:0046441A B057
mov al, 57
:0046441C BF00000100 mov edi,
00010000
:00464421 B900003F00 mov ecx,
003F0000
:00464426 33D2
xor edx, edx
:00464428 6844444600 push 00464444
:0046442D 64FF32
push dword ptr fs:[edx]
:00464430 892524AF4900 mov dword ptr
[0049AF24], esp
:00464436 892D28AF4900 mov dword ptr
[0049AF28], ebp
:0046443C 648922
mov dword ptr fs:[edx], esp
:0046443F EB1A
jmp 0046445B
:00464441 90
nop
:00464442 90
nop
:00464443 90
nop
:00464444 8B2524AF4900 mov esp, dword
ptr [0049AF24]
:0046444A 8B2D28AF4900 mov ebp, dword
ptr [0049AF28]
:00464450 5A
pop edx
:00464451 646789160000 mov fs:[0000],
edx
:00464457 58
pop eax
:00464458 33C0
xor eax, eax
:0046445A C3
ret
* Referenced by a (U)nconditional or (C)onditional Jump at Addresses:
|:0046443F(U), :00464472(U), :0046447D(C)
|
:0046445B F2
repnz
:0046445C AE
scasb
:0046445D E325
jcxz 00464484
:0046445F 90
nop
:00464460 90
nop
:00464461 90
nop
:00464462 90
nop
:00464463 90
nop
:00464464 90
nop
:00464465 90
nop
:00464466 813F494E4943 cmp dword ptr
[edi], 43494E49
:0046446C 7406
je 00464474
:0046446E 90
nop
:0046446F 90
nop
:00464470 90
nop
:00464471 90
nop
:00464472 EBE7
jmp 0046445B
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:0046446C(C)
|
:00464474 83C704
add edi, 00000004
:00464477 813F452E4252 cmp dword ptr
[edi], 52422E45
:0046447D 75DC
jne 0046445B
:0046447F B801000000 mov eax,
00000001
:00464484 5A
pop edx
:00464485 646789160000 mov fs:[0000],
edx
:0046448B 5A
pop edx
:0046448C C3
ret
;--------------------------------------------------------------------
* Referenced by a CALL at Address:
|:004643CA
|
:0046448D 33D2
xor edx, edx
:0046448F 68AB444600 push 004644AB
:00464494 64FF32
push dword ptr fs:[edx]
:00464497 892524AF4900 mov dword ptr
[0049AF24], esp
:0046449D 892D28AF4900 mov dword ptr
[0049AF28], ebp
:004644A3 648922
mov dword ptr fs:[edx], esp
:004644A6 EB1A
jmp 004644C2
:004644A8 90
nop
:004644A9 90
nop
:004644AA 90
nop
:004644AB 8B2524AF4900 mov esp, dword
ptr [0049AF24]
:004644B1 8B2D28AF4900 mov ebp, dword
ptr [0049AF28]
:004644B7 5A
pop edx
:004644B8 646789160000 mov fs:[0000],
edx
:004644BE 58
pop eax
:004644BF 33C0
xor eax, eax
:004644C1 C3
ret
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:004644A6(U)
|
:004644C2 B804000000 mov eax,
00000004
:004644C7 BD4B484342 mov ebp,
4243484B
:004644CC CC
int 03
:004644CD 5A
pop edx
:004644CE 646789160000 mov fs:[0000],
edx
:004644D4 5A
pop edx
:004644D5 B801000000 mov eax,
00000001
:004644DA C3
ret
;--------------------------------------------------------------------
* Referenced by a CALL at Address:
|:004643B5
|
:004644DB 33D2
xor edx, edx
:004644DD 68F9444600 push 004644F9
:004644E2 64FF32
push dword ptr fs:[edx]
:004644E5 892524AF4900 mov dword ptr
[0049AF24], esp
:004644EB 892D28AF4900 mov dword ptr
[0049AF28], ebp
:004644F1 648922
mov dword ptr fs:[edx], esp
:004644F4 EB1A
jmp 00464510
:004644F6 90
nop
:004644F7 90
nop
:004644F8 90
nop
:004644F9 8B2524AF4900 mov esp, dword
ptr [0049AF24]
:004644FF 8B2D28AF4900 mov ebp, dword
