sp; jnz end cmp dword ptr [eax+4], 0EE80000h jnz end mov eax, [ebp+4] cmp eax, 80000000h jb end cmp byte ptr [eax], 83h jnz end cmp byte ptr [eax+1], 4Dh jnz end cmp byte ptr [eax+2], 0FCh jnz end cmp byte ptr [eax+3], 0FFh jnz end cmp byte ptr [eax+4], 6Ah push dword ptr [ebp-4] call ZwClose pop eax jmp dword ptr [ebp+4]
end: pop eax push ebp mov ebp, esp jmp [retaddr] }
}
_declspec(naked)int recover(){ _asm{ sub esp,ecx shr ecx,2 mov edi,esp cmp esi, 7FFF0000h } }
VOID ReinITialize( IN PDR 上一页 [1] [2] [3] [4] [5] [6] [7] [8] [9] [10] ... 下一页 >>
|