Clone of PhatAC @ https://github.com/floaterxk/PhatAC

crcwheel.cpp 39KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122112311241125112611271128112911301131113211331134113511361137113811391140114111421143114411451146114711481149115011511152115311541155115611571158115911601161116211631164116511661167116811691170117111721173117411751176117711781179118011811182118311841185118611871188118911901191119211931194119511961197119811991200120112021203120412051206120712081209121012111212121312141215121612171218121912201221122212231224122512261227122812291230123112321233123412351236123712381239124012411242124312441245124612471248124912501251125212531254125512561257125812591260126112621263126412651266126712681269127012711272127312741275127612771278127912801281128212831284128512861287128812891290129112921293129412951296129712981299130013011302130313041305130613071308130913101311131213131314131513161317131813191320132113221323132413251326132713281329133013311332133313341335133613371338133913401341134213431344134513461347134813491350135113521353135413551356135713581359136013611362136313641365136613671368136913701371137213731374137513761377137813791380138113821383138413851386138713881389
  1. #include "StdAfx.h"
  2. extern void *SubTableEntry3__VTBL[5];
  3. #define SubTableEntry2_seqnum 0
  4. #define SubTableEntry2_encryption_key 4
  5. #define SubTableEntry2_ptr_SubTableEntry3 8
  6. #define SubTableEntry3_ptr_VTBL 0
  7. #define SubTableEntry3_counter 4
  8. #define SubTableEntry3_ptr_xortable 8
  9. #define SubTableEntry3_ptr_unktable 12
  10. #define SubTableEntry3_arg0 16
  11. #define SubTableEntry3_arg1 20
  12. #define SubTableEntry3_arg2 24
  13. #define SubTableEntry4_counter 0
  14. #define SubTableEntry4_ptr_xortable 4
  15. #define SubTableEntry4_ptr_unktable 8
  16. #define SubTableEntry4_arg0 12
  17. #define SubTableEntry4_arg1 16
  18. #define SubTableEntry4_arg2 20
  19. //check
  20. __declspec(naked) void SubTableEntry4__Constructor(void)
  21. {
  22. ULONG *xortab, *unktab;
  23. __asm
  24. {
  25. push ebp
  26. mov ebp, esp
  27. sub esp, __LOCAL_SIZE
  28. push ecx
  29. push 256
  30. push 4
  31. call calloc
  32. mov[xortab], eax
  33. add esp, 8h
  34. push 256
  35. push 4
  36. call calloc
  37. mov[unktab], eax
  38. add esp, 8h
  39. pop ecx
  40. mov eax, [xortab]
  41. mov dword ptr[ecx + SubTableEntry4_ptr_xortable], eax
  42. mov eax, [unktab]
  43. mov dword ptr[ecx + SubTableEntry4_ptr_unktable], eax
  44. mov esp, ebp
  45. pop ebp
  46. ret
  47. }
  48. }
  49. //check
  50. #if 0
  51. __declspec(naked) void SubTableEntry3__DESTRUCTOR(void)
  52. {
  53. //void *woot;
  54. __asm
  55. {
  56. push ebp
  57. mov ebp, esp
  58. sub esp, __LOCAL_SIZE
  59. push ecx
  60. int 3
  61. call free
  62. add esp, 4h
  63. ; mov dword ptr[woot], ecx
  64. }
  65. //delete [] woot;
  66. __asm
  67. {
  68. mov esp, ebp
  69. pop ebp
  70. ret
  71. }
  72. }
  73. #endif
  74. #define ptr_SubTableEntry3 -48
  75. #define local_unk -44
  76. #define local_counter -40
  77. #define xor0 -36
  78. #define xor1 -32
  79. #define xor2 -28
  80. #define xor3 -24
  81. #define xor4 -20
  82. #define xor5 -16
  83. #define xor6 -12
  84. #define local_xor -8
  85. #define xor7 -4
  86. #define ptr_SubTableEntry4 8
  87. #define bool_use_keys 12
  88. //check
  89. __declspec(naked) void SubTableEntry3__Fill_Out_Tables_Part2(void)
  90. {
  91. __asm
  92. {
  93. push ebp
  94. mov ebp, esp
  95. sub esp, 30h
  96. mov dword ptr[ebp + ptr_SubTableEntry3], ecx
  97. mov dword ptr[ebp + xor0], 9E3779B9h
  98. mov eax, [ebp + xor0]
  99. mov dword ptr[ebp + xor1], eax
  100. mov ecx, [ebp + xor1]
  101. mov dword ptr[ebp + xor2], ecx
  102. mov edx, [ebp + xor2]
  103. mov dword ptr[ebp + xor3], edx
  104. mov eax, [ebp + xor3]
  105. mov dword ptr[ebp + xor4], eax
  106. mov ecx, [ebp + xor4]
  107. mov dword ptr[ebp + xor5], ecx
  108. mov edx, [ebp + xor5]
  109. mov dword ptr[ebp + xor6], edx
  110. mov eax, [ebp + xor6]
  111. mov dword ptr[ebp + xor7], eax
  112. mov ecx, [ebp + ptr_SubTableEntry4]
  113. mov edx, [ecx + SubTableEntry4_ptr_unktable]
  114. mov dword ptr[ebp + local_unk], edx
  115. mov eax, [ebp + ptr_SubTableEntry4]
  116. mov ecx, [eax + SubTableEntry4_ptr_xortable]
  117. mov dword ptr[ebp + local_xor], ecx
  118. cmp dword ptr[ebp + bool_use_keys], 0
  119. jnz short USE_GIVEN_KEYS
  120. mov edx, [ebp + ptr_SubTableEntry4]
  121. mov dword ptr[edx + SubTableEntry4_arg0], 0
  122. mov eax, [ebp + ptr_SubTableEntry4]
  123. mov dword ptr[eax + SubTableEntry4_arg1], 0
  124. mov ecx, [ebp + ptr_SubTableEntry4]
  125. mov dword ptr[ecx + SubTableEntry4_arg2], 0
  126. USE_GIVEN_KEYS:; CODE XREF : SubTableEntry3__Fill_Out_Tables_Part2 + 50.j
  127. mov dword ptr[ebp + local_counter], 0
  128. jmp short loc_4BD862
  129. ; -------------------------------------------------------------------------- -
  130. loc_4BD859:; CODE XREF : SubTableEntry3__Fill_Out_Tables_Part2 + B3.j
  131. mov edx, [ebp + local_counter]
  132. add edx, 1
  133. mov dword ptr[ebp + local_counter], edx
  134. loc_4BD862 : ; CODE XREF : SubTableEntry3__Fill_Out_Tables_Part2 + 77.j
