EBIGP
̽Ë÷ÔÓÖ¾
HJQDM
֪ʶ¹²Ïí ×ÊÔ´¹²Ïí ×ÊÁϹ²Ïí
¡¾ÖÆ×÷³ÉÔ±¡¿³ÌʽÁÔÈË
¡¾·¢ÐÐʱ¼ä¡¿
¡¾ÆÚ¿¯ºÅÂë¡¿µÚÊ®ÆÚ
¡¾ÍøÕ¾µØÖ·¡¿http://programhunter.home.china.com

¡¾±à¼­¼ÄÓï¡¿

    
    {~._.~} 
     ( Y )  
    ()~*~() 
    (_)-(_) 
½ñÌìÕâ·ÝÔÓÖ¾ÒѾ­ÊǵÚÊ®ÆÚÁË£¬ÏÖÔÚÔÓÖ¾µÄ±ä»¯ÎÒÏë´ó¼Ò¶¼¿´µ½ÁË£¬ÔÚÕâÀïÎÒÒ²Ö»ÄܶÔÔÓÖ¾µÄ½çÃæ˵һÏ£¨ÖÁÓÚÄÚÈÝ»¹Òª´ó¼ÒÀ´Ëµ£©£¬Ïëµ±³õµÚÒ»ÆÚÔÓÖ¾½ñÌìÔÙ¿´Ò»Ï·¢ÏÖËýµÄÈ·ÊDZȽϲîµÄ£¬ÕâÀïרÃÅÖ¸½çÃæÁË¡£ÏÖÔÚÎÒÏëÔÓÖ¾µÄ½çÃæÒѾ­±È½ÏÒÔÇ°µÄºÃ¶àÁË¡£
¡¾Ä¿ ÿÿ ¼¡¿
ÿÿÿÿ&ÆƽâÐĵÃ
1¡­¡­Noterpro V1.1 ³ÌʽÁÔÈË
2¡­¡­¼üÅÌÓïÒôÌáʾ(InsTalk) V2.51°æ ³ÌʽÁÔÈË
3¡­¡­²ËÄñÆƽâ¼֮ GIF Construction Set Pro¼°Ëã·¨·ÖÎö xiA Qin
ÿÿÿÿ%³õѧÌìµØ
ÿÿÿÿOÎÊÌâ´ðÒÉ
ÿÿÿÿ4ÍøÕ¾½éÉÜ
ÿÿÿÿ,ÔÓÖ¾ÐÅÏä
&¡¾ÆƽâÐĵá¿
 Noterpro V1.1
                    ³ÌʽÁÔÈË
¼ò½é£ºÕâ¸öÈí¼þÊÇÒ»¸öСÐ͵ı༭Èí¼þ£¬¹¦ÄܱÈnoteÇ¿´ó¡£
×·×Ù£ºname:dahuilang
      RN:01234567
      ÔÚдÕâ¸ö½Ì³ÌÇ°£¬ÎÒ¿´µ½ÁË¿´Ñ©¹ØÓÚÕâ¸öÈí¼þµÄÕû¸ö¼ÆËã¹ý³Ì£¬ÔÚËûµÄÎÄÕÂÖн²½âµÄ
·Ç³£Çå³þ£¬ÈçºÎµÃµ½µÄ×¢²áÂë´ó¼ÒÏë±ØÒ»¿´¾ÍÖªµÀÁË¡£µ«ÊÇ¿´Ñ©Ã»ÓÐд³öÀ´ÈçºÎÄܹ»×·×Ùµ½
¼ÆËãµÄµØ·½£¬ÎÒÏë¶ÔÓÚ³õѧÕßÀ´Ëµ×·×Ùµ½ÕâÀïÊǷdz£¹Ø¼üµÄ£¬¶ø´ó¼ÒûÓÐ×·×Ù³öÀ´µÄÔ­Òò´ó
¶àÊýÒ²¾ÍÔÚ´Ë£¬ËùÒÔÎҾͽ«Ëü´Ó¿ªÊ¼´¦Ö±µ½×·×Ùµ½¼ÆËã¹ý³Ì´¦Ð´³öÀ´£¬¹©´ó¼Òѧϰ¡£
    ÏÂbpx hmemcpyºóÄ㽫±»À¹Ï¡£ÌøÔ¾µ½Ö÷³ÌÐòÖУ¬ÈçÏ£º
0040b1f7  call 0049a768
          lea edx [ebp-08]  <-³öÀ´
          xor eax eax
          ¡­¡­
          ¡­¡­
0040b214  call 0049a768
          lea edx [ebp-08]
          mov edx [edx]
          mov eax [004e9c80]
          pop eax
          call 00406bb0
          push eax      ****
          ¡­¡­
          ¡­¡­
0040b245  call 004dccc
          pop ecx
          test cl cl 
          jz 0040b38b
  ÏÖÔÚÎÒÃǾÍ×·×Ùµ½ÕâÀÄ㽫Ê×ÏÈ´ÓÉÏÃæ±ê¼ÇµÄµØ·½³öÀ´£¬ÒòΪ³ÌÐòÒª¶ÁÈ¡Á½´Î£¬ËùÒÔËü
ʹÓÃÁËcall 0049a768Á½´ÎµÄ£¬³ÌÐò¶ÁÈ¡ÍêºóÏÂÃæµÄÄǸöcall¾ÍÊǹؼüµÄµØ·½£¬ÎÒÔÚÕâÀïÏò
´ó¼Ò½âÊÍÒ»ÏÂΪʲô˵call 00406bb0¾ÍÊÇÖØÒªµÄµØ·½¡£
  ÒòΪÔÚÏÂÃæ0040b245´¦¿ªÊ¼£¬Èç¹û³ÌÐòÔÚÕâÀïÌøÔ¾»°£¬½«³öÏÖ´íóÌáʾ£¬ËùÒÔ˵Õâ¸?
Ô¾ÊÇÒ»¸öÏ൱¹Ø¼üµÄµØ·½£¬ÄÇôecxµÄÖµ¾ö¶¨Õâ¸ö³ÌÐòÄܹ»×¢²á³É¹¦Óë·ñÁË¡£³ÌÐòµ÷ÓÃecxÊÇ
ʹÓóöÕ»µÄ·½·¨µÃµ½ecxµÄ£¬ÄÇôÍÒª¿´ÔÚÄÇÀï½øÕ»ÁË£¬¹Û²ì³ÌÐò·¢ÏÖÖ»Ó?***´¦½øÈë¶ÑÕ»
£¬ËùÒÔÏÖÔÚ¾ÍÖªµÀcall 00406bb0ÊÇÒ»¸öÖØÒªµÄº¯ÊýÁË¡£
   ½øÈëcall 00406bb0ÖУ¬ÈçÏ£º

