laoqian 老大,qinhanshi老师傅还是让我来请教你,我跟他说过了,也发邮件给你了,你就加我下吧。还有个问题求教:
我用Nolan和你的方法。跟踪到了这里:
0041507F /$ 55 PUSH EBP
00415080 |. 8BEC MOV EBP,ESP
00415082 |. 83EC 30 SUB ESP,30
00415085 |. C745 F0 8EB948>MOV DWORD PTR SS:[EBP-10],7648B98E
0041508C |. C745 EC 030000>MOV DWORD PTR SS:[EBP-14],3
00415093 |. 8B45 08 MOV EAX,DWORD PTR SS:[EBP+8]
00415096 |. 8B48 6C MOV ECX,DWORD PTR DS:[EAX+6C]
00415099 |. 8B91 D4010000 MOV EDX,DWORD PTR DS:[ECX+1D4]
0041509F |. 81E2 00800000 AND EDX,8000
004150A5 |. 85D2 TEST EDX,EDX
004150A7 |. 74 23 JE SHORT seiko.004150CC
004150A9 |. 833D 5CB94700 >CMP DWORD PTR DS:[47B95C],0
004150B0 |. 74 1A JE SHORT seiko.004150CC
004150B2 |. 8B45 10 MOV EAX,DWORD PTR SS:[EBP+10]
004150B5 |. 50 PUSH EAX
004150B6 |. 8B4D 0C MOV ECX,DWORD PTR SS:[EBP+C]
004150B9 |. 51 PUSH ECX
004150BA |. 8B55 08 MOV EDX,DWORD PTR SS:[EBP+8]
004150BD |. 52 PUSH EDX
004150BE |. FF15 5CB94700 CALL DWORD PTR DS:[47B95C]
004150C4 |. 83C4 0C ADD ESP,0C
004150C7 |. E9 13010000 JMP seiko.004151DF
004150CC |> 6A 04 PUSH 4 ; /Arg4 = 00000004
我在 0041507F /$ 55 PUSH EBP
和004150BE |. FF15 5CB94700 CALL DWORD PTR DS:[47B95C]
处下了断,你看对码?我F9后没有跳出,但是死了,进程没反应,关掉后再来,F8单步到了004150CC |> 6A 04 PUSH 4 ,然后用你的方法:dd [esp+4] 但得到address points to nowhere,dd [esp+8]得到的冬冬我高不清那个是你说的data 0 和1 是哪个?我找不到了,laoqian请提点一下啊。谢谢了,+我啊!!
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课