  135. cmp dword ptr[ebp + local_counter], 4; for (int i = 0; i < 4; i++)
  136. ; {
  137. ; SubTableEntry3::VTBL_func[0x10](
  138. ; }
  139. jge short loc_4BD895
  140. lea eax, [ebp + xor0]
  141. push eax
  142. lea ecx, [ebp + xor1]
  143. push ecx
  144. lea edx, [ebp + xor2]
  145. push edx
  146. lea eax, [ebp + xor3]
  147. push eax
  148. lea ecx, [ebp + xor4]
  149. push ecx
  150. lea edx, [ebp + xor5]
  151. push edx
  152. lea eax, [ebp + xor6]
  153. push eax
  154. lea ecx, [ebp + xor7]
  155. push ecx
  156. mov edx, [ebp + ptr_SubTableEntry3]
  157. mov eax, [edx + SubTableEntry3_ptr_VTBL]
  158. mov ecx, [ebp + ptr_SubTableEntry3]
  159. call dword ptr[eax + 10h]; SubTableEntry3::XOR_LOOP1
  160. jmp short loc_4BD859
  161. ; -------------------------------------------------------------------------- -
  162. loc_4BD895:; CODE XREF : SubTableEntry3__Fill_Out_Tables_Part2 + 86.j
  163. cmp dword ptr[ebp + bool_use_keys], 0
  164. jz dont_use_keys_route
  165. mov dword ptr[ebp + local_counter], 0
  166. jmp short loc_4BD8B1
  167. ; -------------------------------------------------------------------------- -
  168. loc_4BD8A8:; CODE XREF : SubTableEntry3__Fill_Out_Tables_Part2 + 1EF.j
  169. mov ecx, [ebp + local_counter]
  170. add ecx, 8; note, I += 2
  171. mov dword ptr[ebp + local_counter], ecx
  172. loc_4BD8B1 : ; CODE XREF : SubTableEntry3__Fill_Out_Tables_Part2 + C6.j
  173. cmp dword ptr[ebp + local_counter], 100h
  174. jge iteration_256_complete
  175. mov edx, [ebp + local_counter]
  176. mov eax, [ebp + local_xor]
  177. mov ecx, [ebp + xor7]
  178. add ecx, [eax + edx * 4]
  179. mov dword ptr[ebp + xor7], ecx
  180. mov edx, [ebp + local_counter]
  181. mov eax, [ebp + local_xor]
  182. mov ecx, [ebp + xor6]
  183. add ecx, [eax + edx * 4 + 4]
  184. mov dword ptr[ebp + xor6], ecx
  185. mov edx, [ebp + local_counter]
  186. mov eax, [ebp + local_xor]
  187. mov ecx, [ebp + xor5]
  188. add ecx, [eax + edx * 4 + 8]
  189. mov dword ptr[ebp + xor5], ecx
  190. mov edx, [ebp + local_counter]
  191. mov eax, [ebp + local_xor]
  192. mov ecx, [ebp + xor4]
  193. add ecx, [eax + edx * 4 + 0Ch]
  194. mov dword ptr[ebp + xor4], ecx
  195. mov edx, [ebp + local_counter]
  196. mov eax, [ebp + local_xor]
  197. mov ecx, [ebp + xor3]
  198. add ecx, [eax + edx * 4 + 10h]
  199. mov dword ptr[ebp + xor3], ecx
  200. mov edx, [ebp + local_counter]
  201. mov eax, [ebp + local_xor]
  202. mov ecx, [ebp + xor2]
  203. add ecx, [eax + edx * 4 + 14h]
  204. mov dword ptr[ebp + xor2], ecx
  205. mov edx, [ebp + local_counter]
  206. mov eax, [ebp + local_xor]
  207. mov ecx, [ebp + xor1]
  208. add ecx, [eax + edx * 4 + 18h]
  209. mov dword ptr[ebp + xor1], ecx
  210. mov edx, [ebp + local_counter]
  211. mov eax, [ebp + local_xor]
  212. mov ecx, [ebp + xor0]
  213. add ecx, [eax + edx * 4 + 1Ch]
  214. mov dword ptr[ebp + xor0], ecx
  215. lea edx, [ebp + xor0]
  216. push edx
  217. lea eax, [ebp + xor1]
  218. push eax
  219. lea ecx, [ebp + xor2]
  220. push ecx
  221. lea edx, [ebp + xor3]
  222. push edx
  223. lea eax, [ebp + xor4]
  224. push eax
  225. lea ecx, [ebp + xor5]
  226. push ecx
  227. lea edx, [ebp + xor6]
  228. push edx
  229. lea eax, [ebp + xor7]
  230. push eax
  231. mov ecx, [ebp + ptr_SubTableEntry3]
  232. mov edx, [ecx]
  233. mov ecx, [ebp + ptr_SubTableEntry3]
  234. call dword ptr[edx + 10h]; SubTableEntry3::XOR_LOOP1
  235. mov eax, [ebp + local_counter]
  236. mov ecx, [ebp + local_unk]
  237. mov edx, [ebp + xor7]
  238. mov dword ptr[ecx + eax * 4], edx
  239. mov eax, [ebp + local_counter]
  240. mov ecx, [ebp + local_unk]
  241. mov edx, [ebp + xor6]
  242. mov dword ptr[ecx + eax * 4 + 4], edx
  243. mov eax, [ebp + local_counter]
  244. mov ecx, [ebp + local_unk]
  245. mov edx, [ebp + xor5]
  246. mov dword ptr[ecx + eax * 4 + 8], edx
  247. mov eax, [ebp + local_counter]
  248. mov ecx, [ebp + local_unk]
  249. mov edx, [ebp + xor4]
  250. mov dword ptr[ecx + eax * 4 + 0Ch], edx
  251. mov eax, [ebp + local_counter]
  252. mov ecx, [ebp + local_unk]
  253. mov edx, [ebp + xor3]
  254. mov dword ptr[ecx + eax * 4 + 10h], edx
  255. mov eax, [ebp + local_counter]
  256. mov ecx, [ebp + local_unk]
  257. mov edx, [ebp + xor2]
  258. mov dword ptr[ecx + eax * 4 + 14h], edx
  259. mov eax, [ebp + local_counter]
  260. mov ecx, [ebp + local_unk]
  261. mov edx, [ebp + xor1]
  262. mov dword ptr[ecx + eax * 4 + 18h], edx
  263. mov eax, [ebp + local_counter]
  264. mov ecx, [ebp + local_unk]
  265. mov edx, [ebp + xor0]
  266. mov dword ptr[ecx + eax * 4 + 1Ch], edx
  267. jmp loc_4BD8A8
  268. ; -------------------------------------------------------------------------- -
  269. iteration_256_complete:; CODE XREF : SubTableEntry3__Fill_Out_Tables_Part2 + D8.j
  270. mov dword ptr[ebp + local_counter], 0
  271. jmp short loc_4BD9E6
  272. ; -------------------------------------------------------------------------- -
  273. loc_4BD9DD:; CODE XREF : SubTableEntry3__Fill_Out_Tables_Part2 + 324.j
  274. mov eax, [ebp + local_counter]
  275. add eax, 8; note, I += 2
  276. mov dword ptr[ebp + local_counter], eax