00406e6b  mov edx [ebp-08]
          call notepro!@stratil@xordecord$qqrx17
          lea edx [ebp-2c]
          lea eax [ebp-14]
          call 004dcd9c
          push eax      ****
          ¡­¡­
          ¡­¡­
00406e92  call 004dcccc
          pop ecx
          test cl cl
          jz 00406e98
          mov byte [ebp-51] 01  ****
00406e98  dec dword [ebp-34]
          ¡­¡­
          ¡­¡­
00406eae  mov al [ebp-51] ***
          mov edx 02
          push eax  **
          leax eax [ebp-08]
          ¡­¡­
          ¡­¡­
00406ecd  call 004dcccc
          pop eax  *
          mov edx [ebp-50]
   ÏÖÔÚ¿ªÊ¼½éÉܳÌÐòÔÚÕâ¸öcallÖÐÈçºÎµÃµ½µÄeaxÖµµÄ£¬ÒòΪ³öÕâ¸öcallºóÎÒÃÇ×î¹ØÐĵľÍ
ÊÇeaxÖµ£¬ÄÇô¾ÍҪעÒâÕâ¸öÖµµÄ±ä»¯¡£ÎÒÏÈ´ÓºóÃæ¿´£¬Õâ¸öeax¾ÍÊdzÌÐò·µ»ØµÄÖµ£¬Ëü´ÓÕâ
ÀïµÃµ½µÄ¡£
          pop eax   *
   ÄÇôÔÚÉÏÃæ¾ÍÓнøÈë¶ÑÕ»µÄµØ·½
          push eax  **
    ËüÓÖÊÇmov al [ebp-51]´ÓÕâµÃµ½µÄ£¬ÔÙÏòÉϲéÕÒ³ÌÐòÔÚÕâÀïʹÓÃmov byte [ebp-51] 0
1£¬Õâ¸öÊǾö¶¨Äã×¢²á³É¹¦µÄ¹Ø¼ü£¬ÄÇôÉÏÃæÕýºÃÓÐÒ»¸öjz£¬Õâ¾ÍÓ¦µ±ÕÒµ½Á˹ؼüµØ·½ÁË¡£
µ«ÊÇÔÚÕâÀïÄã²»Òª½øÈë
00406e92  call 004dcccc
   ÖУ¬ÒòΪËü²»ÊÇ×îºóµÄÔËÐÐcall£¬ÎªÊ²Ã´£¿»¹ÊÇʹÓÃÇ°Ãæ½²µ½µÄµØ·½£¬ÒòΪ³ÌÐòʹÓõÄ
ÊÇpop ecxÀ´´«ÖµµÄ£¬ËùÒÔÉÏÃæ²ÅÊǹؼüµÄµØ·½¡£
          call 004dcd9c
          push eax   
  ÕâÀïÕ߹ؼüµÄµØ·½£¬ÄÇôÈç¹ûÄã½øÈëÕâÀïcallÖÐÄã»á·¢ÏÖÕâÀïÖ»ÊÇÒ»¸ö±È½Ï¹ý³Ì£¬ËüµÄÁ½
¸öÖµÒ»¸öÊÇÃ÷Â룬ÁíÒ»¸ö²»ÊÇ£¬ÆäÖÐÃûÂë¾ÍÊÇͨ¹ýÄãµÄname¼ÆËãµÃµ½µÄ£¬¶ø²»ÊÇÃ÷ÂëµÄ¾ÍÊÇ
ͨ¹ýÄãµÄ×¢²áÂë¼ÆËãµÃµ½µÄ¡£ÏÖÔڵĹؼüÊÇÕÒµ½ÈçºÎͨ¹ýÄãµÄ×¢²áÂë¼ÆËãµÃµ½Õâ¸ö±È½ÏÂëµÄ
¡£ÄÇôÔÚÉÏÃæããµÄ´úÂëÖÐÈçºÎÕÒÄØ£¿
   ÕâÀïÒ²ÓÐÒ»¸ö¼¼ÇÉ£¬ÒòΪÈç¹ûÄã½øÈëcall 00406bb0ÕâÀïºó£¬Äã»á·¢ÏÖ³ÌÐòÇ°ÃæµÄ¼ÆËãÈë
¿ÚÖµ¶¼ÊÇname£¬Ò²¾ÍÊÇÇ°ÃæµÄ¼ÆË㶼Õæ¶ÔnameµÄ£¬¶øÔÚÕâÀïÄã¿ÉÒÔ¿´µ½ËüµÄÈë¿ÚÖµÊÇÄãÊäÈë
µÄRN
00406e6b  mov edx [ebp-08]   <-RN    *******
          call notepro!@stratil@xordecord$qqrx17
          lea edx [ebp-2c]
          lea eax [ebp-14]
 ÄÇôÏÂÃæµÄÄǸöcall¾ÍÊÇÔËÐеĹؼüÁË£¬½øÈëºóÄã¾Í»á·¢ÏÖËüͬ¿´Ñ©½éÉܵÄÒ»Ñù£¬ÄãÊÖÖÐ
Ò»¶¨ÒªÓÐÒ»¸öXOR±í£¬Èç¹ûûÓл°£¬×Ô¼º×öÒ»¸ö¾ÍÐÐÁË¡£ÏÂÃæ¾ÍÊÇ¿´Ñ©ÆƽâµÄ¼ÆËã¹ý³Ì¡£

³ÌÐòÃûÊÇ£ºnotepro  1.04 
ÏÂÔØ£ºhttp://www.newhua.com.cn/down/notepro.zip 
ÎÒÃÇ¿´¿´Õâ¸ö³ÌÐòµÄËã·¨£¬Õâ³ÌÐòÏȸú¾ÝÐÕÃûÈ磺toye£¬¼ÆËã³öÒ»ÖмäÊým,ÕâÀïm=40913271
26,È»ºó½«Õâm¸÷λÒÀ´Îת»»ASCIIÂ룬ÔÙÒÀ´ÎÓëÄÚ²¿¹Ì¶¨×Ö´®£º67gjhab480klvn176 Òì»òÔË
Ë㣬½á¹û¾ÍÊÇÒÔÁ½Î»Ê®Áù½øÖƱíʾ£¬Õâ¾ÍÊÇ×¢²áÂë¡£ 
È磺ÉèÎÒÃÇÊäÈëµÄÐÕÃû¸ñʽ£ºa1 a2 a3 ...a(n) 
m·Ö³ÉÈý¶Î£¬ÒÀ´Î¸ù¾ÝÐÕÃû¼ÆËã¡£Éèm=m1+m2+m3 
m1=a1+a2+a3+--+a(n-1)+61  (È«²¿Êý×ÖÊÇÒÔÊ®½øÖƱíʾ¼ÆËãµÄ£© 
m2=£¨a1+a(n))*3D  (È«²¿Êý×ÖÒÔÊ®Áù½øÖƼÆË㣬½á¹ûת»»³ÉÊ®½øÖÆ£© 
m3=3D+3D+n  (È«²¿Êý×ÖÒÔÊ®Áù½øÖƼÆË㣬½á¹ûת»»³ÉÊ®½øÖÆ£© 

ÔÚÕâÀtoye 
m=m1 m2 m3= 409  1327  126 =4091327126 

      m=4091327126 
Õ¹¿ª£º34 30 39 31 33 32 37 31 32 36  (½«mת»»³ÉASDCIIÂ룩 
XOR£º36 37 67 6A 68 61 62 34 38 30  (¹Ì¶¨×Ö´®67gjhab480klvn176ÒÔASCII±íʾ£© 
¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª¡ª 
          02 07 5e 5b 5b 53 51 03 09 02 5d 
Òò´Ë£º×¢²áÂë¾ÍÊÇ£º02075e5b5b53510309025d 

