-
-
[旧帖] 过注册 0.00雪花
-
发表于: 2013-9-2 21:26 1366
-
0040D26E . 8985 28FDFFFF mov dword ptr [ebp-2D8], eax
0040D274 . 8B95 28FDFFFF mov edx, dword ptr [ebp-2D8]
0040D27A . 8995 24FDFFFF mov dword ptr [ebp-2DC], edx
0040D280 . C645 FC 0E mov byte ptr [ebp-4], 0E
0040D284 . 8B85 24FDFFFF mov eax, dword ptr [ebp-2DC]
0040D28A . 50 push eax
0040D28B . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D291 . 81C1 F8000000 add ecx, 0F8
0040D297 . E8 28510700 call <jmp.&MFC42.#858_CString::operat>
0040D29C . C645 FC 0D mov byte ptr [ebp-4], 0D
0040D2A0 . 8D8D 3CFDFFFF lea ecx, dword ptr [ebp-2C4]
0040D2A6 . E8 CB500700 call <jmp.&MFC42.#800_CString::~CStri>
0040D2AB . E8 F93EFFFF call 004011A9
0040D2B0 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D2B6 . E8 AC49FFFF call 00401C67
0040D2BB . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D2C1 . E8 2D40FFFF call 004012F3
0040D2C6 . A3 087C4D00 mov dword ptr [4D7C08], eax
0040D2CB . 833D 087C4D00>cmp dword ptr [4D7C08], 0
0040D2D2 . 0F84 B7000000 je 0040D38F
0040D2D8 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D2DE . E8 3746FFFF call 0040191A
0040D2E3 . A3 087C4D00 mov dword ptr [4D7C08], eax
0040D2E8 . 833D 087C4D00>cmp dword ptr [4D7C08], 0
0040D2EF . 0F85 9A000000 jnz 0040D38F
0040D2F5 . 68 B8F44A00 push 004AF4B8 ; ASCII ", U"
0040D2FA . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D300 . 81C1 0C010000 add ecx, 10C
0040D306 . E8 7D500700 call <jmp.&MFC42.#860_CString::operat>
0040D30B . 68 BCF44A00 push 004AF4BC ; ASCII "nr"
0040D310 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D316 . 81C1 0C010000 add ecx, 10C
0040D31C . E8 61500700 call <jmp.&MFC42.#941_CString::operat>
0040D321 . 68 C0F44A00 push 004AF4C0 ; ASCII "eg"
0040D326 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D32C . 81C1 0C010000 add ecx, 10C
0040D332 . E8 4B500700 call <jmp.&MFC42.#941_CString::operat>
0040D337 . 68 C4F44A00 push 004AF4C4 ; ASCII "is"
0040D33C . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D342 . 81C1 0C010000 add ecx, 10C
0040D348 . E8 35500700 call <jmp.&MFC42.#941_CString::operat>
0040D34D . 68 C8F44A00 push 004AF4C8 ; ASCII "te"
0040D352 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D358 . 81C1 0C010000 add ecx, 10C
0040D35E . E8 1F500700 call <jmp.&MFC42.#941_CString::operat>
0040D363 . 68 CCF44A00 push 004AF4CC ; ASCII "re"
0040D368 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D36E . 81C1 0C010000 add ecx, 10C
0040D374 . E8 09500700 call <jmp.&MFC42.#941_CString::operat>
0040D379 . 68 D0F44A00 push 004AF4D0
0040D37E . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D384 . 81C1 0C010000 add ecx, 10C
0040D38A . E8 F34F0700 call <jmp.&MFC42.#941_CString::operat>
0040D38F > 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D395 . 8B51 20 mov edx, dword ptr [ecx+20]
0040D398 . 52 push edx
0040D399 . B9 F8524D00 mov ecx, 004D52F8
0040D39E . E8 FD41FFFF call 004015A0
0040D3A3 . 8D85 38FDFFFF lea eax, dword ptr [ebp-2C8]
0040D3A9 . 50 push eax
0040D3AA . B9 F8524D00 mov ecx, 004D52F8
