sp;891F mov dword ptr ds:[edi],ebx
Modified: 9090 NOP ★
00909129 83C3 0A add ebx,0A
0090912C E9 49FFFFFF jmp 0090907A
*/
//IsDebuggerPresent————————————————————————————————
gpa "IsDebuggerPresent", "KERNEL32.dll"
cmp $RESULT, 0
je NoFind
find $RESULT,#C3#
cmp $RESULT, 0
je NoFind
mov IsDebuggerPresent,$RESULT
eob IsDebuggerPresent
bp IsDebuggerPresent
//SpecialImportingFunction————————————————————————————————
find FixCode1,#C214008B#
cmp $RESULT, 0
je NoFind
mov SpecialFiXed,$RESULT
log SpecialFiXed
find FixCode1,#FF501850#
cmp $RESULT, 0
je NoFind
mov EAX=3,$RESULT
log EAX=3
find EAX=3,#FF5018EB1C#
cmp $RESULT, 0
je NoFind
mov EAX=0,$RESULT
log EAX=0
find EAX=3,#FF5018EB0D#
cmp $RESULT, 0
je NoFind
mov EAX=1,$RESULT
log EAX=1
find EAX=3,#FF5018C603#
cmp $RESULT, 0
je NoFind
mov EAX=2,$RESULT
log EAX=2
EAX:
eob SpecialImportingFunction
bp SpecialFiXed
bp EAX=0
bp EAX=1
bp EAX=2
bp EAX=3
esto
GoOn1:
log eip
esto
/*
009090FC 8B46 04 mov eax,dword ptr ds:[esi+4]
009090FF 83F8 00 cmp eax,0
00909102 74 45 je short 00909149
00909104 83F8 01 cmp eax,1
00909107 74 4F je short 00909158
00909109 83F8 02 cmp eax,2
0090910C 74 59 je short 00909167
0090910E 83F8 03 cmp eax,3
00909111 74 12 je short 00909125
00909113 83F8 04 cmp eax,4
00909116 75 CA jnz short 009090E2
00909118 8B45 14 mov eax,dword ptr ss:[ebp+14]
0090911B 8B90 E8000000 mov edx,dword ptr ds:[eax+E8]
00909121 8917 mov dword ptr ds:[edi],edx
00909123 EB BD jmp short 009090E2
00909125 8B45 14 mov eax,dword ptr ss:[ebp+14]
00909128 68 C5B1662D push 2D66B1C5
0090912D 6A 00 push 0
0090912F FF50 18 &nb 上一页 [1] [2] [3] [4] [5] [6] [7] [8] 下一页
|