003E00C0 58 pop eax //返回到这里
003E00C1 EB 03 jmp short 003E00C6
003E00C3 33C0 xor eax,eax
003E00C5 48 dec eax
003E00C6 5D pop ebp
003E00C7 5B pop ebx
003E00C8 5F pop edi
003E00C9 5E pop esi
003E00CA C2 0C00 retn 0C //F4过来,F8返回
003E0D2E 8BC8 mov ecx,eax //返回到这里,继续向下
003E0D30 40 inc eax
003E0D31 74 74 je short 003E0DA7
。。。。。。。。。。。。
003E0DA0 5E pop esi
003E0DA1 5F pop edi
003E0DA2 5B pop ebx
003E0DA3 C9 leave
003E0DA4 C2 0400 retn 4 //F4这里,F8返回
003E086F 85C0 test eax,eax //返回这里,继续向下
003E0871 0F85 A6000000 jnz 003E091D
003E0877 56 push esi
003E0878 E8 31030000 call 003E0BAE
003E087D 56 push esi
003E087E E8 50020000 call 003E0AD3
。。。。。。。
003E096F 5D pop ebp
003E0970 5E pop esi
003E0971 5F pop edi
003E0972 5B pop ebx
003E0973 C3 retn //F4过来,F8返回
0101AB6D 8985 5B120010 mov dword ptr ss:[ebp+1000125B],eax ; notepad.0100739D //返回到这里
0101AB73 8BF0 mov esi,eax
0101AB75 59 pop ecx
0101AB76 5A pop edx
0101AB77 EB 0C jmp short notepad.0101AB85
0101AB79 03CA add ecx,edx
0101AB7B 68 00800000 push 8000
0101AB80 6A 00 push 0
0101AB82 57 push edi
0101AB83 FF11 call dword ptr ds:[ecx]
0101AB85 8BC6 mov eax,esi
0101AB87 5A pop edx
0101AB88 5E pop esi
0101AB89 5F pop edi
0101AB8A 59 pop ecx
0101AB8B 5B pop ebx
0101AB8C 5D pop ebp
0101AB8D FFE0 jmp eax //飞向OEP EAX=0100739D