- UID
- 20757
注册时间2006-8-18
阅读权限20
最后登录1970-1-1
以武会友
该用户从未签到
|
楼主 |
发表于 2006-9-16 22:57:40
|
显示全部楼层
还是自己解决了
00E3F8D0 55 push ebp ; 断在这里
00E3F8D1 8BEC mov ebp,esp
00E3F8D3 83C4 F8 add esp,-8
00E3F8D6 53 push ebx
00E3F8D7 56 push esi
00E3F8D8 57 push edi
00E3F8D9 8B5D 08 mov ebx,dword ptr ss:[ebp+8]
00E3F8DC EB 01 jmp short dumped_A.00E3F8DF ; 这里跳到00E3F8DF!
......
由00E3F8DC跳来,到这里.
00E3F8DF 8B45 18 mov eax,dword ptr ss:[ebp+18] ; 来到这里
00E3F8E2 83E8 08 sub eax,8
00E3F8E5 8B00 mov eax,dword ptr ds:[eax]
00E3F8E7 50 push eax
00E3F8E8 8A8B 96000000 mov cl,byte ptr ds:[ebx+96]
00E3F8EE 8B55 14 mov edx,dword ptr ss:[ebp+14]
00E3F8F1 8BC3 mov eax,ebx
00E3F8F3 E8 B4FFFFFF call dumped_A.00E3F8AC
00E3F8F8 8B45 18 mov eax,dword ptr ss:[ebp+18]
00E3F8FB 50 push eax
00E3F8FC B1 04 mov cl,4
00E3F8FE 8B55 14 mov edx,dword ptr ss:[ebp+14]
00E3F901 8BC3 mov eax,ebx
00E3F903 E8 A4FFFFFF call dumped_A.00E3F8AC
00E3F908 EB 01 jmp short dumped_A.00E3F90B
00E3F90A 698B 73308B7B 1>imul ecx,dword ptr ds:[ebx+7B8B3073],AA4>
00E3F914 E5 00 in eax,0
00E3F916 8B40 34 mov eax,dword ptr ds:[eax+34] ; 从这里开始修改。特征码
00E3F919 FFD0 call eax
00E3F91B 2945 0C sub dword ptr ss:[ebp+C],eax
00E3F91E 8B45 0C mov eax,dword ptr ss:[ebp+C]
00E3F921 2B43 18 sub eax,dword ptr ds:[ebx+18]
00E3F924 2B43 68 sub eax,dword ptr ds:[ebx+68]
00E3F927 8945 FC mov dword ptr ss:[ebp-4],eax
00E3F92A 8D43 24 lea eax,dword ptr ds:[ebx+24]
00E3F92D 8945 F8 mov dword ptr ss:[ebp-8],eax
00E3F930 85FF test edi,edi
00E3F932 76 63 jbe short dumped_A.00E3F997
00E3F934 EB 01 jmp short dumped_A.00E3F937
00E3F936 C7 ??? ; 未知命令
00E3F937 8B45 F8 mov eax,dword ptr ss:[ebp-8]
00E3F93A 0FB600 movzx eax,byte ptr ds:[eax]
00E3F93D 8B5483 40 mov edx,dword ptr ds:[ebx+eax*4+40]
00E3F941 8BC6 mov eax,esi
00E3F943 FFD2 call edx
00E3F945 3B45 FC cmp eax,dword ptr ss:[ebp-4]
00E3F948 75 45 jnz short dumped_A.00E3F98F
00E3F94A EB 01 jmp short dumped_A.00E3F94D
00E3F94C 9A 807B7400 742>call far 2274:00747B80
00E3F953 EB 01 jmp short dumped_A.00E3F956
00E3F955 9A 8B451050 8B4>call far 458B:5010458B
00E3F95C 14 50 adc al,50
00E3F95E E8 69FCFFFF call dumped_A.00E3F5CC
00E3F963 50 push eax
00E3F964 8BCE mov ecx,esi
00E3F966 8B55 18 mov edx,dword ptr ss:[ebp+18]
00E3F969 8BC3 mov eax,ebx
00E3F96B E8 70F8FFFF call dumped_A.00E3F1E0
00E3F970 EB 1D jmp short dumped_A.00E3F98F
00E3F972 EB 01 jmp short dumped_A.00E3F975
00E3F974 - E9 8B451050 jmp 50F43F04
00E3F979 8B45 14 mov eax,dword ptr ss:[ebp+14]
00E3F97C 50 push eax
00E3F97D E8 4AFCFFFF call dumped_A.00E3F5CC
00E3F982 50 push eax
00E3F983 8BCE mov ecx,esi
00E3F985 8B55 18 mov edx,dword ptr ss:[ebp+18]
00E3F988 8BC3 mov eax,ebx
00E3F98A E8 D5F9FFFF call dumped_A.00E3F364
00E3F98F 4F dec edi
00E3F990 0373 6C add esi,dword ptr ds:[ebx+6C]
00E3F993 85FF test edi,edi
00E3F995 ^ 77 A0 ja short dumped_A.00E3F937
00E3F997 68 B4F9E300 push dumped_A.00E3F9B4 ; ASCII "111"
00E3F99C E8 9357FFFF call dumped_A.00E35134 |
|