax], bl :761159E0 741F je 76115A01 :761159E2 53 push ebx :761159E3 55 push ebp :761159E4 68A0000000 push 000000A0 :761159E9 57 push edi :761159EA FFD6 call esi :761159EC 85C0 test eax, eax :761159EE 7411 je 76115A01 * Possible StringData Ref from Code Obj ->"It is a Directory " | :761159F0 68CC271176 push 761127CC :761159F5 6807030000 push 00000307 :761159FA E81BE0FFFF call 76113A1A :761159FF 59 pop ecx :76115A00 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761159AD(C), :761159BB(C), :761159D3(U), :761159E0(C), :761159EE(C) | :76115A01 33C0 xor eax, eax :76115A03 EB26 jmp 76115A2B * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761159DC(C) | :76115A05 8418 test byte ptr [eax], bl :76115A07 741F je 76115A28 :76115A09 53 push ebx :76115A0A 55 push ebp :76115A0B 68A5000000 push 000000A5 :76115A10 57 push edi :76115A11 FFD6 call esi :76115A13 85C0 test eax, eax :76115A15 7411 je 76115A28 * Possible StringData Ref from Code Obj ->"File exists" | :76115A17 68BC271176 push 761127BC :76115A1C 6807030000 push 00000307 :76115A21 E8F4DFFFFF call 76113A1A :76115A26 59 pop ecx :76115A27 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115A07(C), :76115A15(C) | :76115A28 6A01 push 00000001 :76115A2A 58 pop eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115A03(U) | :76115A2B 5F pop edi :76115A2C 5E pop esi :76115A2D 5D pop ebp :76115A2E 5B pop ebx :76115A2F C20400 ret 0004 * Referenced by a CALL at Addresses: |:76115E01 , :76115EB6 | :76115A32 A1E4101176 mov eax, dword ptr [761110E4] :76115A37 53 push ebx :76115A38 55 push ebp :76115A39 56 push esi * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76115A3A 8B35EC101176 mov esi, dword ptr [761110EC] :76115A40 57 push edi :76115A41 6A04 push 00000004 * Possible StringData Ref from Code Obj ->"DoesDirExist" | :76115A43 BD64281176 mov ebp, 76112864 :76115A48 5B pop ebx :76115A49 BF08761176 mov edi, 76117608 :76115A4E 8418 test byte ptr [eax], bl :76115A50 7424 je 76115A76 :76115A52 53 push ebx :76115A53 55 push ebp :76115A54 68C2000000 push 000000C2 :76115A59 57 push edi :76115A5A FFD6 call esi :76115A5C 85C0 test eax, eax :76115A5E 7416 je 76115A76 :76115A60 FF742414 push [esp+14] * Possible StringData Ref from Code Obj ->" Checking for %s" | :76115A64 6850281176 push 76112850 :76115A69 6807030000 push 00000307 :76115A6E E8A7DFFFFF call 76113A1A :76115A73 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115A50(C), :76115A5E(C) | :76115A76 FF742414 push [esp+14] * Reference To: KERNEL32.GetFileAttributesA, Ord:0120h | :76115A7A FF1540101176 Call dword ptr [76111040] :76115A80 83F8FF cmp eax, FFFFFFFF :76115A83 7532 jne 76115AB7 :76115A85 A1E4101176 mov eax, dword ptr [761110E4] :76115A8A 8418 test byte ptr [eax], bl :76115A8C 747D je 76115B0B :76115A8E 53 push ebx :76115A8F 55 push ebp :76115A90 68C8000000 push 000000C8 :76115A95 57 push edi :76115A96 FFD6 call esi :76115A98 85C0 test eax, eax :76115A9A 746F je 76115B0B * Reference To: KERNEL32.GetLastError, Ord:012Dh | :76115A9C FF154C101176 Call dword ptr [7611104C] :76115AA2 50 push eax * Possible StringData Ref from Code Obj ->"GetFileAttributes failed 0x%x" | :76115AA3 68E0271176 push 761127E0 :76115AA8 6807030000 push 00000307 :76115AAD E868DFFFFF call 76113A1A :76115AB2 83C40C add esp, 0000000C :76115AB5 EB54 jmp 76115B0B * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115A83(C) | :76115AB7 A810 test al, 10 :76115AB9 A1E4101176 mov eax, dword ptr [761110E4] :76115ABE 7428 je 76115AE8 :76115AC0 8418 test byte ptr [eax], bl :76115AC2 741F je 76115AE3 :76115AC4 53 push ebx :76115AC5 55 push ebp :76115AC6 68D0000000 push 000000D0 :76115ACB 57 push edi :76115ACC FFD6 call esi :76115ACE 85C0 test eax, eax :76115AD0 7411 je 76115AE3 * Possible StringData Ref from Code Obj ->"Directory exists " | :76115AD2 683C281176 push 7611283C :76115AD7 6807030000 push 00000307 :76115ADC E839DFFFFF call 76113A1A :76115AE1 59 pop ecx :76115AE2 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115AC2(C), :76115AD0(C) | :76115AE3 6A01 push 00000001 :76115AE5 58 pop eax :76115AE6 EB25 jmp 76115B0D * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115ABE(C) | :76115AE8 8418 test byte ptr [eax], bl :76115AEA 741F je 76115B0B :76115AEC 53 push ebx :76115AED 55 push ebp :76115AEE 68D5000000 push 000000D5 :76115AF3 57 push edi :76115AF4 FFD6 call esi :76115AF6 85C0 test eax, eax :76115AF8 7411 je 76115B0B * Possible StringData Ref from Code Obj ->"Directory does not exist" | :76115AFA 6820281176 push 76112820 :76115AFF 6807030000 push 00000307 :76115B04 E811DFFFFF call 76113A1A :76115B09 59 pop ecx :76115B0A 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115A8C(C), :76115A9A(C), :76115AB5(U), :76115AEA(C), :76115AF8(C) | :76115B0B 33C0 xor eax, eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115AE6(U) | :76115B0D 5F pop edi :76115B0E 5E pop esi :76115B0F 5D pop ebp :76115B10 5B pop ebx :76115B11 C20400 ret 0004 * Referenced by a CALL at Address: |:76115C12 | :76115B14 57 push edi :76115B15 8B7C2408 mov edi, dword ptr [esp+08] :76115B19 83C9FF or ecx, FFFFFFFF :76115B1C 33C0 xor eax, eax :76115B1E F2 repnz :76115B1F AE scasb :76115B20 F7D1 not ecx :76115B22 49 dec ecx :76115B23 5F pop edi :76115B24 8BC1 mov eax, ecx :76115B26 40 inc eax :76115B27 C20400 ret 0004 * Referenced by a CALL at Address: |:76115CDD | :76115B2A 55 push ebp :76115B2B 8BEC mov ebp, esp :76115B2D B804100000 mov eax, 00001004 :76115B32 E8A9050000 call 761160E0 :76115B37 56 push esi :76115B38 57 push edi :76115B39 33FF xor edi, edi :76115B3B 397D08 cmp dword ptr [ebp+08], edi :76115B3E 897DFC mov dword ptr [ebp-04], edi :76115B41 0F8412010000 je 76115C59 :76115B47 397D0C cmp dword ptr [ebp+0C], edi :76115B4A 0F8409010000 je 76115C59 :76115B50 8D85FCF7FFFF lea eax, dword ptr [ebp+FFFFF7FC] :76115B56 6800040000 push 00000400 :76115B5B 50 push eax :76115B5C 6AFF push FFFFFFFF :76115B5E FF7508 push [ebp+08] :76115B61 57 push edi :76115B62 6A01 push 00000001 * Reference To: KERNEL32.MultiByteToWideChar, Ord:0202h | :76115B64 FF152C101176 Call dword ptr [7611102C] :76115B6A 85C0 test eax, eax :76115B6C 754D jne 76115BBB * Reference To: KERNEL32.GetLastError, Ord:012Dh | :76115B6E FF154C101176 Call dword ptr [7611104C] :76115B74 8BF0 mov esi, eax :76115B76 A1E4101176 mov eax, dword ptr [761110E4] :76115B7B F60002 test byte ptr [eax], 02 :76115B7E 0F84D5000000 je 76115C59 :76115B84 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"CXMLFileListParser::GetField" | :76115B86 689C281176 push 7611289C :76115B8B 68E6030000 push 000003E6 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115C51(U) | :76115B90 6808761176 push 76117608 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76115B95 FF15EC101176 Call dword ptr [761110EC] :76115B9B 85C0 test eax, eax :76115B9D 0F84B6000000 je 76115C59 :76115BA3 56 push esi * Possible StringData Ref from Code Obj ->"MultiByteToWideChar( ) failed- " ->" ec--%d" | :76115BA4 6874281176 push 76112874 :76115BA9 6807030000 push 00000307 :76115BAE E867DEFFFF call 76113A1A :76115BB3 83C40C add esp, 0000000C :76115BB6 E99E000000 jmp 76115C59 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115B6C(C) | :76115BBB 6639BDFCF7FFFF cmp word ptr [ebp+FFFFF7FC], di :76115BC2 8B7510 mov esi, dword ptr [ebp+10] :76115BC5 8D85FCF7FFFF lea eax, dword ptr [ebp+FFFFF7FC] :76115BCB 8D8DFCEFFFFF lea ecx, dword ptr [ebp+FFFFEFFC] :76115BD1 7416 je 76115BE9 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115BE7(C) | :76115BD3 3BF7 cmp esi, edi :76115BD5 7E12 jle 76115BE9 :76115BD7 660FB65514 movzx dx, byte ptr [ebp+14] :76115BDC 663910 cmp word ptr [eax], dx :76115BDF 7501 jne 76115BE2 :76115BE1 4E dec esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115BDF(C) | :76115BE2 40 inc eax :76115BE3 40 inc eax :76115BE4 663938 cmp word ptr [eax], di :76115BE7 75EA jne 76115BD3 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115BD1(C), :76115BD5(C) | :76115BE9 668B30 mov si, word ptr [eax] :76115BEC 663BF7 cmp si, di :76115BEF 7468 je 76115C59 :76115BF1 660FB65514 movzx dx, byte ptr [ebp+14] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115C08(C) | :76115BF6 663BF2 cmp si, dx :76115BF9 740F je 76115C0A :76115BFB 668931 mov word ptr [ecx], si :76115BFE 41 inc ecx :76115BFF 41 inc ecx :76115C00 40 inc eax :76115C01 40 inc eax :76115C02 668B30 mov si, word ptr [eax] :76115C05 663BF7 cmp si, di :76115C08 75EC jne 76115BF6 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115BF9(C) | :76115C0A 57 push edi :76115C0B 57 push edi :76115C0C FF7508 push [ebp+08] :76115C0F 668939 mov word ptr [ecx], di :76115C12 E8FDFEFFFF call 76115B14 :76115C17 50 push eax :76115C18 8D85FCEFFFFF lea eax, dword ptr [ebp+FFFFEFFC] :76115C1E FF750C push [ebp+0C] :76115C21 6AFF push FFFFFFFF :76115C23 50 push eax :76115C24 57 push edi :76115C25 6A01 push 00000001 :76115C27 5E pop esi :76115C28 56 push esi * Reference To: KERNEL32.WideCharToMultiByte, Ord:0301h | :76115C29 FF1550101176 Call dword ptr [76111050] :76115C2F 85C0 test eax, eax :76115C31 7523 jne 76115C56 * Reference To: KERNEL32.GetLastError, Ord:012Dh | :76115C33 FF154C101176 Call dword ptr [7611104C] :76115C39 8BF0 mov esi, eax :76115C3B A1E4101176 mov eax, dword ptr [761110E4] :76115C40 F60002 test byte ptr [eax], 02 :76115C43 7414 je 76115C59 :76115C45 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"CXMLFileListParser::GetField" | :76115C47 689C281176 push 7611289C :76115C4C 6820040000 push 00000420 :76115C51 E93AFFFFFF jmp 76115B90 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115C31(C) | :76115C56 8975FC mov dword ptr [ebp-04], esi * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115B41(C), :76115B4A(C), :76115B7E(C), :76115B9D(C), :76115BB6(U) |:76115BEF(C), :76115C43(C) | :76115C59 8B45FC mov eax, dword ptr [ebp-04] :76115C5C 5F pop edi :76115C5D 5E pop esi :76115C5E C9 leave :76115C5F C21000 ret 0010 * Referenced by a CALL at Address: |:76113EF3 | :76115C62 55 push ebp :76115C63 8BEC mov ebp, esp :76115C65 81EC00010000 sub esp, 00000100 :76115C6B 56 push esi :76115C6C 33F6 xor esi, esi :76115C6E 3935E8791176 cmp dword ptr [761179E8], esi :76115C74 0F85C0000000 jne 76115D3A :76115C7A 68F0261176 push 761126F0 :76115C7F 6A02 push 00000002 :76115C81 8935EC791176 mov dword ptr [761179EC], esi * Reference To: MSVCRT.setlocale, Ord:02AAh | :76115C87 FF1564101176 Call dword ptr [76111064] :76115C8D 59 pop ecx :76115C8E 3BC6 cmp eax, esi :76115C90 59 pop ecx :76115C91 753E jne 76115CD1 :76115C93 A1E4101176 mov eax, dword ptr [761110E4] :76115C98 F60002 test byte ptr [eax], 02 :76115C9B 0F8499000000 je 76115D3A :76115CA1 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"GetCurrentCodePage" | :76115CA3 68F4281176 push 761128F4 :76115CA8 684C040000 push 0000044C :76115CAD 6808761176 push 76117608 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76115CB2 FF15EC101176 Call dword ptr [761110EC] :76115CB8 85C0 test eax, eax :76115CBA 747E je 76115D3A :76115CBC 56 push esi * Possible StringData Ref from Code Obj ->"Error querying code locale." | :76115CBD 68D8281176 push 761128D8 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115D11(U) | :76115CC2 6807030000 push 00000307 :76115CC7 E84EDDFFFF call 76113A1A :76115CCC 83C40C add esp, 0000000C :76115CCF EB69 jmp 76115D3A * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115C91(C) | :76115CD1 6A2E push 0000002E :76115CD3 8D8D00FFFFFF lea ecx, dword ptr [ebp+FFFFFF00] :76115CD9 6A01 push 00000001 :76115CDB 51 push ecx :76115CDC 50 push eax :76115CDD E848FEFFFF call 76115B2A :76115CE2 85C0 test eax, eax :76115CE4 752D jne 76115D13 :76115CE6 A1E4101176 mov eax, dword ptr [761110E4] :76115CEB F60002 test byte ptr [eax], 02 :76115CEE 744A je 76115D3A :76115CF0 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"GetCurrentCodePage" | :76115CF2 68F4281176 push 761128F4 :76115CF7 6852040000 push 00000452 :76115CFC 6808761176 push 76117608 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76115D01 FF15EC101176 Call dword ptr [761110EC] :76115D07 85C0 test eax, eax :76115D09 742F je 76115D3A :76115D0B 56 push esi * Possible StringData Ref from Code Obj ->"Error getting code page." | :76115D0C 68BC281176 push 761128BC :76115D11 EBAF jmp 76115CC2 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115CE4(C) | :76115D13 8D8500FFFFFF lea eax, dword ptr [ebp+FFFFFF00] :76115D19 50 push eax * Reference To: MSVCRT.atoi, Ord:023Ah | :76115D1A FF1574101176 Call dword ptr [76111074] :76115D20 3BC6 cmp eax, esi :76115D22 59 pop ecx :76115D23 A3EC791176 mov dword ptr [761179EC], eax :76115D28 7506 jne 76115D30 :76115D2A 8935EC791176 mov dword ptr [761179EC], esi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115D28(C) | :76115D30 C705E879117601000000 mov dword ptr [761179E8], 00000001 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115C74(C), :76115C9B(C), :76115CBA(C), :76115CCF(U), :76115CEE(C) |:76115D09(C) | :76115D3A A1EC791176 mov eax, dword ptr [761179EC] :76115D3F 5E pop esi :76115D40 C9 leave :76115D41 C3 ret * Referenced by a CALL at Addresses: |:76115015 , :761151EB | :76115D42 56 push esi :76115D43 8BF1 mov esi, ecx :76115D45 832600 and dword ptr [esi], 00000000 * Reference To: KERNEL32.GetProcessHeap, Ord:0155h | :76115D48 FF1534101176 Call dword ptr [76111034] :76115D4E 894604 mov dword ptr [esi+04], eax :76115D51 8BC6 mov eax, esi :76115D53 5E pop esi :76115D54 C3 ret * Referenced by a CALL at Addresses: |:761151BB , :7611553B | :76115D55 8B01 mov eax, dword ptr [ecx] :76115D57 85C0 test eax, eax :76115D59 740C je 76115D67 :76115D5B 50 push eax :76115D5C 6A00 push 00000000 :76115D5E FF7104 push [ecx+04] * Reference To: KERNEL32.HeapFree, Ord:01BAh | :76115D61 FF1530101176 Call dword ptr [76111030] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115D59(C) | :76115D67 C3 ret * Referenced by a CALL at Addresses: |:7611506B , :76115237 | :76115D68 81EC00080000 sub esp, 00000800 :76115D6E 53 push ebx :76115D6F 8BD9 mov ebx, ecx :76115D71 55 push ebp :76115D72 56 push esi :76115D73 8B03 mov eax, dword ptr [ebx] :76115D75 33F6 xor esi, esi :76115D77 3BC6 cmp eax, esi :76115D79 57 push edi :76115D7A 740B je 76115D87 :76115D7C 50 push eax :76115D7D 56 push esi :76115D7E FF7304 push [ebx+04] * Reference To: KERNEL32.HeapFree, Ord:01BAh | :76115D81 FF1530101176 Call dword ptr [76111030] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115D7A(C) | :76115D87 8D842410040000 lea eax, dword ptr [esp+00000410] :76115D8E 6800040000 push 00000400 :76115D93 50 push eax * Reference To: KERNEL32.GetSystemDirectoryA, Ord:0170h | :76115D94 FF1528101176 Call dword ptr [76111028] :76115D9A 85C0 test eax, eax :76115D9C 7539 jne 76115DD7 :76115D9E A1E4101176 mov eax, dword ptr [761110E4] :76115DA3 F60002 test byte ptr [eax], 02 :76115DA6 0F8471010000 je 76115F1D :76115DAC 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"CCatUtils::Init()" | :76115DAE 6844291176 push 76112944 :76115DB3 688D000000 push 0000008D * Possible StringData Ref from Data Obj ->"d:\mpcfre\restore\src\catutils\catutils.cpp" | :76115DB8 6838761176 push 76117638 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76115DBD FF15EC101176 Call dword ptr [761110EC] :76115DC3 85C0 test eax, eax :76115DC5 0F8452010000 je 76115F1D :76115DCB 56 push esi * Possible StringData Ref from Code Obj ->"Error getting the system directory" | :76115DCC 68FC291176 push 761129FC :76115DD1 56 push esi :76115DD2 E93E010000 jmp 76115F15 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115D9C(C) | * Possible StringData Ref from Code Obj ->"{F750E6C3-38EE-11D1-85E5-00C04FC295EE}" | :76115DD7 68D4291176 push 761129D4 :76115DDC 8D842414040000 lea eax, dword ptr [esp+00000414] * Possible StringData Ref from Code Obj ->"CatRoot" | :76115DE3 68CC291176 push 761129CC :76115DE8 50 push eax :76115DE9 8D44241C lea eax, dword ptr [esp+1C] * Possible StringData Ref from Code Obj ->"%s\%s\%s" | :76115DED 68C0291176 push 761129C0 :76115DF2 50 push eax * Reference To: MSVCRT.sprintf, Ord:02AFh | :76115DF3 FF156C101176 Call dword ptr [7611106C] :76115DF9 83C414 add esp, 00000014 :76115DFC 8D442410 lea eax, dword ptr [esp+10] :76115E00 50 push eax :76115E01 E82CFCFFFF call 76115A32 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76115E06 8B35EC101176 mov esi, dword ptr [761110EC] * Possible StringData Ref from Code Obj ->"CCatUtils::Init()" | :76115E0C BD44291176 mov ebp, 76112944 :76115E11 85C0 test eax, eax * Possible StringData Ref from Data Obj ->"d:\mpcfre\restore\src\catutils\catutils.cpp" | :76115E13 BF38761176 mov edi, 76117638 :76115E18 0F85C3000000 jne 76115EE1 :76115E1E A1E4101176 mov eax, dword ptr [761110E4] :76115E23 F60002 test byte ptr [eax], 02 :76115E26 7420 je 76115E48 :76115E28 6A02 push 00000002 :76115E2A 55 push ebp :76115E2B 689A000000 push 0000009A :76115E30 57 push edi :76115E31 FFD6 call esi :76115E33 85C0 test eax, eax :76115E35 7411 je 76115E48 :76115E37 6A00 push 00000000 * Possible StringData Ref from Code Obj ->"CATALOG directory not found-- " ->"checking C:\windows\catroot .." | :76115E39 6880291176 push 76112980 :76115E3E 6A00 push 00000000 :76115E40 E8D5DBFFFF call 76113A1A :76115E45 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115E26(C), :76115E35(C) | :76115E48 8D842410040000 lea eax, dword ptr [esp+00000410] :76115E4F 6800040000 push 00000400 :76115E54 50 push eax * Reference To: KERNEL32.GetWindowsDirectoryA, Ord:0197h | :76115E55 FF1554101176 Call dword ptr [76111054] :76115E5B 85C0 test eax, eax :76115E5D 752D jne 76115E8C :76115E5F A1E4101176 mov eax, dword