|
马上注册,结交更多好友,享用更多功能^_^
您需要 登录 才可以下载或查看,没有账号?立即注册
x
ADVAPI32.RegCloseKey
ADVAPI32.RegCreateKeyExA
ADVAPI32.RegDeleteKeyA
ADVAPI32.RegDeleteValueA
ADVAPI32.RegOpenKeyExA
ADVAPI32.RegQueryValueExA
ADVAPI32.RegSetValueExA
COMCTL32.CreatePropertySheetPageA
COMCTL32.DestroyPropertySheetPage
COMCTL32.ImageList_Create
COMCTL32.ImageList_Destroy
COMCTL32.ImageList_Draw
COMCTL32.ImageList_DrawEx
COMCTL32.ImageList_GetIcon
COMCTL32.ImageList_GetImageCount
COMCTL32.ImageList_Remove
COMCTL32.ImageList_ReplaceIcon
COMCTL32.InitCommonControls
COMCTL32.PropertySheetA
comdlg32.ChooseColorA
comdlg32.ChooseFontA
comdlg32.GetFileTitleA
comdlg32.GetOpenFileNameA
comdlg32.GetSaveFileNameA
GDI32.CreateBitmap
GDI32.CreateCompatibleDC
GDI32.CreateFontIndirectA
GDI32.CreatePen
GDI32.CreateSolidBrush
GDI32.DeleteDC
GDI32.DeleteObject
GDI32.Escape
GDI32.ExtTextOutA
GDI32.GetClipBox
GDI32.GetDeviceCaps
GDI32.GetObjectA
GDI32.GetStockObject
GDI32.GetTextExtentPointA
GDI32.LineTo
GDI32.MoveToEx
GDI32.OffsetViewportOrgEx
GDI32.PtVisible
GDI32.RectVisible
GDI32.RestoreDC
GDI32.SaveDC
GDI32.ScaleViewportExtEx
GDI32.ScaleWindowExtEx
GDI32.SelectObject
GDI32.SetBkColor
GDI32.SetMapMode
GDI32.SetROP2
GDI32.SetTextColor
GDI32.SetViewportExtEx
GDI32.SetViewportOrgEx
GDI32.SetWindowExtEx
GDI32.TextOutA
KERNEL32.CloseHandle
KERNEL32.CompareStringA
KERNEL32.CompareStringW
KERNEL32.CopyFileA
KERNEL32.CreateFileA
KERNEL32.DeleteCriticalSection
KERNEL32.DeleteFileA
KERNEL32.DuplicateHandle
KERNEL32.EnterCriticalSection
KERNEL32.ExitProcess
KERNEL32.ExpandEnvironmentStringsA
KERNEL32.FileTimeToDosDateTime
KERNEL32.FileTimeToLocalFileTime
KERNEL32.FileTimeToSystemTime
KERNEL32.FindClose
KERNEL32.FindFirstFileA
KERNEL32.FindNextFileA
KERNEL32.FindResourceA
KERNEL32.FlushFileBuffers
KERNEL32.FreeEnvironmentStringsA
KERNEL32.FreeEnvironmentStringsW
KERNEL32.FreeLibrary
KERNEL32.GetACP
KERNEL32.GetCommandLineA
KERNEL32.GetCPInfo
KERNEL32.GetCurrentProcess
KERNEL32.GetCurrentThread
KERNEL32.GetCurrentThreadId
KERNEL32.GetDateFormatA
KERNEL32.GetDriveTypeA
KERNEL32.GetEnvironmentStrings
KERNEL32.GetEnvironmentStringsW
KERNEL32.GetFileAttributesA
KERNEL32.GetFileSize
KERNEL32.GetFileTime
KERNEL32.GetFileType
KERNEL32.GetFullPathNameA
KERNEL32.GetLastError
KERNEL32.GetLocaleInfoA
KERNEL32.GetLocaleInfoW
KERNEL32.GetLocalTime
KERNEL32.GetModuleFileNameA
KERNEL32.GetModuleHandleA
KERNEL32.GetOEMCP
KERNEL32.GetPrivateProfileStringA
KERNEL32.GetProcAddress