ÖÁ´Ë£¬×¢²á»úÓ¦²»ÄÑдÁË¡£ 

ÏÂÃæ¼òµ¥½«Æƽâ¹ý³ÌµÄ´úÂëÀý³ö£º 

ÓÃSOFTICEÀ´ÆÆ£¬ÓÃWF´ò¿ª¸¡µã¿ª¹Ø¡£ 

¢Ù¼ÆËãm1²¿·Ö 

ST0  111.                              ST4  empty 
ST1  empty                              ST5  empty  
ST2  empty                              ST6  empty  
ST3  empty                              ST7  empty  
0167:00406898  MOV      ESI,EBX 
0167:0040689A  PUSH      ESI 
0167:0040689B  LEA      EAX,[EBP-04] 
0167:0040689E  PUSH      EAX
0167:0040689F  CALL      004DBEDC  
0167:004068A4  ADD      ESP,08          
0167:004068A7  LEA      EAX,[EBP-04] 
0167:004068AA  CALL      004DC178    
0167:004068AF  ADD      ESI,[EBP-04]
0167:004068B2  DEC      ESI   
0167:004068B3  MOVSX    EDX,BYTE PTR [ESI]  //ÒÀ´Î½«ÐÕÃû¸÷¸ö×Ö·û´«¸øedx 
0167:004068B6  AND      EDX,7F     
0167:004068B9  MOV      [EBP-70],EDX 
0167:004068BC  FILD      DWORD PTR [EBP-70]    //½«Õâ¸ö×Ö·û·Å½ø¸¡µã¼Ä´æÆ÷ST0 
0167:004068BF  FADD      REAL8 PTR [EBP-5C]    //ebp-5cµÄ³õֵΪ0 £¬ST0Óëebp-5cµÄ
ÖµÏà¼Ó
0167:004068C2  FSTP      REAL8 PTR [EBP-5C]      //½«½á¹ûÈ¡³ö£¬·Å½øebp-5c  
0167:004068C5  INC      EBX                                                    
0167:004068C6  CMP      DWORD PTR [EBP-04],00  
0167:004068CA  JZ        004068D4   
0167:004068CC  MOV      ECX,[EBP-04]    
0167:004068CF  MOV      EAX,[ECX-04] 
0167:004068D2  JMP      004068D6 
0167:004068D4  XOR      EAX,EAX 
0167:004068D6  CMP      EBX,EAX    //ÒÀ´ÎÑ­»·n-1´Î£¬Ö»ÓÐÐÕÃûµÄ×îºóÒ»×Ö·ûû²Î¼ÓÔË
0167:004068D8  JL        00406898                                    (JUMP )  
0167:004068DA  FILD      DWORD PTR [EDI+000005C8]  //½«¶¨Öµ 61£¨Ê®½øÖÆ£©·Å½ø¸¡µã
¼Ä´æÆ÷ ST1 
0167:004068E0  FADD      REAL8 PTR [EBP-5C]    //½«61¼ÓÉÏÇ°n-1λµÄºÍ¡£³ÉΪm1 
0167:004068E3  FSTP      REAL8 PTR [EBP-5C] 
0167:004068E6  PUSH      01                  
0167:004068E8  LEA      EDX,[EBP-04] 
0167:004068EB  PUSH      EDX 

¢Úm2²¿·Ö¼ÆËã 
ST0  13237.                            ST4  empty   
ST1  empty                              ST5  empty 
ST2  empty                              ST6  empty 
ST3  empty                              ST7  empty
0167:00406929  ADD      EBX,[EBP-04]
0167:0040692C  DEC      EBX  
0167:0040692D  MOVSX    EDX,BYTE PTR [EBX] 
0167:00406930  AND      EDX,7F  
0167:00406933  POP      ECX     
0167:00406934  ADD      ECX,EDX      //ecx=ÊÇÐÕÃûµÚÒ»×Ö·û£¬edx=ÐÕÃûµÄµÚºóÒ»×Ö·û
0167:00406936  IMUL      ECX,[EDI+000005C8] //½«ÉÏÃæµÄ½á¹û³ËÒÔÊ®Áù½øÖÆÊý£º3D. ³ÉΪm2
0167:0040693D  MOV      [EBP-70],ECX  
0167:00406940  FILD      DWORD PTR [EBP-70] 
0167:00406943  FSTP      REAL8 PTR [EBP-64] 
0167:00406946  CMP      DWORD PTR [EBP-04],00 
0167:0040694A  JZ        00406954 
0167:0040694C  MOV      EAX,[EBP-04] 
0167:0040694F  MOV      EDX,[EAX-04]  
0167:00406952  JMP      00406956 

¢Ûm3µÄ¼ÆËã 
0167:0040695C  ADD      EAX,EAX  //EAXµÄÖµÊǶ¨Öµ£º3D£¨Ê®Áù½øÖÆ£©
0167:0040695E  ADD      EDX,EAX  //EDXÖµÊÇÐÕÃûµÄλÊýn  ¼ÆËãµÄ½á¹û¾ÍÊÇm3 
0167:00406960  MOV      [EBP-70],EDX  
0167:00406963  FILD      DWORD PTR [EBP-70] 
0167:00406966  FSTP      REAL8 PTR [EBP-6C] 
0167:00406969  MOV      WORD PTR [EBP-40],0038 
0167:0040696F  FLD      REAL8 PTR [EBP-6C] 
0167:00406972  CALL      004D5094 
0167:00406977  PUSH      EDX  
¢Ü  
167:00406A4E  XOR      ECX,ECX 
0167:00406A50  MOV      [EBP-2C],ECX 
0167:00406A53  LEA      ECX,[EBP-2C]
0167:00406A56  INC      DWORD PTR [EBP-34]
0167:00406A59  MOV      EAX,[EDI+000005DC]
0167:00406A5F  MOV      EDX,[EBP-08]                                          
0167:00406A62  CALL      004354D8  //½«ÊäÈëµÄ×¢²áÂëÓ붨ֵ67gjhab480klvn176 Òì»ò
ÔËË㣬ÒÔ½á¹ûK±íʾ 
0167:00406A67  LEA      EDX,[EBP-2C]
0167:00406A6A  LEA      EAX,[EBP-14] 
0167:00406A6D  CALL      004DC0F0  // ½«½á¹ûkÓëM±È½Ï  
0167:00406A72  PUSH      EAX  //ÈçÏàµÈEAX £½1  ,½«EAXÈëÕ»                     
0167:00406A73  DEC      DWORD PTR [EBP-34]
0167:00406A76  LEA      EAX,[EBP-2C] 
0167:00406A79  MOV      EDX,00000002
0167:00406A7E  CALL      004DC020                                      
0167:00406A83  POP      ECX //cl³öÕ»£¬¼´½«EAXµÄÖµ´«µ½cl  
0167:00406A84  TEST      CL,CL  //  ÈçÏàµÈcl =1 
0167:00406A86  JZ        00406A8C   
0167:00406A88  MOV      BYTE PTR [EBP-51],01 
0167:00406A8C  DEC      DWORD PTR [EBP-34] 
·µ»Ø
                         ¼üÅÌÓïÒôÌáʾ(InsTalk) V2.51°æ
                                         ³ÌʽÁÔÈË
¼ò½é£º¼üÅÌÓïÒôÌáʾ(InsTalk) V2.51°æÊÇÃæÏòWIN95,WINNTµÄ¹¤¾ßÈí¼þ¡£ÀûÓÃËüÓû§ÔÚʹÓÃ
¼üÅÌÊäÈëÊý×ÖºÍÓ¢ÎÄ×Ö·ûʱ£¬µçÄÔ¸½´øµÄÀ®°È¿ÉÒÔ¸úËæ¼ÈëµÄ×Ö·ûͬ²½·¢³öÏàÓ¦µÄÓïÒôÌáʾ
¡£Óû§¿ÉʹÓÃ×ÀÃæÉϵÄÉùÒôÈí¿ª¹Ø£¬Ëæʱ¿ªÆôºÍ¹Ø±ÕÉùÒô¡£ÎªÁ˱ÜÃâ¸÷ÖÖ¼Èë´íÎó£¬ÓïÒôÌá
ʾ»¹Óдí¼ü±¨¾¯¼°»Ø³µ¼üºÍСÊýµã·¢ÉùÌáʾµÄ¹¦ÄÜ¡£´ËÍ⣬ʹÓÃÈí¼þµÄ×Ô¶¯ÔĶÁ¹¦ÄÜ¿ÉÒÔ°Ñ
Ñ¡ÖеÄÎÄ×Ö£¨ÖÐÎÄ¡¢Êý×ÖÓ¢ÎÄ×ÖĸµÈ£©Í¨¹ýµçÄԵĶàýÌ幦Äܱä³ÉººÓï·¢ÒôÀʶÁ³öÀ´£¬ÒÔ¹©
ʹÓÃÕßÐÀÉÍ»ò½øÐÐУ¶Ô¡£±¾Èí¼þ¿ÉÔÚOFFICE97ÏÂÕý³£ÔËÐУ¬ÒªÇóµçÄÔÅäÖÃÉù¿¨ºÍÍâ½ÓÀ®°È¡£
×·×Ù£ºÎÒÔÚ2000-7-12°²×°Õâ¸öÈí¼þºó£¬ÌáʾÒѾ­¹ýÆÚ£¬ËùÒÔ¾ÍÆƽâµôÕâ¸öÈí¼þµÄtime bomb
¡£ÔÚÕâÀïʹÓÃTRWÔØÈëÕâ¸öÈí¼þ¡£
* Reference To: KERNEL32.GetModuleHandleA, Ord00FEh
                                  |
0040D7A6 FF155C324300            Call dword ptr [0043325C]
0040D7AC 50                      push eax
0040D7AD E805F40000              call 0041CBB7    <-³ö´í
0040D7B2 8945A0                  mov dword ptr [ebp-60], eax
0040D7B5 50                      push eax
0040D7B6 E8050A0000              call 0040E1C0
0040D7BB EB21                    jmp 0040D7DE
  ÔØÈëºó£¬×·×ÙËü£¬·¢ÏÖ³ÌÐò½«ÔÚÉÏÃæµÄµØ·½³ö´í£¬½øÈë¡£
0041CBB7 FF742410                push [esp+10]
0041CBBB FF742410                push [esp+10]
0041CBBF FF742410                push [esp+10]
0041CBC3 FF742410                push [esp+10]
0041CBC7 E898830000              call 00424F64
0041CBCC C21000                  ret 0010
 ûÓÐʲô¶à˵µÄ£¬½øÈëcall 00424F64
00424F64 56                      push esi
00424F65 57                      push edi
00424F66 83CFFF                  or edi, FFFFFFFF
00424F69 E8DF7D0000              call 0042CD4D
00424F6E FF742418                push [esp+18]
00424F72 8B7004                  mov esi, dword ptr [eax+04]
00424F75 FF742418                push [esp+18]
00424F79 FF742418                push [esp+18]
00424F7D FF742418                push [esp+18]
00424F81 E8CB8E0000              call 0042DE51
00424F86 85C0                    test eax, eax
00424F88 7437                    je 00424FC1
00424F8A 8B06                    mov eax, dword ptr [esi]
00424F8C 8BCE                    mov ecx, esi
00424F8E FF908C000000            call dword ptr [eax+0000008C]
00424F94 85C0                    test eax, eax
00424F96 7429                    je 00424FC1
00424F98 8B06                    mov eax, dword ptr [esi]
00424F9A 8BCE                    mov ecx, esi
00424F9C FF5058                  call [eax+58]   <-³ö´í
00424F9F 85C0                    test eax, eax
00424FA1 7515                    jne 00424FB8
00424FA3 8B4E1C                  mov ecx, dword ptr [esi+1C]
00424FA6 85C9                    test ecx, ecx
00424FA8 7405                    je 00424FAF
   ÔÚÉÏÃæ³ö´í£¬ÒòΪͨ¹ý¾­ÑéºÍÊÔÑéÖªµÀÖ»ÓнøÈëcallÖвÅÄÜÆƽâËü¡£½øÈë
0040306E 90                      nop
0040306F 90                      nop
00403070 64A100000000            mov eax, dword ptr fs:[00000000]