ptr [761110E4] :76115E64 F60002 test byte ptr [eax], 02 :76115E67 0F84B0000000 je 76115F1D :76115E6D 6A02 push 00000002 :76115E6F 55 push ebp :76115E70 689E000000 push 0000009E :76115E75 57 push edi :76115E76 FFD6 call esi :76115E78 85C0 test eax, eax :76115E7A 0F849D000000 je 76115F1D :76115E80 6A00 push 00000000 * Possible StringData Ref from Code Obj ->"Error getting the system directory" | :76115E82 68FC291176 push 761129FC :76115E87 E987000000 jmp 76115F13 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115E5D(C) | * Possible StringData Ref from Code Obj ->"{F750E6C3-38EE-11D1-85E5-00C04FC295EE}" | :76115E8C 68D4291176 push 761129D4 :76115E91 8D842414040000 lea eax, dword ptr [esp+00000414] * Possible StringData Ref from Code Obj ->"CatRoot" | :76115E98 68CC291176 push 761129CC :76115E9D 50 push eax :76115E9E 8D44241C lea eax, dword ptr [esp+1C] * Possible StringData Ref from Code Obj ->"%s\%s\%s" | :76115EA2 68C0291176 push 761129C0 :76115EA7 50 push eax * Reference To: MSVCRT.sprintf, Ord:02AFh | :76115EA8 FF156C101176 Call dword ptr [7611106C] :76115EAE 83C414 add esp, 00000014 :76115EB1 8D442410 lea eax, dword ptr [esp+10] :76115EB5 50 push eax :76115EB6 E877FBFFFF call 76115A32 :76115EBB 85C0 test eax, eax :76115EBD 7522 jne 76115EE1 :76115EBF A1E4101176 mov eax, dword ptr [761110E4] :76115EC4 F60002 test byte ptr [eax], 02 :76115EC7 7454 je 76115F1D :76115EC9 6A02 push 00000002 :76115ECB 55 push ebp :76115ECC 68A5000000 push 000000A5 :76115ED1 57 push edi :76115ED2 FFD6 call esi :76115ED4 85C0 test eax, eax :76115ED6 7445 je 76115F1D :76115ED8 6A00 push 00000000 * Possible StringData Ref from Code Obj ->"Alternate cat directory non-existant." | :76115EDA 6858291176 push 76112958 :76115EDF EB32 jmp 76115F13 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115E18(C), :76115EBD(C) | :76115EE1 8D442410 lea eax, dword ptr [esp+10] :76115EE5 8BCB mov ecx, ebx :76115EE7 50 push eax :76115EE8 E832010000 call 7611601F :76115EED 85C0 test eax, eax :76115EEF 8903 mov dword ptr [ebx], eax :76115EF1 7540 jne 76115F33 :76115EF3 A1E4101176 mov eax, dword ptr [761110E4] :76115EF8 F60002 test byte ptr [eax], 02 :76115EFB 7420 je 76115F1D :76115EFD 6A02 push 00000002 :76115EFF 55 push ebp :76115F00 68AC000000 push 000000AC :76115F05 57 push edi :76115F06 FFD6 call esi :76115F08 85C0 test eax, eax :76115F0A 7411 je 76115F1D :76115F0C 6A00 push 00000000 * Possible StringData Ref from Code Obj ->"Error duplicating catalog root " ->"path" | :76115F0E 6820291176 push 76112920 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115E87(U), :76115EDF(U) | :76115F13 6A00 push 00000000 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115DD2(U) | :76115F15 E800DBFFFF call 76113A1A :76115F1A 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115DA6(C), :76115DC5(C), :76115E67(C), :76115E7A(C), :76115EC7(C) |:76115ED6(C), :76115EFB(C), :76115F0A(C) | :76115F1D 8B03 mov eax, dword ptr [ebx] :76115F1F 85C0 test eax, eax :76115F21 740C je 76115F2F :76115F23 50 push eax :76115F24 6A00 push 00000000 :76115F26 FF7304 push [ebx+04] * Reference To: KERNEL32.HeapFree, Ord:01BAh | :76115F29 FF1530101176 Call dword ptr [76111030] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115F21(C) | :76115F2F 33C0 xor eax, eax :76115F31 EB03 jmp 76115F36 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115EF1(C) | :76115F33 6A01 push 00000001 :76115F35 58 pop eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115F31(U) | :76115F36 5F pop edi :76115F37 5E pop esi :76115F38 5D pop ebp :76115F39 5B pop ebx :76115F3A 81C400080000 add esp, 00000800 :76115F40 C3 ret * Referenced by a CALL at Addresses: |:761150C8 , :76115293 | :76115F41 55 push ebp :76115F42 8BEC mov ebp, esp :76115F44 81EC00040000 sub esp, 00000400 :76115F4A 8B01 mov eax, dword ptr [ecx] :76115F4C 56 push esi :76115F4D 33F6 xor esi, esi :76115F4F 57 push edi :76115F50 3BC6 cmp eax, esi :76115F52 7538 jne 76115F8C :76115F54 A1E4101176 mov eax, dword ptr [761110E4] :76115F59 F60002 test byte ptr [eax], 02 :76115F5C 0F848C000000 je 76115FEE :76115F62 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"CCatUtils::GetFullCatPath" | :76115F64 684C2A1176 push 76112A4C :76115F69 685B010000 push 0000015B * Possible StringData Ref from Data Obj ->"d:\mpcfre\restore\src\catutils\catutils.cpp" | :76115F6E 6838761176 push 76117638 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76115F73 FF15EC101176 Call dword ptr [761110EC] :76115F79 85C0 test eax, eax :76115F7B 7471 je 76115FEE * Possible StringData Ref from Code Obj ->"Unitialized Utilities" | :76115F7D 68342A1176 push 76112A34 :76115F82 56 push esi :76115F83 E892DAFFFF call 76113A1A :76115F88 59 pop ecx :76115F89 59 pop ecx :76115F8A EB62 jmp 76115FEE * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115F52(C) | :76115F8C FF7508 push [ebp+08] :76115F8F 50 push eax :76115F90 8D8500FCFFFF lea eax, dword ptr [ebp+FFFFFC00] * Possible StringData Ref from Code Obj ->"%s\%s" | :76115F96 6828261176 push 76112628 :76115F9B 50 push eax * Reference To: MSVCRT.sprintf, Ord:02AFh | :76115F9C FF156C101176 Call dword ptr [7611106C] :76115FA2 8DBD00FCFFFF lea edi, dword ptr [ebp+FFFFFC00] :76115FA8 83C9FF or ecx, FFFFFFFF :76115FAB 33C0 xor eax, eax :76115FAD 83C410 add esp, 00000010 :76115FB0 F2 repnz :76115FB1 AE scasb :76115FB2 F7D1 not ecx :76115FB4 49 dec ecx :76115FB5 3B4D0C cmp ecx, dword ptr [ebp+0C] :76115FB8 7238 jb 76115FF2 :76115FBA A1E4101176 mov eax, dword ptr [761110E4] :76115FBF F60002 test byte ptr [eax], 02 :76115FC2 742A je 76115FEE :76115FC4 6A02 push 00000002 * Possible StringData Ref from Code Obj ->"CCatUtils::GetFullCatPath" | :76115FC6 684C2A1176 push 76112A4C :76115FCB 6863010000 push 00000163 * Possible StringData Ref from Data Obj ->"d:\mpcfre\restore\src\catutils\catutils.cpp" | :76115FD0 6838761176 push 76117638 * Reference To: atrace._SetAsyncTraceParams@16, Ord:0006h | :76115FD5 FF15EC101176 Call dword ptr [761110EC] :76115FDB 85C0 test eax, eax :76115FDD 740F je 76115FEE :76115FDF 56 push esi * Possible StringData Ref from Code Obj ->"Buffer too small" | :76115FE0 68202A1176 push 76112A20 :76115FE5 56 push esi :76115FE6 E82FDAFFFF call 76113A1A :76115FEB 83C40C add esp, 0000000C * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:76115F5C(C), :76115F7B(C), :76115F8A(U), :76115FC2(C), :76115FDD(C) | :76115FEE 33C0 xor eax, eax :76115FF0 EB27 jmp 76116019 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115FB8(C) | :76115FF2 8DBD00FCFFFF lea edi, dword ptr [ebp+FFFFFC00] :76115FF8 83C9FF or ecx, FFFFFFFF :76115FFB 33C0 xor eax, eax :76115FFD 6A01 push 00000001 :76115FFF F2 repnz :76116000 AE scasb :76116001 F7D1 not ecx :76116003 2BF9 sub edi, ecx :76116005 8BC1 mov eax, ecx :76116007 8BF7 mov esi, edi :76116009 8B7D08 mov edi, dword ptr [ebp+08] :7611600C C1E902 shr ecx, 02 :7611600F F3 repz :76116010 A5 movsd :76116011 8BC8 mov ecx, eax :76116013 58 pop eax :76116014 83E103 and ecx, 00000003 :76116017 F3 repz :76116018 A4 movsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76115FF0(U) | :76116019 5F pop edi :7611601A 5E pop esi :7611601B C9 leave :7611601C C20800 ret 0008 * Referenced by a CALL at Address: |:76115EE8 | :7611601F 56 push esi :76116020 8B742408 mov esi, dword ptr [esp+08] :76116024 85F6 test esi, esi :76116026 57 push edi :76116027 8BD1 mov edx, ecx :76116029 741C je 76116047 :7611602B 8BFE mov edi, esi :7611602D 83C9FF or ecx, FFFFFFFF :76116030 33C0 xor eax, eax :76116032 F2 repnz :76116033 AE scasb :76116034 F7D1 not ecx :76116036 51 push ecx :76116037 50 push eax :76116038 FF7204 push [edx+04] * Reference To: KERNEL32.HeapAlloc, Ord:01B4h | :7611603B FF1538101176 Call dword ptr [76111038] :76116041 8BD0 mov edx, eax :76116043 85D2 test edx, edx :76116045 7504 jne 7611604B * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116029(C) | :76116047 33C0 xor eax, eax :76116049 EB21 jmp 7611606C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116045(C) | :7611604B 8BFE mov edi, esi :7611604D 83C9FF or ecx, FFFFFFFF :76116050 33C0 xor eax, eax :76116052 F2 repnz :76116053 AE scasb :76116054 F7D1 not ecx :76116056 2BF9 sub edi, ecx :76116058 8BC1 mov eax, ecx :7611605A 8BF7 mov esi, edi :7611605C 8BFA mov edi, edx :7611605E C1E902 shr ecx, 02 :76116061 F3 repz :76116062 A5 movsd :76116063 8BC8 mov ecx, eax :76116065 8BC2 mov eax, edx :76116067 83E103 and ecx, 00000003 :7611606A F3 repz :7611606B A4 movsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116049(U) | :7611606C 5F pop edi :7611606D 5E pop esi :7611606E C20400 ret 0004 :76116071 CC int 03 * Referenced by a CALL at Address: |:761155A5 | * Reference To: WINTRUST.CryptCATClose, Ord:0011h | :76116072 FF25DC101176 Jmp dword ptr [761110DC] :76116078 CC int 03 :76116079 CC