c0lo Posted March 7, 2009 Posted March 7, 2009 How can make Hook to rtcMsgBox...? i don't understand...similar to __vbaStrCmp... injert in msvbvm60.dll but can learn me about this?Thanks 1
c0lo Posted March 12, 2009 Author Posted March 12, 2009 Advance :Me load msvbvm60.dll version 6.0.96.90and see in calls..All names, item 359 Address=73482F29 msvbvm60 Section=.text Type=Export Name=rtcMsgBoxNow have this :73482F29 >/$ 55 PUSH EBP73482F2A |. 8BEC MOV EBP,ESP73482F2C |. 83EC 4C SUB ESP,4C73482F2F |. 8B4D 14 MOV ECX,DWORD PTR SS:[EBP+14]73482F32 |. 53 PUSH EBX73482F33 |. 56 PUSH ESI73482F34 |. 57 PUSH EDI73482F35 |. 66:8339 0A CMP WORD PTR DS:[ECX],0A73482F39 |. B8 04000280 MOV EAX,8002000473482F3E |. 0F85 FC000000 JNZ msvbvm60.7348304073482F44 |. 3941 08 CMP DWORD PTR DS:[ECX+8],EAX73482F47 |. 0F85 F3000000 JNZ msvbvm60.7348304073482F4D |. 834D FC FF OR DWORD PTR SS:[EBP-4],FFFFFFFF73482F51 |. 33F6 XOR ESI,ESI73482F53 |> 8B4D 18 MOV ECX,DWORD PTR SS:[EBP+18]73482F56 |. 66:8339 0A CMP WORD PTR DS:[ECX],0A73482F5A |. 0F85 EA000000 JNZ msvbvm60.7348304A73482F60 |. 3941 08 CMP DWORD PTR DS:[ECX+8],EAX73482F63 |. 0F85 E1000000 JNZ msvbvm60.7348304A73482F69 |. 834D F8 FF OR DWORD PTR SS:[EBP-8],FFFFFFFF73482F6D |> 8B7D 10 MOV EDI,DWORD PTR SS:[EBP+10]73482F70 |. 66:833F 0A CMP WORD PTR DS:[EDI],0A73482F74 |. 0F85 D8000000 JNZ msvbvm60.7348305273482F7A |. 3947 08 CMP DWORD PTR DS:[EDI+8],EAX73482F7D |. 0F85 CF000000 JNZ msvbvm60.7348305273482F83 |. 834D F4 FF OR DWORD PTR SS:[EBP-C],FFFFFFFF73482F87 |> FF75 08 PUSH DWORD PTR SS:[EBP+8]73482F8A |. 8D45 D4 LEA EAX,DWORD PTR SS:[EBP-2C]73482F8D |. 8975 F0 MOV DWORD PTR SS:[EBP-10],ESI73482F90 |. 50 PUSH EAX73482F91 |. E8 A5040000 CALL msvbvm60.7348343B73482F96 |. 8BD8 MOV EBX,EAX73482F98 |. 8B45 DC MOV EAX,DWORD PTR SS:[EBP-24]73482F9B |. 8945 E8 MOV DWORD PTR SS:[EBP-18],EAX73482F9E |. 8B45 0C MOV EAX,DWORD PTR SS:[EBP+C]73482FA1 |. 83E0 0F AND EAX,0F73482FA4 |. 895D E4 MOV DWORD PTR SS:[EBP-1C],EBX73482FA7 |. 3C 05 CMP AL,573482FA9 |. 7F 1C JG SHORT msvbvm60.73482FC773482FAB |. 8B45 0C MOV EAX,DWORD PTR SS:[EBP+C]73482FAE |. 25 F0000000 AND EAX,0F073482FB3 |. 83F8 40 CMP EAX,4073482FB6 |. 7F 0F JG SHORT msvbvm60.73482FC773482FB8 |. 8B45 0C MOV EAX,DWORD PTR SS:[EBP+C]73482FBB |. 25 000F0000 AND EAX,0F0073482FC0 |. 3D 00030000 CMP EAX,30073482FC5 |. 