static Bytes_0(void) {
auto x;
update_extra_cmt (
0X20000
, E_PREV
+
0
,
"; File Name : G://1.mem"
);
update_extra_cmt (
0X20000
, E_PREV
+
1
,
"; Format : Binary file"
);
update_extra_cmt (
0X20000
, E_PREV
+
2
,
"; Base Address: 0000h Range: 0000h - 2000h Loaded length: 2000h"
);
create_dword (
0X20000
);
create_dword (
0X20004
);
create_dword (
0X20008
);
create_dword (
0X2000C
);
create_dword (
0X20010
);
create_dword (
0X20014
);
create_dword (
0X20018
);
create_dword (
0X2001C
);
create_dword (
0X20020
);
create_dword (
0X20024
);
create_dword (
0X20028
);
create_dword (
0X2002C
);
create_word (
0X20036
);
create_word (
0X2003A
);
create_dword (
0X2003C
);
make_array (
0X2003C
,
0X9
);
create_strlit (
0X20060
,
0X20068
);
set_name (
0X20060
,
"a753"
);
create_strlit (
0X20068
,
0X20094
);
set_name (
0X20068
,
"aSystem32Wuaucl"
);
create_strlit (
0X20094
,
0X200C0
);
set_name (
0X20094
,
"aSyswow64Svchos"
);
create_insn (
0X200C0
);
create_insn (x
=
0X200C3
);
op_hex (x,
1
);
create_insn (
0X2014F
);
create_insn (
0X203C9
);
set_cmt (
0X2041D
,
"Trap to Debugger"
,
0
);
create_insn (x
=
0X2041D
);
op_hex (x,
0
);
create_insn (
0X2041E
);
create_insn (
0X20424
);
create_insn (
0X2042A
);
create_insn (
0X20430
);
create_insn (
0X20436
);
create_insn (
0X2043C
);
create_insn (
0X20442
);
create_insn (
0X20448
);
create_insn (
0X2044E
);
create_insn (
0X20454
);
create_insn (
0X2045A
);
create_insn (
0X20460
);
create_insn (
0X20466
);
create_insn (
0X2046C
);
create_insn (
0X20472
);
create_insn (
0X20478
);
create_insn (
0X2047E
);
create_insn (
0X20484
);
create_insn (
0X2048A
);
create_dword (x
=
0X20490
);
op_plain_offset (x,
0
,
0
);
op_plain_offset (x,
128
,
0
);
create_dword (
0X20494
);
make_array (
0X20494
,
0X2
);
create_byte (
0X2049D
);
make_array (
0X2049D
,
0X3
);
create_dword (x
=
0X204A0
);
op_plain_offset (x,
0
,
0
);
op_plain_offset (x,
128
,
0
);
create_dword (x
=
0X204A4
);
op_plain_offset (x,
0
,
0
);
op_plain_offset (x,
128
,
0
);
make_array (
0X204A8
,
0X8
);
make_array (
0X204B2
,
0X2
);
create_dword (
0X204B4
);
make_array (
0X204B4
,
0X6
);
create_dword (x
=
0X204CC
);
op_plain_offset (x,
0
,
0
);
op_plain_offset (x,
128
,
0
);
create_dword (x
=
0X204D0
);
op_plain_offset (x,
0
,
0
);
op_plain_offset (x,
128
,
0
);
create_byte (
0X204D5
);
make_array (
0X204D5
,
0X3
);
make_array (
0X204DA
,
0X2
);
make_array (
0X204DE
,
0X2
);
make_array (
0X204E2
,
0X2
);
create_dword (x
=
0X204E4
);
op_plain_offset (x,
0
,
0
);
op_plain_offset (x,
128
,
0
);
create_dword (x
=
0X204E8
);
op_plain_offset (x,
0
,
0
);
op_plain_offset (x,
128