int 03 :7611607A CC int 03 :7611607B CC int 03 :7611607C CC int 03 :7611607D CC int 03 :7611607E CC int 03 :7611607F CC int 03 :76116080 80F940 cmp cl, 40 :76116083 7315 jnb 7611609A :76116085 80F920 cmp cl, 20 :76116088 7306 jnb 76116090 :7611608A 0FA5C2 shld edx, eax, cl :7611608D D3E0 shl eax, cl :7611608F C3 ret * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116088(C) | :76116090 8BD0 mov edx, eax :76116092 33C0 xor eax, eax :76116094 80E11F and cl, 1F :76116097 D3E2 shl edx, cl :76116099 C3 ret * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116083(C) | :7611609A 33C0 xor eax, eax :7611609C 33D2 xor edx, edx :7611609E C3 ret :7611609F CC int 03 :761160A0 8B442408 mov eax, dword ptr [esp+08] :761160A4 8B4C2410 mov ecx, dword ptr [esp+10] :761160A8 0BC8 or ecx, eax :761160AA 8B4C240C mov ecx, dword ptr [esp+0C] :761160AE 7509 jne 761160B9 :761160B0 8B442404 mov eax, dword ptr [esp+04] :761160B4 F7E1 mul ecx :761160B6 C21000 ret 0010 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761160AE(C) | :761160B9 53 push ebx :761160BA F7E1 mul ecx :761160BC 8BD8 mov ebx, eax :761160BE 8B442408 mov eax, dword ptr [esp+08] :761160C2 F7642414 mul [esp+14] :761160C6 03D8 add ebx, eax :761160C8 8B442408 mov eax, dword ptr [esp+08] :761160CC F7E1 mul ecx :761160CE 03D3 add edx, ebx :761160D0 5B pop ebx :761160D1 C21000 ret 0010 :761160D4 CC int 03 :761160D5 CC int 03 :761160D6 CC int 03 :761160D7 CC int 03 :761160D8 CC int 03 :761160D9 CC int 03 :761160DA CC int 03 :761160DB CC int 03 :761160DC CC int 03 :761160DD CC int 03 :761160DE CC int 03 :761160DF CC int 03 * Referenced by a CALL at Address: |:76115B32 | :761160E0 51 push ecx :761160E1 3D00100000 cmp eax, 00001000 :761160E6 8D4C2408 lea ecx, dword ptr [esp+08] :761160EA 7214 jb 76116100 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761160FE(C) | :761160EC 81E900100000 sub ecx, 00001000 :761160F2 2D00100000 sub eax, 00001000 :761160F7 8501 test dword ptr [ecx], eax :761160F9 3D00100000 cmp eax, 00001000 :761160FE 73EC jnb 761160EC * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761160EA(C) | :76116100 2BC8 sub ecx, eax :76116102 8BC4 mov eax, esp :76116104 8501 test dword ptr [ecx], eax :76116106 8BE1 mov esp, ecx :76116108 8B08 mov ecx, dword ptr [eax] :7611610A 8B4004 mov eax, dword ptr [eax+04] :7611610D 50 push eax :7611610E C3 ret :7611610F CC int 03 :76116110 1462 adc al, 62 :76116112 0000 add byte ptr [eax], al :76116114 1F pop ds :76116115 3C40 cmp al, 40 :76116117 39FF cmp edi, edi :76116119 FFFFFF BYTE 3 DUP(0ffh) :7611611C D462 aam (base98) :7611611E 0000 add byte ptr [eax], al :76116120 641000 adc byte ptr fs:[eax], al :76116123 003462 add byte ptr [edx], dh :76116126 0000 add byte ptr [eax], al :76116128 E43B in al, 3B :7611612A 40 inc eax :7611612B 39FF cmp edi, edi :7611612D FFFFFF BYTE 3 DUP(0ffh) :76116130 AA stosb :76116131 64 BYTE 064h :76116132 0000 add byte ptr [eax], al :76116134 8410 test byte ptr [eax], dl :76116136 0000 add byte ptr [eax], al :76116138 8C6200 mov [edx+00], fs :7611613B 004B3C add byte ptr [ebx+3C], cl :7611613E 40 inc eax :7611613F 39FF cmp edi, edi :76116141 FFFFFF BYTE 3 DUP(0ffh) :76116144 C6640000DC mov [eax+eax], DC :76116149 1000 adc byte ptr [eax], al :7611614B 0094620000ED3B add byte ptr [edx+3BED0000], dl :76116152 40 inc eax :76116153 39FF cmp edi, edi :76116155 FFFFFF BYTE 3 DUP(0ffh) :76116158 26 BYTE 026h :76116159 65 BYTE 065h :7611615A 0000 add byte ptr [eax], al :7611615C E410 in al, 10 :7611615E 0000 add byte ptr [eax], al :76116160 C8610000 enter 0061, 00 :76116164 0E push cs :76116165 3C3F cmp al, 3F :76116167 39FF cmp edi, edi :76116169 FFFFFF BYTE 3 DUP(0ffh) :7611616C 626600 bound esp, dword ptr [esi+00] :7611616F 0018 add byte ptr [eax], bl :76116171 1000 adc byte ptr [eax], al :76116173 0084620000E03B add byte ptr [edx+3BE00000], al :7611617A 40 inc eax :7611617B 39FF cmp edi, edi :7611617D FFFFFF BYTE 3 DUP(0ffh) :76116180 7C66 jl 761161E8 :76116182 0000 add byte ptr [eax], al :76116184 D410 aam (base16) :76116186 0000 add byte ptr [eax], al :76116188 B061 mov al, 61 :7611618A 0000 add byte ptr [eax], al :7611618C E13B loopz 761161C9 :7611618E 40 inc eax :7611618F 39FF cmp edi, edi :76116191 FFFFFF BYTE 3 DUP(0ffh) :76116194 DC6600 fsub qword ptr [esi+00] :76116197 0000 add byte ptr [eax], al :76116199 1000 adc byte ptr [eax], al :7611619B 00000000000000000000 BYTE 10 DUP(0) :761161A5 00000000000000000000 BYTE 10 DUP(0) :761161AF 00 BYTE 0 :761161B0 AA stosb :761161B1 660000 add byte ptr [eax], al :761161B4 CC int 03 :761161B5 660000 add byte ptr [eax], al :761161B8 BA66000096 mov edx, 96000066 :761161BD 660000 add byte ptr [eax], al :761161C0 886600 mov byte ptr [esi+00], ah :761161C3 0000000000 BYTE 5 DUP(0) :761161C8 7265 jb 7611622F :761161CA 0000 add byte ptr [eax], al :761161CC D26500 shl byte ptr [ebp+00], cl :761161CF 00DE add dh, bl :761161D1 65 BYTE 065h :761161D2 0000 add byte ptr [eax], al :761161D4 98 cwde :761161D5 65 BYTE 065h :761161D6 0000 add byte ptr [eax], al :761161D8 4C dec esp :761161D9 660000 add byte ptr [eax], al :761161DC 36660000 add byte ptr ss:[eax], al :761161E0 2A6600 sub ah, byte ptr [esi+00] :761161E3 0018 add byte ptr [eax], bl :761161E5 660000 add byte ptr [eax], al * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116180(C) | :761161E8 0C66 or al, 66 :761161EA 0000 add byte ptr [eax], al :761161EC EA650000F66500 jmp 0065:F6000065 :761161F3 006265 add byte ptr [edx+65], ah :761161F6 0000 add byte ptr [eax], al :761161F8 50 push eax :761161F9 65 BYTE 065h :761161FA 0000 add byte ptr [eax], al :761161FC 40 inc eax :761161FD 65 BYTE 065h :761161FE 0000 add byte ptr [eax], al :76116200 82650000 and byte ptr [ebp+00], 00 :76116204 AE scasb :76116205 65 BYTE 065h :76116206 0000 add byte ptr [eax], al :76116208 C6650000 mov [ebp+00], 00 :7611620C 326500 xor ah, byte ptr [ebp+00] :7611620F 0000000000 BYTE 5 DUP(0) :76116214 F2 repnz :76116215 660000 add byte ptr [eax], al :76116218 C0620000 shl byte ptr [edx+00], 00 :7611621C FE BYTE 0feh :7611621D 660000 add byte ptr [eax], al :76116220 A4 movsb :76116221 6200 bound eax, dword ptr [eax] :76116223 00EA add dl, ch :76116225 660000 add byte ptr [eax], al :76116228 B8620000CA mov eax, CA000062 :7611622D 6200 bound eax, dword ptr [eax] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761161C8(C) | :7611622F 0000000000 BYTE 5 DUP(0) :76116234 8C6300 mov [ebx+00], fs :76116237 0026 add byte ptr [esi], ah :76116239 6300 arpl dword ptr [eax], eax :7611623B 00446300 add byte ptr [ebx], al :7611623F 00986400007C add byte ptr [eax+7C000064], bl :76116245 64 BYTE 064h :76116246 0000 add byte ptr [eax], al :76116248 54 push esp :76116249 6300 arpl dword ptr [eax], eax :7611624B 0010 add byte ptr [eax], dl :7611624D 6300 arpl dword ptr [eax], eax :7611624F 004A64 add byte ptr [edx+64], cl :76116252 0000 add byte ptr [eax], al :76116254 2C64 sub al, 64 :76116256 0000 add byte ptr [eax], al :76116258 0C64 or al, 64 :7611625A 0000 add byte ptr [eax], al :7611625C F0 lock :7611625D 6300 arpl dword ptr [eax], eax :7611625F 00D6 add dh, dl :76116261 6300 arpl dword ptr [eax], eax :76116263 00BA630000A6 add byte ptr [edx+A6000063], bh :76116269 6300 arpl dword ptr [eax], eax :7611626B 005C6400 add byte ptr [esp], bl :7611626F 006C6300 add byte ptr [ebx], ch :76116273 00FE add dh, bh :76116275 6200 bound eax, dword ptr [eax] :76116277 00F0 add al, dh :76116279 6200 bound eax, dword ptr [eax] :7611627B 00E0 add al, ah :7611627D 6200 bound eax, dword ptr [eax] :7611627F 0000000000 BYTE 5 DUP(0) :76116284 7066 jo 761162EC :76116286 000000000000 BYTE 6 DUP(0) :7611628C B664 mov dh, 64 :7611628E 000000000000 BYTE 6 DUP(0) :76116294 FA cli :76116295 64 BYTE 064h :76116296 0000 add byte ptr [eax], al :76116298 0E push cs :76116299 65 BYTE 065h :7611629A 0000 add byte ptr [eax], al :7611629C E064 loopnz 76116302 :7611629E 000000000000 BYTE 6 DUP(0) :761162A4 C7005F657863 mov dword ptr [eax], 6378655F :761162AA 65 BYTE 065h :761162AB 7074 jo 76116321 :761162AD 5F pop edi :761162AE 68616E646C push 6C646E61 :761162B3 65 BYTE 065h :761162B4 7233 jb 761162E9 :761162B6 0000 add byte ptr [eax], al :761162B8 5B pop ebx :761162B9 026672 add ah, byte ptr [esi+72] :761162BC 65 BYTE 065h :761162BD 65 BYTE 065h :761162BE 0000 add byte ptr [eax], al :761162C0 B402 mov ah, 02 :761162C2 7374 jnb 76116338 :761162C4 7263 jb 76116329 :761162C6 687200008E push 8E000072 :761162CB 026D61 add ch, byte ptr [ebp+61] :761162CE 6C insb :761162CF 6C insb :761162D0 6F outsd :761162D1 6300 arpl dword ptr [eax], eax :761162D3 004D53 add byte ptr [ebp+53], cl :761162D6 56 push esi :761162D7 43 inc ebx :761162D8 52 push edx :761162D9 54 push esp :761162DA 2E BYTE 02eh :761162DB 64 BYTE 064h :761162DC 6C insb :761162DD 