* Referenced by a (U)nconditional or (C)onditional Jump at Address: :0045F4D3(U)
:0045F4DA 8B45F8 mov eax, dword ptr [ebp-08] ====>EAX=RfaLLs1:0045F4DD 0FB64430FF movzx eax, byte ptr [eax+esi-01] ====>依次取RfaLLs1字符的HEX值 共取与用户名相同位数 1、 ====>EAX=52 2、 ====>EAX=66 3、 ====>EAX=61 :0045F4E2 33D8 xor ebx, eax 1、 ====>EBX=52 XOR 52=00 2、 ====>EBX=6C XOR 66=0A 3、 ====>EBX=61 XOR 83=E2 :0045F4E4 8D45D8 lea eax, dword ptr [ebp-28] :0045F4E7 50 push eax :0045F4E8 895DDC mov dword ptr [ebp-24], ebx :0045F4EB C645E000 mov [ebp-20], 00 :0045F4EF 8D55DC lea edx, dword ptr [ebp-24] :0045F4F2 33C9 xor ecx, ecx
* Possible StringData Ref from Code Obj ->"%1.2x" :0045F4F4 B840F64500 mov eax, 0045F640 :0045F4F9 E8E690FAFF call 004085E4 ====>将以上所得直接转成字符 :0045F4FE 8B55D8 mov edx, dword ptr [ebp-28]
上一篇:WinBowl Version 3.2 PJ小记(2)
下一篇:VirTime HTMLock V1.4.0 pj之温柔篇(1)
|