好久没脱壳了,难的脱不动,先拿这个出出气,呵呵.
003802AA 64:8F05 0000000>pop dword ptr fs:[0] ; 0012FFE0
003802B1 83C4 04 add esp, 4
003802B4 85C0 test eax, eax
003802B6 74 19 je short 003802D1
003802B8 EB 35 jmp short 003802EF
003802BA 8B4424 0C mov eax, dword ptr [esp+C]
003802BE C780 B0000000 F>mov dword ptr [eax+B0], -1
003802C8 FF80 B8000000 inc dword ptr [eax+B8]
003802CE 33C0 xor eax, eax
003802D0 C3 retn
003802F9 /78 0F js short 0038030A
003802FB |8B40 0C mov eax, dword ptr [eax+C]
003802FE |8B40 0C mov eax, dword ptr [eax+C]
00380301 |C740 20 0010000>mov dword ptr [eax+20], 1000
00380308 |EB 1C jmp short 00380326
0038030A \6A 00 push 0
0038030C FF95 FE030000 call dword ptr [ebp+3FE]
00380312 85D2 test edx, edx
00380314 79 10 jns short 00380326
00380316 837A 08 FF cmp dword ptr [edx+8], -1
0038031A 75 0A jnz short 00380326
0038031C 8B52 04 mov edx, dword ptr [edx+4]
0038031F C742 50 0010000>mov dword ptr [edx+50], 1000
00380326 FF85 16040000 inc dword ptr [ebp+416]
0038032C 8B85 42030000 mov eax, dword ptr [ebp+342]
00380332 8B8D 0E040000 mov ecx, dword ptr [ebp+40E]
00380338 8D0408 lea eax, dword ptr [eax+ecx]
0038033B 894424 1C mov dword ptr [esp+1C], eax
0038033F 61 popad
00380340 50 push eax
00380341 C3 retn