6C insb :761162DE 0000 add byte ptr [eax], al :761162E0 B9004E6472 mov ecx, 72644E00 :761162E5 46 inc esi :761162E6 7265 jb 7611634D :761162E8 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761162B4(C) | :761162E9 42 inc edx :761162EA 7566 jne 76116352 :761162EC 66 BYTE 066h :761162ED 65 BYTE 065h :761162EE 7200 jb 761162F0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761162EE(C) | :761162F0 A4 movsb :761162F1 004E64 add byte ptr [esi+64], cl :761162F4 7243 jb 76116339 :761162F6 6F outsd :761162F7 6E outsb :761162F8 7665 jbe 7611635F :761162FA 7274 jb 76116370 :761162FC 0000 add byte ptr [eax], al :761162FE FD std :761162FF 004E64 add byte ptr [esi+64], cl :76116302 7253 jb 76116357 :76116304 65 BYTE 065h :76116305 6E outsb :76116306 64 BYTE 064h :76116307 52 push edx :76116308 65636569 arpl dword ptr gs:[ebp+69], esp :7611630C 7665 jbe 76116373 :7611630E 0000 add byte ptr [eax], al :76116310 ED in ax, dx :76116311 004E64 add byte ptr [esi+64], cl :76116314 7250 jb 76116366 :76116316 6F outsd :76116317 696E7465724D61 imul ebp, dword ptr [esi+74], 614D7265 :7611631E 7273 jb 76116393 :76116320 68616C6C00 push 006C6C61 :76116325 0090004E6472 add byte ptr [eax+72644E00], dl :7611632B 43 inc ebx :7611632C 6F outsd :7611632D 6E outsb :7611632E 666F outsw :76116330 726D jb 7611639F :76116332 61 popad :76116333 6E outsb :76116334 7453 je 76116389 :76116336 7472 je 761163AA * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761162C2(C) | :76116338 696E674D617273 imul ebp, dword ptr [esi+67], 7372614D :7611633F 68616C6C00 push 006C6C61 :76116344 C0004E rol byte ptr [eax], 4E :76116347 64 BYTE 064h :76116348 7247 jb 76116391 :7611634A 65 BYTE 065h :7611634B 7442 je 7611638F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761162E6(C) | :7611634D 7566 jne 761163B5 :7611634F 66 BYTE 066h :76116350 65 BYTE 065h :76116351 7200 jb 76116353 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116351(C) | :76116353 00EB add bl, ch :76116355 004E64 add byte ptr [esi+64], cl :76116358 7250 jb 761163AA :7611635A 6F outsd :7611635B 696E7465724275 imul ebp, dword ptr [esi+74], 75427265 :76116362 66 BYTE 066h :76116363 66 BYTE 066h :76116364 65 BYTE 065h :76116365 7253 jb 761163BA :76116367 697A6500008F00 imul edi, dword ptr [edx+65], 008F0000 :7611636E 4E dec esi :7611636F 64 BYTE 064h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761162FA(C) | :76116370 7243 jb 761163B5 :76116372 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611630C(C) | :76116373 6E outsb :76116374 666F outsw :76116376 726D jb 761163E5 :76116378 61 popad :76116379 6E outsb :7611637A 7453 je 761163CF :7611637C 7472 je 761163F0 :7611637E 696E6742756666 imul ebp, dword ptr [esi+67], 66667542 :76116385 65 BYTE 065h :76116386 7253 jb 761163DB :76116388 697A65007F004E imul edi, dword ptr [edx+65], 4E007F00 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611634B(C) | :7611638F 64 BYTE 064h :76116390 7243 jb 761163D5 :76116392 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611631E(C) | :76116393 69656E74496E69 imul esp, dword ptr [ebp+6E], 696E4974 :7611639A 7469 je 76116405 :7611639C 61 popad :7611639D 6C insb :7611639E 697A654E657700 imul edi, dword ptr [edx+65], 0077654E :761163A5 007A01 add byte ptr [edx+01], bh :761163A8 52 push edx :761163A9 7063 jo 7611640E :761163AB 52 push edx :761163AC 61 popad :761163AD 69736545786365 imul esi, dword ptr [ebx+65], 65637845 :761163B4 7074 jo 7611642A :761163B6 696F6E000F014E imul ebp, dword ptr [edi+6E], 4E010F00 :761163BD 64 BYTE 064h :761163BE 7253 jb 76116413 :761163C0 696D706C655374 imul ebp, dword ptr [ebp+70], 7453656C :761163C7 7275 jb 7611643E :761163C9 6374556E arpl dword ptr [ebp+2*edx+6E], esi :761163CD 6D insd :761163CE 61 popad * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611637A(C) | :761163CF 7273 jb 76116444 :761163D1 68616C6C00 push 006C6C61 :761163D6 0D014E6472 or eax, 72644E01 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116386(C) | :761163DB 53 push ebx :761163DC 696D706C655374 imul ebp, dword ptr [ebp+70], 7453656C :761163E3 7275 jb 7611645A * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116376(C) | :761163E5 63744D61 arpl dword ptr [ebp+2*ecx+61], esi :761163E9 7273 jb 7611645E :761163EB 68616C6C00 push 006C6C61 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611637C(C) | :761163F0 0B01 or eax, dword ptr [ecx] :761163F2 4E dec esi :761163F3 64 BYTE 064h :761163F4 7253 jb 76116449 :761163F6 696D706C655374 imul ebp, dword ptr [ebp+70], 7453656C :761163FD 7275 jb 76116474 :761163FF 63744275 arpl dword ptr [edx+2*eax+75], esi :76116403 66 BYTE 066h :76116404 66 BYTE 066h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611639A(C) | :76116405 65 BYTE 065h :76116406 7253 jb 7611645B :76116408 697A650092004E imul edi, dword ptr [edx+65], 4E009200 :7611640F 64 BYTE 064h :76116410 7243 jb 76116455 :76116412 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761163BE(C) | :76116413 6E outsb :76116414 666F outsw :76116416 726D jb 76116485 :76116418 61 popad :76116419 6E outsb :7611641A 7453 je 7611646F :7611641C 7472 je 76116490 :7611641E 696E67556E6D61 imul ebp, dword ptr [esi+67], 616D6E55 :76116425 7273 jb 7611649A :76116427 68616C6C00 push 006C6C61 :7611642C 8900 mov dword ptr [eax], eax :7611642E 4E dec esi :7611642F 64 BYTE 064h :76116430 7243 jb 76116475 :76116432 6F outsd :76116433 6D insd :76116434 706C jo 761164A2 :76116436 65 BYTE 065h :76116437 7853 js 7611648C :76116439 7472 je 761164AD :7611643B 7563 jne 761164A0 :7611643D 7455 je 76116494 :7611643F 6E outsb :76116440 6D insd :76116441 61 popad :76116442 7273 jb 761164B7 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761163CF(C) | :76116444 68616C6C00 push 006C6C61 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761163F4(C) | :76116449 00B40152706353 add byte ptr [ecx+eax+53637052], dh :76116450 7472 je 761164C4 :76116452 696E6746726565 imul ebp, dword ptr [esi+67], 65657246 :76116459 41 inc ecx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761163E3(C) | :7611645A 0000 add byte ptr [eax], al :7611645C 3301 xor eax, dword ptr [ecx] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761163E9(C) | :7611645E 52 push edx :7611645F 7063 jo 761164C4 :76116461 42 inc edx :76116462 696E64696E6746 imul ebp, dword ptr [esi+64], 46676E69 :76116469 726F jb 761164DA :7611646B 6D insd :7611646C 53 push ebx :7611646D 7472 je 761164E1 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611641A(C) | :7611646F 696E6742696E64 imul ebp, dword ptr [esi+67], 646E6942 :76116476 696E67410000B0 imul ebp, dword ptr [esi+67], B0000041 :7611647D 015270 add dword ptr [edx+70], edx :76116480 635374 arpl dword ptr [ebx+74], edx :76116483 7269 jb 761164EE * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116416(C) | :76116485 6E outsb :76116486 6742 inc edx :76116488 696E64696E6743 imul ebp, dword ptr [esi+64], 43676E69 :7611648F 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611641C(C) | :76116490 6D insd :76116491 706F jo 76116502 :76116493 7365 jnb 761164FA :76116495 41 inc ecx :76116496 0000 add byte ptr [eax], al :76116498 3201 xor al, byte ptr [ecx] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116425(C) | :7611649A 52 push edx :7611649B 7063 jo 76116500 :7611649D 42 inc edx :7611649E 696E64696E6746 imul ebp, dword ptr [esi+64], 46676E69 :761164A5 7265 jb 7611650C :761164A7 65 BYTE 065h :761164A8 0000 add byte ptr [eax], al :761164AA 52 push edx :761164AB 50 push eax :761164AC 43 inc ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116439(C) | :761164AD 52 push edx :761164AE 54 push esp :761164AF 342E xor al, 2E :761164B1 64 BYTE 064h :761164B2 6C insb :761164B3 6C insb :761164B4 0000 add byte ptr [eax], al :761164B6 1100 adc dword ptr [eax], eax :761164B8 43 inc ebx :761164B9 7279 jb 76116534 :761164BB 7074 jo 76116531 :761164BD 43 inc ebx :761164BE 41 inc ecx :761164BF 54 push esp :761164C0 43 inc ebx :761164C1 6C insb :761164C2 6F outsd :761164C3 7365 jnb 7611652A :761164C5 005749 add byte ptr [edi+49], dl :761164C8 4E dec esi :761164C9 54 push esp :761164CA 52 push edx :761164CB 55 push ebp :761164CC 53 push ebx :761164CD 54 push esp :761164CE 2E BYTE 02eh :761164CF 64 BYTE 064h :761164D0 6C insb :761164D1 6C insb :761164D2 0000 add byte ptr [eax], al :761164D4 43 inc ebx :761164D5 52 push edx :761164D6 59 pop ecx :761164D7 50 push eax :761164D8 54 push esp :761164D9 3332 xor esi, dword ptr [edx] :761164DB 2E BYTE 02eh :761164DC 64 BYTE 064h :761164DD 6C insb :761164DE 6C insb :761164DF 0006 add byte ptr [esi], al * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611646D(C) | :761164E1 005F53 add byte ptr [edi+53], bl :761164E4 65 BYTE 065h :761164E5 7441 je 76116528 :761164E7 7379 jnb 76116562 :761164E9 6E outsb :761164EA 63547261 