ptr [0049AF28]
:00464505 5A
pop edx
:00464506 646789160000 mov fs:[0000],
edx
:0046450C 58
pop eax
:0046450D 33C0
xor eax, eax
:0046450F C3
ret
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:004644F4(U)
|
:00464510 B443
mov ah, 43
:00464512 CD68
int 68
:00464514 5A
pop edx
:00464515 646789160000 mov fs:[0000],
edx
:0046451B 5A
pop edx
:0046451C 663D86F3 cmp
ax, F386
:00464520 7407
je 00464529
:00464522 90
nop
:00464523 90
nop
:00464524 90
nop
:00464525 90
nop
:00464526 33C0
xor eax, eax
:00464528 C3
ret
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:00464520(C)
|
:00464529 B801000000 mov eax,
00000001
:0046452E C3
ret
;--------------------------------------------------------------------
* Referenced by a CALL at Address:
|:004643EF
|
:0046452F 33D2
xor edx, edx
:00464531 684D454600 push 0046454D
:00464536 64FF32
push dword ptr fs:[edx]
:00464539 892524AF4900 mov dword ptr
[0049AF24], esp
:0046453F 892D28AF4900 mov dword ptr
[0049AF28], ebp
:00464545 648922
mov dword ptr fs:[edx], esp
:00464548 EB1A
jmp 00464564
:0046454A 90
nop
:0046454B 90
nop
:0046454C 90
nop
:0046454D 8B2524AF4900 mov esp, dword
ptr [0049AF24]
:00464553 8B2D28AF4900 mov ebp, dword
ptr [0049AF28]
:00464559 5A
pop edx
:0046455A 646789160000 mov fs:[0000],
edx
:00464560 58
pop eax
:00464561 33C0
xor eax, eax
:00464563 C3
ret
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:00464548(U)
|
:00464564 0F010D2CAF4900 sidt [0049AF2C]
:0046456B A12EAF4900 mov eax,
dword ptr [0049AF2E]
:00464570 83C008
add eax, 00000008
:00464573 8B18
mov ebx, dword ptr [eax]
:00464575 83C010
add eax, 00000010
:00464578 8B00
mov eax, dword ptr [eax]
:0046457A 25FFFF0000 and eax,
0000FFFF
:0046457F 81E3FFFF0000 and ebx, 0000FFFF
:00464585 2BC3
sub eax, ebx
:00464587 83F81E
cmp eax, 0000001E
:0046458A 7406
je 00464592
:0046458C 90
nop
:0046458D 90
nop
:0046458E 90
nop
:0046458F 90
nop
:00464590 33C0
xor eax, eax
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:0046458A(C)
|
:00464592 5A
pop edx
:00464593 646789160000 mov fs:[0000],
edx
:00464599 5A
pop edx
:0046459A C3
ret
;--------------------------------------------------------------------
* Referenced by a CALL at Address:
|:00464404
|
* Possible StringData Ref from Data Obj ->"C:\ntice\nmtrans.dll"
|
:0046459B 683DAF4900 push 0049AF3D
* Reference To: KERNEL32.LoadLibraryA, Ord:0000h
|
:004645A0 E8BF20FAFF Call 00406664
:004645A5 85C0
test eax, eax
:004645A7 7419
je 004645C2
:004645A9 90
nop
:004645AA 90
nop
:004645AB 90
nop
:004645AC 90
nop
* Possible StringData Ref from Data Obj ->"NmSymIsSoftICELoaded"
|
:004645AD 6852AF4900 push 0049AF52
:004645B2 50
push eax
* Reference To: KERNEL32.GetProcAddress, Ord:0000h
|
:004645B3 E81420FAFF Call 004065CC
:004645B8 85C0
test eax, eax
:004645BA 7406
je 004645C2
:004645BC 90
nop
:004645BD 90
nop
:004645BE 90
nop
:004645BF 90
nop
:004645C0 FFD0
call eax
* Referenced by a (U)nconditional or (C)onditional Jump at Addresses:
|:004645A7(C), :004645BA(C)
|
:004645C2 C3
ret