* Possible Reference to Dialog: DialogID_0081, CONTROL_ID00FF, ""
                                  |
00403076 6AFF                    push FFFFFFFF
00403078 684D104300              push 0043104D
0040307D 50                      push eax
0040307E 64892500000000          mov dword ptr fs:[00000000], esp
00403085 81EC40020000            sub esp, 00000240
0040308B 53                      push ebx
0040308C 56                      push esi
0040308D 57                      push edi
0040308E 8BD9                    mov ebx, ecx
00403090 6A00                    push 00000000
00403092 E8C8460000              call 0040775F
00403097 83C404                  add esp, 00000004
0040309A 8BCB                    mov ecx, ebx
0040309C E875A30200              call 0042D416

* Possible StringData Ref from Data Obj ->"InsTalk for ZRM"
                                  |
004030A1 68F4224400              push 004422F4
004030A6 6A00                    push 00000000

* Reference To: USER32.FindWindowA, Ord00CDh
                                  |
004030A8 FF157C354300            Call dword ptr [0043357C]
004030AE 85C0                    test eax, eax
004030B0 0F8547020000            jne 004032FD
004030B6 E885FFFFFF              call 00403040
004030BB 85C0                    test eax, eax
004030BD 7419                    je 004030D8
004030BF 6A30                    push 00000030
004030C1 68EC224400              push 004422EC
004030C6 6878224400              push 00442278
004030CB 6A00                    push 00000000

* Reference To: USER32.MessageBoxA, Ord:0195h
                                  |
004030CD FF1520354300            Call dword ptr [00433520]
004030D3 E925020000              jmp 004032FD

* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|004030BD(C)
|

* Possible StringData Ref from Data Obj ->"Happy Studio"
                                  |
004030D8 6868224400              push 00442268
004030DD 8BCB                    mov ecx, ebx
004030DF E896A00200              call 0042D17A
  MessageBoxAÕâ¸öº¯ÊýÏë±Ø´ó¼ÒÒ»¶¨±È½ÏÊìϤÁË°É£¬Ëü¾ÍÊdzöÏÖ´íÎóÌáʾµÄº¯Êý¡£ÄÇôֻ
Òª±Ü¿ªËü¾Í¿ÉÒÔÁË£¬ÏÖÔÚÉÏÃæÕýºÃÓÐÒ»¸öje£¬½øÈëcall 00403040
00403040 83EC10                  sub esp, 00000010
00403043 8D442400                lea eax, dword ptr [esp]
00403047 50                      push eax

* Reference To: KERNEL32.GetSystemTime, Ord:0135h
                                  |
00403048 FF1530324300            Call dword ptr [00433230]
0040304E 66817C2400CE07          cmp word ptr [esp], 07CE
00403055 7611                    jbe 00403068
00403057 66837C240202            cmp word ptr [esp+02], 0002
0040305D 7609                    jbe 00403068
0040305F B801000000              mov eax, 00000001
00403064 83C410                  add esp, 00000010
00403067 C3                      ret
   ÏÖÔÚ´ó¼Ò¿ÉÒÔ¿´µ½GetSystemTimeÕâ¸öº¯ÊýÁË°É£¬ËüÏÂÃæ¾ÍÓÐÒ»¸ö±È½ÏµÄµØ·½£¬ËùÒÔÖ»Òª
ÔÚÕâÀォjbe¸ÄΪjmp¾Í¿ÉÒÔÁË¡£

                 ********************************
                 *      ²éÕÒ£º00CE07761166837   *
                 *      Ìæ»»£º------EB-------   *
                 ********************************
 - ±íʾ²»ÓÃÌæ»»¡£
·µ»Ø

Èí¼þÃû³Æ£º  GIF Construction Set Pro
Èí¼þ°æ±¾£º  2.0a(Ptach 20) 
Èí¼þ´óС£º  4132KB 
Èí¼þÊÚȨ£º  ¹²ÏíÈí¼þ 
ʹÓÃƽ̨£º  Win95/98/NT 
·¢²¼¹«Ë¾£º  http:www.mindworkshop.com/alchemy/gifcon.html
Èí¼þ¼ò½é£º 
          ¿ìËÙ¡¢×¨ÒµµØ´´½¨ÎªÄãµÄÍøÒ³´´½¨Í¸Ã÷¡¢½»´íºÍ»î¶¯µÄGIFÎļþ¡£¶¯»­Ïòµ¼¿ÉÁí
ÄãÔÚ¼¸·ÖÖÓÖ®ÄÚ´´½¨¼«¾ß÷ÈÁ¦µÄWebͼÐΡ£
 