7E 03 JLE SHORT msvbvm60.73482FCA73482FC7 |> 8975 0C MOV DWORD PTR SS:[EBP+C],ESI73482FCA |> 66:3975 F4 CMP WORD PTR SS:[EBP-C],SI73482FCE |. 8B35 F0193A73 MOV ESI,DWORD PTR DS:[<&OLEAUT32.#6>]73482FD4 |. 0F84 80000000 JE msvbvm60.7348305A73482FDA |. 8365 10 00 AND DWORD PTR SS:[EBP+10],073482FDE |. 8365 08 00 AND DWORD PTR SS:[EBP+8],073482FE2 |> 33C0 XOR EAX,EAX73482FE4 |. 66:3945 FC CMP WORD PTR SS:[EBP-4],AX73482FE8 |. 0F84 A7000000 JE msvbvm60.7348309573482FEE |. 66:3945 F8 CMP WORD PTR SS:[EBP-8],AX73482FF2 |. 0F84 97000000 JE msvbvm60.7348308F73482FF8 |. 8945 EC MOV DWORD PTR SS:[EBP-14],EAX73482FFB |. 33FF XOR EDI,EDI73482FFD |> 8B55 E8 MOV EDX,DWORD PTR SS:[EBP-18]73483000 |. 85D2 TEST EDX,EDX73483002 |. 75 03 JNZ SHORT msvbvm60.7348300773483004 |. 8D55 F0 LEA EDX,DWORD PTR SS:[EBP-10]73483007 |> 8B4D 08 MOV ECX,DWORD PTR SS:[EBP+8]7348300A |. 85C9 TEST ECX,ECX7348300C |. 75 09 JNZ SHORT msvbvm60.734830177348300E |. 66:394D F4 CMP WORD PTR SS:[EBP-C],CX73483012 |. 75 03 JNZ SHORT msvbvm60.7348301773483014 |. 8D4D F0 LEA ECX,DWORD PTR SS:[EBP-10]73483017 |> 6A 01 PUSH 173483019 |. 50 PUSH EAX7348301A |. 57 PUSH EDI7348301B |. FF75 0C PUSH DWORD PTR SS:[EBP+C]7348301E |. 51 PUSH ECX7348301F |. 52 PUSH EDX73483020 |. E8 1EB6F9FF CALL msvbvm60.7341E64373483025 |. FF75 E4 PUSH DWORD PTR SS:[EBP-1C]73483028 |. 8BF8 MOV EDI,EAX7348302A |. FFD6 CALL ESI7348302C |. FF75 10 PUSH DWORD PTR SS:[EBP+10]7348302F |. FFD6 CALL ESI73483031 |. FF75 EC PUSH DWORD PTR SS:[EBP-14]73483034 |. FFD6 CALL ESI73483036 |. 0FBFC7 MOVSX EAX,DI73483039 |. 5F POP EDI7348303A |. 5E POP ESI7348303B |. 5B POP EBX7348303C |. C9 LEAVE7348303D |. C2 1400 RETN 1473483040 |> 33F6 XOR ESI,ESI73483042 |. 8975 FC MOV DWORD PTR SS:[EBP-4],ESI73483045 |.^ E9 09FFFFFF JMP msvbvm60.73482F537348304A |> 8975 F8 MOV DWORD PTR SS:[EBP-8],ESI7348304D |.^ E9 1BFFFFFF JMP msvbvm60.73482F6D73483052 |> 8975 F4 MOV DWORD PTR SS:[EBP-C],ESI73483055 |.^ E9 2DFFFFFF JMP msvbvm60.73482F877348305A |> 8D45 B4 LEA EAX,DWORD PTR SS:[EBP-4C]7348305D |. 66:8365 D4 00 AND WORD PTR SS:[EBP-2C],073483062 |. 50 PUSH EAX73483063 |. 8D45 10 LEA EAX,DWORD PTR SS:[EBP+10]73483066 |. 50 PUSH EAX73483067 |. 8D45 D4 LEA EAX,DWORD PTR SS:[EBP-2C]7348306A |. 57 PUSH EDI7348306B |. 50 PUSH EAX7348306C |. E8 00040000 CALL msvbvm60.7348347173483071 |. 