arpl dword ptr [edx+2*esi+61], edx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116483(C) | :761164EE 636550 arpl dword ptr [ebp+50], esp :761164F1 61 popad :761164F2 7261 jb 76116555 :761164F4 6D insd :761164F5 7340 jnb 76116537 :761164F7 3136 xor dword ptr [esi], esi :761164F9 0008 add byte ptr [eax], cl :761164FB 005F5F add byte ptr [edi+5F], bl :761164FE 64 BYTE 064h :761164FF 7745 ja 76116546 :76116501 6E outsb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116491(C) | :76116502 61 popad :76116503 626C6564 bound ebp, dword ptr [ebp+64] :76116507 54 push esp :76116508 7261 jb 7611656B :7611650A 636573 arpl dword ptr [ebp+73], esp :7611650D 0001 add byte ptr [ecx], al :7611650F 005F41 add byte ptr [edi+41], bl :76116512 7379 jnb 7611658D :76116514 6E outsb :76116515 635374 arpl dword ptr [ebx+74], edx :76116518 7269 jb 76116583 :7611651A 6E outsb :7611651B 6754 push esp :7611651D 7261 jb 76116580 :7611651F 636540 arpl dword ptr [ebp+40], esp :76116522 3132 xor dword ptr [edx], esi :76116524 0000 add byte ptr [eax], al :76116526 61 popad :76116527 7472 je 7611659B :76116529 61 popad * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761164C3(C) | :7611652A 63652E arpl dword ptr [ebp+2E], esp :7611652D 64 BYTE 064h :7611652E 6C insb :7611652F 6C insb :76116530 0000 add byte ptr [eax], al :76116532 C3 ret :76116533 00 BYTE 0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761164B9(C) | :76116534 46 inc esi :76116535 7265 jb 7611659C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761164F5(C) | :76116537 65 BYTE 065h :76116538 4C dec esp :76116539 69627261727900 imul esp, dword ptr [edx+72], 00797261 :76116540 2D01476574 sub eax, 74654701 :76116545 4C dec esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761164FF(C) | :76116546 61 popad :76116547 7374 jnb 761165BD :76116549 45 inc ebp :7611654A 7272 jb 761165BE :7611654C 6F outsd :7611654D 7200 jb 7611654F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611654D(C) | :7611654F 005301 add byte ptr [ebx+01], dl :76116552 47 inc edi :76116553 65 BYTE 065h :76116554 7450 je 761165A6 :76116556 726F jb 761165C7 :76116558 634164 arpl dword ptr [ecx+64], eax :7611655B 64 BYTE 064h :7611655C 7265 jb 761165C3 :7611655E 7373 jnb 761165D3 :76116560 0000 add byte ptr [eax], al * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761164E7(C) | :76116562 DF01 fild word ptr [ecx] :76116564 4C dec esp :76116565 6F outsd :76116566 61 popad :76116567 64 BYTE 064h :76116568 4C dec esp :76116569 69627261727941 imul esp, dword ptr [edx+72], 41797261 :76116570 0000 add byte ptr [eax], al :76116572 9C pushfd :76116573 025365 add dl, byte ptr [ebx+65] :76116576 744C je 761165C4 :76116578 61 popad :76116579 7374 jnb 761165EF :7611657B 45 inc ebp :7611657C 7272 jb 761165F0 :7611657E 6F outsd :7611657F 7200 jb 76116581 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611657F(C) | :76116581 0001 add byte ptr [ecx], al * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116518(C) | :76116583 035769 add edx, dword ptr [edi+69] :76116586 64 BYTE 064h :76116587 65 BYTE 065h :76116588 43 inc ebx :76116589 686172546F push 6F547261 :7611658E 4D dec ebp :7611658F 756C jne 761165FD :76116591 7469 je 761165FC :76116593 42 inc edx :76116594 7974 jns 7611660A :76116596 65001401 add byte ptr gs:[ecx+eax], dl :7611659A 47 inc edi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116527(C) | :7611659B 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116535(C) | :7611659C 7444 je 761165E2 :7611659E 69736B46726565 imul esi, dword ptr [ebx+6B], 65657246 :761165A5 53 push ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116554(C) | :761165A6 7061 jo 76116609 :761165A8 636545 arpl dword ptr [ebp+45], esp :761165AB 7841 js 761165EE :761165AD 009701476574 add byte ptr [edi+74654701], dl :761165B3 57 push edi :761165B4 696E646F777344 imul ebp, dword ptr [esi+64], 4473776F :761165BB 69726563746F72 imul esi, dword ptr [edx+65], 726F7463 :761165C2 7941 jns 76116605 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116576(C) | :761165C4 0000 add byte ptr [eax], al :761165C6 35036C7374 xor eax, 74736C03 :761165CB 726C jb 76116639 :761165CD 65 BYTE 065h :761165CE 6E outsb :761165CF 41 inc ecx :761165D0 0000 add byte ptr [eax], al :761165D2 2B00 sub eax, dword ptr [eax] :761165D4 43 inc ebx :761165D5 6F outsd :761165D6 7079 jo 76116651 :761165D8 46 inc esi :761165D9 696C65410026036C imul ebp, dword ptr [ebp+41], 6C032600 :761165E1 7374 jnb 76116657 :761165E3 7263 jb 76116648 :761165E5 61 popad :761165E6 7441 je 76116629 :761165E8 0000 add byte ptr [eax], al :761165EA 2F das :761165EB 036C7374 add ebp, dword ptr [ebx+2*esi+74] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116579(C) | :761165EF 7263 jb 76116654 :761165F1 7079 jo 7611666C :761165F3 41 inc ecx :761165F4 0000 add byte ptr [eax], al :761165F6 2001 and byte ptr [ecx], al :761165F8 47 inc edi :761165F9 65 BYTE 065h :761165FA 7446 je 76116642 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116591(C) | :761165FC 696C654174747269 imul ebp, dword ptr [ebp+41], 69727474 :76116604 627574 bound esi, dword ptr [ebp+74] :76116607 65 BYTE 065h :76116608 7341 jnb 7611664B * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116594(C) | :7611660A 0000 add byte ptr [eax], al :7611660C B401 mov ah, 01 :7611660E 48 dec eax :7611660F 65 BYTE 065h :76116610 61 popad :76116611 7041 jo 76116654 :76116613 6C insb :76116614 6C insb :76116615 6F outsd :76116616 6300 arpl dword ptr [eax], eax :76116618 55 push ebp :76116619 014765 add dword ptr [edi+65], eax :7611661C 7450 je 7611666E :7611661E 726F jb 7611668F :76116620 636573 arpl dword ptr [ebp+73], esp :76116623 7348 jnb 7611666D :76116625 65 BYTE 065h :76116626 61 popad :76116627 7000 jo 76116629 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761165E6(C), :76116627(C) | :76116629 00BA01486561 add byte ptr [edx+61654801], bh :7611662F 7046 jo 76116677 :76116631 7265 jb 76116698 :76116633 65 BYTE 065h :76116634 0000 add byte ptr [eax], al :76116636 0202 add al, byte ptr [edx] :76116638 4D dec ebp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761165CB(C) | :76116639 756C jne 761166A7 :7611663B 7469 je 761166A6 :7611663D 42 inc edx :7611663E 7974 jns 761166B4 :76116640 65 BYTE 065h :76116641 54 push esp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761165FA(C) | :76116642 6F outsd :76116643 57 push edi :76116644 6964654368617200 imul esp, dword ptr [ebp+43], 00726168 :7611664C 7001 jo 7611664F :7611664E 47 inc edi * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611664C(C) | :7611664F 65 BYTE 065h :76116650 7453 je 761166A5 :76116652 7973 jns 761166C7 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:761165EF(C), :76116611(C) | :76116654 7465 je 761166BB :76116656 6D insd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761165E1(C) | :76116657 44 inc esp :76116658 69726563746F72 imul esi, dword ptr [edx+65], 726F7463 :7611665F 7941 jns 761166A2 :76116661 004B45 add byte ptr [ebx+45], cl :76116664 52 push edx :76116665 4E dec esi :76116666 45 inc ebp :76116667 4C dec esp :76116668 3332 xor esi, dword ptr [edx] :7611666A 2E BYTE 02eh :7611666B 64 BYTE 064h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761165F1(C) | :7611666C 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116623(C) | :7611666D 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611661C(C) | :7611666E 0000 add byte ptr [eax], al :76116670 B302 mov bl, 02 :76116672 7773 ja 761166E7 :76116674 7072 jo 761166E8 :76116676 696E7466410055 imul ebp, dword ptr [esi+74], 55004166 :7611667D 53 push ebx :7611667E 45 inc ebp :7611667F 52 push edx :76116680 3332 xor esi, dword ptr [edx] :76116682 2E BYTE 02eh :76116683 64 BYTE 064h :76116684 6C insb :76116685 6C insb :76116686 0000 add byte ptr [eax], al :76116688 8401 test byte ptr [ecx], al :7611668A 52 push edx :7611668B 656743 inc ebx :7611668E 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611661E(C) | :7611668F 6F outsd :76116690 7365 jnb 761166F7 :76116692 4B dec ebx :76116693 65 BYTE 065h :76116694 7900 jns 76116696 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116694(C) | :76116696 A7 cmpsd :76116697 015265 add dword ptr [edx+65], edx :7611669A 6751 push ecx :7611669C 7565 jne 76116703 :7611669E 7279 jb 76116719 :761166A0 56 push esi :761166A1 61 popad * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611665F(C) | :761166A2 6C insb :761166A3 7565 jne 7611670A * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116650(C) | :761166A5 45 inc ebp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611663B(C) | :761166A6 7841 js 761166E9 :761166A8 0000 add byte ptr [eax], al :761166AA 9D popfd :761166AB 015265 add dword ptr [edx+65], edx :761166AE 674F dec edi :761166B0 