强,不早说,天蓝蓝了
.text:0001104E mov ecx, [ebp+var_4]
.text:00011051 add ecx, 1
.text:00011054 mov [ebp+var_4], ecx
.text:00011057
.text:00011057 loc_11057: ; CODE XREF: sub_11040+Cj
.text:00011057 mov edx, ds:PsTerminateSystemThread
.text:0001105D add edx, 1000h
.text:00011063 cmp [ebp+var_4], edx
.text:00011066 jnb short loc_1109B
.text:00011068 mov eax, [ebp+var_4]
.text:0001106B movzx ecx, byte ptr [eax]
.text:0001106E cmp ecx, 0E8h
.text:00011074 jnz short loc_11099
.text:00011076 mov edx, [ebp+var_4]
.text:00011079 movzx eax, word ptr [edx+5]
.text:0001107D cmp eax, 0C25Dh
.text:00011082 jnz short loc_11099
.text:00011084 mov ecx, [ebp+var_4]
.text:00011087 mov edx, [ecx+1]
.text:0001108A mov eax, [ebp+var_4]
.text:0001108D lea ecx, [eax+edx+5]
.text:00011091 mov dword_1404C, ecx
.text:00011097 jmp short loc_1109B
.text:00011099 ; ---------------------------------------------------------------------------
.text:00011099
.text:00011099 loc_11099: ; CODE XREF: sub_11040+34j
.text:00011099 ; sub_11040+42j
.text:00011099 jmp short loc_1104E
一个小循环
[ 本帖最后由 黄金马甲出租 于 2007-11-26 11:07 编辑 ] |