8BF8 MOV EDI,EAX73483073 |. 85FF TEST EDI,EDI73483075 |. 7D 0D JGE SHORT msvbvm60.7348308473483077 |. 53 PUSH EBX73483078 |. FFD6 CALL ESI7348307A |. 8D45 B4 LEA EAX,DWORD PTR SS:[EBP-4C]7348307D |. 50 PUSH EAX7348307E |. 57 PUSH EDI7348307F |. E8 BFAAF3FF CALL msvbvm60.733BDB4373483084 |> 8B45 DC MOV EAX,DWORD PTR SS:[EBP-24]73483087 |. 8945 08 MOV DWORD PTR SS:[EBP+8],EAX7348308A |.^ E9 53FFFFFF JMP msvbvm60.73482FE27348308F |> 66:3945 FC CMP WORD PTR SS:[EBP-4],AX73483093 |. 75 54 JNZ SHORT msvbvm60.734830E973483095 |> 66:3945 F8 CMP WORD PTR SS:[EBP-8],AX73483099 |. 75 4E JNZ SHORT msvbvm60.734830E97348309B |. 66:8945 D4 MOV WORD PTR SS:[EBP-2C],AX7348309F |. 8D45 B4 LEA EAX,DWORD PTR SS:[EBP-4C]734830A2 |. 50 PUSH EAX734830A3 |. 8D45 EC LEA EAX,DWORD PTR SS:[EBP-14]734830A6 |. 50 PUSH EAX734830A7 |. 8D45 D4 LEA EAX,DWORD PTR SS:[EBP-2C]734830AA |. FF75 14 PUSH DWORD PTR SS:[EBP+14]734830AD |. 50 PUSH EAX734830AE |. E8 BE030000 CALL msvbvm60.73483471734830B3 |. 8BF8 MOV EDI,EAX734830B5 |. 85FF TEST EDI,EDI734830B7 |. 7D 12 JGE SHORT msvbvm60.734830CB734830B9 |. 53 PUSH EBX734830BA |. FFD6 CALL ESI734830BC |. FF75 10 PUSH DWORD PTR SS:[EBP+10]734830BF |. FFD6 CALL ESI734830C1 |. 8D45 B4 LEA EAX,DWORD PTR SS:[EBP-4C]734830C4 |. 50 PUSH EAX734830C5 |. 57 PUSH EDI734830C6 |. E8 78AAF3FF CALL msvbvm60.733BDB43734830CB |> 8B7D DC MOV EDI,DWORD PTR SS:[EBP-24]734830CE |. 66:8365 D4 00 AND WORD PTR SS:[EBP-2C],0734830D3 |. 6A 03 PUSH 3734830D5 |. 8D45 D4 LEA EAX,DWORD PTR SS:[EBP-2C]734830D8 |. FF75 18 PUSH DWORD PTR SS:[EBP+18]734830DB |. 50 PUSH EAX734830DC |. E8 CE360000 CALL msvbvm60.734867AF734830E1 |. 8B45 DC MOV EAX,DWORD PTR SS:[EBP-24]734830E4 |.^ E9 14FFFFFF JMP msvbvm60.73482FFD734830E9 |> 53 PUSH EBX734830EA |. FFD6 CALL ESI734830EC |. FF75 10 PUSH DWORD PTR SS:[EBP+10]734830EF |. FFD6 CALL ESI734830F1 |. 6A 05 PUSH 5734830F3 |. E8 9D25F4FF CALL msvbvm60.733C5695734830F8 >|$ 55 PUSH EBP734830F9 |. 8BEC MOV EBP,ESP734830FB |. 83EC 54 SUB ESP,54734830FE |. 8B45 1C MOV EAX,DWORD PTR SS:[EBP+1C]73483101 |. 53 PUSH EBX73483102 |. 56 PUSH ESI73483103 |. 57 PUSH EDI73483104 |. 66:8338 0A CMP WORD PTR DS:[EAX],0A73483108 |. BF 04000280 MOV EDI,800200047348310D |. 0F85 5F010000 JNZ msvbvm60.7348327273483113 |. 3978 08 CMP DWORD PTR DS:[EAX+8],EDI73483116 |. 