0040D3AF . E8 2441FFFF call 004014D8
0040D3B4 . 8985 20FDFFFF mov dword ptr [ebp-2E0], eax
0040D3BA . 8B8D 20FDFFFF mov ecx, dword ptr [ebp-2E0]
0040D3C0 . 898D 1CFDFFFF mov dword ptr [ebp-2E4], ecx
0040D3C6 . C645 FC 0F mov byte ptr [ebp-4], 0F
0040D3CA . 8B95 1CFDFFFF mov edx, dword ptr [ebp-2E4]
0040D3D0 . 52 push edx
0040D3D1 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D3D7 . 81C1 FC000000 add ecx, 0FC
0040D3DD . E8 E24F0700 call <jmp.&MFC42.#858_CString::operat>
0040D3E2 . C645 FC 0D mov byte ptr [ebp-4], 0D
0040D3E6 . 8D8D 38FDFFFF lea ecx, dword ptr [ebp-2C8]
0040D3EC . E8 854F0700 call <jmp.&MFC42.#800_CString::~CStri>
0040D3F1 . 8D85 34FDFFFF lea eax, dword ptr [ebp-2CC]
0040D3F7 . 50 push eax
0040D3F8 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D3FE . E8 F13DFFFF call 004011F4
0040D403 . 8985 18FDFFFF mov dword ptr [ebp-2E8], eax
0040D409 . 8B8D 18FDFFFF mov ecx, dword ptr [ebp-2E8]
0040D40F . 898D 14FDFFFF mov dword ptr [ebp-2EC], ecx
0040D415 . C645 FC 10 mov byte ptr [ebp-4], 10
0040D419 . 8B95 14FDFFFF mov edx, dword ptr [ebp-2EC]
0040D41F . 52 push edx
0040D420 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D426 . 81C1 04010000 add ecx, 104
0040D42C . E8 934F0700 call <jmp.&MFC42.#858_CString::operat>
0040D431 . C645 FC 0D mov byte ptr [ebp-4], 0D
0040D435 . 8D8D 34FDFFFF lea ecx, dword ptr [ebp-2CC]
0040D43B . E8 364F0700 call <jmp.&MFC42.#800_CString::~CStri>
0040D440 . 68 70170000 push 1770
这段代码0040D2EF已经关键跳到0040D38F过注册了,后面0040D395到0040D43B 这段在做什么?似乎没完全过注册,请高手指点
0040D274 . 8B95 28FDFFFF mov edx, dword ptr [ebp-2D8]
0040D27A . 8995 24FDFFFF mov dword ptr [ebp-2DC], edx
0040D280 . C645 FC 0E mov byte ptr [ebp-4], 0E
0040D284 . 8B85 24FDFFFF mov eax, dword ptr [ebp-2DC]
0040D28A . 50 push eax
0040D28B . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D291 . 81C1 F8000000 add ecx, 0F8
0040D297 . E8 28510700 call <jmp.&MFC42.#858_CString::operat>
0040D29C . C645 FC 0D mov byte ptr [ebp-4], 0D
0040D2A0 . 8D8D 3CFDFFFF lea ecx, dword ptr [ebp-2C4]
0040D2A6 . E8 CB500700 call <jmp.&MFC42.#800_CString::~CStri>
0040D2AB . E8 F93EFFFF call 004011A9
0040D2B0 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D2B6 . E8 AC49FFFF call 00401C67
0040D2BB . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D2C1 . E8 2D40FFFF call 004012F3
0040D2C6 . A3 087C4D00 mov dword ptr [4D7C08], eax
0040D2CB . 833D 087C4D00>cmp dword ptr [4D7C08], 0
0040D2D2 . 0F84 B7000000 je 0040D38F
0040D2D8 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D2DE . E8 3746FFFF call 0040191A
0040D2E3 . A3 087C4D00 mov dword ptr [4D7C08], eax
0040D2E8 . 833D 087C4D00>cmp dword ptr [4D7C08], 0
0040D2EF . 0F85 9A000000 jnz 0040D38F
0040D2F5 . 68 B8F44A00 push 004AF4B8 ; ASCII ", U"
0040D2FA . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D300 . 81C1 0C010000 add ecx, 10C
0040D306 . E8 7D500700 call <jmp.&MFC42.#860_CString::operat>
0040D30B . 68 BCF44A00 push 004AF4BC ; ASCII "nr"
0040D310 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D316 . 81C1 0C010000 add ecx, 10C
