本帖最后由 LeyBc 于 2024-4-29 11:56 编辑
第1个跳转长度对比 nop掉
第2个跳转是注册码对比 直接jmp
[Asm] 纯文本查看 复制代码 00FC742F . 8B4424 40 MOV EAX, DWORD PTR SS:[ESP+0x40]
00FC7433 . 8378 04 06 CMP DWORD PTR DS:[EAX+0x4], 0x6
00FC7437 75 25 JNZ SHORT 00FC745E
00FC7439 . 8B00 MOV EAX, DWORD PTR DS:[EAX]
00FC743B . 8D0D E8F8FD00 LEA ECX, DWORD PTR DS:[0xFDF8E8] ; 123456StringFormat[]byte' for string390625uint16uint32uint64structchan<-<-chan ValueGetACPsysmontimersefenceselect, not object next= jobs= goid sweep B -> % util alloc free span= prev= list=, i = code= addr= m->p= p->m=SCHED curg= ctxt: min= max= (..
00FC7441 . 890C24 MOV DWORD PTR SS:[ESP], ECX
00FC7444 . 894424 04 MOV DWORD PTR SS:[ESP+0x4], EAX
00FC7448 . C74424 08 06000000 MOV DWORD PTR SS:[ESP+0x8], 0x6
00FC7450 . E8 6BBBF6FF CALL 00F32FC0
00FC7455 . 0FB64424 0C MOVZX EAX, BYTE PTR SS:[ESP+0xC]
00FC745A . 84C0 TEST AL, AL
00FC745C 75 56 JNZ SHORT 00FC74B4
00FC745E > C74424 28 00000000 MOV DWORD PTR SS:[ESP+0x28], 0x0
00FC7466 . C74424 2C 00000000 MOV DWORD PTR SS:[ESP+0x2C], 0x0
[Asm] 纯文本查看 复制代码 00FC7433 . 8378 04 06 CMP DWORD PTR DS:[EAX+0x4], 0x6
00FC7437 90 NOP
00FC7438 90 NOP
00FC7439 . 8B00 MOV EAX, DWORD PTR DS:[EAX]
00FC743B . 8D0D E8F8FD00 LEA ECX, DWORD PTR DS:[0xFDF8E8] ; 123456StringFormat[]byte' for string390625uint16uint32uint64structchan<-<-chan ValueGetACPsysmontimersefenceselect, not object next= jobs= goid sweep B -> % util alloc free span= prev= list=, i = code= addr= m->p= p->m=SCHED curg= ctxt: min= max= (..
00FC7441 . 890C24 MOV DWORD PTR SS:[ESP], ECX
00FC7444 . 894424 04 MOV DWORD PTR SS:[ESP+0x4], EAX
00FC7448 . C74424 08 06000000 MOV DWORD PTR SS:[ESP+0x8], 0x6
00FC7450 . E8 6BBBF6FF CALL 00F32FC0
00FC7455 . 0FB64424 0C MOVZX EAX, BYTE PTR SS:[ESP+0xC]
00FC745A . 84C0 TEST AL, AL
00FC745C EB 56 JMP SHORT 00FC74B4
00FC745E > C74424 28 00000000 MOV DWORD PTR SS:[ESP+0x28], 0x0
00FC7466 . C74424 2C 00000000 MOV DWORD PTR SS:[ESP+0x2C], 0x0
对比一下
|