21,458
社区成员
发帖
与我相关
我的任务
分享
Exported fn(): _LastMsgBoxInfo_HookAllApps@8 - Ord:0001h
:1001124E E9BD1F0000 jmp 10013210
* Referenced by a CALL at Address:
|:100139CF |
* Reference To: MSVCR90D._except_handler4_common, Ord:01A8h |
:10011253 E9C43B0000 Jmp 10014E1C
* Referenced by a CALL at Address:
|:10011C86 |
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10016833(U)|
:10011258 E9630B0000 jmp 10011DC0
* Reference To: KERNEL32.lstrlenA, Ord:04B5h|
:1001125D E972460000 Jmp 100158D4
....
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:1001124E(U)|
:10013210 55 push ebp
:10013211 8BEC mov ebp, esp
:10013213 81ECCC000000 sub esp, 000000CC
:10013219 53 push ebx
:1001321A 56 push esi
:1001321B 57 push edi
:1001321C 8DBD34FFFFFF lea edi, dword ptr [ebp+FFFFFF34]
:10013222 B933000000 mov ecx, 00000033
:10013227 B8CCCCCCCC mov eax, CCCCCCCC
:1001322C F3 repz
:1001322D AB stosd
:1001322E 837D0800 cmp dword ptr [ebp+08], 00000000
:10013232 7462 je 10013296
:10013234 833DBCC1011000 cmp dword ptr [1001C1BC], 00000000
:1001323B 741B je 10013258
:1001323D 6898A90110 push 1001A998
:10013242 A104C00110 mov eax, dword ptr [1001C004]
:10013247 83C006 add eax, 00000006
:1001324A 50 push eax
:1001324B 6838A90110 push 1001A938
:10013250 E8EADFFFFF call 1001123F
:10013255 83C40C add esp, 0000000C
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:1001323B(C)
|
:10013258 8BF4 mov esi, esp
Exported fn(): file_settings_getArea - Ord:005Fh
:10001306 FF742408 push [esp+08]
:1000130A B9FCB50110 mov ecx, 1001B5FC
:1000130F FF742408 push [esp+08]
:10001313 E8E64D0000 call 100060FE
:10001318 C3 ret
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10001010(U)|
:10001319 8BC1 mov eax, ecx
:1000131B 802000 and byte ptr [eax], 00
:1000131E C3 ret
text:39D28F8C push esi
.text:39D28F8D mov esi, ecx
.text:39D28F8F push [esp+4+arg_8]
.text:39D28F93 push [esp+8+arg_4]
.text:39D28F97 push 1
.text:39D28F99 push [esp+10h+arg_0]
这五个,心生疑惑所以提出来,不管怎么样,非常感谢您花费宝贵的时间来解答我的困惑。
:39D28F8C public qt_mt312_2
.text:39D28F8C qt_mt312_2 proc near ; DATA XREF: .rdata:off_39F671F8o
.text:39D28F8C
.text:39D28F8C arg_0 = dword ptr 4
.text:39D28F8C arg_4 = dword ptr 8
.text:39D28F8C arg_8 = dword ptr 0Ch
.text:39D28F8C
.text:39D28F8C push esi
.text:39D28F8D mov esi, ecx
.text:39D28F8F push [esp+4+arg_8]
.text:39D28F93 push [esp+8+arg_4]
.text:39D28F97 push 1
.text:39D28F99 push [esp+10h+arg_0]
.text:39D28F9D call qt_mt312_415
.text:39D28FA2 mov dword ptr [esi], offset qt_mt312_2502
.text:39D28FA8 mov eax, esi
.text:39D28FAA pop esi
.text:39D28FAB retn 0Ch
.text:39D28FAB qt_mt312_2 endp
void *__thiscall qt_mt312_2(void *this, int a2, int a3, int a4)
{
void *v4; // esi@1
v4 = this;
qt_mt312_415(a2, 1, a3, a4);
*(_DWORD *)v4 = qt_mt312_2502;
return v4;
}