oep:
004BFD6D > $ E8 150C0100 call 004D0987
004BFD72 .^ E9 16FEFFFF jmp 004BFB8D
call:
004D0987 /$ 55 push ebp
004D0988 |. 8BEC mov ebp, esp
004D098A |. 83EC 10 sub esp, 10
004D098D |. A1 E0365300 mov eax, dword ptr [5336E0]
004D0992 |. 8365 F8 00 and dword ptr [ebp-8], 0
004D0996 |. 8365 FC 00 and dword ptr [ebp-4], 0
004D099A |. 53 push ebx
004D099B |. 57 push edi
004D099C |. BF 4EE640BB mov edi, BB40E64E
004D09A1 |. 3BC7 cmp eax, edi
004D09A3 |. BB 0000FFFF mov ebx, FFFF0000
004D09A8 |. 74 0D je short 004D09B7
004D09AA |. 85C3 test ebx, eax
004D09AC |. 74 09 je short 004D09B7
004D09AE |. F7D0 not eax
004D09B0 |. A3 E4365300 mov dword ptr [5336E4], eax
004D09B5 |. EB 60 jmp short 004D0A17
004D09B7 |> 56 push esi
004D09B8 |. 8D45 F8 lea eax, dword ptr [ebp-8]
004D09BB |. 50 push eax ; /pFileTime
004D09BC |. FF15 FCC24E00 call dword ptr [<&KERNEL32.GetSystemT>; \GetSystemTimeAsFileTime
004D09C2 |. 8B75 FC mov esi, dword ptr [ebp-4]
004D09C5 |. 3375 F8 xor esi, dword ptr [ebp-8]
004D09C8 |. FF15 ACC34E00 call dword ptr [<&KERNEL32.GetCurrent>; [GetCurrentProcessId
004D09CE |. 33F0 xor esi, eax
004D09D0 |. FF15 60C24E00 call dword ptr [<&KERNEL32.GetCurrent>; [GetCurrentThreadId
004D09D6 |. 33F0 xor esi, eax
004D09D8 |. FF15 68C24E00 call dword ptr [<&KERNEL32.GetTickCou>; [GetTickCount
004D09DE |. 33F0 xor esi, eax
004D09E0 |. 8D45 F0 lea eax, dword ptr [ebp-10]
004D09E3 |. 50 push eax ; /pPerformanceCount
004D09E4 |. FF15 C0C14E00 call dword ptr [<&KERNEL32.QueryPerfo>; \QueryPerformanceCounter
004D09EA |. 8B45 F4 mov eax, dword ptr [ebp-C]
004D09ED |. 3345 F0 xor eax, dword ptr [ebp-10]
004D09F0 |. 33F0 xor esi, eax
004D09F2 |. 3BF7 cmp esi, edi
004D09F4 |. 75 07 jnz short 004D09FD
004D09F6 |. BE 4FE640BB mov esi, BB40E64F
004D09FB |. EB 0B jmp short 004D0A08
004D09FD |> 85F3 test ebx, esi
004D09FF |. 75 07 jnz short 004D0A08
004D0A01 |. 8BC6 mov eax, esi
004D0A03 |. C1E0 10 shl eax, 10
004D0A06 |. 0BF0 or esi, eax
004D0A08 |> 8935 E0365300 mov dword ptr [5336E0], esi
004D0A0E |. F7D6 not esi
004D0A10 |. 8935 E4365300 mov dword ptr [5336E4], esi
004D0A16 |. 5E pop esi
004D0A17 |> 5F pop edi
004D0A18 |. 5B pop ebx
004D0A19 |. C9 leave
004D0A1A \. C3 retn
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课