KERNEL32.GetProcessVersion
KERNEL32.GetShortPathNameA
KERNEL32.GetStartupInfoA
KERNEL32.GetStdHandle
KERNEL32.GetStringTypeA
KERNEL32.GetStringTypeW
KERNEL32.GetTempPathA
KERNEL32.GetTimeFormatA
KERNEL32.GetTimeZoneInformation
KERNEL32.GetVersion
KERNEL32.GetVersionExA
KERNEL32.GetVolumeInformationA
KERNEL32.GetWindowsDirectoryA
KERNEL32.GlobalAddAtomA
KERNEL32.GlobalAlloc
KERNEL32.GlobalDeleteAtom
KERNEL32.GlobalFlags
KERNEL32.GlobalFree
KERNEL32.GlobalGetAtomNameA
KERNEL32.GlobalHandle
KERNEL32.GlobalLock
KERNEL32.GlobalReAlloc
KERNEL32.GlobalUnlock
KERNEL32.HeapAlloc
KERNEL32.HeapCreate
KERNEL32.HeapDestroy
KERNEL32.HeapFree
KERNEL32.HeapReAlloc
KERNEL32.HeapSize
KERNEL32.InitializeCriticalSection
KERNEL32.InterlockedDecrement
KERNEL32.InterlockedIncrement
KERNEL32.IsBadCodePtr
KERNEL32.IsBadReadPtr
KERNEL32.IsBadWritePtr
KERNEL32.LCMapStringA
KERNEL32.LCMapStringW
KERNEL32.LeaveCriticalSection
KERNEL32.LoadLibraryA
KERNEL32.LoadResource
KERNEL32.LocalAlloc
KERNEL32.LocalFree
KERNEL32.LocalReAlloc
KERNEL32.LockFile
KERNEL32.LockResource
KERNEL32.lstrcatA
KERNEL32.lstrcmpA
KERNEL32.lstrcmpiA
KERNEL32.lstrcpyA
KERNEL32.lstrcpynA
KERNEL32.lstrlenA
KERNEL32.MoveFileA
KERNEL32.MulDiv
KERNEL32.MultiByteToWideChar
KERNEL32.OpenProcess
KERNEL32.RaiseException
KERNEL32.ReadFile
KERNEL32.RtlUnwind
KERNEL32.SetEndOfFile
KERNEL32.SetEnvironmentVariableA
KERNEL32.SetErrorMode
KERNEL32.SetFilePointer
KERNEL32.SetHandleCount
KERNEL32.SetLastError
KERNEL32.SetStdHandle
KERNEL32.SetUnhandledExceptionFilter
KERNEL32.Sleep
KERNEL32.SystemTimeToFileTime
KERNEL32.TerminateProcess
KERNEL32.TlsAlloc
KERNEL32.TlsGetValue
KERNEL32.TlsSetValue
KERNEL32.UnhandledExceptionFilter
KERNEL32.UnlockFile
KERNEL32.VirtualAlloc
KERNEL32.VirtualFree
KERNEL32.WideCharToMultiByte
KERNEL32.WinExec
KERNEL32.WriteFile
KERNEL32.WritePrivateProfileStringA
ole32.CoCreateInstance
ole32.CoInitialize
ole32.CoUninitialize
ole32.OleInitialize
PPro.DisableHotKeys
PPro.GetAModuleFileName
PPro.GetTrayMonitorHwnd
PPro.TrayMonitor
SHELL32.DragFinish
SHELL32.DragQueryFileA
SHELL32.ExtractIconExA
SHELL32.FindExecutableA
SHELL32.SHAppBarMessage
SHELL32.SHBrowseForFolderA
SHELL32.ShellExecuteExA
SHELL32.SHGetDesktopFolder
SHELL32.SHGetFileInfoA
SHELL32.SHGetMalloc
SHELL32.SHGetPathFromIDListA
USER32.AdjustWindowRectEx
USER32.AppendMenuA
USER32.BeginDeferWindowPos
USER32.BeginPaint
USER32.BringWindowToTop
USER32.CallNextHookEx
USER32.CallWindowProcA
USER32.CharLowerA
USER32.CharUpperA