7065 jo 76116717 :761166B2 6E outsb :761166B3 4B dec ebx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611663E(C) | :761166B4 65 BYTE 065h :761166B5 7945 jns 761166FC :761166B7 7841 js 761166FA :761166B9 00B201526567 add byte ptr [edx+67655201], dh :761166BF 53 push ebx :761166C0 65 BYTE 065h :761166C1 7456 je 76116719 :761166C3 61 popad :761166C4 6C insb :761166C5 7565 jne 7611672C * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116652(C) | :761166C7 45 inc ebp :761166C8 7841 js 7611670B :761166CA 0000 add byte ptr [eax], al :761166CC 94 xchg eax,esp :761166CD 015265 add dword ptr [edx+65], edx :761166D0 6745 inc ebp :761166D2 6E outsb :761166D3 756D jne 76116742 :761166D5 56 push esi :761166D6 61 popad :761166D7 6C insb :761166D8 7565 jne 7611673F :761166DA 41 inc ecx :761166DB 004144 add byte ptr [ecx+44], al :761166DE 56 push esi :761166DF 41 inc ecx :761166E0 50 push eax :761166E1 49 dec ecx :761166E2 3332 xor esi, dword ptr [edx] :761166E4 2E BYTE 02eh :761166E5 64 BYTE 064h :761166E6 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116672(C) | :761166E7 6C insb * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116674(C) | :761166E8 0000 add byte ptr [eax], al :761166EA 3A02 cmp al, byte ptr [edx] :761166EC 61 popad :761166ED 746F je 7611675E :761166EF 690000AA0273 imul eax, dword ptr [eax], 7302AA00 :761166F5 65 BYTE 065h :761166F6 746C je 76116764 :761166F8 6F outsd :761166F9 63616C arpl dword ptr [ecx+6C], esp :761166FC 6500AF02737072 add byte ptr gs:[edi+72707302], ch :76116703 696E7466005645 imul ebp, dword ptr [esi+74], 45560066 :7611670A 52 push edx :7611670B 53 push ebx :7611670C 49 dec ecx :7611670D 4F dec edi :7611670E 4E dec esi :7611670F 2E BYTE 02eh :76116710 64 BYTE 064h :76116711 6C insb :76116712 6C insb :76116713 00000000000000000000 BYTE 10 DUP(0) :7611671D 00000000000000 BYTE 7 DUP(0) :76116724 D1 BYTE 0d0h :76116725 37 aaa :76116726 3539000000 xor eax, 00000039 :7611672B 00FA add dl, bh :7611672D 670000 add [bx+si], al :76116730 0800 or byte ptr [eax], al :76116732 0000 add byte ptr [eax], al :76116734 1300 adc eax, dword ptr [eax] :76116736 0000 add byte ptr [eax], al :76116738 1100 adc dword ptr [eax], eax :7611673A 0000 add byte ptr [eax], al :7611673C 48 dec eax :7611673D 670000 add [bx+si], al :76116740 94 xchg eax,esp :76116741 670000 add [bx+si], al :76116744 D86700 fsub dword ptr [edi+00] :76116747 00823A0000B5 add byte ptr [edx+B500003A], al :7611674D 3C00 cmp al, 00 :7611674F 00B0550000BC add byte ptr [eax+BC000055], dh :76116755 4D dec ebp :76116756 0000 add byte ptr [eax], al :76116758 E442 in al, 42 :7611675A 0000 add byte ptr [eax], al :7611675C CD49 int 49 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761166ED(C) | :7611675E 0000 add byte ptr [eax], al :76116760 E54E in ax, 4E :76116762 0000 add byte ptr [eax], al * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761166F6(C) | :76116764 7B44 jpo 761167AA :76116766 0000 add byte ptr [eax], al :76116768 154400008A adc eax, 8A000044 :7611676D 48 dec eax :7611676E 0000 add byte ptr [eax], al :76116770 49 dec ecx :76116771 47 inc edi :76116772 0000 add byte ptr [eax], al :76116774 294C0000 sub dword ptr [eax+eax], ecx :76116778 FB sti :76116779 4A dec edx :7611677A 0000 add byte ptr [eax], al :7611677C 1B4600 sbb eax, dword ptr [esi+00] :7611677F 0037 add byte ptr [edi], dh :76116781 40 inc eax :76116782 0000 add byte ptr [eax], al :76116784 293E sub dword ptr [esi], edi :76116786 0000 add byte ptr [eax], al :76116788 06 push es :76116789 50 push eax :7611678A 0000 add byte ptr [eax], al :7611678C C9 leave :7611678D 51 push ecx :7611678E 0000 add byte ptr [eax], al :76116790 B641 mov dh, 41 :76116792 0000 add byte ptr [eax], al :76116794 116800 adc dword ptr [eax+00], ebp :76116797 001D68000028 add byte ptr [28000068], bl :7611679D 6800003268 push 68320000 :761167A2 0000 add byte ptr [eax], al :761167A4 3D68000050 cmp eax, 50000068 :761167A9 6800006868 push 68680000 :761167AE 0000 add byte ptr [eax], al :761167B0 7468 je 7611681A :761167B2 0000 add byte ptr [eax], al :761167B4 026800 add ch, byte ptr [eax+00] :761167B7 008168000093 add byte ptr [ecx+93000068], al :761167BD 680000A968 push 68A90000 :761167C2 0000 add byte ptr [eax], al :761167C4 BC680000D4 mov esp, D4000068 :761167C9 680000E768 push 68E70000 :761167CE 0000 add byte ptr [eax], al :761167D0 FB sti :761167D1 6800000B69 push 690B0000 :761167D6 0000 add byte ptr [eax], al :761167D8 0300 add eax, dword ptr [eax] :761167DA 0400 add al, 00 :761167DC 0500060007 add eax, 07000600 :761167E1 0008 add byte ptr [eax], cl :761167E3 0009 add byte ptr [ecx], cl :761167E5 000A add byte ptr [edx], cl :761167E7 0002 add byte ptr [edx], al :761167E9 000B add byte ptr [ebx], cl :761167EB 000C00 add byte ptr [eax+eax], cl :761167EE 0D000E000F or eax, 0F000E00 :761167F3 0010 add byte ptr [eax], dl :761167F5 0011 add byte ptr [ecx], dl :761167F7 0012 add byte ptr [edx], dl :761167F9 005346 add byte ptr [ebx+46], dl :761167FC 43 inc ebx :761167FD 2E BYTE 02eh :761167FE 64 BYTE 064h :761167FF 6C insb :76116800 6C insb :76116801 005352 add byte ptr [ebx+52], dl :76116804 44 inc esp :76116805 65 BYTE 065h :76116806 7465 je 7611686D :76116808 6374556E arpl dword ptr [ebp+2*edx+6E], esi :7611680C 64 BYTE 064h :7611680D 6F outsd :7611680E 65 BYTE 065h :7611680F 7200 jb 76116811 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:7611680F(C) | :76116811 44 inc esp :76116812 697361626C6546 imul esi, dword ptr [ebx+61], 46656C62 :76116819 49 dec ecx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761167B0(C) | :7611681A 46 inc esi :7611681B 4F dec edi :7611681C 00446973 add byte ptr [ecx+2*ebp+73], al :76116820 61 popad :76116821 626C6553 bound ebp, dword ptr [ebp+53] :76116825 46 inc esi :76116826 50 push eax :76116827 00446973 add byte ptr [ecx+2*ebp+73], al :7611682B 61 popad :7611682C 626C6553 bound ebp, dword ptr [ebp+53] :76116830 52 push edx :76116831 00456E add byte ptr [ebp+6E], al :76116834 61 popad :76116835 626C6546 bound ebp, dword ptr [ebp+46] :76116839 49 dec ecx :7611683A 46 inc esi :7611683B 4F dec edi :7611683C 004765 add byte ptr [edi+65], al :7611683F 7453 je 76116894 :76116841 7461 je 761168A4 :76116843 7465 je 761168AA :76116845 4D dec ebp :76116846 677244 jb 7611688D :76116849 69736B4D617800 imul esi, dword ptr [ebx+6B], 0078614D :76116850 47 inc edi :76116851 65 BYTE 065h :76116852 7457 je 761168AB :76116854 696E646F777344 imul ebp, dword ptr [esi+64], 4473776F :7611685B 69736B46726565 imul esi, dword ptr [ebx+6B], 65657246 :76116862 53 push ebx :76116863 7061 jo 761168C6 :76116865 636500 arpl dword ptr [ebp+00], esp :76116868 49 dec ecx :76116869 7353 jnb 761168BE :7611686B 52 push edx :7611686C 45 inc ebp * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116806(C) | :7611686D 6E outsb :7611686E 61 popad :7611686F 626C6564 bound ebp, dword ptr [ebp+64] :76116873 005275 add byte ptr [edx+75], dl :76116876 6E outsb :76116877 44 inc esp :76116878 697361626C6553 imul esi, dword ptr [ebx+61], 53656C62 :7611687F 52 push edx :76116880 005352 add byte ptr [ebx+52], dl :76116883 53 push ebx :76116884 65 BYTE 065h :76116885 7452 je 761168D9 :76116887 65 BYTE 065h :76116888 7374 jnb 761168FE :7611688A 6F outsd :7611688B 7265 jb 761168F2 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116847(C) | :7611688D 50 push eax :7611688E 6F outsd :7611688F 696E7400535255 imul ebp, dword ptr [esi+74], 55525300 :76116896 7064 jo 761168FC :76116898 61 popad :76116899 7465 je 76116900 :7611689B 4D dec ebp :7611689C 6F outsd :7611689D 6E outsb :7611689E 69746F7265644C69 imul esi, dword ptr [edi+2*ebp+72], 694C6465 :761168A6 7374 jnb 7611691C :761168A8 005365 add byte ptr [ebx+65], dl * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116852(C) | :761168AB 7453 je 76116900 :761168AD 7461 je 76116910 :761168AF 7465 je 76116916 :761168B1 4D dec ebp :761168B2 677244 jb 761168F9 :761168B5 69736B4D617800 imul esi, dword ptr [ebx+6B], 0078614D :761168BC 53 push ebx :761168BD 66634765 arpl word ptr [edi+65], ax :761168C1 744E je 76116911 :761168C3 65 BYTE 065h :761168C4 7874 js 7611693A * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:76116863(C) | :761168C6 50 push eax :761168C7 726F jb 76116938 :761168C9 7465 je 76116930 :761168CB 63746564 arpl dword ptr [ebp+64], esi :761168CF 46 inc esi :761168D0 696C650053666349 imul ebp, dword ptr [ebp], 49636653 :761168D8 7346 jnb 76116920 :761168DA 696C6550726F7465 imul ebp, dword ptr [ebp+50], 65746F72 :761168E2 63746564 arpl dword ptr [ebp+64], esi :761168E6 005366 add byte ptr [ebx+66], dl :761168E9 7044 jo 7611692F :761168EB 7570 jne 7611695D :761168ED 6C insb :761168EE 69636174654361 imul esp, dword ptr [ebx+61], 61436574 :761168F5 7461 je 76116958 :761168F7 6C insb :761168F8 