PEID什么也没有,exeinfoPE查是Microsoft Visual C++ v.10
代码:
0105F0CE E> E8 556B0000 call EduBoard.01065C28 载入点
0105F0D3 ^ E9 89FEFFFF jmp EduBoard.0105EF61
0105F0D8 3B0D BCD10D01 cmp ecx,dword ptr ds:[10DD1BC]
0105F0DE 75 02 jnz short EduBoard.0105F0E2
0105F0E0 F3: prefix rep:
0105F0E1 C3 retn
0105F0E2 E9 DC6B0000 jmp EduBoard.01065CC3
0105F0E7 8BFF mov edi,edi
0105F0E9 51 push ecx
0105F0EA C701 103A0B01 mov dword ptr ds:[ecx],EduBoard.010B3A10
0105F0F0 E8 D46C0000 call EduBoard.01065DC9
0105F0F5 59 pop ecx
0105F0F6 C3 retn
。。。。。。
0105EF61 6A 58 push 58
0105EF63 68 B83E0D01 push EduBoard.010D3EB8
0105EF68 E8 93140000 call EduBoard.01060400
0105EF6D 8D45 98 lea eax,dword ptr ss:[ebp-68]
0105EF70 50 push eax
0105EF71 FF15 90820801 call dword ptr ds:[<&KERNEL32.GetStartupInfoW>] ; kernel32.GetStartupInfoW
0105EF77 33F6 xor esi,esi
0105EF79 3935 78610E01 cmp dword ptr ds:[10E6178],esi
0105EF7F 75 0B jnz short EduBoard.0105EF8C
0105EF81 56 push esi
0105EF82 56 push esi
0105EF83 6A 01 push 1
0105EF85 56 push esi
0105EF86 FF15 94820801 call dword ptr ds:[<&KERNEL32.HeapSetInformation>] ; kernel32.HeapSetInformation
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课