ropshell> use 22f450c23d8abdfa6bed991ad1c34b1c (download)
name         : VsaVb7rt.dll (i386/RAW)
base address : 0x0
total gadgets: 29415
ropshell> suggest "load mem"
> 0x00035b31 : mov eax, [esi]; pop esi; ret
> 0x0005ec46 : mov eax, [ecx + 0x10]; ret
> 0x0005882f : mov eax, [edx + 0x13c]; pop ebp; ret 8
> 0x000bfa87 : mov eax, [esi + 0x1c]; pop esi; ret
> 0x0001f7ac : mov eax, [ebp + 0xc]; pop ebp; ret 8
> 0x000aa005 : mov edx, [eax + 0x48]; call edx; ret
> 0x000a8131 : mov edx, [ecx + 0xc]; call edx; ret
> 0x00046586 : mov esi, [ecx + 0x27]; pop esi; ret
> 0x00055570 : mov eax, [ecx]; call eax
> 0x00067a22 : mov eax, [edx]; call eax
> 0x00059cf9 : mov ecx, [edi]; call ecx
> 0x000c2e73 : mov edx, [ecx]; call edx
> 0x0011307d : mov ecx, [eax]; push eax; call [ecx + 0x10]; ret 0xc
> 0x000541c7 : mov edx, [eax]; push 1; call edx
> 0x00065096 : mov eax, [ebx + 4]; call eax
> 0x000c657a : mov eax, [edi + 0x14]; call eax
> 0x0005797d : mov ecx, [eax + 4]; call ecx
> 0x000c644a : mov ecx, [edx + 0x10]; call ecx
> 0x00059e0a : mov ecx, [esi + 0xc]; call ecx
> 0x000c693c : mov ecx, [edi + 0x10]; call ecx
> 0x000f270c : mov edx, [edi + 0xa0]; call edx
> 0x00063ec1 : mov eax, [ebx]; add ecx, edi; call eax
> 0x00063de6 : mov eax, [edi]; add ecx, esi; call eax
> 0x00036d35 : mov edx, [ebx]; call [edx + 0x1c]
> 0x000c47ea : mov edx, [edi]; push eax; push ecx; call edx
> 0x0007f396 : mov ecx, [ebx + 0x90]; push edx; call ecx
> 0x000de286 : mov ecx, [ebp + 0x30]; mov [ecx], 0; pop ebp; ret 0x2c
> 0x00064705 : mov edx, [ebx + 4]; push eax; call edx
> 0x00055985 : mov edx, [esi + 8]; push edx; call ebx
> 0x000660da : mov edx, [ebp + 0x10]; push edx; call eax
> 0x00082321 : mov ebp, [ebx + 0x5e5ffffe]; pop ebx; mov esp, ebp; pop ebp; ret
> 0x0003ee3d : mov ecx, [ebx]; push ebx; call [ecx + 0x24]
> 0x00022076 : mov ecx, [esi]; mov [eax], ecx; mov [esi], eax; ret
> 0x000f69de : mov edi, [eax + 0x14]; mov eax, edi; pop edi; pop esi; pop ebp; ret 8
> 0x000aa1b7 : mov edx, [esi]; mov ecx, esi; mov eax, [edx + 0x48]; call eax; ret
> 0x00044e2a : mov esi, [edi + 0x10]; push eax; call [ecx + 0x20]
> 0x000d5212 : mov esi, [ebp + 8]; push esi; call [ebp + 0x18]
> 0x0005030a : mov esi, [ecx]; push edx; push eax; push ecx; call [esi + 0x14]
> 0x0004c05d : mov esi, [edx]; push ecx; push edi; push edx; call [esi + 0x68]
> 0x0001e11d : mov edi, [ecx]; push 2; push edx; push eax; call [edi + 8]
> 0x000502e6 : mov edi, [edx]; push esi; push eax; push edx; call [edi + 0x10]
> 0x00043502 : mov ebx, [eax]; mov eax, [esi]; push esi; call [eax + 0x10]
> 0x0002a7d6 : mov esi, [eax]; add esi, [ebp + 8]; call [eax + 4]
> 0x00041fd7 : mov edi, [eax]; mov eax, [esi]; push esi; call [eax + 0x20]
> 0x00048356 : mov ebx, [eax + 4]; push eax; mov ecx, edi; call [edx + 0x44]
> 0x000af127 : mov ebx, [ebp + 0xc]; lea eax, [esi + 4]; push ebx; push eax; call edi
> 0x0004448f : mov edi, [ebp + 0xc]; mov eax, [edi]; push edi; call [eax + 0x20]
> 0x0002be64 : mov esi, [eax + 0x14]; mov eax, [esi]; mov ecx, esi; call [eax + 0x48]
> 0x0004ee72 : mov ecx, [edx]; lea esi, [ebp + 0xc]; push esi; push eax; push edx; call [ecx + 0x38]
> 0x000f27e2 : mov ebx, [edi + 4]; push ebx; push ecx; push ecx; push eax; mov eax, [edx + 0x40]; call eax
> 0x00112f7a : mov edi, [ecx + 4]; mov [eax + 4], edi; pop edi; mov [ecx + 4], esi; mov [ecx], edx; pop esi; ret 8
> 0x000b0be2 : mov ebx, [ecx + edi]; add ecx, edi; push edx; mov edx, [eax]; mov eax, [ebx + 0x14]; push edx; call eax