×÷    ÕߣºxiA Qin 
½âÃÜÈÕÇ°£º2000Äê8ÔÂ30ÈÕ
½âÃܹ¤¾ß£ºTrw2000 1.22
˵    Ã÷£ºÕâÊÇÎÒдµÄµÚһƪËã·¨·ÖÎöµÄÆÆÎÄ£¬ÄÑÃâÓдíÎó´æÔÚ£¬Íû¸÷λ´óÏÀÖ¸µã¡£ 
Õâ¸ö³ÌÐòÐèÒªÔÚ°²×°Ê±£¬¾ÍÐèÒªÊäÈë×¢²áÂëºÍ×¢²áÃû¡£ 

ÊäÈë×¢²áÐÅÏ¢£º
×¢²á Â룺11111-22-33333-44
×¢£ºÎªÁË·½±ã˵Ã÷£¬·ÖΪ4¶Î¡£ 
    µÚ1¶ÎΪ£º11111
    µÚ2¶ÎΪ£º22
    µÚ3¶ÎΪ£º33333
    µÚ4¶ÎΪ£º44
×¢²áÃû£ºChinese        #×Ö·ûÊý±ØÐë´óÓÚ5λÊý¡£ 
.............................. 
015F:00403163  PUSH    EAX
015F:00403164  LEA      EDX,[EBP+FFFFFBF4]
015F:0040316A  PUSH    EDX
015F:0040316B  CALL    00424508
015F:00403170  ADD      ESP,BYTE +08
015F:00403173  LEA      ECX,[EBP+FFFFFBF4]
015F:00403179  PUSH    ECX
015F:0040317A  PUSH    DWORD 0042FCB6
015F:0040317F  CALL    00424598
015F:00403184  ADD      ESP,BYTE +08
015F:00403187  MOV      DWORD [EBP-04],01
015F:0040318E  PUSH    DWORD 0042FCB6
015F:00403193  CALL    004245C8
015F:00403198  POP      ECX
015F:00403199  CMP      EAX,BYTE +11        ÓÖÒª¼ì²é×¢²áÂëλÊý£¬17λ¡£
015F:0040319C  JZ      004031A3            ²»ÏàµÈ£¬¾ÍÌø¡£
015F:0040319E  XOR      EAX,EAX
015F:004031A0  MOV      [EBP-04],EAX
015F:004031A3  CMP      DWORD [EBP-04],BYTE +00
015F:004031A7  JZ      00403203
015F:004031A9  XOR      EDX,EDX
015F:004031AB  MOV      [EBP-08],EDX
015F:004031AE  MOV      ESI,EDX
015F:004031B0  JMP      SHORT 004031D4
015F:004031B2  XOR      EAX,EAX                  ½«eaxÇåÁã¡£
015F:004031B4  MOV      AL,[ESI+0042F8B4]        ÒÀ´ÎÔØÈëÐÕÃû×Ö·û¡£
015F:004031BA  PUSH    EAX                     
015F:004031BB  CALL    00429FCC                  ½«´óдA~Zת»»ÎªÐ¡Ð´a~z¡£
015F:004031C0  POP      ECX                     
015F:004031C1  MOV      EDX,ESI               
015F:004031C3  AND      EDX,BYTE +07             
015F:004031C6  XOR      ECX,ECX                 
015F:004031C8  MOV      CL,[EDX+0042E088]       
015F:004031CE  XOR      EAX,ECX                   °ÑEAXºÍECX×öÒì»ò²Ù×÷£¬
015F:004031D0  ADD      [EBP-08],EAX              ÀÛ¼ÓÒì»ò²Ù×÷ [EBP-08]=[EBP-08]+EAX
015F:004031D3  INC      ESI                     
015F:004031D4  CMP      BYTE [ESI+0042F8B4],00    ȡϸö×Ö·û£¬µÈÓÚ00£¬¾Í½áÊø¼ÆËã¡£
015F:004031DB  JNZ      004031B2                  ±È½ÏÐÕÃû×Ö·ûÊÇ·ñ¼ÆËã½áÊø
015F:004031DD  MOV      EAX,[EBP-08]              ½«[EBP-08]µÄÖµÒÆÈë¼Ä´æÆ÷eaxÖÐ
015F:004031E0  MOV      ECX,64                    ½«16½øÖƵÄ64ÒÆÈë¼Ä´æÆ÷ECX
015F:004031E5  CDQ                                ÅжÏeaxÖеÄÖµÊÇ·ñ´óÓÚ80000000,
015F:004031E6  IDIV    ECX                      ÓÃEAXÓëECXÇóÓà.
015F:004031E8  MOV      ESI,EDX                  ÓàÊý´ÓEDXÒÆÈëESI¡£
Ò»¡¢Ëã·¨×ܽá: 
1¡¢Õⲿ·Ö¾ÍÊÇ°ÑÄãÊäÈëµÄ×¢²áÃûµÄÿ¸ö×Ö·û¶¼×ª³ÉÏàÓ¦µÄAsciiÂ룡
2¡¢È»ºó£¬ÓëÏà¶ÔÓ¦80 40 20 10 08 04 02 01½øÐÐÒì»ò¼ÆËã¡£ÔÙ½«¼ÆËãºóµÄÖµÀÛ¼Ó¡£ 
È»ºó×¢²áÃû´óÓÚ8룬¾ÍÑ­»·Ê¹ÓÃ80 40 20 10 08 04 02 01¡£
3¡¢Ö±µ½×¢²áÃû¼ÆËãÍê±ÏµÄÖµAÓë64ÇóÓà¡£µÃµ½B.Õâ¾ÍÊÇÎÒÃÇÐèÒªµÄÊǵÚ2¶Î×¢²áÂë 
4¡¢½«Bת»»³ÉÊ®½øÖÆÊý¾ÍÊÇ×¢²áÂ룬Õâ¾ÍÊÇÎÒÃÇÐèÒªµÄÊǵÚ2¶Î×¢²áÂë
¼ÆË㹫ʽ£º 
×¢:×¢²áÃûµÄµÚһλÓÃa1À´´úÌ棬µÚ¶þλÓÃa2À´´úÌ棬µÚÈýλÓÃa3À´´úÌæ......£¬ÒÔ´ÎÀàÍÆ¡£
(a1 xor 80)+(a2 xor 40)+(a3 xor 20)+(a4 xor 10)+(a5 xor 08)+(a6 xor 04)+(a7 xor 02) 
+(a8 xor 80)+(a9 xor 80)+(a10 xor 40)+(a10 xor 20)+(a11 xor 10)+(a12 xor 08).......=A
A IDIV 64=B 
½«Bת»»³ÉÊ®½øÖÆÊý¾ÍÊÇ×¢²áÂë. ÊǵÚ2¶Î×¢²áÂë¡£ 
¶þ¡¢¾ÙÀý˵Ã÷£º 
ÎÒÊäÈëµÄ×¢²áÃûÊÇchinese£¬Ëü¶ÔÓ¦µÄAsciiÈçÏ¡£ 
×Ö    ·û:  c  h  i  n  e s  e 
  Ascii: 63 68 69 6e 65 73 65  Óë80 40 20 10 08 04 02 ½øÐÐÒì»ò¼ÆËã
(63 xor 80)+(68 xor 40)+(69 xor 20)+(6e xor 10)+(65 xor 08)+(73 xor 04)+(65xor 02)= 
e3+28+49+7e+6d+77+67=31D
31D IDIV 64 =61 
61ת»»³ÉÊ®½øÖÆΪ97¡£  <<--µÚ2¶Î×¢²áÂë 
015F:004031EA  TEST    ESI,ESI 
015F:004031EC  JNZ      004031EF
015F:004031EE  INC      ESI
015F:004031EF  PUSH    DWORD 0042FCBC
015F:004031F4  CALL    0042A088
015F:004031F9  POP      ECX
015F:004031FA  CMP      ESI,EAX        ±È½Ï×¢²áÂë¡£
015F:004031FC  JZ      00403203        ²»ÏàµÈ£¬¾ÍÌø¡£
015F:004031FE  XOR      EAX,EAX
015F:00403200  MOV      [EBP-04],EAX
015F:00403203  CMP      DWORD [EBP-04],BYTE +00
015F:00403207  JZ      NEAR 0040328E
015F:0040320D  XOR      EDX,EDX
015F:0040320F  MOV      [EBP-08],EDX
015F:00403212  XOR      ESI,ESI
015F:00403214  JMP      SHORT 0040322F
015F:00403216  MOV      AL,[ESI+0042FCB6]    <<--|  11111
015F:0040321C  MOV      EDX,ESI                  |
015F:0040321E  AND      EDX,BYTE +07             |
015F:00403221  XOR      AL,[EDX+0042E088]        |
015F:00403227  XOR      ECX,ECX                  |
015F:00403229  MOV      CL,AL                    |
015F:0040322B  ADD      [EBP-08],ECX             |
015F:0040322E  INC      ESI                      |
015F:0040322F  CMP      BYTE [ESI+0042FCB6],00   |
015F:00403236  JZ      0040323D                |
015F:00403238  CMP      ESI,BYTE +05             |
015F:0040323B  JL      00403216            <<--|
015F:0040323D  XOR      ESI,ESI
015F:0040323F  JMP      SHORT 0040325A
015F:00403241  MOV      AL,[ESI+0042FCBF]    <<--|
015F:00403247  MOV      EDX,ESI                  | 33333
015F:00403249  AND      EDX,BYTE +07            |
015F:0040324C  XOR      AL,[EDX+0042E088]        |
015F:00403252  XOR      ECX,ECX                  |
015F:00403254  MOV      CL,AL                    |
015F:00403256  ADD      [EBP-08],ECX            |
015F:00403259  INC      ESI                      |
015F:0040325A  CMP      BYTE [ESI+0042FCBF],00  |
015F:00403261  JZ      00403268                |
015F:00403263  CMP      ESI,BYTE +05             |
015F:00403266  JL      00403241            <<--|
015F:00403268  MOV      EAX,[EBP-08]
015F:0040326B  MOV      ECX,64         
015F:00403270  CDQ   
015F:00403271  IDIV    ECX
015F:00403273  MOV      ESI,EDX
´Ë´¦µÄ¼ÆËã·½·¨»ù±¾Ïàͬ£¬²»Í¬µÄµØ·½ÊÇËüÊÇÓÃ×¢²áÂëµÄµÚ1¶Î(11111)ºÍµÚ3¶Î(33333)À´¼ÆËã¡£ 
                                                   