  277. loc_4BD9E6 : ; CODE XREF : SubTableEntry3__Fill_Out_Tables_Part2 + 1FB.j
  278. cmp dword ptr[ebp + local_counter], 100h
  279. jge iteration_256_2_complete
  280. mov ecx, [ebp + local_counter]
  281. mov edx, [ebp + local_unk]
  282. mov eax, [ebp + xor7]
  283. add eax, [edx + ecx * 4]
  284. mov dword ptr[ebp + xor7], eax
  285. mov ecx, [ebp + local_counter]
  286. mov edx, [ebp + local_unk]
  287. mov eax, [ebp + xor6]
  288. add eax, [edx + ecx * 4 + 4]
  289. mov dword ptr[ebp + xor6], eax
  290. mov ecx, [ebp + local_counter]
  291. mov edx, [ebp + local_unk]
  292. mov eax, [ebp + xor5]
  293. add eax, [edx + ecx * 4 + 8]
  294. mov dword ptr[ebp + xor5], eax
  295. mov ecx, [ebp + local_counter]
  296. mov edx, [ebp + local_unk]
  297. mov eax, [ebp + xor4]
  298. add eax, [edx + ecx * 4 + 0Ch]
  299. mov dword ptr[ebp + xor4], eax
  300. mov ecx, [ebp + local_counter]
  301. mov edx, [ebp + local_unk]
  302. mov eax, [ebp + xor3]
  303. add eax, [edx + ecx * 4 + 10h]
  304. mov dword ptr[ebp + xor3], eax
  305. mov ecx, [ebp + local_counter]
  306. mov edx, [ebp + local_unk]
  307. mov eax, [ebp + xor2]
  308. add eax, [edx + ecx * 4 + 14h]
  309. mov dword ptr[ebp + xor2], eax
  310. mov ecx, [ebp + local_counter]
  311. mov edx, [ebp + local_unk]
  312. mov eax, [ebp + xor1]
  313. add eax, [edx + ecx * 4 + 18h]
  314. mov dword ptr[ebp + xor1], eax
  315. mov ecx, [ebp + local_counter]
  316. mov edx, [ebp + local_unk]
  317. mov eax, [ebp + xor0]
  318. add eax, [edx + ecx * 4 + 1Ch]
  319. mov dword ptr[ebp + xor0], eax
  320. lea ecx, [ebp + xor0]
  321. push ecx
  322. lea edx, [ebp + xor1]
  323. push edx
  324. lea eax, [ebp + xor2]
  325. push eax
  326. lea ecx, [ebp + xor3]
  327. push ecx
  328. lea edx, [ebp + xor4]
  329. push edx
  330. lea eax, [ebp + xor5]
  331. push eax
  332. lea ecx, [ebp + xor6]
  333. push ecx
  334. lea edx, [ebp + xor7]
  335. push edx
  336. mov eax, [ebp + ptr_SubTableEntry3]
  337. mov edx, [eax]
  338. mov ecx, [ebp + ptr_SubTableEntry3]
  339. call dword ptr[edx + 10h]; SubTableEntry3::XOR_LOOP1
  340. mov eax, [ebp + local_counter]
  341. mov ecx, [ebp + local_unk]
  342. mov edx, [ebp + xor7]
  343. mov dword ptr[ecx + eax * 4], edx
  344. mov eax, [ebp + local_counter]
  345. mov ecx, [ebp + local_unk]
  346. mov edx, [ebp + xor6]
  347. mov dword ptr[ecx + eax * 4 + 4], edx
  348. mov eax, [ebp + local_counter]
  349. mov ecx, [ebp + local_unk]
  350. mov edx, [ebp + xor5]
  351. mov dword ptr[ecx + eax * 4 + 8], edx
  352. mov eax, [ebp + local_counter]
  353. mov ecx, [ebp + local_unk]
  354. mov edx, [ebp + xor4]
  355. mov dword ptr[ecx + eax * 4 + 0Ch], edx
  356. mov eax, [ebp + local_counter]
  357. mov ecx, [ebp + local_unk]
  358. mov edx, [ebp + xor3]
  359. mov dword ptr[ecx + eax * 4 + 10h], edx
  360. mov eax, [ebp + local_counter]
  361. mov ecx, [ebp + local_unk]
  362. mov edx, [ebp + xor2]
  363. mov dword ptr[ecx + eax * 4 + 14h], edx
  364. mov eax, [ebp + local_counter]
  365. mov ecx, [ebp + local_unk]
  366. mov edx, [ebp + xor1]
  367. mov dword ptr[ecx + eax * 4 + 18h], edx
  368. mov eax, [ebp + local_counter]
  369. mov ecx, [ebp + local_unk]
  370. mov edx, [ebp + xor0]
  371. mov dword ptr[ecx + eax * 4 + 1Ch], edx
  372. jmp loc_4BD9DD
  373. ; -------------------------------------------------------------------------- -
  374. iteration_256_2_complete:; CODE XREF : SubTableEntry3__Fill_Out_Tables_Part2 + 20D.j
  375. jmp last_part
  376. ; -------------------------------------------------------------------------- -
  377. dont_use_keys_route:; CODE XREF : SubTableEntry3__Fill_Out_Tables_Part2 + B9.j
  378. lea eax, [ebp + xor0]
  379. push eax
  380. lea ecx, [ebp + xor1]
  381. push ecx
  382. lea edx, [ebp + xor2]
  383. push edx
  384. lea eax, [ebp + xor3]
  385. push eax
  386. lea ecx, [ebp + xor4]
  387. push ecx
  388. lea edx, [ebp + xor5]
  389. push edx
  390. lea eax, [ebp + xor6]
  391. push eax
  392. lea ecx, [ebp + xor7]
  393. push ecx
  394. mov edx, [ebp + ptr_SubTableEntry3]
  395. mov eax, [edx]
  396. mov ecx, [ebp + ptr_SubTableEntry3]
  397. call dword ptr[eax + 10h]; SubTableEntry3::XOR_LOOP1
  398. mov ecx, [ebp + local_counter]
  399. mov edx, [ebp + local_unk]
  400. mov eax, [ebp + xor7]
  401. mov dword ptr[edx + ecx * 4], eax
  402. mov ecx, [ebp + local_counter]
  403. mov edx, [ebp + local_unk]
  404. mov eax, [ebp + xor6]
  405. mov dword ptr[edx + ecx * 4 + 4], eax
  406. mov ecx, [ebp + local_counter]
  407. mov edx, [ebp + local_unk]
  408. mov eax, [ebp + xor5]
  409. mov dword ptr[edx + ecx * 4 + 8], eax
  410. mov ecx, [ebp + local_counter]
  411. mov edx, [ebp + local_unk]
  412. mov eax, [ebp + xor4]
  413. mov dword ptr[edx + ecx * 4 + 0Ch], eax
  414. mov ecx, [ebp + local_counter]
  415. mov edx, [ebp + local_unk]
  416. mov eax, [ebp + xor3]
  417. mov dword ptr[edx + ecx * 4 + 10h], eax
  418. mov ecx, [ebp + local_counter]
  419. mov edx, [ebp + local_unk]
  420. mov eax, [ebp + xor2]
  421. mov dword ptr[edx + ecx * 4 + 14h], eax
  422. mov ecx, [ebp + local_counter]
  423. mov edx, [ebp + local_unk]
  424. mov eax, [ebp + xor1]