USER32.CheckDlgButton
USER32.CheckMenuItem
USER32.ClientToScreen
USER32.CopyImage
USER32.CopyRect
USER32.CreateDialogIndirectParamA
USER32.CreateDialogParamA
USER32.CreatePopupMenu
USER32.CreateWindowExA
USER32.DeferWindowPos
USER32.DefWindowProcA
USER32.DestroyIcon
USER32.DestroyMenu
USER32.DestroyWindow
USER32.DialogBoxParamA
USER32.DispatchMessageA
USER32.DrawFocusRect
USER32.DrawTextA
USER32.EnableMenuItem
USER32.EnableWindow
USER32.EndDeferWindowPos
USER32.EndDialog
USER32.EndPaint
USER32.EnumWindows
USER32.EqualRect
USER32.FillRect
USER32.FindWindowA
USER32.GetActiveWindow
USER32.GetAsyncKeyState
USER32.GetCapture
USER32.GetClassInfoA
USER32.GetClassLongA
USER32.GetClassNameA
USER32.GetClientRect
USER32.GetCursorPos
USER32.GetDC
USER32.GetDesktopWindow
USER32.GetDlgCtrlID
USER32.GetDlgItem
USER32.GetDlgItemInt
USER32.GetDlgItemTextA
USER32.GetFocus
USER32.GetForegroundWindow
USER32.GetKeyboardLayout
USER32.GetKeyboardState
USER32.GetKeyState
USER32.GetLastActivePopup
USER32.GetMenu
USER32.GetMenuCheckMarkDimensions
USER32.GetMenuItemCount
USER32.GetMenuItemID
USER32.GetMenuState
USER32.GetSysColor
USER32.GetSysColorBrush
0042F7C7 . /74 5E je short 0042F827 好像行了
762EC124 FF15 BC002D76 call dword ptr [<&ntdll.NtCallbackReturn>] ; ntdll_1.ZwCallbackReturn
740C2320 EA 1E270C74 330>jmp far 0033:740C271E
43B08AAF FF15 A011AE73 call dword ptr [<&GDI32.SetBkColor>] ; gdi32.SetBkColor
43B08D9E 8B73 10 mov esi, dword ptr [ebx+0x10]
43B08DA1 8BBD D8FEFFFF mov edi, dword ptr [ebp-0x128]
43B08DA7 8BCE mov ecx, esi
43B08DA9 E8 BCDBFFFF call 43B0696A
43B08DAE 84C0 test al, al
43B08DB0 74 47 je short 43B08DF9
43B08DB2 8B46 3C mov eax, dword ptr [esi+0x3C]
43B08DB5 C1E8 0C shr eax, 0xC
43B08DB8 24 01 and al, 0x1
43B08DBA 0F85 8A170000 jnz 43B0A54A
43B08DC0 84C0 test al, al
43B08DC2 75 1A jnz short 43B08DDE
43B08DC4 8B86 58010000 mov eax, dword ptr [esi+0x158]
43B08DCA 8B40 08 mov eax, dword ptr [eax+0x8]
43B08DCD FFB5 D0FEFFFF push dword ptr [ebp-0x130]
43B08DD3 8B40 50 mov eax, dword ptr [eax+0x50]
43B08DD6 50 push eax
43B08DD7 E8 FB950000 call DPA_GetPtr
43B08DDC 8BF8 mov edi, eax
43B08DDE FFB5 D4FEFFFF push dword ptr [ebp-0x12C]
43B08DE4 8B43 10 mov eax, dword ptr [ebx+0x10]
43B08DE7 8B88 58010000 mov ecx, dword ptr [eax+0x158]
43B08DED 6A FF push -0x1
43B08DEF 57 push edi
43B08DF0 E8 3D360800 call 43B8C432
43B08DF5 85C0 test eax, eax
43B08DF7 74 59 je short 43B08E52
43B08DF9 8B43 10 mov eax, dword ptr [ebx+0x10]
|
|