Ò»¡¢Ëã·¨×ܽá:
1¡¢°ÑÄãÊäÈëµÄ×¢²áÂëµÚ1¶Î(11111)µÄÿ¸ö×Ö·û¶¼×ª³ÉÏàÓ¦µÄAsciiÂ룡
2¡¢È»ºó£¬ÓëÏà¶ÔÓ¦80 40 20 10 08 ½øÐÐÒì»ò¼ÆËã¡£ÔÙ½«¼ÆËãºóµÄÖµAÀÛ¼Ó¡£
3¡¢°ÑÄãÊäÈëµÄ×¢²áÂëµÚ3¶Î(33333)µÄÿ¸ö×Ö·û¶¼×ª³ÉÏàÓ¦µÄAsciiÂ룡
4¡¢È»ºó£¬ÓëÏà¶ÔÓ¦80 40 20 10 08 ½øÐÐÒì»ò¼ÆËã¡£ÔÙ½«¼ÆËãºóµÄÖµBÀÛ¼Ó¡£
5¡¢Ö±µ½×¢²áÂë¼ÆËãÍê±ÏµÄÖµBÓë64ÇóÓà¡£µÃµ½C.Õâ¾ÍÊÇÎÒÃÇÐèÒªµÄ×¢²áÂëC¡£
6¡¢½«Cת»»³ÉÊ®½øÖÆÊý¾ÍÊÇ×¢²áÂ룬Õâ¾ÍÊÇÎÒÃÇÐèÒªµÄµÚ4¶Î×¢²áÂë¡£
¼ÆË㹫ʽ£º 
×¢:×¢²áÂëµÚ1¶Î(11111)µÄµÚһλÓÃa1À´´úÌ棬µÚ¶þλÓÃa2À´´úÌ棬µÚÈýλÓÃa3À´´úÌæ.....
.£¬ÒÔ´ÎÀàÍÆ
  ×¢²áÂëµÚ3¶Î(33333)µÄµÚһλÓÃb1À´´úÌ棬µÚ¶þλÓÃb2À´´úÌ棬µÚÈýλÓÃb3À´´úÌæ......
£¬ÒÔ´ÎÀàÍÆ
(a1 xor 80)+(a2 xor 40)+(a3 xor 20)+(a4 xor 10)+(a5 xor 08)=A 
A+(b1 xor 80)+(b2 xor 40)+(b3 xor 20)+(b4 xor 10)+(b5 xor 08)=B 
B IDIV 64=C 
½«Cת»»³ÉÊ®½øÖÆÊý¾ÍÊÇ×¢²áÂë. 
¶þ¡¢¾ÙÀý˵Ã÷£º 
ÎÒÊäÈëµÄ×¢²áÂëµÚ1¶ÎÊÇ11111¡¢µÚ2¶Î33333¡£
(31 xor 80)+(31 xor 40)+(31 xor 20)+(31 xor 10)+(31 xor 08)=B1+71+11+21+39=18D 
18D+(33 xor 80)+(33 xor 40)+(33 xor 20)+(33 xor 10)+(33 xor 08)=18D+B3+73+13+23+3B=324 
324 IDIV 64=04 

04ת»»³ÉÊ®½øÖÆΪ04¡£<<--µÚ4¶Î×¢²áÂë¡£

015F:00403275  TEST    ESI,ESI
015F:00403277  JNZ      0040327A
015F:00403279  INC      ESI
015F:0040327A  PUSH    DWORD 0042FCC5
015F:0040327F  CALL    0042A088
015F:00403284  POP      ECX
015F:00403285  CMP      ESI,EAX               ? eax 44  ÊÇÊäÈëµÄ×¢²áÂë.
015F:00403287  JZ      0040328E                ? esi 04    ÕýÈ·µÄ×¢²áÂë.
015F:00403289  XOR      EAX,EAX
015F:0040328B  MOV      [EBP-04],EAX
015F:0040328E  CMP      DWORD [EBP-04],BYTE +00
015F:00403292  JNZ      004032A6
015F:00403294  PUSH    DWORD 00430FCC
015F:00403299  PUSH    EBX
015F:0040329A  CALL    004038FD              ÃÜÂëʧ°Ü¶Ô»°¿ò
015F:0040329F  ADD      ESP,BYTE +08
015F:004032A2  XOR      EAX,EAX
015F:004032A4  JMP      SHORT 00403310
.........................