  425. mov dword ptr[edx + ecx * 4 + 18h], eax
  426. mov ecx, [ebp + local_counter]
  427. mov edx, [ebp + local_unk]
  428. mov eax, [ebp + xor0]
  429. mov dword ptr[edx + ecx * 4 + 1Ch], eax
  430. last_part : ; CODE XREF : SubTableEntry3__Fill_Out_Tables_Part2 + 329.j
  431. mov ecx, [ebp + ptr_SubTableEntry4]
  432. push ecx
  433. mov edx, [ebp + ptr_SubTableEntry3]
  434. mov eax, [edx + SubTableEntry3_ptr_VTBL]
  435. mov ecx, [ebp + ptr_SubTableEntry3]
  436. call dword ptr[eax + 0Ch]
  437. mov ecx, [ebp + ptr_SubTableEntry4]
  438. mov dword ptr[ecx + SubTableEntry4_counter], 100h
  439. mov esp, ebp
  440. pop ebp
  441. retn 8
  442. }
  443. }
  444. #undef ptr_SubTableEntry3
  445. #undef local_counter
  446. #define temp_int -12
  447. #define ptr_SubTableEntry3 -8
  448. #define local_counter -4
  449. #define arg_0 8
  450. #define arg_4 12
  451. #define arg_8 16
  452. #define ptr_initvals 20
  453. //check
  454. __declspec(naked) void SubTableEntry3__Fill_Out_Tables(void)
  455. {
  456. __asm
  457. {
  458. push ebp
  459. mov ebp, esp
  460. sub esp, 0Ch
  461. mov dword ptr[ebp + ptr_SubTableEntry3], ecx
  462. mov dword ptr[ebp + local_counter], 0
  463. jmp short loc_4BDBDB
  464. loc_4BDBD2 : ; CODE XREF : SubTableEntry3__Fill_Out_Tables + 4E.j
  465. mov eax, [ebp + local_counter]
  466. add eax, 1
  467. mov dword ptr[ebp + local_counter], eax
  468. loc_4BDBDB : ; CODE XREF : SubTableEntry3__Fill_Out_Tables + 10.j
  469. cmp dword ptr[ebp + local_counter], 100h
  470. jge short loc_4BDC10
  471. cmp dword ptr[ebp + ptr_initvals], 0
  472. jz short loc_4BDBF8
  473. mov ecx, [ebp + local_counter]
  474. mov edx, [ebp + ptr_initvals]
  475. mov eax, [edx + ecx * 4]
  476. mov dword ptr[ebp + temp_int], eax
  477. jmp short loc_4BDBFF
  478. loc_4BDBF8 : ; CODE XREF : SubTableEntry3__Fill_Out_Tables + 28.j
  479. mov dword ptr[ebp + temp_int], 0
  480. loc_4BDBFF : ; CODE XREF : SubTableEntry3__Fill_Out_Tables + 36.j
  481. mov ecx, [ebp + ptr_SubTableEntry3]
  482. mov edx, [ecx + SubTableEntry3_ptr_xortable]
  483. mov eax, [ebp + local_counter]
  484. mov ecx, [ebp + temp_int]
  485. mov dword ptr[edx + eax * 4], ecx
  486. jmp short loc_4BDBD2
  487. loc_4BDC10 : ; CODE XREF : SubTableEntry3__Fill_Out_Tables + 22.j
  488. mov edx, [ebp + ptr_SubTableEntry3]
  489. mov eax, [ebp + arg_0]
  490. mov dword ptr[edx + SubTableEntry3_arg0], eax
  491. mov ecx, [ebp + ptr_SubTableEntry3]
  492. mov edx, [ebp + arg_4]
  493. mov dword ptr[ecx + SubTableEntry3_arg1], edx
  494. mov eax, [ebp + ptr_SubTableEntry3]
  495. mov ecx, [ebp + arg_8]
  496. mov dword ptr[eax + SubTableEntry3_arg2], ecx
  497. push 1; USE GIVEN KEYS
  498. mov edx, [ebp + ptr_SubTableEntry3]
  499. add edx, 4
  500. push edx
  501. mov eax, [ebp + ptr_SubTableEntry3]
  502. mov edx, [eax + SubTableEntry3_ptr_VTBL]
  503. mov ecx, [ebp + ptr_SubTableEntry3]
  504. call dword ptr[edx + 4]; SubTableEntry3::Fill_Out_Tables_Part2
  505. mov esp, ebp
  506. pop ebp
  507. retn 10h
  508. }
  509. }
  510. #undef ptr_SubTableEntry3
  511. #define ptr_SubTableEntry3 -4
  512. #define arg_0 8
  513. #define arg_4 12
  514. //check
  515. __declspec(naked) void SubTableEntry3__Crazy_XOR_01(void)
  516. {
  517. __asm
  518. {
  519. push ebp
  520. mov ebp, esp
  521. push ecx
  522. mov dword ptr[ebp + ptr_SubTableEntry3], ecx
  523. mov eax, [ebp + arg_4]
  524. and eax, 3FCh
  525. mov ecx, [ebp + arg_0]
  526. mov eax, [ecx + eax]
  527. mov esp, ebp
  528. pop ebp
  529. retn 8
  530. }
  531. }
  532. #undef ptr_SubTableEntry3
  533. #define ptr_SubTableEntry3 -4
  534. #define arg_0 8
  535. #define arg_4 12
  536. #define arg_8 16
  537. #define arg_C 20
  538. #define arg_10 24
  539. #define arg_14 28
  540. #define arg_18 32
  541. #define arg_1C 36
  542. #define arg_20 40
  543. //check
  544. __declspec(naked) void SubTableEntry3__Crazy_XOR_00(void)
  545. {
  546. __asm
  547. {
  548. push ebp
  549. mov ebp, esp
  550. push ecx
  551. mov dword ptr[ebp + ptr_SubTableEntry3], ecx
  552. mov eax, [ebp + arg_10]
  553. mov ecx, [eax]
  554. mov edx, [ebp + arg_1C]
  555. mov eax, [ecx]
  556. mov dword ptr[edx], eax
  557. mov ecx, [ebp + arg_4]
  558. mov edx, [ecx]
  559. xor edx, [ebp + arg_0]
  560. mov eax, [ebp + arg_14]
  561. mov ecx, [eax]
  562. add edx, [ecx]
  563. mov eax, [ebp + arg_4]
  564. mov dword ptr[eax], edx
  565. mov ecx, [ebp + arg_14]
  566. mov edx, [ecx]
  567. add edx, 4
  568. mov eax, [ebp + arg_14]
  569. mov dword ptr[eax], edx
  570. mov ecx, [ebp + arg_1C]
  571. mov edx, [ecx]
  572. push edx
  573. mov eax, [ebp + arg_C]
  574. mov ecx, [eax]
  575. push ecx
  576. mov ecx, [ebp + ptr_SubTableEntry3]
  577. call SubTableEntry3__Crazy_XOR_01
  578. mov edx, [ebp + arg_4]
  579. add eax, [edx]
  580. mov ecx, [ebp + arg_8]
  581. add eax, [ecx]
  582. mov edx, [ebp + arg_20]
  583. mov dword ptr[edx], eax
  584. mov eax, [ebp + arg_10]
  585. mov ecx, [eax]
  586. mov edx, [ebp + arg_20]
  587. mov eax, [edx]
  588. mov dword ptr[ecx], eax
  589. mov ecx, [ebp + arg_10]
  590. mov edx, [ecx]
  591. add edx, 4
  592. mov eax, [ebp + arg_10]
