PEID v0.95 什么都没找到
OD加载完
00421AE1 > $ E8 25B70000 CALL tradeage.0042D20B
00421AE6 .^ E9 40FEFFFF JMP tradeage.0042192B
。。。。。
F7步入,
0042D20B /$ 55 PUSH EBP
0042D20C |. 8BEC MOV EBP,ESP
0042D20E |. 83EC 10 SUB ESP,10
0042D211 |. A1 30B64400 MOV EAX,DWORD PTR DS:[44B630]
。。。
0042D23F |. 50 PUSH EAX ; /pFileTime
0042D240 |. FF15 10B14300 CALL DWORD PTR DS:[<&KERNEL32.GetSystemTimeAsFileTime>] ; \GetSystemTimeAsFileTime
0042D246 |. 8B75 FC MOV ESI,DWORD PTR SS:[EBP-4]
0042D249 |. 3375 F8 XOR ESI,DWORD PTR SS:[EBP-8]
0042D24C |. FF15 34B04300 CALL DWORD PTR DS:[<&KERNEL32.GetCurrentProcessId>] ; [GetCurrentProcessId
0042D252 |. 33F0 XOR ESI,EAX
0042D254 |. FF15 BCB04300 CALL DWORD PTR DS:[<&KERNEL32.GetCurrentThreadId>] ; [GetCurrentThreadId
0042D25A |. 33F0 XOR ESI,EAX
0042D25C |. FF15 38B04300 CALL DWORD PTR DS:[<&KERNEL32.GetTickCount>] ; [GetTickCount
0042D262 |. 33F0 XOR ESI,EAX
0042D264 |. 8D45 F0 LEA EAX,DWORD PTR SS:[EBP-10]
0042D267 |. 50 PUSH EAX ; /pPerformanceCount
0042D268 |. FF15 3CB04300 CALL DWORD PTR DS:[<&KERNEL32.QueryPerformanceCounter>] ; \QueryPerformanceCounter
貌似用了
QueryPerformanceCounter反Debug
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课