ͨ¹ýÒÔÉÏ·ÖÎö¿ÉÒÔÖªµÀ£¬Õâ¸ö³ÌÐòÊÇÓÃ×¢²á²áÃû¼ÆËãµÚ2¶Î×¢²áÂð¡£ÓõÚ1¶ÎºÍµÚ3¶ÎÀ´¼ÆËã
µÚ4¶Î×¢²áÂë¡£
Ò²¾ÍÊÇ˵£¬×¢²áÂëµÚ2¶Î£¬Í¬×¢²áÃûÓйء£ 
          ×¢²áÂëµÚ4¶Î£¬Í¬×¢²áÂëµÚ1¶ÎºÍµÚ3¶ÎÓйء£
ÕûÀíһϣº 
×¢²áÂ룺11111-97-33333-04 
×¢²áÃû£ºChinese
ÂÞÂÞàÂིÁËÒ»´ó¶Ñ£¬Ï£Íû´ó¼ÒÄܹ»Ã÷°×ÎÒµÄÒâ˼!
·µ»Ø
%¡¾³õѧÌìµØ¡¿
                    ½âÃ̳̰ܽË
                         ³ÌʽÁÔÈË
   ÓÖµ½ÁËÎÒÃǽâÃܳõѧÕßÌìµØµÄʱ¼äÁË£¬ÎÒÒ²²»ÖªµÀ´ó¼Ò¶ÔÕâ¸ö½âÃÜÀí½âµÄÈçºÎ£¬ÎÒÒ²Ö»
ÄÜÂÛ¾Ý×Ô¼ºµÄ½âÃܾ­Ñé½éÉܸø´ó¼ÒÁË¡£
    Ç°ÌìÊÕµ½Ò»Î»ÍøÓѵÄÀ´ÐÅ˵£¬ÈÃÎÒÔÚ½âÃ̳ܽÌÖнéÉÜһϻã±àÓïÑÔ¡£µ±È»¶ÔÓÚ»ã±àÓïÑÔ
À´Ëµ£¬ÊǽâÃÜÕß±ØÐèÕÆÎյģ¬Èç¹ûÄãÏë³ÉΪһ¸ö½âÃÜÕߣ¬ÄãÁ¬»ã±à¶¼²»»á£¬Ä㻹Ïëѧϰ½âÃÜ
£¬ÄÇÊDz»¿ÉÄܵġ£ÄÇô´ó¼ÒÈçºÎÀ´Ñ§Ï°»ã±àÄØ£¿ÎÒÏë¶ÔÓÚ³õѧÕßÀ´Ëµ£¬ÏëÒªÍêÈ«ÕÆÎÕ»ã±àµÃ
»¨Çຣʡʱ¼äÀ´Ñ§Ï°Ëü£¬±Ï¾¹»ã±àÊÇÒ»¸ö±È½ÏÄѵıà³ÌÓïÑÔ¡£ÎÒÔÚÕâÀïÏëÏòÄãÃdzõѧÕß˵һ
¸öÎÊÌ⣬ÎÞÂÛÄãÊdzõѧÕßÕß»¹ÊǸßÊÖÀ´Ëµ£¬×Ô¼º±Ø±¸µÄÊéÖÁÉÙ¾ÍÊÇ»ã±àÊéÁË¡£ÆäËüµÄ¶«Î÷Äã
¿ÉÒÔµ½ÍøÉÏѧϰ£¬µ«ÊÇÕâ¸ö»ã±àÊéÒ»¶¨ÒªÈËÊÖÒ»±¾£¬ËüÎÞÂÛÈçºÎ¶¼×îΪ»ù±¾µÄ¶«Î÷¡£
   ÄÇô¶ÔÓÚÎÒÃǽâÃÜÕßÀ´Ëµ£¬»ã±àÒªÕÆÎÕµ½Ê²Ã´Ë®Æ½ÄØ£¿ÎÒ¸æËß´ó¼Òµ±È»ÊÇÔ½¶à³¬ºÃ£¬¿É
ÊǶÔÓÚÏ뼸Ìì¿´µ½³É¼¨µÄÈËÀ´Ëµ£¬Ñ§Ï°ÏÂÃæµÄ¶«Î÷¾Í¿ÉÒÔÈÃÄã¶Ô¸ºÒ»ÏÂÁË¡£
    MOV AA,BB    ½« BB ·Åµ½ AA Àï
    CALL         µ÷ÓÃ×Ó³ÌÐò (Ï൱ÓÚ BASIC µÄ GOSUB)
    RET Óë RETF  ·µ»Ø³ÌÐò   (Ï൱ÓÚ BASIC µÄ RETURN)
    CMP XX,YY    ±È½Ï XX Óë YY
    JZ           ÈôÏàµÈÔòתÒÆ
    JNZ          Èô²»ÏàµÈÔòתÒÆ
    JB           ÈôСÓÚÔòתÒÆ
    JG           Èô´óÓÚÔòתÒÆ
    JMP          ÎÞÌõ¼þתÒÆ
    J???         (¸÷ÖÖתÒÆÖ¸Áî)
    LOOP         Ñ­»·
    INT XX       ÀàËÆ CALL µÄÖжϺ­Êý
¡¡¡¡PUSH ÍÆÈëÕ»£¨STACK£©ESP£ºPUSH AX
¡¡¡¡POP ³öÕ»ESP£ºPOP CX
¡¡¡¡XCHG ½»»»ESP£ºXCHG AX£¬BX
¡¡¡¡IN¡¢OUT ÓëPORTÓйصÄIN/OUT
¡¡¡¡XLAT ²é±í
¡¡¡¡LEA ¶ÎÄÚÆ«ÒÆÁ¿¡£ESP£ºLEA AX£¬AREA1=MOV AX£¬OFFSET AREA1
¡¡¡¡LAHF¡¢SAHFÓëÆå±êÓйصļĴæÆ÷ AH
¡¡¡¡PUSHF¡¢POPF½«Æå±êÈë/³öÕ»
¡¡¡¡ADD ESP ADD AX£¬CX £¨AX=AX+CX£©
¡¡¡¡ADC ¼ÓÈëÆå±êCµÄADD
¡¡¡¡INC ESP INC AX£¨AX=AX+1£©
¡¡¡¡AAA ¼Ó·¨Ð£Õý
¡¡¡¡SUB¡¢SBB ¼õ·¨
¡¡¡¡DEC ESP£º DEC AX£¨AX=AX-1£©
¡¡¡¡NEG È¥²¹£¬
¡¡¡¡MUL¡¢IMUL ³Ë
¡¡¡¡DIV¡¢IDIV ³ý
¡¡¡¡SHR¡¢SAR¡¢SHL ËãÊõ¡¢Âß¼­Î»ÒÆR=RIGHT L=LEFT
¡¡¡¡OR¡¢XOR¡¢AND Âß¼­ÔËËã ESP £ºXOR AX£¬AX£¨AX=0£©
Ö±½Ó±ê־תÒÆ
Ö¸Áî¸ñʽ  »úÆ÷Âë  ²âÊÔÌõ¼þ  Èç...ÔòתÒÆ ¡¡
¡¡ JC      72      C=1        Óнøλ
   JNS     79      S=0        ÕýºÅ
   JNC     73      C=0        ÎÞ½øλ
   JO      70      O=1        ÓÐÒç³ö
   JZ/JE   74      Z=1        Áã/µÈÓÚ
   JNO     71      O=0        ÎÞÒç³ö
   JNZ/JNE 75      Z=0        ²»ÎªÁã/²»µÈÓÚ
   JP/JPE  7A      P=1        ÆæżλΪż
   JS      78      S=1        ¸ººÅ
   JNP/IPO 7B      P=0        ÆæżλΪÆæ
¼ä½Ó±ê־תÒÆ
Ö¸Áî¸ñʽ                »úÆ÷Âë         ²âÊÔ¸ñʽ            Èç...ÔòתÒÆ 
JA/JNBE(±È½ÏÎÞ·ûºÅÊý)   77             C»òZ=0 > ¡¡         ¸ßÓÚ/²»µÍÓÚ»òµÈÓÚ
JAE/JNB(±È½ÏÎÞ·ûºÅÊý)   73             C=0 >=¡¡            ¸ßÓÚ»òµÈÓÚ/²»µÍÓÚ
JB/JNAE(±È½ÏÎÞ·ûºÅÊý)   72             C=1 <       ¡¡      µÍÓÚ/²»¸ßÓÚ»òµÈÓÚ
JBE/JNA(±È½ÏÎÞ·ûºÅÊý)   76             C»òZ=1 <=  ¡¡       µÍÓÚ»òµÈÓÚ/²»¸ßÓÚ
JG/JNLE(±È½Ï´ø·ûºÅÊý)   7F             (SÒì»òO£©»òZ=0 >  ¡¡´óÓÚ/²»Ð¡ÓÚ»òµÈÓÚ
JGE/JNL(±È½Ï´ø·ûºÅÊý)   7D             SÒì»òO=0 >=¡¡       ´óÓÚ»òµÈÓÚ/²»Ð¡ÓÚ
JL/JNGE(±È½Ï´ø·ûºÅÊý)   7C             SÒì»òO=1 < ¡¡       СÓÚ/²»´óÓÚ»òµÈÓÚ
JLE/JNG(±È½Ï´ø·ûºÅÊý)   7E             (SÒì»òO)»òZ=1 <=¡¡  СÓÚ»òµÈÓÚ/²»´óÓÚ
ÎÞÌõ¼þתÒÆÖ¸ÁîJMP
Ö¸Áî¸ñʽ                   Ö´ÐвÙ×÷               »úÆ÷Âë     ˵Ã÷ 
¶ÎÄÚÖ±½Ó¶ÌתÒÆJmp short    (IP)¡û(IP)+8λλÒÆÁ¿   EB         תÒÆ·¶Î§-128µ½+127×Ö½Ú
¶ÎÄÚÖ±½Ó½üתÒÆJmp near     (IP)¡û(IP)+16λλÒÆÁ¿  E9         תÒƵ½¶ÎÄÚµÄÈÎһλÖÃ
¶ÎÄÚ¼ä½ÓתÒÆJmp word       (IP)¡û(ÓÐЧµØÖ·EA)     FF
¶Î¼äÖ±½Ó(Ô¶)תÒÆJmp far    (IP)¡û(Æ«ÒƵØÖ·)
                           (CS)¡û(¶ÎµØÖ·)         EA
¶Î¼ä¼ä½ÓתÒÆ Jmp           dword (IP)¡û(EA)
                           (CS)¡û(EA+2)
 ×ÛºÏʹÓûã±àÀ´½øÐбȽϵÄ×éºÏ£º
1
     mov  eax [      ]  ÕâÀï¿ÉÒÔÊǵØÖ·£¬Ò²¿ÉÒÔÊÇÆäËü¼Ä´æÆ÷
     mov  edx [      ]  ͬÉÏ  ͨ³£ÕâÁ½¸öµØÖ·¾Í´¢´æ×ÅÖØÒªÐÅÏ¢
     call 00??????
     test eax eax
     jz(jnz)
2
     mov  eax [      ]  ÕâÀï¿ÉÒÔÊǵØÖ·£¬Ò²¿ÉÒÔÊÇÆäËü¼Ä´æÆ÷
     mov  edx [      ]  ͬÉÏ  ͨ³£ÕâÁ½¸öµØÖ·¾Í´¢´æ×ÅÖØÒªÐÅÏ¢
     call 00??????
     jne(je)
 3
   mov eax [   ]
   mov edx [   ]
   cmp eax,edx
   jnz(jz)
»òÕß
begin  mov al [   ]
       mov cl [   ]
       cmp al,cl
       jnz(jz)
       mov al [  +1]
       mov cl [  +1]
       cmp al,cl
       jnz(jz)
       cmp eax ecx (eaxΪ¼ÆÊýÆ÷£©
       jnl begin
       mov al 01
4
     lea edi [    ]
     lea esi [    ]
     repz cmpsd
     jz(jnz)
5
     mov  eax [      ]  ÕâÀï¿ÉÒÔÊǵØÖ·£¬Ò²¿ÉÒÔÊÇÆäËü¼Ä´æÆ÷
     mov  edx [      ]  ͬÉÏ  ͨ³£ÕâÁ½¸öµØÖ·¾Í´¢´æ×ÅÖØÒªÐÅÏ¢
     call 00??????
     setz (setnz) al (bl,cl¡­)
6
     mov  eax [      ]  ÕâÀï¿ÉÒÔÊǵØÖ·£¬Ò²¿ÉÒÔÊÇÆäËü¼Ä´æÆ÷
     mov  edx [      ]  ͬÉÏ  ͨ³£ÕâÁ½¸öµØÖ·¾Í´¢´æ×ÅÖØÒªÐÅÏ¢
     call 00??????
     test eax eax
     setz (setnz) bl,cl¡­
7
     call 00??????  ***
     push eax (ebx,ecx¡­)
     ¡­¡­
     ¡­¡­
     call 00??????
     pop eax (ebx,ecx¡­)
     test eax eax
     jz(jnz)
     Õâ¸öÐÎʽ±È½ÏÌرð£¬ËüµÄ¹Ø¼ü±È½ÏµØ·½ÖÐÔÚµÚ¶þcallÖУ¬¶øÊÇÔÚµÚÒ»callÖУ¬´ó¼ÒÒ»
¿´¾ÍÖªµÀÁË¡£
  ˵µ½ÕâÀïÎÒÏëÆäËü¾ÍÊÇÄãÃÇÊÂÇéÁË£¬¾ÍÊÇŬÁ¦Ñ§Ï°ÁË¡£
  ÔÙ¼ûÁË
·µ»Ø
O¡¾ÎÊÌâ´ðÒÉ¡¿
 