0F85 56010000 JNZ msvbvm60.734832727348311C |. 834D F8 FF OR DWORD PTR SS:[EBP-8],FFFFFFFF73483120 |. 33F6 XOR ESI,ESI73483122 |> 8B45 20 MOV EAX,DWORD PTR SS:[EBP+20]73483125 |. 66:8338 0A CMP WORD PTR DS:[EAX],0A73483129 |. 0F85 4D010000 JNZ msvbvm60.7348327C7348312F |. 3978 08 CMP DWORD PTR DS:[EAX+8],EDI73483132 |. 0F85 44010000 JNZ msvbvm60.7348327C73483138 |. 834D F4 FF OR DWORD PTR SS:[EBP-C],FFFFFFFF7348313C |> 8B5D 0C MOV EBX,DWORD PTR SS:[EBP+C]7348313F |. 66:833B 0A CMP WORD PTR DS:[EBX],0A73483143 |. 0F85 3B010000 JNZ msvbvm60.7348328473483149 |. 397B 08 CMP DWORD PTR DS:[EBX+8],EDI7348314C |. 0F85 32010000 JNZ msvbvm60.7348328473483152 |. 834D F0 FF OR DWORD PTR SS:[EBP-10],FFFFFFFF73483156 |> FF75 08 PUSH DWORD PTR SS:[EBP+8]73483159 |. 8D45 CC LEA EAX,DWORD PTR SS:[EBP-34]7348315C |. 8975 E8 MOV DWORD PTR SS:[EBP-18],ESI7348315F |. 50 PUSH EAX73483160 |. E8 D6020000 CALL msvbvm60.7348343B73483165 |. 66:3975 F0 CMP WORD PTR SS:[EBP-10],SI73483169 |. 8B35 F0193A73 MOV ESI,DWORD PTR DS:[<&OLEAUT32.#6>]7348316F |. 8945 0C MOV DWORD PTR SS:[EBP+C],EAX73483172 |. 8B45 D4 MOV EAX,DWORD PTR SS:[EBP-2C]73483175 |. 8945 DC MOV DWORD PTR SS:[EBP-24],EAX73483178 |. 0F84 0E010000 JE msvbvm60.7348328C7348317E |. 8365 08 00 AND DWORD PTR SS:[EBP+8],073483182 |. 8365 E0 00 AND DWORD PTR SS:[EBP-20],073483186 |> 8B45 10 MOV EAX,DWORD PTR SS:[EBP+10]73483189 |. 66:8338 0A CMP WORD PTR DS:[EAX],0A7348318D |. 0F85 2B010000 JNZ msvbvm60.734832BE73483193 |. 3978 08 CMP DWORD PTR DS:[EAX+8],EDI73483196 |. 0F85 22010000 JNZ msvbvm60.734832BE7348319C |. 83C9 FF OR ECX,FFFFFFFF7348319F |> 66:85C9 TEST CX,CX734831A2 |. 0F84 1D010000 JE msvbvm60.734832C5734831A8 |. 8365 FC 00 AND DWORD PTR SS:[EBP-4],0734831AC |. 8365 EC 00 AND DWORD PTR SS:[EBP-14],0734831B0 |> 8B45 14 MOV EAX,DWORD PTR SS:[EBP+14]734831B3 |. 66:8365 CC 00 AND WORD PTR SS:[EBP-34],0734831B8 |. 66:8338 0A CMP WORD PTR DS:[EAX],0A734831BC |. 0F85 3A010000 JNZ msvbvm60.734832FC734831C2 |. 3978 08 CMP DWORD PTR DS:[EAX+8],EDI734831C5 |. 0F85 31010000 JNZ msvbvm60.734832FC734831CB |. 83C9 FF OR ECX,FFFFFFFF734831CE |> 66:85C9 TEST CX,CX734831D1 |. 0F84 2C010000 JE msvbvm60.73483303734831D7 |. BB 00000080 MOV EBX,80000000734831DC |. 895D 14 MOV DWORD PTR SS:[EBP+14],EBX734831DF |> 8B45 18 MOV EAX,DWORD PTR SS:[EBP+18]734831E2 |. 