77E18524 85C0 test eax,eax
77E18526 59 pop ecx
77E18527 59 pop ecx
77E18528 74 10 je short kernel32.77E1853A
77E1852A 6A 00 push 0
77E1852C 6A 00 push 0
77E1852E 53 push ebx
77E1852F E8 B4FFFFFF call kernel32.LoadLibraryExA
77E18534 5F pop edi
77E18535 5E pop esi
77E18536 5B pop ebx
77E18537 C2 0400 retn 4 ;到这!
*****************************************
EBP 77E16366 kernel32.VirtualFree
ESI 00970000
EDI 00401000 Proj2.<ModuleEntryPoint>
EIP 003E00C0
******************************************
003E1222 5E pop esi
003E1223 5E pop esi
003E1224 5A pop edx
003E1225 59 pop ecx
003E1226 83C6 1C add esi,1C
003E1229 49 dec ecx
003E122A ^ 0F85 0BFFFFFF jnz 003E113B :上?
003E1230 33C0 xor eax,eax :f4! 到这!
003E1232 5E pop esi
003E1233 5F pop edi
003E1234 5B pop ebx
003E0E09 03C7 add eax,edi
003E0E0B 68 00800000 push 8000
003E0E10 6A 00 push 0
003E0E12 FFB5 9B1D0010 push dword ptr ss:[ebp+10001D9B]
003E0E18 FF10 call dword ptr ds:[eax] ; kernel32.VirtualFree
003E0E1A 8B46 0C mov eax,dword ptr ds:[esi+C] ;ds:[003E0B3C]=00065B60 , oep!
003E0E1D 03C7 add eax,edi
003E0E1F 5D pop ebp
003E0E20 5E pop esi
003E0E21 5F pop edi
003E0E22 5B pop ebx
003E0E23 C3 retn
00487EF5 8985 D0120010 mov dword ptr ss:[ebp+100012D0],eax ; Proj2.00465B60
00487EFB 8BF0 mov esi,eax
00487EFD 59 pop ecx
00487EFE 5A pop edx
00487EFF EB 0C jmp short Proj2.00487F0D
00487F01 03CA add ecx,edx
00487F03 68 00800000 push 8000
00487F08 6A 00 push 0
00487F0A 57 push edi
00487F0B FF11 call dword ptr ds:[ecx]
00487F0D 8BC6 mov eax,esi
00487F0F 5A pop edx
00487F10 5E pop esi
00487F11 5F pop edi
00487F12 59 pop ecx
00487F13 5B pop ebx
00487F14 5D pop ebp
00487F15 FFE0 jmp eax ;<<-------oep!跳过去,就是传说中的天堂!
00487F17 0000 add byte ptr ds:[eax],al