暴力搜索:
//xp
INIT:005E36C3 89 75 B4 mov [ebp+var_4C], esi
INIT:005E36C6 66 C7 45 9C 4C 00 mov word ptr [ebp+var_64], 4Ch
INIT:005E36CC C6 45 B8 01 mov [ebp+var_48], 1
INIT:005E36D0 89 5D A0 mov [ebp+var_60], ebx
INIT:005E36D3 89 5D BC mov [ebp+var_44], ebx
INIT:005E36D6 C7 45 D4 EF 85 4A 00 mov [ebp+var_2C], offset xHalLocateHiberRanges(x)
INIT:005E36DD C7 45 D0 71 AD 58 00 mov [ebp+var_30], offset DbgkpCloseObject(x,x,x,x,x)
INIT:005E36E4 8D 75 E8 lea esi, [ebp+var_18]
INIT:005E36E7 8D 7D A4 lea edi, [ebp+var_5C]
INIT:005E36EA A5 movsd
INIT:005E36EB A5 movsd
INIT:005E36EC 68 3C 95 48 00 push offset _DbgkDebugObjectType ; int
//win 7
INIT:00792903 6A 50 push 50h
INIT:00792905 58 pop eax
INIT:00792906 89 75 B4 mov [ebp+var_4C], esi
INIT:00792909 66 89 45 98 mov word ptr [ebp+var_68], ax
INIT:0079290D 89 5D A0 mov [ebp+var_60], ebx
INIT:00792910 89 5D BC mov [ebp+var_44], ebx
INIT:00792913 C7 45 D4 61 10 66 00 mov [ebp+var_2C], offset _xHalLocateHiberRanges@4 ; xHalLocateHiberRanges(x)
INIT:0079291A C7 45 D0 23 30 6A 00 mov [ebp+var_30], offset _DbgkpCloseObject@16 ; DbgkpCloseObject(x,x,x,x)
INIT:00792921 8D 75 E8 lea esi, [ebp+var_18]
INIT:00792924 8D 7D A4 lea edi, [ebp+var_5C]
INIT:00792927 A5 movsd
INIT:00792928 A5 movsd
INIT:00792929 68 EC E4 52 00 push offset _DbgkDebugObjectType ; int