  593. mov dword ptr[eax], edx
  594. mov ecx, [ebp + arg_20]
  595. mov edx, [ecx]
  596. shr edx, 8
  597. push edx
  598. mov eax, [ebp + arg_C]
  599. mov ecx, [eax]
  600. push ecx
  601. mov ecx, [ebp + ptr_SubTableEntry3]
  602. call SubTableEntry3__Crazy_XOR_01
  603. mov edx, [ebp + arg_1C]
  604. add eax, [edx]
  605. mov ecx, [ebp + arg_8]
  606. mov dword ptr[ecx], eax
  607. mov edx, [ebp + arg_18]
  608. mov eax, [edx]
  609. mov ecx, [ebp + arg_8]
  610. mov edx, [ecx]
  611. mov dword ptr[eax], edx
  612. mov eax, [ebp + arg_18]
  613. mov ecx, [eax]
  614. add ecx, 4
  615. mov edx, [ebp + arg_18]
  616. mov dword ptr[edx], ecx
  617. mov esp, ebp
  618. pop ebp
  619. retn 24h
  620. }
  621. }
  622. #undef ptr_SubTableEntry3
  623. #undef local_unk
  624. #undef local_xor
  625. #define ptr_SubTableEntry3 -40
  626. #define lc_unk0 -36
  627. #define lc_unk200 -32
  628. #define var_1C -28
  629. #define var_18 -24
  630. #define local_unk -20
  631. #define local_xor -16
  632. #define key2 -12
  633. #define key0 -8
  634. #define lc_unk0_stop_point -4
  635. #define ptr_SubTableEntry4 8
  636. //check
  637. __declspec(naked) void SubTableEntry3__Final_INIT_Stage(void)
  638. {
  639. __asm
  640. {
  641. push ebp
  642. mov ebp, esp
  643. sub esp, 28h
  644. mov dword ptr[ebp + ptr_SubTableEntry3], ecx
  645. //puts argument unktable into localstack
  646. mov eax, [ebp + ptr_SubTableEntry4]
  647. mov ecx, [eax + SubTableEntry4_ptr_unktable]
  648. mov dword ptr[ebp + local_unk], ecx
  649. //puts argument xortable into localstack
  650. mov edx, [ebp + ptr_SubTableEntry4]
  651. mov eax, [edx + SubTableEntry4_ptr_xortable]
  652. mov dword ptr[ebp + local_xor], eax
  653. //puts argument arg0 into evilstack
  654. mov ecx, [ebp + ptr_SubTableEntry4]
  655. mov edx, [ecx + SubTableEntry4_arg0]
  656. mov dword ptr[ebp + key0], edx
  657. //
  658. mov eax, [ebp + ptr_SubTableEntry4]
  659. mov ecx, [eax + SubTableEntry4_arg2]
  660. add ecx, 1
  661. mov edx, [ebp + ptr_SubTableEntry4]
  662. mov dword ptr[edx + SubTableEntry4_arg2], ecx
  663. mov eax, [ebp + ptr_SubTableEntry4]
  664. mov ecx, [eax + SubTableEntry4_arg1]
  665. mov edx, [ebp + ptr_SubTableEntry4]
  666. add ecx, [edx + SubTableEntry4_arg2]
  667. mov dword ptr[ebp + key2], ecx
  668. mov eax, [ebp + local_unk]
  669. mov dword ptr[ebp + lc_unk0], eax
  670. mov ecx, [ebp + lc_unk0]
  671. add ecx, 200h
  672. mov dword ptr[ebp + lc_unk200], ecx
  673. mov edx, [ebp + lc_unk200]
  674. mov dword ptr[ebp + lc_unk0_stop_point], edx
  675. loc_4BDCAA : ; CODE XREF : SubTableEntry3__Final_INIT_Stage + 122.j
  676. mov eax, [ebp + lc_unk0]
  677. cmp eax, [ebp + lc_unk0_stop_point]
  678. jnb loc_4BDD77
  679. lea ecx, [ebp + var_1C]
  680. push ecx
  681. lea edx, [ebp + var_18]
  682. push edx
  683. lea eax, [ebp + local_xor]
  684. push eax
  685. lea ecx, [ebp + lc_unk200]
  686. push ecx
  687. lea edx, [ebp + lc_unk0]
  688. push edx
  689. lea eax, [ebp + local_unk]
  690. push eax
  691. lea ecx, [ebp + key2]
  692. push ecx
  693. lea edx, [ebp + key0]
  694. push edx
  695. mov eax, [ebp + key0]
  696. shl eax, 0Dh
  697. push eax
  698. mov ecx, [ebp + ptr_SubTableEntry3]
  699. call SubTableEntry3__Crazy_XOR_00
  700. lea ecx, [ebp + var_1C]
  701. push ecx
  702. lea edx, [ebp + var_18]
  703. push edx
  704. lea eax, [ebp + local_xor]
  705. push eax
  706. lea ecx, [ebp + lc_unk200]
  707. push ecx
  708. lea edx, [ebp + lc_unk0]
  709. push edx
  710. lea eax, [ebp + local_unk]
  711. push eax
  712. lea ecx, [ebp + key2]
  713. push ecx
  714. lea edx, [ebp + key0]
  715. push edx
  716. mov eax, [ebp + key0]
  717. shr eax, 6
  718. push eax
  719. mov ecx, [ebp + ptr_SubTableEntry3]
  720. call SubTableEntry3__Crazy_XOR_00
  721. lea ecx, [ebp + var_1C]
  722. push ecx
  723. lea edx, [ebp + var_18]
  724. push edx
  725. lea eax, [ebp + local_xor]
  726. push eax
  727. lea ecx, [ebp + lc_unk200]
  728. push ecx
  729. lea edx, [ebp + lc_unk0]
  730. push edx
  731. lea eax, [ebp + local_unk]
  732. push eax
  733. lea ecx, [ebp + key2]
  734. push ecx
  735. lea edx, [ebp + key0]
  736. push edx
  737. mov eax, [ebp + key0]
  738. shl eax, 2
  739. push eax
  740. mov ecx, [ebp + ptr_SubTableEntry3]
  741. call SubTableEntry3__Crazy_XOR_00
  742. lea ecx, [ebp + var_1C]
  743. push ecx
  744. lea edx, [ebp + var_18]
  745. push edx
  746. lea eax, [ebp + local_xor]
  747. push eax
  748. lea ecx, [ebp + lc_unk200]
  749. push ecx
  750. lea edx, [ebp + lc_unk0]
  751. push edx
  752. lea eax, [ebp + local_unk]
  753. push eax
  754. lea ecx, [ebp + key2]
  755. push ecx
  756. lea edx, [ebp + key0]
  757. push edx
  758. mov eax, [ebp + key0]
  759. shr eax, 10h
  760. push eax
  761. mov ecx, [ebp + ptr_SubTableEntry3]
  762. call SubTableEntry3__Crazy_XOR_00
  763. jmp loc_4BDCAA
  764. ; -------------------------------------------------------------------------- -
  765. loc_4BDD77:; CODE XREF : SubTableEntry3__Final_INIT_Stage + 60.j
  766. mov ecx, [ebp + local_unk]
  767. mov dword ptr[ebp + lc_unk200], ecx
  768. loc_4BDD7D : ; CODE XREF : SubTableEntry3__Final_INIT_Stage + 1F5.j