66:8338 0A CMP WORD PTR DS:[EAX],0A734831E6 |. 0F85 63010000 JNZ msvbvm60.7348334F734831EC |. 3978 08 CMP DWORD PTR DS:[EAX+8],EDI734831EF |. 0F85 5A010000 JNZ msvbvm60.7348334F734831F5 |. 83C9 FF OR ECX,FFFFFFFF734831F8 |> 66:85C9 TEST CX,CX734831FB |. 0F84 55010000 JE msvbvm60.7348335673483201 |. 895D 10 MOV DWORD PTR SS:[EBP+10],EBX73483204 |> 33FF XOR EDI,EDI73483206 |. 66:397D F8 CMP WORD PTR SS:[EBP-8],DI7348320A |. 0F84 96010000 JE msvbvm60.734833A673483210 |. 66:397D F4 CMP WORD PTR SS:[EBP-C],DI73483214 |. 0F84 82010000 JE msvbvm60.7348339C7348321A |. 897D E4 MOV DWORD PTR SS:[EBP-1C],EDI7348321D |. 33DB XOR EBX,EBX7348321F |> 8B55 DC MOV EDX,DWORD PTR SS:[EBP-24]73483222 |. 85D2 TEST EDX,EDX73483224 |. 75 03 JNZ SHORT msvbvm60.7348322973483226 |. 8D55 E8 LEA EDX,DWORD PTR SS:[EBP-18]73483229 |> 8B4D E0 MOV ECX,DWORD PTR SS:[EBP-20]7348322C |. 85C9 TEST ECX,ECX7348322E |. 75 09 JNZ SHORT msvbvm60.7348323973483230 |. 66:394D F0 CMP WORD PTR SS:[EBP-10],CX73483234 |. 75 03 JNZ SHORT msvbvm60.7348323973483236 |. 8D4D E8 LEA ECX,DWORD PTR SS:[EBP-18]73483239 |> 8B45 EC MOV EAX,DWORD PTR SS:[EBP-14]7348323C |. 85C0 TEST EAX,EAX7348323E |. 75 03 JNZ SHORT msvbvm60.7348324373483240 |. 8D45 E8 LEA EAX,DWORD PTR SS:[EBP-18]73483243 |> 57 PUSH EDI73483244 |. 53 PUSH EBX73483245 |. FF75 10 PUSH DWORD PTR SS:[EBP+10]73483248 |. FF75 14 PUSH DWORD PTR SS:[EBP+14]7348324B |. 50 PUSH EAX7348324C |. 51 PUSH ECX7348324D |. 52 PUSH EDX7348324E |. E8 39B1F9FF CALL msvbvm60.7341E38C73483253 |. FF75 0C PUSH DWORD PTR SS:[EBP+C]73483256 |. 8BF8 MOV EDI,EAX73483258 |. FFD6 CALL ESI7348325A |. FF75 08 PUSH DWORD PTR SS:[EBP+8]7348325D |. FFD6 CALL ESI7348325F |. FF75 FC PUSH DWORD PTR SS:[EBP-4]73483262 |. FFD6 CALL ESI73483264 |. FF75 E4 PUSH DWORD PTR SS:[EBP-1C]73483267 |. FFD6 CALL ESI73483269 |. 8BC7 MOV EAX,EDI7348326B |. 5F POP EDI7348326C |. 5E POP ESI7348326D |. 5B POP EBX7348326E |. C9 LEAVE7348326F |. C2 1C00 RETN 1C73483272 |> 33F6 XOR ESI,ESI73483274 |. 8975 F8 MOV DWORD PTR SS:[EBP-8],ESI73483277 |.^ E9 A6FEFFFF JMP msvbvm60.734831227348327C |> 8975 F4 MOV DWORD PTR SS:[EBP-C],ESI7348327F |.^ E9 B8FEFFFF JMP msvbvm60.7348313C73483284 |> 8975 F0 MOV DWORD PTR SS:[EBP-10],ESI73483287 |.^ E9 CAFEFFFF JMP msvbvm60.734831567348328C |> 8D45 AC LEA EAX,DWORD PTR SS:[EBP-54]7348328F |. 