6F outsd * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761168B3(C) | :761168F9 67005366 add [bp+di+66], dl :761168FD 7051 jo 76116950 :761168FF 7565 jne 76116966 :76116901 7279 jb 7611697C :76116903 43 inc ebx :76116904 61 popad :76116905 7461 je 76116968 :76116907 6C insb :76116908 6F outsd :76116909 67005366 add [bp+di+66], dl :7611690D 7056 jo 76116965 :7611690F 65 BYTE 065h * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:761168AD(C) | :76116910 7269 jb 7611697B :76116912 667946 jns 7611695B :76116915 696C650000000000 imul ebp, dword ptr [ebp], 00000000 :7611691D 00000000000000000000 BYTE 10 DUP(0) :76116927 00000000000000000000 BYTE 10 DUP(0) :76116931 00000000000000000000 BYTE 10 DUP(0) :7611693B 00000000000000000000 BYTE 10 DUP(0) :76116945 00000000000000000000 BYTE 10 DUP(0) :7611694F 00000000000000000000 BYTE 10 DUP(0) :76116959 00000000000000000000 BYTE 10 DUP(0) :76116963 00000000000000000000 BYTE 10 DUP(0) :7611696D 00000000000000000000 BYTE 10 DUP(0) :76116977 00000000000000000000 BYTE 10 DUP(0) :76116981 00000000000000000000 BYTE 10 DUP(0) :7611698B 00000000000000000000 BYTE 10 DUP(0) :76116995 00000000000000000000 BYTE 10 DUP(0) :7611699F 00000000000000000000 BYTE 10 DUP(0) :761169A9 00000000000000000000 BYTE 10 DUP(0) :761169B3 00000000000000000000 BYTE 10 DUP(0) :761169BD 00000000000000000000 BYTE 10 DUP(0) :761169C7 00000000000000000000 BYTE 10 DUP(0) :761169D1 00000000000000000000 BYTE 10 DUP(0) :761169DB 00000000000000000000 BYTE 10 DUP(0) :761169E5 00000000000000000000 BYTE 10 DUP(0) :761169EF 00000000000000000000 BYTE 10 DUP(0) :761169F9 00000000000000000000 BYTE 10 DUP(0) :76116A03 00000000000000000000 BYTE 10 DUP(0) :76116A0D 00000000000000000000 BYTE 10 DUP(0) :76116A17 00000000000000000000 BYTE 10 DUP(0) :76116A21 00000000000000000000 BYTE 10 DUP(0) :76116A2B 00000000000000000000 BYTE 10 DUP(0) :76116A35 00000000000000000000 BYTE 10 DUP(0) :76116A3F 00000000000000000000 BYTE 10 DUP(0) :76116A49 00000000000000000000 BYTE 10 DUP(0) :76116A53 00000000000000000000 BYTE 10 DUP(0) :76116A5D 00000000000000000000 BYTE 10 DUP(0) :76116A67 00000000000000000000 BYTE 10 DUP(0) :76116A71 00000000000000000000 BYTE 10 DUP(0) :76116A7B 00000000000000000000 BYTE 10 DUP(0) :76116A85 00000000000000000000 BYTE 10 DUP(0) :76116A8F 00000000000000000000 BYTE 10 DUP(0) :76116A99 00000000000000000000 BYTE 10 DUP(0) :76116AA3 00000000000000000000 BYTE 10 DUP(0) :76116AAD 00000000000000000000 BYTE 10 DUP(0) :76116AB7 00000000000000000000 BYTE 10 DUP(0) :76116AC1 00000000000000000000 BYTE 10 DUP(0) :76116ACB 00000000000000000000 BYTE 10 DUP(0) :76116AD5 00000000000000000000 BYTE 10 DUP(0) :76116ADF 00000000000000000000 BYTE 10 DUP(0) :76116AE9 00000000000000000000 BYTE 10 DUP(0) :76116AF3 00000000000000000000 BYTE 10 DUP(0) :76116AFD 00000000000000000000 BYTE 10 DUP(0) :76116B07 00000000000000000000 BYTE 10 DUP(0) :76116B11 00000000000000000000 BYTE 10 DUP(0) :76116B1B 00000000000000000000 BYTE 10 DUP(0) :76116B25 00000000000000000000 BYTE 10 DUP(0) :76116B2F 00000000000000000000 BYTE 10 DUP(0) :76116B39 00000000000000000000 BYTE 10 DUP(0) :76116B43 00000000000000000000 BYTE 10 DUP(0) :76116B4D 00000000000000000000 BYTE 10 DUP(0) :76116B57 00000000000000000000 BYTE 10 DUP(0) :76116B61 00000000000000000000 BYTE 10 DUP(0) :76116B6B 00000000000000000000 BYTE 10 DUP(0) :76116B75 00000000000000000000 BYTE 10 DUP(0) :76116B7F 00000000000000000000 BYTE 10 DUP(0) :76116B89 00000000000000000000 BYTE 10 DUP(0) :76116B93 00000000000000000000 BYTE 10 DUP(0) :76116B9D 00000000000000000000 BYTE 10 DUP(0) :76116BA7 00000000000000000000 BYTE 10 DUP(0) :76116BB1 00000000000000000000 BYTE 10 DUP(0) :76116BBB 00000000000000000000 BYTE 10 DUP(0) :76116BC5 00000000000000000000 BYTE 10 DUP(0) :76116BCF 00000000000000000000 BYTE 10 DUP(0) :76116BD9 00000000000000000000 BYTE 10 DUP(0) :76116BE3 00000000000000000000 BYTE 10 DUP(0) :76116BED 00000000000000000000 BYTE 10 DUP(0) :76116BF7 00000000000000000000 BYTE 10 DUP(0) :76116C01 00000000000000000000 BYTE 10 DUP(0) :76116C0B 00000000000000000000 BYTE 10 DUP(0) :76116C15 00000000000000000000 BYTE 10 DUP(0) :76116C1F 00000000000000000000 BYTE 10 DUP(0) :76116C29 00000000000000000000 BYTE 10 DUP(0) :76116C33 00000000000000000000 BYTE 10 DUP(0) :76116C3D 00000000000000000000 BYTE 10 DUP(0) :76116C47 00000000000000000000 BYTE 10 DUP(0) :76116C51 00000000000000000000 BYTE 10 DUP(0) :76116C5B 00000000000000000000 BYTE 10 DUP(0) :76116C65 00000000000000000000 BYTE 10 DUP(0) :76116C6F 00000000000000000000 BYTE 10 DUP(0) :76116C79 00000000000000000000 BYTE 10 DUP(0) :76116C83 00000000000000000000 BYTE 10 DUP(0) :76116C8D 00000000000000000000 BYTE 10 DUP(0) :76116C97 00000000000000000000 BYTE 10 DUP(0) :76116CA1 00000000000000000000 BYTE 10 DUP(0) :76116CAB 00000000000000000000 BYTE 10 DUP(0) :76116CB5 00000000000000000000 BYTE 10 DUP(0) :76116CBF 00000000000000000000 BYTE 10 DUP(0) :76116CC9 00000000000000000000 BYTE 10 DUP(0) :76116CD3 00000000000000000000 BYTE 10 DUP(0) :76116CDD 00000000000000000000 BYTE 10 DUP(0) :76116CE7 00000000000000000000 BYTE 10 DUP(0) :76116CF1 00000000000000000000 BYTE 10 DUP(0) :76116CFB 00000000000000000000 BYTE 10 DUP(0) :76116D05 00000000000000000000 BYTE 10 DUP(0) :76116D0F 00000000000000000000 BYTE 10 DUP(0) :76116D19 00000000000000000000 BYTE 10 DUP(0) :76116D23 00000000000000000000 BYTE 10 DUP(0) :76116D2D 00000000000000000000 BYTE 10 DUP(0) :76116D37 00000000000000000000 BYTE 10 DUP(0) :76116D41 00000000000000000000 BYTE 10 DUP(0) :76116D4B 00000000000000000000 BYTE 10 DUP(0) :76116D55 00000000000000000000 BYTE 10 DUP(0) :76116D5F 00000000000000000000 BYTE 10 DUP(0) :76116D69 00000000000000000000 BYTE 10 DUP(0) :76116D73 00000000000000000000 BYTE 10 DUP(0) :76116D7D 00000000000000000000 BYTE 10 DUP(0) :76116D87 00000000000000000000 BYTE 10 DUP(0) :76116D91 00000000000000000000 BYTE 10 DUP(0) :76116D9B 00000000000000000000 BYTE 10 DUP(0) :76116DA5 00000000000000000000 BYTE 10 DUP(0) :76116DAF 00000000000000000000 BYTE 10 DUP(0) :76116DB9 00000000000000000000 BYTE 10 DUP(0) :76116DC3 00000000000000000000 BYTE 10 DUP(0) :76116DCD 00000000000000000000 BYTE 10 DUP(0) :76116DD7 00000000000000000000 BYTE 10 DUP(0) :76116DE1 00000000000000000000 BYTE 10 DUP(0) :76116DEB 00000000000000000000 BYTE 10 DUP(0) :76116DF5 00000000000000000000 BYTE 10 DUP(0) :76116DFF 00000000000000000000 BYTE 10 DUP(0) :76116E09 00000000000000000000 BYTE 10 DUP(0) :76116E13 00000000000000000000 BYTE 10 DUP(0) :76116E1D 00000000000000000000 BYTE 10 DUP(0) :76116E27 00000000000000000000 BYTE 10 DUP(0) :76116E31 00000000000000000000 BYTE 10 DUP(0) :76116E3B 00000000000000000000 BYTE 10 DUP(0) :76116E45 00000000000000000000 BYTE 10 DUP(0) :76116E4F 00000000000000000000 BYTE 10 DUP(0) :76116E59 00000000000000000000 BYTE 10 DUP(0) :76116E63 00000000000000000000 BYTE 10 DUP(0) :76116E6D 00000000000000000000 BYTE 10 DUP(0) :76116E77 00000000000000000000 BYTE 10 DUP(0) :76116E81 00000000000000000000 BYTE 10 DUP(0) :76116E8B 00000000000000000000 BYTE 10 DUP(0) :76116E95 00000000000000000000 BYTE 10 DUP(0) :76116E9F 00000000000000000000 BYTE 10 DUP(0) :76116EA9 00000000000000000000 BYTE 10 DUP(0) :76116EB3 00000000000000000000 BYTE 10 DUP(0) :76116EBD 00000000000000000000 BYTE 10 DUP(0) :76116EC7 00000000000000000000 BYTE 10 DUP(0) :76116ED1 00000000000000000000 BYTE 10 DUP(0) :76116EDB 00000000000000000000 BYTE 10 DUP(0) :76116EE5 00000000000000000000 BYTE 10 DUP(0) :76116EEF 00000000000000000000 BYTE 10 DUP(0) :76116EF9 00000000000000000000 BYTE 10 DUP(0) :76116F03 00000000000000000000 BYTE 10 DUP(0) :76116F0D 00000000000000000000 BYTE 10 DUP(0) :76116F17 00000000000000000000 BYTE 10 DUP(0) :76116F21 00000000000000000000 BYTE 10 DUP(0) :76116F2B 00000000000000000000 BYTE 10 DUP(0) :76116F35 00000000000000000000 BYTE 10 DUP(0) :76116F3F 00000000000000000000 BYTE 10 DUP(0) :76116F49 00000000000000000000 BYTE 10 DUP(0) :76116F53 00000000000000000000 BYTE 10 DUP(0) :76116F5D 00000000000000000000 BYTE 10 DUP(0) :76116F67 00000000000000000000 BYTE 10 DUP(0) :76116F71 00000000000000000000 BYTE 10 DUP(0) :76116F7B 00000000000000000000 BYTE 10 DUP(0) :76116F85 00000000000000000000 BYTE 10 DUP(0) :76116F8F 00000000000000000000 BYTE 10 DUP(0) :76116F99 00000000000000000000 BYTE 10 DUP(0) :76116FA3 00000000000000000000 BYTE 10 DUP(0) :76116FAD 00000000000000000000 BYTE 10 DUP(0) :76116FB7 00000000000000000000 BYTE 10 DUP(0) :76116FC1 00000000000000000000 BYTE 10 DUP(0) :76116FCB 00000000000000000000 BYTE 10 DUP(0) :76116FD5 00000000000000000000 BYTE 10 DUP(0) :76116FDF 00000000000000000000 BYTE 10 DUP(0) :76116FE9 00000000000000000000 BYTE 10 DUP(0) :76116FF3 00000000000000000000 BYTE 10 DUP(0) :76116FFD 00000058111176F01111 BYTE 10 DUP(0) :FFFFFFFF End Of Listing