·µ»Ø
4¡¾ÍøÕ¾½éÉÜ¡¿
°ËצÓãÍøÕ¾£ºhttp://fwd.yeah.net »òhttp://www.8bn.com/fwd/

½ñÌìÏò´ó¼Ò½éÉܵÄÊÇÕâ¸ö³öÃûµÄ°ËצÓãÍøÕ¾£¬Õâ¸öÍøÕ¾µÄÀ¸Ä¿ÈçÏ£º

¹ú²úÈí¼þ ×¢ ²á Âë ¹úÍâÈí¼þ ÆƽâÎÄÏ× Æƽ⹤¾ß ¹ÉƱÈí¼þ ɱ¶¾Èí¼þ ÔÓÖ¾Æƽ⠿ÚÁîÆƽâ Íøҳ׬Ǯ ÓÑÇéÁ´½Ó ÂÛ Ì³ ÊÒ

´ó¼Ò¿´µ½ÁË°É£¬ËüÊÇÒ»¸öÏ൱ºÃµÄÆƽâÍøÕ¾£¬¹â´ÓËüµÄÀ¸Ä¿ÖоͿÉÒÔ¿´µ½Õâ¸öÍøÕ¾Ïò´ó¼ÒÌṩÁ˺ܶàµÄ·þÎñ£¬Èç¹ûÄã¡­¡­£¬ÎÒÏë´ó¼ÒÔÚ½âÃÜ·½ÃæÓÈÆäÊÇÔÚ×¢²áÂë·½ÃæËû¿ÉÊÇÒ»¸ö±È½ÏºÃµÄµØ·½£¬Èç¹û´ó¼ÒÏëÒª²éÕÒÒ»¸ö×¢²áÂëµÄ»°£¬ÔÚÆäËüµØ·½²éÕÒ²»µ½µÄ£¬Äã×îºóÀ´ÕâÀïÊÔÒ»ÊÔ£¬ÎÒÏëÄã»áÂúÒâ¶ø¹éµÄ¡£

·µ»Ø
,¡¾ÔÓÖ¾ÐÅÏä¡¿
Ͷ¸åÐÅÏ䣺discoveredit@china.com
´ðÒÉÐÅÏ䣺discoveranswer@china.com
°ßÖñÐÅÏ䣺programhunter@china.com
·µ»Ø