关于策略范围显示
0046FC40 /$ 55 PUSH EBP
0046FC41 |. 8BEC MOV EBP,ESP
0046FC43 |. 6A FF PUSH -1
0046FC45 |. 68 90594800 PUSH Ekd5.00485990 ; SE 处理程序安装
0046FC4A |. 64:A1 0000000>MOV EAX,DWORD PTR FS:[0]
0046FC50 |. 50 PUSH EAX
0046FC51 |. 64:8925 00000>MOV DWORD PTR FS:[0],ESP
0046FC58 |. 83EC 0C SUB ESP,0C
0046FC5B |. 894D E8 MOV DWORD PTR SS:[EBP-18],ECX
0046FC5E |. 0FB689 242000>MOVZX ECX,BYTE PTR DS:[ECX+2024]
0046FC65 |. E8 98430100 CALL Ekd5.00484002
0046FC6A |. E8 2190FAFF CALL Ekd5.00418C90
0046FC6F |. 8845 EC MOV BYTE PTR SS:[EBP-14],AL
0046FC72 |. 90 NOP
0046FC73 |. 90 NOP
0046FC74 |. 90 NOP
0046FC75 |. 90 NOP
0046FC76 |. 3C FF CMP AL,0FF
0046FC78 |. 75 07 JNZ SHORT Ekd5.0046FC81
0046FC7A |. C645 EC 10 MOV BYTE PTR SS:[EBP-14],10
0046FC7E |. 90 NOP
0046FC7F |. 90 NOP
0046FC80 |. 90 NOP
0046FC81 |> 90 NOP
0046FC82 |. 90 NOP
0046FC83 |. 90 NOP
0046FC84 |. 90 NOP
0046FC85 |. 6A 00 PUSH 0 ; /ShowState = SW_HIDE
0046FC87 |. 8B15 F85F4B00 MOV EDX,DWORD PTR DS:[4B5FF8] ; |
0046FC8D |. 52 PUSH EDX ; |hWnd => NULL
0046FC8E |. FF15 E0624800 CALL DWORD PTR DS:[<&USER32.ShowWindow>] ; \ShowWindow
0046FC94 |. 6A 0B PUSH 0B
0046FC96 |. E8 48CE0000 CALL Ekd5.0047CAE3
0046FC9B |. 83C4 04 ADD ESP,4
0046FC9E |. 05 00040000 ADD EAX,400
0046FCA3 |. 3E:8945 F0 MOV DWORD PTR DS:[EBP-10],EAX
0046FCA7 |. 90 NOP
0046FCA8 |. 90 NOP
0046FCA9 |. 90 NOP
0046FCAA |. 6A 07 PUSH 7
0046FCAC |. E8 19D50000 CALL Ekd5.0047D1CA
0046FCB1 |. 83C4 04 ADD ESP,4
0046FCB4 |. 6A 00 PUSH 0 ; /Arg3 = 00000000
0046FCB6 |. 6A 00 PUSH 0 ; |Arg2 = 00000000
0046FCB8 |. 6A 00 PUSH 0 ; |Arg1 = 00000000
0046FCBA |. E8 32D50000 CALL Ekd5.0047D1F1 ; \Ekd5.0047D1F1
0046FCBF |. 83C4 0C ADD ESP,0C
0046FCC2 |. 8B45 E8 MOV EAX,DWORD PTR SS:[EBP-18]
0046FCC5 |. 90 NOP
0046FCC6 |. 90 NOP
0046FCC7 |. 90 NOP
0046FCC8 |. 83C0 24 ADD EAX,24
0046FCCB |. 50 PUSH EAX
0046FCCC |. 8B0D 9C684800 MOV ECX,DWORD PTR DS:[48689C]
0046FCD2 |. 51 PUSH ECX
0046FCD3 |. 8B15 98684800 MOV EDX,DWORD PTR DS:[486898]
0046FCD9 |. 52 PUSH EDX
0046FCDA |. 6A 00 PUSH 0
0046FCDC |. 6A 00 PUSH 0
0046FCDE |. E8 B8E30000 CALL Ekd5.0047E09B
0046FCE3 |. 83C4 14 ADD ESP,14
0046FCE6 |. 6A 00 PUSH 0
0046FCE8 |. E8 F6CD0000 CALL Ekd5.0047CAE3
0046FCED |. 83C4 04 ADD ESP,4
0046FCF0 |. C745 FC FFFFF>MOV DWORD PTR SS:[EBP-4],-1
0046FCF7 |. 90 NOP
0046FCF8 |. 90 NOP
0046FCF9 |. 90 NOP
0046FCFA |. 90 NOP
0046FCFB |. 90 NOP
0046FCFC |. 57 PUSH EDI
0046FCFD |. 8B7D F0 MOV EDI,DWORD PTR SS:[EBP-10]
0046FD00 |. 33C0 XOR EAX,EAX
0046FD02 |. B9 00100000 MOV ECX,1000
0046FD07 |. F3:AA REP STOS BYTE PTR ES:[EDI]
0046FD09 |. 5F POP EDI
0046FD0A |. 90 NOP
0046FD0B |. 90 NOP
0046FD0C |. 90 NOP
0046FD0D |. 8B4D F0 MOV ECX,DWORD PTR SS:[EBP-10]
0046FD10 |. 90 NOP
0046FD11 |. 90 NOP
0046FD12 |. 90 NOP
0046FD13 |. 90 NOP
0046FD14 |. 90 NOP
0046FD15 |. 90 NOP
0046FD16 |. 90 NOP
0046FD17 |. 90 NOP
0046FD18 |. 90 NOP
0046FD19 |. 90 NOP
0046FD1A |. 90 NOP
0046FD1B |. 90 NOP
0046FD1C |. 90 NOP
0046FD1D |. 90 NOP
0046FD1E |. 90 NOP
0046FD1F |. 90 NOP
0046FD20 |. 90 NOP
0046FD21 |. 8A45 EC MOV AL,BYTE PTR SS:[EBP-14]
0046FD24 |. 50 PUSH EAX ; /Arg1
0046FD25 |. E8 26850000 CALL Ekd5.00478250 ; \Ekd5.00478250
0046FD2A |. 90 NOP
0046FD2B |. 90 NOP
0046FD2C |. 8B4D F4 MOV ECX,DWORD PTR SS:[EBP-C]
0046FD2F |. 64:890D 00000>MOV DWORD PTR FS:[0],ECX
0046FD36 |. 8BE5 MOV ESP,EBP
0046FD38 |. 5D POP EBP
0046FD39 \. C3 RETN
跟那个一样的 调用函数来画图
|