50 PUSH EAX73483290 |. 8D45 08 LEA EAX,DWORD PTR SS:[EBP+8]73483293 |. 50 PUSH EAX73483294 |. 8D45 CC LEA EAX,DWORD PTR SS:[EBP-34]73483297 |. 53 PUSH EBX73483298 |. 50 PUSH EAX73483299 |. E8 D3010000 CALL msvbvm60.734834717348329E |. 8BD8 MOV EBX,EAX734832A0 |. 85DB TEST EBX,EBX734832A2 |. 7D 0F JGE SHORT msvbvm60.734832B3734832A4 |. FF75 0C PUSH DWORD PTR SS:[EBP+C]734832A7 |. FFD6 CALL ESI734832A9 |. 8D45 AC LEA EAX,DWORD PTR SS:[EBP-54]734832AC |. 50 PUSH EAX734832AD |. 53 PUSH EBX734832AE |. E8 90A8F3FF CALL msvbvm60.733BDB43734832B3 |> 8B45 D4 MOV EAX,DWORD PTR SS:[EBP-2C]734832B6 |. 8945 E0 MOV DWORD PTR SS:[EBP-20],EAX734832B9 |.^ E9 C8FEFFFF JMP msvbvm60.73483186734832BE |> 33C9 XOR ECX,ECX734832C0 |.^ E9 DAFEFFFF JMP msvbvm60.7348319F734832C5 |> 8D4D AC LEA ECX,DWORD PTR SS:[EBP-54]734832C8 |. 51 PUSH ECX734832C9 |. 8D4D FC LEA ECX,DWORD PTR SS:[EBP-4]734832CC |. 51 PUSH ECX734832CD |. 50 PUSH EAX734832CE |. 8D45 CC LEA EAX,DWORD PTR SS:[EBP-34]734832D1 |. 50 PUSH EAX734832D2 |. E8 9A010000 CALL msvbvm60.73483471734832D7 |. 8BD8 MOV EBX,EAX734832D9 |. 85DB TEST EBX,EBX734832DB |. 7D 14 JGE SHORT msvbvm60.734832F1734832DD |. FF75 0C PUSH DWORD PTR SS:[EBP+C]734832E0 |. FFD6 CALL ESI734832E2 |. FF75 08 PUSH DWORD PTR SS:[EBP+8]734832E5 |. FFD6 CALL ESI734832E7 |. 8D45 AC LEA EAX,DWORD PTR SS:[EBP-54]734832EA |. 50 PUSH EAX734832EB |. 53 PUSH EBX734832EC |. E8 52A8F3FF CALL msvbvm60.733BDB43734832F1 |> 8B45 D4 MOV EAX,DWORD PTR SS:[EBP-2C]734832F4 |. 8945 EC MOV DWORD PTR SS:[EBP-14],EAX734832F7 |.^ E9 B4FEFFFF JMP msvbvm60.734831B0734832FC |> 33C9 XOR ECX,ECX734832FE |.^ E9 CBFEFFFF JMP msvbvm60.734831CE73483303 |> 8D4D AC LEA ECX,DWORD PTR SS:[EBP-54]73483306 |. 51 PUSH ECX73483307 |. 6A 02 PUSH 273483309 |. 50 PUSH EAX7348330A |. 8D45 CC LEA EAX,DWORD PTR SS:[EBP-34]7348330D |. 50 PUSH EAX7348330E |. E8 84340000 CALL msvbvm60.7348679773483313 |. 8BF8 MOV EDI,EAX73483315 |. 85FF TEST EDI,EDI73483317 |. 7D 19 JGE SHORT msvbvm60.7348333273483319 |. FF75 0C PUSH DWORD PTR SS:[EBP+C]7348331C |. FFD6 CALL ESI7348331E |. FF75 08 PUSH DWORD PTR SS:[EBP+8]73483321 |. FFD6 CALL ESI73483323 |. FF75 FC PUSH DWORD PTR SS:[EBP-4]73483326 |. FFD6 CALL ESI73483328 |. 8D45 AC LEA EAX,DWORD PTR SS:[EBP-54]7348332B |. 50 PUSH EAX7348332C |. 