彩虹02年微狗
下断在 DeviceIoControl
请帮我看看如下情况我该如何处理?
77E1B277 > $ 6A 18 push 18 《===断在这里
(提示多处来自
Local Calls from 77E2DF4B, 77E397BD, 77E3983D, 77E3B373, 77E3B4DC, 77E3BA74, 77E3BB8A, 77E482C7, 77E6B374, 77E6B770, 77E6B93A, 77E6BA8D, SetVolumeMountPointW+30D, 77E6BF79, DeleteVolumeMountPointW+137, DeleteVolumeMountPointW+23C
的 call kernel32.DeviceIoControl 在调用这里
)
77E1B279 . 68 78FDE477 push kernel32.77E4FD78
77E1B27E . E8 7364FFFF call kernel32.77E116F6
77E1B283 . 8B7D 0C mov edi,dword ptr ss:[ebp+C]
77E1B286 . 81FF 08482D00 cmp edi,2D4808
77E1B28C ^ 0F84 CDFEFFFF je kernel32.77E1B15F
77E1B292 . 81FF 08480700 cmp edi,74808
77E1B298 ^ 0F84 C1FEFFFF je kernel32.77E1B15F
77E1B29E . 81FF 20000900 cmp edi,90020
77E1B2A4 ^ 0F84 B5FEFFFF je kernel32.77E1B15F
77E1B2AA > 33DB xor ebx,ebx
77E1B2AC > 8BC7 mov eax,edi
77E1B2AE . 25 0000FFFF and eax,FFFF0000
77E1B2B3 . 3D 00000900 cmp eax,90000
77E1B2B8 . 0F95C0 setne al
77E1B2BB . 8B75 24 mov esi,dword ptr ss:[ebp+24]
77E1B2BE . FF75 1C push dword ptr ss:[ebp+1C]
77E1B2C1 . FF75 18 push dword ptr ss:[ebp+18]
77E1B2C4 . FF75 14 push dword ptr ss:[ebp+14]
77E1B2C7 . FF75 10 push dword ptr ss:[ebp+10]
77E1B2CA . 57 push edi
77E1B2CB . 3BF3 cmp esi,ebx
77E1B2CD .^ 0F85 36FFFFFF jnz kernel32.77E1B209
77E1B2D3 . 3AC3 cmp al,bl
77E1B2D5 . 8D45 D8 lea eax,dword ptr ss:[ebp-28]
77E1B2D8 . 50 push eax
77E1B2D9 . 53 push ebx
77E1B2DA . 53 push ebx
77E1B2DB . 53 push ebx
77E1B2DC . FF75 08 push dword ptr ss:[ebp+8]
77E1B2DF ^ 0F84 E5FEFFFF je kernel32.77E1B1CA
77E1B2E5 . FF15 3810E177 call dword ptr ds:[<&ntdll.NtDeviceIoContro>; ntdll.ZwDeviceIoControlFile
77E1B2EB > 3D 03010000 cmp eax,103
77E1B2F0 .^ 0F84 DFFEFFFF je kernel32.77E1B1D5
77E1B2F6 > 3BC3 cmp eax,ebx
77E1B2F8 . 7C 13 jl short kernel32.77E1B30D
77E1B2FA . 8B45 20 mov eax,dword ptr ss:[ebp+20]
77E1B2FD . 8B4D DC mov ecx,dword ptr ss:[ebp-24]
77E1B300 . 8908 mov dword ptr ds:[eax],ecx
77E1B302 > 33C0 xor eax,eax
77E1B304 . 40 inc eax
77E1B305 > E8 2C64FFFF call kernel32.77E11736
77E1B30A . C2 2000 retn 20
77E1B30D > 8BD0 mov edx,eax
77E1B30F . B9 000000C0 mov ecx,C0000000
77E1B314 . 23D1 and edx,ecx
77E1B316 . 3BD1 cmp edx,ecx
77E1B318 . 74 08 je short kernel32.77E1B322
77E1B31A . 8B4D 20 mov ecx,dword ptr ss:[ebp+20]
...
[培训]科锐逆向工程师培训第53期2025年7月8日开班!