TA的每日心情 | 衰 2016-3-10 10:33 |
---|
签到天数: 14 天 [LV.3]偶尔看看II
管理员
- 积分
- 804
|
0040D301 43 INC EBX
0040D302 49 DEC ECX
0040D303 ^ EB ED JMP SHORT chap703.0040D2F2 往回跳
0040D305 291E SUB DWORD PTR DS:[ESI],EBX F4到这里
0040D307 83C3 05 ADD EBX,5
0040D30A 83C6 04 ADD ESI,4
0040D30D 83E9 05 SUB ECX,5
0040D310 ^ EB E0 JMP SHORT chap703.0040D2F2 又往回跳
0040D312 5B POP EBX F4到这里
0040D313 5E POP ESI
0040D314 59 POP ECX
........................................................
0040D339 68 00800000 PUSH 8000
0040D33E 6A 00 PUSH 0
0040D340 50 PUSH EAX
0040D341 FF95 BD504400 CALL DWORD PTR SS:[EBP+4450BD]
到这里我们看到信息框中写有 VirtualFree
0040D341 FF95 BD504400 CALL DWORD PTR SS:[EBP+4450BD] ; kernel32.VirtualFree
0040D347 83C6 08 ADD ESI,8
0040D34A 833E 00 CMP DWORD PTR DS:[ESI],0
0040D34D ^ 0F85 46FFFFFF JNZ chap703.0040D299 又往回跳
0040D353 8B9D DF4A4400 MOV EBX,DWORD PTR SS:[EBP+444ADF] F4到这里
0040D359 0BDB OR EBX,EBX
0040D35B 74 08 JE SHORT chap703.0040D365
0040D35D 8B03 MOV EAX,DWORD PTR DS:[EBX]
..................................................
0040D3A9 74 0C JE SHORT chap703.0040D3B7
0040D3AB 83FB 02 CMP EBX,2
0040D3AE 74 16 JE SHORT chap703.0040D3C6
0040D3B0 83FB 03 CMP EBX,3
0040D3B3 74 20 JE SHORT chap703.0040D3D5
0040D3B5 EB 2C JMP SHORT chap703.0040D3E3
0040D3B7 66:8B1E MOV BX,WORD PTR DS:[ESI]
0040D3BA 81E3 FF0F0000 AND EBX,0FFF
0040D3C0 66:01041F ADD WORD PTR DS:[EDI+EBX],AX
0040D3C4 EB 1D JMP SHORT chap703.0040D3E3
0040D3C6 66:8B1E MOV BX,WORD PTR DS:[ESI]
0040D3C9 81E3 FF0F0000 AND EBX,0FFF
0040D3CF 66:01141F ADD WORD PTR DS:[EDI+EBX],DX
0040D3D3 EB 0E JMP SHORT chap703.0040D3E3
0040D3D5 66:8B1E MOV BX,WORD PTR DS:[ESI]
0040D3D8 81E3 FF0F0000 AND EBX,0FFF
0040D3DE 01141F ADD DWORD PTR DS:[EDI+EBX],EDX
0040D3E1 EB 00 JMP SHORT chap703.0040D3E3
0040D3E3 66:830E FF OR WORD PTR DS:[ESI],0FFFF
0040D3E7 83C6 02 ADD ESI,2
0040D3EA ^ E2 B4 LOOPD SHORT chap703.0040D3A0 |
|