  769. mov edx, [ebp + lc_unk200]
  770. cmp edx, [ebp + lc_unk0_stop_point]
  771. jnb loc_4BDE4A
  772. lea eax, [ebp + var_1C]
  773. push eax
  774. lea ecx, [ebp + var_18]
  775. push ecx
  776. lea edx, [ebp + local_xor]
  777. push edx
  778. lea eax, [ebp + lc_unk200]
  779. push eax
  780. lea ecx, [ebp + lc_unk0]
  781. push ecx
  782. lea edx, [ebp + local_unk]
  783. push edx
  784. lea eax, [ebp + key2]
  785. push eax
  786. lea ecx, [ebp + key0]
  787. push ecx
  788. mov edx, [ebp + key0]
  789. shl edx, 0Dh
  790. push edx
  791. mov ecx, [ebp + ptr_SubTableEntry3]
  792. call SubTableEntry3__Crazy_XOR_00
  793. lea eax, [ebp + var_1C]
  794. push eax
  795. lea ecx, [ebp + var_18]
  796. push ecx
  797. lea edx, [ebp + local_xor]
  798. push edx
  799. lea eax, [ebp + lc_unk200]
  800. push eax
  801. lea ecx, [ebp + lc_unk0]
  802. push ecx
  803. lea edx, [ebp + local_unk]
  804. push edx
  805. lea eax, [ebp + key2]
  806. push eax
  807. lea ecx, [ebp + key0]
  808. push ecx
  809. mov edx, [ebp + key0]
  810. shr edx, 6
  811. push edx
  812. mov ecx, [ebp + ptr_SubTableEntry3]
  813. call SubTableEntry3__Crazy_XOR_00
  814. lea eax, [ebp + var_1C]
  815. push eax
  816. lea ecx, [ebp + var_18]
  817. push ecx
  818. lea edx, [ebp + local_xor]
  819. push edx
  820. lea eax, [ebp + lc_unk200]
  821. push eax
  822. lea ecx, [ebp + lc_unk0]
  823. push ecx
  824. lea edx, [ebp + local_unk]
  825. push edx
  826. lea eax, [ebp + key2]
  827. push eax
  828. lea ecx, [ebp + key0]
  829. push ecx
  830. mov edx, [ebp + key0]
  831. shl edx, 2
  832. push edx
  833. mov ecx, [ebp + ptr_SubTableEntry3]
  834. call SubTableEntry3__Crazy_XOR_00
  835. lea eax, [ebp + var_1C]
  836. push eax
  837. lea ecx, [ebp + var_18]
  838. push ecx
  839. lea edx, [ebp + local_xor]
  840. push edx
  841. lea eax, [ebp + lc_unk200]
  842. push eax
  843. lea ecx, [ebp + lc_unk0]
  844. push ecx
  845. lea edx, [ebp + local_unk]
  846. push edx
  847. lea eax, [ebp + key2]
  848. push eax
  849. lea ecx, [ebp + key0]
  850. push ecx
  851. mov edx, [ebp + key0]
  852. shr edx, 10h
  853. push edx
  854. mov ecx, [ebp + ptr_SubTableEntry3]
  855. call SubTableEntry3__Crazy_XOR_00
  856. jmp loc_4BDD7D
  857. ; -------------------------------------------------------------------------- -
  858. loc_4BDE4A:; CODE XREF : SubTableEntry3__Final_INIT_Stage + 133.j
  859. mov eax, [ebp + ptr_SubTableEntry4]
  860. mov ecx, [ebp + key2]
  861. mov dword ptr[eax + SubTableEntry4_arg1], ecx
  862. mov edx, [ebp + ptr_SubTableEntry4]
  863. mov eax, [ebp + key0]
  864. mov dword ptr[edx + SubTableEntry4_arg0], eax
  865. mov esp, ebp
  866. pop ebp
  867. retn 4
  868. }
  869. }
  870. #undef ptr_SubTableEntry3
  871. #define ptr_SubTableEntry3 -4
  872. #define arg_0 8
  873. #define arg_4 12
  874. #define arg_8 16
  875. #define arg_C 20
  876. #define arg_10 24
  877. #define arg_14 28
  878. #define arg_18 32
  879. #define arg_1C 36
  880. //check
  881. __declspec(naked) void SubTableEntry3__XOR_LOOP1(void)
  882. {
  883. __asm
  884. {
  885. push ebp
  886. mov ebp, esp
  887. push ecx
  888. mov dword ptr[ebp + ptr_SubTableEntry3], ecx
  889. mov eax, [ebp + arg_4]
  890. mov ecx, [eax]
  891. shl ecx, 0Bh
  892. mov edx, [ebp + arg_0]
  893. mov eax, [edx]
  894. xor eax, ecx
  895. mov ecx, [ebp + arg_0]
  896. mov dword ptr[ecx], eax
  897. mov edx, [ebp + arg_C]
  898. mov eax, [edx]
  899. mov ecx, [ebp + arg_0]
  900. add eax, [ecx]
  901. mov edx, [ebp + arg_C]
  902. mov dword ptr[edx], eax
  903. mov eax, [ebp + arg_4]
  904. mov ecx, [eax]
  905. mov edx, [ebp + arg_8]
  906. add ecx, [edx]
  907. mov eax, [ebp + arg_4]
  908. mov dword ptr[eax], ecx
  909. mov ecx, [ebp + arg_8]
  910. mov edx, [ecx]
  911. shr edx, 2
  912. mov eax, [ebp + arg_4]
  913. mov ecx, [eax]
  914. xor ecx, edx
  915. mov edx, [ebp + arg_4]
  916. mov dword ptr[edx], ecx
  917. mov eax, [ebp + arg_10]
  918. mov ecx, [eax]
  919. mov edx, [ebp + arg_4]
  920. add ecx, [edx]
  921. mov eax, [ebp + arg_10]
  922. mov dword ptr[eax], ecx
  923. mov ecx, [ebp + arg_8]
  924. mov edx, [ecx]
  925. mov eax, [ebp + arg_C]
  926. add edx, [eax]
  927. mov ecx, [ebp + arg_8]
  928. mov dword ptr[ecx], edx
  929. mov edx, [ebp + arg_C]
  930. mov eax, [edx]
  931. shl eax, 8
  932. mov ecx, [ebp + arg_8]
  933. mov edx, [ecx]
  934. xor edx, eax
  935. mov eax, [ebp + arg_8]
  936. mov dword ptr[eax], edx
  937. mov ecx, [ebp + arg_14]
  938. mov edx, [ecx]
  939. mov eax, [ebp + arg_8]
  940. add edx, [eax]
  941. mov ecx, [ebp + arg_14]
  942. mov dword ptr[ecx], edx
  943. mov edx, [ebp + arg_C]
  944. mov eax, [edx]
  945. mov ecx, [ebp + arg_10]
  946. add eax, [ecx]
  947. mov edx, [ebp + arg_C]
  948. mov dword ptr[edx], eax
  949. mov eax, [ebp + arg_10]
  950. mov ecx, [eax]
  951. shr ecx, 10h
  952. mov edx, [ebp + arg_C]
  953. mov eax, [edx]
  954. xor eax, ecx
  955. mov ecx, [ebp + arg_C]
  956. mov dword ptr[ecx], eax
  957. mov edx, [ebp + arg_18]
  958. mov eax, [edx]
  959. mov ecx, [ebp + arg_C]
  960. add eax, [ecx]
  961. mov edx, [ebp + arg_18]