,
0
);
make_array (
0X204EE
,
0X2
);
make_array (
0X204F2
,
0X2
);
make_array (
0X204F6
,
0X2
);
make_array (
0X204FA
,
0X6
);
create_dword (x
=
0X20500
);
op_plain_offset (x,
0
,
0
);
op_plain_offset (x,
128
,
0
);
create_dword (x
=
0X20504
);
op_plain_offset (x,
0
,
0
);
op_plain_offset (x,
128
,
0
);
create_byte (
0X20509
);
make_array (
0X20509
,
0X3
);
create_dword (x
=
0X2050C
);
op_plain_offset (x,
0
,
0
);
op_plain_offset (x,
128
,
0
);
make_array (
0X20512
,
0X2
);
create_byte (
0X20515
);
make_array (
0X20515
,
0X3
);
make_array (
0X20519
,
0X7
);
create_strlit (
0X20522
,
0X20533
);
set_name (
0X20522
,
"aNtdelayexecuti"
);
create_strlit (
0X20536
,
0X2053E
);
set_name (
0X20536
,
"aZwclose"
);
create_byte (
0X2053F
);
create_strlit (
0X20541
,
0X20550
);
set_name (
0X20541
,
"aWcreatesection"
);
create_strlit (
0X20552
,
0X20565
);
set_name (
0X20552
,
"aZwmapviewofsec"
);
create_strlit (
0X20569
,
0X20582
);
set_name (
0X20569
,
"aWqueryinformat"
);
create_word (
0X20582
);
create_strlit (
0X20585
,
0X20593
);
set_name (
0X20585
,
"aWresumethread"
);
create_strlit (
0X20597
,
0X205AB
);
set_name (
0X20597
,
"aWunmapviewofse"
);
create_strlit (
0X205AC
,
0X205B6
);
set_name (
0X205AC
,
"aNtdllDll"
);
create_strlit (
0X205B8
,
0X205C4
);
set_name (
0X205B8
,
"aClosehandle"
);
create_strlit (
0X205C7
,
0X205D2
);
set_name (
0X205C7
,
"aReatefilew"
);
create_strlit (
0X205D5
,
0X205E3
);
set_name (
0X205D5
,
"aReateprocessw"
);
create_strlit (
0X205E7
,
0X205F2
);
set_name (
0X205E7
,
"aXitprocess"
);
create_word (
0X205F2
);
create_strlit (
0X205F4
,
0X20607
);
set_name (
0X205F4
,
"aGetmodulefilen"
);
create_byte (
0X20609
);
make_array (
0X20609
,
0X3
);
create_strlit (
0X2060C
,
0X2061B
);
set_name (
0X2060C
,
"aTmodulehandlew"
);
create_strlit (
0X2061E
,
0X2062F
);
set_name (
0X2061E
,
"aGetthreadconte"
);
create_strlit (
0X20633
,
0X20647
);
set_name (
0X20633
,
"aEtwindowsdirec"
);
create_strlit (
0X2064B
,
0X20662
);
set_name (
0X2064B
,
"aEtenvironmentv"
);
create_strlit (
0X20664
,
0X20671
);
set_name (
0X20664
,
"aVirtualalloc"
);
create_byte (
0X20673
);
create_strlit (
0X20674
,
0X20680
);
set_name (
0X20674
,
"aVirtualfree"
);
create_strlit (
0X20682
,
0X2068B
);
set_name (
0X20682
,
"aLstrcatw"
);
create_strlit (
0X2068C
,
0X20699
);
set_name (
0X2068C
,
"aKernel32Dll"
);
make_array (
0X20699
,
0X3
);
create_dword (
0X2069C
);
make_array (
0X2069C
,
0X25A
);
create_dword (x
=
0X21004
);
op_plain_offset (x,
0
,
0
);
op_plain_offset (x,
128
,
0
);
create_word (
0X2100A
);
create_dword (
0X2100C
);
make_array (
0X2100C
,
0X3FD
);
}