016F0CFC 66:8B15 5C0A770>mov dx, word ptr [1770A5C] ;[1770A5C]=60
016F0D03 66:8BCA mov cx, dx
016F0D06 B8 01000000 mov eax, 1
016F0D0B 66:81E1 F00F and cx, 0FF0
016F0D10 66:83F9 50 cmp cx, 50
016F0D14 74 06 je short 016F0D1C
016F0D16 66:83F9 60 cmp cx, 60
016F0D1A 75 26 jnz short 016F0D42
016F0D1C 813D 640A7701 8>cmp dword ptr [1770A64], 61A80 ;[1770A64]=61A80
016F0D26 7C 1A jl short 016F0D42
016F0D28 66:833D BE08770>cmp word ptr [17708BE], 5 ;[17708BE]=5
016F0D30 75 10 jnz short 016F0D42
016F0D32 84D0 test al, dl
016F0D34 75 0C jnz short 016F0D42
016F0D36 66:A3 AC177701 mov word ptr [17717AC], ax ;[17717AC]=1
016F0D3C 5E pop esi
016F0D3D 5B pop ebx
016F0D3E 8BE5 mov esp, ebp
016F0D40 5D pop ebp
016F0D41 C3 retn
比如我们想对[1770A64]赋值;mov dword ptr [1770A64],61A80
但是[1770A64]这个地址好像会变,所以很麻烦
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课