0040691C FF db FF
0040691D 25 db 25 ; CHAR '%'
0040691E 9C db 9C
0040691F C2 db C2
00406920 52 db 52 ; CHAR 'R'
00406921 00 db 00
00406922 8B db 8B
00406923 C0 db C0
00406924 FF db FF
00406925 25 db 25 ; CHAR '%'
00406926 98 db 98
00406927 C2 db C2
00406928 52 db 52 ; CHAR 'R'
00406929 00 db 00
0040692A 8B db 8B
0040692B C0 db C0
0040692C FF db FF
0040692D 25 db 25 ; CHAR '%'
0040692E 94 db 94
0040692F C2 db C2
00406930 52 db 52 ; CHAR 'R'
00406931 00 db 00
00406932 8B db 8B
00406933 C0 db C0
00406934 FF db FF
00406935 25 db 25 ; CHAR '%'
00406936 90 db 90
00406937 C2 db C2
00406938 52 db 52 ; CHAR 'R'
00406939 00 db 00
0040693A 8B db 8B
0040693B C0 db C0
0040693C 53 db 53 ; CHAR 'S'
0040693D B8 db B8
0040693E 10 db 10
0040693F 00 db 00
00406940 00 db 00
00406941 00 db 00
00406942 85 db 85
00406943 C0 db C0
00406944 74 db 74 ; CHAR 't'
00406945 43 db 43 ; CHAR 'C'
00406946 83 db 83
00406947 3D db 3D ; CHAR '='
00406948 D4 db D4
00406949 B4 db B4
0040694A 52 db 52 ; CHAR 'R'
0040694B 00 db 00
0040694C FF db FF
0040694D 75 db 75 ; CHAR 'u'
0040694E 0A db 0A
0040694F B8 db B8
00406950 E2 db E2
00406951 00 db 00
00406952 00 db 00
00406953 00 db 00
00406954 E8 db E8
00406955 AB db AB
00406956 D3 db D3
00406957 FF db FF
00406958 FF db FF
00406959 68 db 68 ; CHAR 'h'
0040695A 10 db 10
0040695B 00 db 00
0040695C 00 db 00
0040695D 00 db 00
0040695E 6A db 6A ; CHAR 'j'
0040695F 40 db 40 ; CHAR '@'
00406960 E8 db E8
00406961 BF db BF
00406962 FF db FF
00406963 FF db FF
00406964 FF db FF
00406965 8B db 8B
00406966 D8 db D8
00406967 85 db 85
00406968 DB db DB
00406969 75 db 75 ; CHAR 'u'
0040696A 0C db 0C
0040696B > B8 E2000000 mov eax,0E2
00406970 . E8 8FD3FFFF call iconxp.00403D04
;这个call前的是被stolen了的code吗?
00406975 ? EB 0C jmp short iconxp.00406983
00406977 . 53 push ebx
00406978 ? A1 D4B45200 mov eax,dword ptr ds:[52B4D4]
0040697D ? 50 push eax
0040697E ? E8 B1FFFFFF call iconxp.00406934
00406983 ? 891D E4B45200 mov dword ptr ds:[52B4E4],ebx
00406989 . 5B pop ebx
0040698A ? C3 retn
0040698B ? 90 nop