0040D31C . E8 61500700 call <jmp.&MFC42.#941_CString::operat>
0040D321 . 68 C0F44A00 push 004AF4C0 ; ASCII "eg"
0040D326 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D32C . 81C1 0C010000 add ecx, 10C
0040D332 . E8 4B500700 call <jmp.&MFC42.#941_CString::operat>
0040D337 . 68 C4F44A00 push 004AF4C4 ; ASCII "is"
0040D33C . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D342 . 81C1 0C010000 add ecx, 10C
0040D348 . E8 35500700 call <jmp.&MFC42.#941_CString::operat>
0040D34D . 68 C8F44A00 push 004AF4C8 ; ASCII "te"
0040D352 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D358 . 81C1 0C010000 add ecx, 10C
0040D35E . E8 1F500700 call <jmp.&MFC42.#941_CString::operat>
0040D363 . 68 CCF44A00 push 004AF4CC ; ASCII "re"
0040D368 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D36E . 81C1 0C010000 add ecx, 10C
0040D374 . E8 09500700 call <jmp.&MFC42.#941_CString::operat>
0040D379 . 68 D0F44A00 push 004AF4D0
0040D37E . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D384 . 81C1 0C010000 add ecx, 10C
0040D38A . E8 F34F0700 call <jmp.&MFC42.#941_CString::operat>
0040D38F > 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D395 . 8B51 20 mov edx, dword ptr [ecx+20]
0040D398 . 52 push edx
0040D399 . B9 F8524D00 mov ecx, 004D52F8
0040D39E . E8 FD41FFFF call 004015A0
0040D3A3 . 8D85 38FDFFFF lea eax, dword ptr [ebp-2C8]
0040D3A9 . 50 push eax
0040D3AA . B9 F8524D00 mov ecx, 004D52F8
0040D3AF . E8 2441FFFF call 004014D8
0040D3B4 . 8985 20FDFFFF mov dword ptr [ebp-2E0], eax
0040D3BA . 8B8D 20FDFFFF mov ecx, dword ptr [ebp-2E0]
0040D3C0 . 898D 1CFDFFFF mov dword ptr [ebp-2E4], ecx
0040D3C6 . C645 FC 0F mov byte ptr [ebp-4], 0F
0040D3CA . 8B95 1CFDFFFF mov edx, dword ptr [ebp-2E4]
0040D3D0 . 52 push edx
0040D3D1 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D3D7 . 81C1 FC000000 add ecx, 0FC
0040D3DD . E8 E24F0700 call <jmp.&MFC42.#858_CString::operat>
0040D3E2 . C645 FC 0D mov byte ptr [ebp-4], 0D
0040D3E6 . 8D8D 38FDFFFF lea ecx, dword ptr [ebp-2C8]
0040D3EC . E8 854F0700 call <jmp.&MFC42.#800_CString::~CStri>
0040D3F1 . 8D85 34FDFFFF lea eax, dword ptr [ebp-2CC]
0040D3F7 . 50 push eax
0040D3F8 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D3FE . E8 F13DFFFF call 004011F4
0040D403 . 8985 18FDFFFF mov dword ptr [ebp-2E8], eax
0040D409 . 8B8D 18FDFFFF mov ecx, dword ptr [ebp-2E8]
0040D40F . 898D 14FDFFFF mov dword ptr [ebp-2EC], ecx
0040D415 . C645 FC 10 mov byte ptr [ebp-4], 10
0040D419 . 8B95 14FDFFFF mov edx, dword ptr [ebp-2EC]
0040D41F . 52 push edx
0040D420 . 8B8D 2CFDFFFF mov ecx, dword ptr [ebp-2D4]
0040D426 . 81C1 04010000 add ecx, 104
0040D42C . E8 934F0700 call <jmp.&MFC42.#858_CString::operat>
0040D431 . C645 FC 0D mov byte ptr [ebp-4], 0D
0040D435 . 8D8D 34FDFFFF lea ecx, dword ptr [ebp-2CC]
0040D43B . E8 364F0700 call <jmp.&MFC42.#800_CString::~CStri>
0040D440 . 68 70170000 push 1770
这段代码0040D2EF已经关键跳到0040D38F过注册了,后面0040D395到0040D43B 这段在做什么?似乎没完全过注册,请高手指点
[培训]《安卓高级研修班(网课)》月薪三万计划,掌握调试、分析还原ollvm、vmp的方法,定制art虚拟机自动化脱壳的方法
赞赏
看原图
赞赏
雪币:
留言: