最初由 wqrsksk 发布
请问兄台 这个是怎么看出来的呀~!
00414355 |. 8D85 78FFFFFF lea eax, [ebp-88] ; |
0041435B |. 50 push eax ; |Buffer
0041435C |. E8 21A00800 call <jmp.&KERNEL32.GetSystemDirectoryA> ; \GetSystemDirectoryA
00414361 |. 66:C745 D8 2C>mov word ptr [ebp-28], 2C
00414367 |. 8D45 EC lea eax, [ebp-14]
0041436A |. E8 99D4FEFF call 00401808
0041436F |. 50 push eax
00414370 |. FF45 E4 inc dword ptr [ebp-1C]
00414373 |. BA DE4E4A00 mov edx, 004A4EDE ; \mkrnl57.dll
00414378 |. 8D45 F0 lea eax, [ebp-10]
0041437B |. E8 F0940800 call 0049D870
00414380 |. 8BD0 mov edx, eax
00414382 |. FF45 E4 inc dword ptr [ebp-1C]
00414385 |. 8D85 78FFFFFF lea eax, [ebp-88]
0041438B |. 59 pop ecx
0041438C |. E8 F79A0800 call 0049DE88
00414391 |. 8D45 EC lea eax, [ebp-14]
00414394 |. 8B00 mov eax, [eax]
00414396 |. E8 956C0700 call 0048B030
0041439B |. FF4D E4 dec dword ptr [ebp-1C]
0041439E |. 8D45 EC lea eax, [ebp-14]
004143A1 |. BA 02000000 mov edx, 2
004143A6 |. E8 91960800 call 0049DA3C
004143AB |. FF4D E4 dec dword ptr [ebp-1C]
004143AE |. 8D45 F0 lea eax, [ebp-10]
004143B1 |. BA 02000000 mov edx, 2
004143B6 |. E8 81960800 call 0049DA3C
004143BB |. 6A 40 push 40
004143BD |. B9 084F4A00 mov ecx, 004A4F08 ; 注册成功!
004143C2 |. BA EB4E4A00 mov edx, 004A4EEB ; 谢谢您,您已经是注册用户了!
004143C7 |. A1 A8DC4A00 mov eax, [4ADCA8]
004143CC |. 8B00 mov eax, [eax]
===+++++++++++++++++++++++++++++++++++++++++++++++++++=============
上面就可以看出来,哈哈