57 PUSH EDI7348332D |. E8 11A8F3FF CALL msvbvm60.733BDB4373483332 |> 0FBF45 D4 MOVSX EAX,WORD PTR SS:[EBP-2C]73483336 |. BB 00000080 MOV EBX,800000007348333B |. 8945 14 MOV DWORD PTR SS:[EBP+14],EAX7348333E |. 3BC3 CMP EAX,EBX73483340 |. 75 03 JNZ SHORT msvbvm60.7348334573483342 |. FF45 14 INC DWORD PTR SS:[EBP+14]73483345 |> BF 04000280 MOV EDI,800200047348334A |.^ E9 90FEFFFF JMP msvbvm60.734831DF7348334F |> 33C9 XOR ECX,ECX73483351 |.^ E9 A2FEFFFF JMP msvbvm60.734831F873483356 |> 8D4D AC LEA ECX,DWORD PTR SS:[EBP-54]73483359 |. 51 PUSH ECX7348335A |. 6A 02 PUSH 27348335C |. 50 PUSH EAX7348335D |. 8D45 CC LEA EAX,DWORD PTR SS:[EBP-34]73483360 |. 50 PUSH EAX73483361 |. E8 31340000 CALL msvbvm60.7348679773483366 |. 8BF8 MOV EDI,EAX73483368 |. 85FF TEST EDI,EDI7348336A |. 7D 19 JGE SHORT msvbvm60.734833857348336C |. FF75 0C PUSH DWORD PTR SS:[EBP+C]7348336F |. FFD6 CALL ESI73483371 |. FF75 08 PUSH DWORD PTR SS:[EBP+8]73483374 |. FFD6 CALL ESI73483376 |. FF75 FC PUSH DWORD PTR SS:[EBP-4]73483379 |. FFD6 CALL ESI7348337B |. 8D45 AC LEA EAX,DWORD PTR SS:[EBP-54]7348337E |. 50 PUSH EAX7348337F |. 57 PUSH EDI73483380 |. E8 BEA7F3FF CALL msvbvm60.733BDB4373483385 |> 0FBF45 D4 MOVSX EAX,WORD PTR SS:[EBP-2C]73483389 |. 3BC3 CMP EAX,EBX7348338B |. 8945 10 MOV DWORD PTR SS:[EBP+10],EAX7348338E |.^ 0F85 70FEFFFF JNZ msvbvm60.7348320473483394 |. FF45 10 INC DWORD PTR SS:[EBP+10]73483397 |.^ E9 68FEFFFF JMP msvbvm60.734832047348339C |> 66:397D F8 CMP WORD PTR SS:[EBP-8],DI734833A0 |. 0F85 7F000000 JNZ msvbvm60.73483425734833A6 |> 66:397D F4 CMP WORD PTR SS:[EBP-C],DI734833AA |. 75 79 JNZ SHORT msvbvm60.73483425734833AC |. 8D45 AC LEA EAX,DWORD PTR SS:[EBP-54]734833AF |. 50 PUSH EAX734833B0 |. 8D45 E4 LEA EAX,DWORD PTR SS:[EBP-1C]734833B3 |. 50 PUSH EAX734833B4 |. 8D45 CC LEA EAX,DWORD PTR SS:[EBP-34]734833B7 |. FF75 1C PUSH DWORD PTR SS:[EBP+1C]734833BA |. 50 PUSH EAX734833BB |. E8 B1000000 CALL msvbvm60.73483471734833C0 |. 8BF8 MOV EDI,EAX734833C2 |. 85FF TEST EDI,EDI734833C4 |. 7D 19 JGE SHORT msvbvm60.734833DF734833C6 |. FF75 0C PUSH DWORD PTR SS:[EBP+C]734833C9 |. FFD6 CALL ESI734833CB |. FF75 08 PUSH DWORD PTR SS:[EBP+8]734833CE |. FFD6 CALL ESI734833D0 |. FF75 FC PUSH DWORD PTR SS:[EBP-4]734833D3 |. FFD6 CALL ESI734833D5 |. 8D45 AC LEA EAX,DWORD PTR SS:[EBP-54]734833D8 |. 50 PUSH EAX734833D9 |. 