  962. mov dword ptr[edx], eax
  963. mov eax, [ebp + arg_10]
  964. mov ecx, [eax]
  965. mov edx, [ebp + arg_14]
  966. add ecx, [edx]
  967. mov eax, [ebp + arg_10]
  968. mov dword ptr[eax], ecx
  969. mov ecx, [ebp + arg_14]
  970. mov edx, [ecx]
  971. shl edx, 0Ah
  972. mov eax, [ebp + arg_10]
  973. mov ecx, [eax]
  974. xor ecx, edx
  975. mov edx, [ebp + arg_10]
  976. mov dword ptr[edx], ecx
  977. mov eax, [ebp + arg_1C]
  978. mov ecx, [eax]
  979. mov edx, [ebp + arg_10]
  980. add ecx, [edx]
  981. mov eax, [ebp + arg_1C]
  982. mov dword ptr[eax], ecx
  983. mov ecx, [ebp + arg_14]
  984. mov edx, [ecx]
  985. mov eax, [ebp + arg_18]
  986. add edx, [eax]
  987. mov ecx, [ebp + arg_14]
  988. mov dword ptr[ecx], edx
  989. mov edx, [ebp + arg_18]
  990. mov eax, [edx]
  991. shr eax, 4
  992. mov ecx, [ebp + arg_14]
  993. mov edx, [ecx]
  994. xor edx, eax
  995. mov eax, [ebp + arg_14]
  996. mov dword ptr[eax], edx
  997. mov ecx, [ebp + arg_0]
  998. mov edx, [ecx]
  999. mov eax, [ebp + arg_14]
  1000. add edx, [eax]
  1001. mov ecx, [ebp + arg_0]
  1002. mov dword ptr[ecx], edx
  1003. mov edx, [ebp + arg_18]
  1004. mov eax, [edx]
  1005. mov ecx, [ebp + arg_1C]
  1006. add eax, [ecx]
  1007. mov edx, [ebp + arg_18]
  1008. mov dword ptr[edx], eax
  1009. mov eax, [ebp + arg_1C]
  1010. mov ecx, [eax]
  1011. shl ecx, 8
  1012. mov edx, [ebp + arg_18]
  1013. mov eax, [edx]
  1014. xor eax, ecx
  1015. mov ecx, [ebp + arg_18]
  1016. mov dword ptr[ecx], eax
  1017. mov edx, [ebp + arg_4]
  1018. mov eax, [edx]
  1019. mov ecx, [ebp + arg_18]
  1020. add eax, [ecx]
  1021. mov edx, [ebp + arg_4]
  1022. mov dword ptr[edx], eax
  1023. mov eax, [ebp + arg_1C]
  1024. mov ecx, [eax]
  1025. mov edx, [ebp + arg_0]
  1026. add ecx, [edx]
  1027. mov eax, [ebp + arg_1C]
  1028. mov dword ptr[eax], ecx
  1029. mov ecx, [ebp + arg_0]
  1030. mov edx, [ecx]
  1031. shr edx, 9
  1032. mov eax, [ebp + arg_1C]
  1033. mov ecx, [eax]
  1034. xor ecx, edx
  1035. mov edx, [ebp + arg_1C]
  1036. mov dword ptr[edx], ecx
  1037. mov eax, [ebp + arg_8]
  1038. mov ecx, [eax]
  1039. mov edx, [ebp + arg_1C]
  1040. add ecx, [edx]
  1041. mov eax, [ebp + arg_8]
  1042. mov dword ptr[eax], ecx
  1043. mov ecx, [ebp + arg_0]
  1044. mov edx, [ecx]
  1045. mov eax, [ebp + arg_4]
  1046. add edx, [eax]
  1047. mov ecx, [ebp + arg_0]
  1048. mov dword ptr[ecx], edx
  1049. mov esp, ebp
  1050. pop ebp
  1051. retn 20h
  1052. }
  1053. }
  1054. #undef ptr_SubTableEntry3
  1055. #undef key0
  1056. #undef key2
  1057. #define ptr_SubTableEntry3 -4
  1058. #define key0 8
  1059. #define key1 12
  1060. #define key2 16
  1061. //check
  1062. __declspec(naked) void SubTableEntry3__Constructor(void)
  1063. {
  1064. __asm
  1065. {
  1066. push ebp
  1067. mov ebp, esp
  1068. push ecx
  1069. mov dword ptr[ebp + ptr_SubTableEntry3], ecx
  1070. mov ecx, [ebp + ptr_SubTableEntry3]
  1071. add ecx, 4
  1072. call SubTableEntry4__Constructor
  1073. mov eax, [ebp + ptr_SubTableEntry3]
  1074. lea ecx, SubTableEntry3__VTBL
  1075. mov dword ptr[eax + SubTableEntry3_ptr_VTBL], ecx
  1076. push 0; Tables start at zero
  1077. mov ecx, [ebp + key2]
  1078. push ecx
  1079. mov edx, [ebp + key1]
  1080. push edx
  1081. mov eax, [ebp + key0]
  1082. push eax
  1083. mov ecx, [ebp + ptr_SubTableEntry3]
  1084. call SubTableEntry3__Fill_Out_Tables
  1085. mov eax, [ebp + ptr_SubTableEntry3]
  1086. mov esp, ebp
  1087. pop ebp
  1088. retn 0Ch
  1089. }
  1090. }
  1091. #undef ptr_SubTableEntry3
  1092. #define result -8
  1093. #define ptr_SubTableEntry3 -4
  1094. //check
  1095. __declspec(naked) void SubTableEntry3__Fetch_XorVal(void)
  1096. {
  1097. __asm
  1098. {
  1099. push ebp
  1100. mov ebp, esp
  1101. sub esp, 8
  1102. mov dword ptr[ebp + ptr_SubTableEntry3], ecx
  1103. mov eax, [ebp + ptr_SubTableEntry3]
  1104. mov ecx, [eax + SubTableEntry3_counter]
  1105. mov edx, [ebp + ptr_SubTableEntry3]
  1106. mov eax, [edx + SubTableEntry3_counter]
  1107. sub eax, 1
  1108. mov edx, [ebp + ptr_SubTableEntry3]
  1109. mov dword ptr[edx + SubTableEntry3_counter], eax
  1110. test ecx, ecx
  1111. jnz short loc_4BD7C2
  1112. mov eax, [ebp + ptr_SubTableEntry3]
  1113. add eax, 4
  1114. push eax
  1115. mov ecx, [ebp + ptr_SubTableEntry3]
  1116. mov edx, [ecx]
  1117. mov ecx, [ebp + ptr_SubTableEntry3]
  1118. call dword ptr[edx + 0Ch]; SubTableEntry3::Final_INIT_Stage(SubTableEntry4 *d)
  1119. mov eax, [ebp + ptr_SubTableEntry3]
  1120. mov dword ptr[eax + SubTableEntry3_counter], 0FFh
  1121. mov ecx, [ebp + ptr_SubTableEntry3]
  1122. mov edx, [ecx + SubTableEntry3_counter]
  1123. mov eax, [ebp + ptr_SubTableEntry3]
  1124. mov ecx, [eax + SubTableEntry3_ptr_xortable]
  1125. mov edx, [ecx + edx * 4]
  1126. mov dword ptr[ebp + result], edx
  1127. jmp short loc_4BD7D4
  1128. ; -------------------------------------------------------------------------- -
  1129. loc_4BD7C2:; CODE XREF : SubTableEntry3__Fetch_XorVal + 20.j
  1130. mov eax, [ebp + ptr_SubTableEntry3]
  1131. mov ecx, [eax + SubTableEntry3_counter]
  1132. mov edx, [ebp + ptr_SubTableEntry3]
