home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
telefisk.org
/
virusCollection.lzx
/
VirusResearch
/
DataType-trojan
/
decode.e
< prev
Wrap
Text File
|
2012-02-06
|
1KB
|
88 lines
MODULE 'tools/file'
PROC main()
DEF datasize=NIL,
dataddr=NIL
->WriteF('\d\n',{enddata}-{data})
->CleanUp()
datasize:={enddata}-{data}
dataddr:={data}
MOVE.L datasize,D7
LSR.L #2,D7
SUB.L #1,D7
MOVEQ #0,D6
MOVEA.L #$4,A0
MOVEA.L dataddr,A2
MOVE.L dataddr,
lab_0004:
MOVEQ #2,D0
CMP D0,D6
BCC.B lab_0005
SWAP D6
CLR D6
SWAP D6
MOVE.L D6,D0
ASL.L #2,D0
SUB.L D6,D0
ASL.L #3,D0
SUB.L D6,D0
ADD.L D0,D0
MOVEA.L A2,A0
ADDA.L D0,A0
LEA 92(A0),A1
MOVEA.L A1,A0
->MOVEA.L #$4,A6
->JSR -558(A6)
ADDQ #1,D6
DBRA.B D7,lab_0004
lab_0005:
writefile('RAM:DataType.decode',{data},datasize)
ENDPROC
data: LONG $FFFF0814,
$09C80A24,
$0B364EFE,
$0C3C14CA,
$1518191A,
$1960198A,
$19F21A60,
$1BF81D82,
$1DD81E38,
$1E882076,
$21A021E0,
$22502276,
$22C622D4,
$22E222F0,
$22FE230C,
$231A2328,
$23362344,
$23522360,
$236E237C,
$238A2398,
$148E23A6,
$24622724,
$27542A54,
$2B342A38,
$2C8A2816,
$27A22992,
$2D4E2D5C,
$FFFFA008,
$0900800A,
$00007A34,
$A00E0600,
$9014002D,
$90160004,
$80180000,
$7A4C0000,
$4E71
enddata: LONG $FFFFFFFF