57 PUSH EDI734833DA |. E8 64A7F3FF CALL msvbvm60.733BDB43734833DF |> 8D45 AC LEA EAX,DWORD PTR SS:[EBP-54]734833E2 |. 8B5D D4 MOV EBX,DWORD PTR SS:[EBP-2C]734833E5 |. 66:8365 CC 00 AND WORD PTR SS:[EBP-34],0734833EA |. 50 PUSH EAX734833EB |. 6A 03 PUSH 3734833ED |. 8D45 CC LEA EAX,DWORD PTR SS:[EBP-34]734833F0 |. FF75 20 PUSH DWORD PTR SS:[EBP+20]734833F3 |. 50 PUSH EAX734833F4 |. E8 9E330000 CALL msvbvm60.73486797734833F9 |. 8BF8 MOV EDI,EAX734833FB |. 85FF TEST EDI,EDI734833FD |. 7D 1E JGE SHORT msvbvm60.7348341D734833FF |. FF75 0C PUSH DWORD PTR SS:[EBP+C]73483402 |. FFD6 CALL ESI73483404 |. FF75 08 PUSH DWORD PTR SS:[EBP+8]73483407 |. FFD6 CALL ESI73483409 |. FF75 FC PUSH DWORD PTR SS:[EBP-4]7348340C |. FFD6 CALL ESI7348340E |. FF75 E4 PUSH DWORD PTR SS:[EBP-1C]73483411 |. FFD6 CALL ESI73483413 |. 8D45 AC LEA EAX,DWORD PTR SS:[EBP-54]73483416 |. 50 PUSH EAX73483417 |. 57 PUSH EDI73483418 |. E8 26A7F3FF CALL msvbvm60.733BDB437348341D |> 8B7D D4 MOV EDI,DWORD PTR SS:[EBP-2C]73483420 |.^ E9 FAFDFFFF JMP msvbvm60.7348321F73483425 |> FF75 0C PUSH DWORD PTR SS:[EBP+C]73483428 |. FFD6 CALL ESI7348342A |. FF75 08 PUSH DWORD PTR SS:[EBP+8]7348342D |. FFD6 CALL ESI7348342F |. FF75 FC PUSH DWORD PTR SS:[EBP-4]73483432 |. FFD6 CALL ESI73483434 |. 6A 05 PUSH 573483436 |. E8 5A22F4FF CALL msvbvm60.733C56957348343B |$ 55 PUSH EBP7348343C |. 8BEC MOV EBP,ESP7348343E |. 83EC 20 SUB ESP,2073483441 |. 57 PUSH EDI73483442 |. 6A 08 PUSH 873483444 |. 59 POP ECX73483445 |. 33C0 XOR EAX,EAX73483447 |. 8D7D E0 LEA EDI,DWORD PTR SS:[EBP-20]7348344A |. F3:AB REP STOS DWORD PTR ES:[EDI]7348344C |. 8D45 E0 LEA EAX,DWORD PTR SS:[EBP-20]7348344F |. 50 PUSH EAX73483450 |. 8D45 E0 LEA EAX,DWORD PTR SS:[EBP-20]73483453 |. 50 PUSH EAX73483454 |. 8D45 0C LEA EAX,DWORD PTR SS:[EBP+C]73483457 |. 50 PUSH EAX73483458 |. FF75 0C PUSH DWORD PTR SS:[EBP+C]7348345B |. FF75 08 PUSH DWORD PTR SS:[EBP+8]7348345E |. E8 0E000000 CALL msvbvm60.7348347173483463 |. 50 PUSH EAX73483464 |. E8 DAA6F3FF CALL msvbvm60.733BDB4373483469 |. 8B45 0C MOV EAX,DWORD PTR SS:[EBP+C]7348346C |. 5F POP EDI7348346D |. C9 LEAVE7348346E \. C2 0800 RETN 8Now how can make jump when proccess call rtcMsgBox, I like call and obtain address in memory...PD: Sorry for speak... my english is very very suck....
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now