004019EA > \A1 8B004900 MOV EAX,DWORD PTR DS:[49008B]
004019EF . C1E0 02 SHL EAX,2
004019F2 . A3 8F004900 MOV DWORD PTR DS:[49008F],EAX
004019F7 . 52 PUSH EDX
004019F8 . 6A 00 PUSH 0 ; /pModule = NULL
004019FA . E8 93E10800 CALL <JMP.&KERNEL32.GetModuleHandleA> ; \GetModuleHandleA
004019FF . 8BD0 MOV EDX,EAX
00401A01 . E8 920A0600 CALL wincmis1.00462498
00401A06 . 5A POP EDX
00401A07 . E8 58E20800 CALL <JMP.&CC3260MT.___CRTL_MEM_UseBorMM>
00401A0C . E8 CB0A0600 CALL wincmis1.004624DC
00401A11 . 6A 00 PUSH 0 ; /Arg1 = 00000000
00401A13 . E8 800B0600 CALL wincmis1.00462598 ; \wincmis1.00462598
00401A18 . 59 POP ECX
00401A19 . 68 34004900 PUSH wincmis1.00490034
00401A1E . 6A 00 PUSH 0 ; /pModule = NULL
00401A20 . E8 6DE10800 CALL <JMP.&KERNEL32.GetModuleHandleA> ; \GetModuleHandleA
00401A25 . A3 93004900 MOV DWORD PTR DS:[490093],EAX
00401A2A . 6A 00 PUSH 0
00401A2C . E9 B1E20800 JMP <JMP.&CC3260MT.__startup>
00401A31 > $ E9 AE0B0600 JMP wincmis1.004625E4
00401A36 . 33C0 XOR EAX,EAX
00401A38 . A0 7D004900 MOV AL,BYTE PTR DS:[49007D]
00401A3D . C3 RETN
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课