本菜鸟有一端汇编代码看不懂,望兄弟指点
00497703 |. 55 push ebp
00497704 |. 68 4A784900 push NeonEdit.0049784A
00497709 |. 64:FF30 push dword ptr fs:[eax]
0049770C |. 64:8920 mov dword ptr fs:[eax],esp
0049770F |. 8D95 F0FEFFFF lea edx,dword ptr ss:[ebp-110]
00497715 |. 8B83 FC020000 mov eax,dword ptr ds:[ebx+2FC]
0049771B |. E8 C4CFFBFF call NeonEdit.004546E4
00497720 |. 8B85 F0FEFFFF mov eax,dword ptr ss:[ebp-110]
00497726 |. 8D55 FC lea edx,dword ptr ss:[ebp-4]
00497729 |. E8 5615F7FF call NeonEdit.00408C84
0049772E |. 8D95 ECFEFFFF lea edx,dword ptr ss:[ebp-114]
00497734 |. 8B83 08030000 mov eax,dword ptr ds:[ebx+308]
0049773A |. E8 A5CFFBFF call NeonEdit.004546E4
0049773F |. 8B85 ECFEFFFF mov eax,dword ptr ss:[ebp-114]
00497745 |. 8D55 F8 lea edx,dword ptr ss:[ebp-8]
00497748 |. E8 3715F7FF call NeonEdit.00408C84
0049774D |. 8B45 F8 mov eax,dword ptr ss:[ebp-8]
00497750 |. E8 7BD7F6FF call NeonEdit.00404ED0
00497755 |. 83F8 0C cmp eax,0C
00497758 |. 7D 1E jge short NeonEdit.00497778
0049775A |. 6A 30 push 30
0049775C |. 68 58784900 push NeonEdit.00497858
00497761 |. 68 60784900 push NeonEdit.00497860
00497766 |. 8BC3 mov eax,ebx
00497768 |. E8 8B38FCFF call NeonEdit.0045AFF8
0049776D |. 50 push eax ; |hOwner
0049776E |. E8 19FEF6FF call <jmp.&user32.MessageBoxA> ; \MessageBoxA
00497773 |. E9 9C000000 jmp NeonEdit.00497814
00497778 |> 68 04010000 push 104 ; /BufSize = 104 (260.)
0049777D |. 8D85 F4FEFFFF lea eax,dword ptr ss:[ebp-10C] ; |
00497783 |. 50 push eax ; |Buffer
00497784 |. E8 5BF6F6FF call <jmp.&kernel32.GetSystemDirec>; \GetSystemDirectoryA
00497789 |. 8D85 E8FEFFFF lea eax,dword ptr ss:[ebp-118]
0049778F |. 8D95 F4FEFFFF lea edx,dword ptr ss:[ebp-10C]
00497795 |. B9 00010000 mov ecx,100
0049779A |. E8 E1D6F6FF call NeonEdit.00404E80
0049779F |. 8B95 E8FEFFFF mov edx,dword ptr ss:[ebp-118]
004977A5 |. 8D45 F4 lea eax,dword ptr ss:[ebp-C]
004977A8 |. B9 84784900 mov ecx,NeonEdit.00497884 ; ASCII "\dcomm.crl"
004977AD |. E8 6AD7F6FF call NeonEdit.00404F1C
004977B2 |. A1 0C615300 mov eax,dword ptr ds:[53610C]
004977B7 |. 8B00 mov eax,dword ptr ds:[eax]
004977B9 |. 8B4D F8 mov ecx,dword ptr ss:[ebp-8]
004977BC |. 8B55 FC mov edx,dword ptr ss:[ebp-4]
004977BF |. E8 389D0800 call NeonEdit.005214FC
004977C4 |. 84C0 test al,al
004977C6 |. 74 26 je short NeonEdit.004977EE
004977C8 |. 8B45 F8 mov eax,dword ptr ss:[ebp-8]
004977CB |. 50 push eax
004977CC |. A1 0C615300 mov eax,dword ptr ds:[53610C]
004977D1 |. 8B00 mov eax,dword ptr ds:[eax]
004977D3 |. 8B4D FC mov ecx,dword ptr ss:[ebp-4]
004977D6 |. 8B55 F4 mov edx,dword ptr ss:[ebp-C]
004977D9 |. E8 269E0800 call NeonEdit.00521604
004977DE |. C683 18030000 01 mov byte ptr ds:[ebx+318],1
004977E5 |. 8BC3 mov eax,ebx
004977E7 |. E8 C8A0FDFF call NeonEdit.004718B4
004977EC |. EB 26 jmp short NeonEdit.00497814
004977EE |> 33D2 xor edx,edx
004977F0 |. 8B83 08030000 mov eax,dword ptr ds:[ebx+308]
004977F6 |. E8 19CFFBFF call NeonEdit.00454714
004977FB |. 6A 30 push 30
004977FD |. 68 58784900 push NeonEdit.00497858
00497802 |. 68 90784900 push NeonEdit.00497890
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课