  1133. mov eax, [edx + SubTableEntry3_ptr_xortable]
  1134. mov ecx, [eax + ecx * 4]
  1135. mov dword ptr[ebp + result], ecx
  1136. loc_4BD7D4 : ; CODE XREF : SubTableEntry3__Fetch_XorVal + 50.j
  1137. mov eax, [ebp + result]
  1138. mov esp, ebp
  1139. pop ebp
  1140. retn
  1141. }
  1142. }
  1143. void *SubTableEntry3__VTBL[5] = {
  1144. NULL, // SubTableEntry3__DESTRUCTOR,
  1145. SubTableEntry3__Fill_Out_Tables_Part2,
  1146. SubTableEntry3__Fill_Out_Tables,
  1147. SubTableEntry3__Final_INIT_Stage,
  1148. SubTableEntry3__XOR_LOOP1
  1149. };
  1150. #undef ptr_SubTableEntry3
  1151. #define ptr_SubTableEntry3_2 -12
  1152. #define ptr_SubTableEntry2 -8
  1153. #define ptr_SubTableEntry3 -4
  1154. #define key 8
  1155. //check
  1156. __declspec(naked) void SubTableEntry2__Constructor(void)
  1157. {
  1158. __asm
  1159. {
  1160. push ebp
  1161. mov ebp, esp
  1162. sub esp, 0Ch
  1163. mov dword ptr[ebp + ptr_SubTableEntry2], ecx
  1164. mov eax, [ebp + ptr_SubTableEntry2]
  1165. mov dword ptr[eax + SubTableEntry2_seqnum], 1
  1166. mov ecx, [ebp + ptr_SubTableEntry2]
  1167. mov edx, [ebp + key]
  1168. mov dword ptr[ecx + SubTableEntry2_encryption_key], edx
  1169. mov eax, [ebp + ptr_SubTableEntry2]
  1170. mov dword ptr[eax + SubTableEntry2_ptr_SubTableEntry3], 0
  1171. push 1Ch
  1172. call malloc
  1173. add esp, 4
  1174. mov dword ptr[ebp + ptr_SubTableEntry3], eax
  1175. cmp dword ptr[ebp + ptr_SubTableEntry3], 0
  1176. jz short loc_4BD5EA
  1177. mov ecx, [ebp + ptr_SubTableEntry2]
  1178. mov edx, [ecx + SubTableEntry2_encryption_key]
  1179. push edx
  1180. mov eax, [ebp + ptr_SubTableEntry2]
  1181. mov ecx, [eax + SubTableEntry2_encryption_key]
  1182. push ecx
  1183. mov edx, [ebp + ptr_SubTableEntry2]
  1184. mov eax, [edx + SubTableEntry2_encryption_key]
  1185. push eax
  1186. mov ecx, [ebp + ptr_SubTableEntry3]
  1187. call SubTableEntry3__Constructor; SubTableEntry3::Constructor(int key0, int key1, int key2)
  1188. mov dword ptr[ebp + ptr_SubTableEntry3_2], eax
  1189. jmp short loc_4BD5F1
  1190. ; -------------------------------------------------------------------------- -
  1191. loc_4BD5EA:; CODE XREF : SubTableEntry2__Constructor + 36.j
  1192. mov dword ptr[ebp + ptr_SubTableEntry3_2], 0
  1193. loc_4BD5F1 : ; CODE XREF : SubTableEntry2__Constructor + 58.j
  1194. mov ecx, [ebp + ptr_SubTableEntry2]
  1195. mov edx, [ebp + ptr_SubTableEntry3_2]
  1196. mov dword ptr[ecx + SubTableEntry2_ptr_SubTableEntry3], edx
  1197. mov eax, [ebp + ptr_SubTableEntry2]
  1198. mov esp, ebp
  1199. pop ebp
  1200. retn 4
  1201. }
  1202. }
  1203. #undef result
  1204. #undef ptr_SubTableEntry2
  1205. #define ptr_SubTableEntry2 -8
  1206. #define result -4
  1207. //check
  1208. __declspec(naked) void SubTableEntry2__Get_xorval_from_table3(void)
  1209. {
  1210. __asm
  1211. {
  1212. push ebp
  1213. mov ebp, esp
  1214. sub esp, 8
  1215. mov dword ptr[ebp + ptr_SubTableEntry2], ecx
  1216. mov eax, [ebp + ptr_SubTableEntry2]
  1217. mov ecx, [eax + SubTableEntry2_ptr_SubTableEntry3]
  1218. call SubTableEntry3__Fetch_XorVal
  1219. mov dword ptr[ebp + result], eax
  1220. mov eax, [ebp + result]
  1221. mov esp, ebp
  1222. pop ebp
  1223. retn
  1224. }
  1225. }
  1226. #undef ptr_SubTableEntry2
  1227. #define ptr_SubTableEntry2 -4
  1228. //check
  1229. __declspec(naked) void SubTableEntry2__IncrementSeqnum_and_get_xorval(void)
  1230. {
  1231. __asm
  1232. {
  1233. push ebp
  1234. mov ebp, esp
  1235. push ecx
  1236. mov dword ptr[ebp + ptr_SubTableEntry2], ecx
  1237. mov eax, [ebp + ptr_SubTableEntry2]
  1238. mov ecx, [eax + SubTableEntry2_seqnum]
  1239. add ecx, 1
  1240. mov edx, [ebp + ptr_SubTableEntry2]
  1241. mov dword ptr[edx + SubTableEntry2_seqnum], ecx
  1242. mov ecx, [ebp + ptr_SubTableEntry2]
  1243. call SubTableEntry2__Get_xorval_from_table3; DWORD SubTableEntry2::Get_CRC_Val_from_table(void)
  1244. mov esp, ebp
  1245. pop ebp
  1246. retn
  1247. }
  1248. }
  1249. DWORD GetSendXORVal(DWORD* lpdwSendCRC)
  1250. {
  1251. //DWORD *lpdwSend = lpdwSendCRC, dwResult;
  1252. DWORD dwResult;
  1253. __asm
  1254. {
  1255. push eax
  1256. push ebx
  1257. push ecx
  1258. push edx
  1259. push esi
  1260. push edi
  1261. mov ecx, [lpdwSendCRC]
  1262. call SubTableEntry2__IncrementSeqnum_and_get_xorval
  1263. mov[dwResult], eax
  1264. pop edi
  1265. pop esi
  1266. pop edx
  1267. pop ecx
  1268. pop ebx
  1269. pop eax
  1270. }
  1271. return dwResult;
  1272. }
  1273. //check
  1274. void GenerateCRCs(DWORD dwSendSeed, DWORD dwRecvSeed, DWORD* lpdwSendSeed, DWORD* lpdwRecvSeed)
  1275. {
  1276. //ULONG *send=lpdwSEND_CRC;
  1277. //ULONG *recv=lpdwRECV_CRC;
  1278. __asm
  1279. {
  1280. push eax
  1281. push ebx
  1282. push ecx
  1283. push edx
  1284. push esi
  1285. push edi
  1286. push dwSendSeed
  1287. mov ecx, [lpdwSendSeed]
  1288. call SubTableEntry2__Constructor
  1289. push dwRecvSeed
  1290. mov ecx, [lpdwRecvSeed]
  1291. call SubTableEntry2__Constructor
  1292. pop edi
  1293. pop esi
  1294. pop edx
  1295. pop ecx
  1296. pop ebx
  1297. pop eax
  1298. }
  1299. return;
  1300. }