00480500 55 push ebp
00480501 8BEC mov ebp,esp
00480503 83EC 18 sub esp,0x18
00480506 53 push ebx
00480507 56 push esi
00480508 57 push edi
00480509 894D E8 mov dword ptr ss:[ebp-0x18],ecx
0048050C 8B45 08 mov eax,dword ptr ss:[ebp+0x8]
0048050F 8B48 0C mov ecx,dword ptr ds:[eax+0xC]
00480512 51 push ecx
00480513 8B55 08 mov edx,dword ptr ss:[ebp+0x8]
00480516 8B42 08 mov eax,dword ptr ds:[edx+0x8]
00480519 50 push eax
0048051A 8B4D 08 mov ecx,dword ptr ss:[ebp+0x8]
0048051D 8B51 04 mov edx,dword ptr ds:[ecx+0x4]
00480520 52 push edx
00480521 8B45 08 mov eax,dword ptr ss:[ebp+0x8]
00480524 8B08 mov ecx,dword ptr ds:[eax]
00480526 51 push ecx
00480527 8B4D E8 mov ecx,dword ptr ss:[ebp-0x18]
0048052A E8 C19BFFFF call DangPing.0047A0F0
0048052F 8945 FC mov dword ptr ss:[ebp-0x4],eax
00480532 837D FC 00 cmp dword ptr ss:[ebp-0x4],0x0
00480536 75 04 jnz short DangPing.0048053C
00480538 33C0 xor eax,eax
0048053A EB 67 jmp short DangPing.004805A3
0048053C 56 push esi
0048053D 57 push edi
0048053E 8B55 08 mov edx,dword ptr ss:[ebp+0x8]
00480541 8B42 0C mov eax,dword ptr ds:[edx+0xC]
00480544 83E8 01 sub eax,0x1
00480547 8945 EC mov dword ptr ss:[ebp-0x14],eax
0048054A EB 09 jmp short DangPing.00480555
0048054C 8B4D EC mov ecx,dword ptr ss:[ebp-0x14]
0048054F 83E9 01 sub ecx,0x1
00480552 894D EC mov dword ptr ss:[ebp-0x14],ecx
00480555 837D EC 00 cmp dword ptr ss:[ebp-0x14],0x0
00480559 7C 12 jl short DangPing.0048056D
0048055B 8B55 EC mov edx,dword ptr ss:[ebp-0x14]
0048055E 8B45 08 mov eax,dword ptr ss:[ebp+0x8]
00480561 8B4C90 10 mov ecx,dword ptr ds:[eax+edx*4+0x10]
00480565 894D F0 mov dword ptr ss:[ebp-0x10],ecx
00480568 FF75 F0 push dword ptr ss:[ebp-0x10]
0048056B ^ EB DF jmp short DangPing.0048054C
0048056D > FF55 FC call dword ptr ss:[ebp-0x4]
//如何在此处下条件断点 [EBP-4]=44EE05 OD一直没作用。。。
00480570 5F pop edi
00480571 5E pop esi
00480572 895D F4 mov dword ptr ss:[ebp-0xC],ebx
00480575 8945 F8 mov dword ptr ss:[ebp-0x8],eax
00480578 8B55 E8 mov edx,dword ptr ss:[ebp-0x18]
0048057B C782 F0010000 0>mov dword ptr ds:[edx+0x1F0],0x0
00480585 837D F4 00 cmp dword ptr ss:[ebp-0xC],0x0
00480589 74 13 je short DangPing.0048059E
0048058B 8B45 08 mov eax,dword ptr ss:[ebp+0x8]
0048058E C740 24 0100000>mov dword ptr ds:[eax+0x24],0x1
00480595 8B4D 08 mov ecx,dword ptr ss:[ebp+0x8]
00480598 8B55 F8 mov edx,dword ptr ss:[ebp-0x8]
0048059B 8951 28 mov dword ptr ds:[ecx+0x28],edx
0048059E B8 01000000 mov eax,0x1
004805A3 5F pop edi
004805A4 5E pop esi
004805A5 5B pop ebx
004805A6 8BE5 mov esp,ebp
004805A8 5D pop ebp
004805A9 C2 0400 retn 0x4
另:烦请高手再多提供点信息。。此段什么作用。
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课