1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36
| 762a2e30 8bff mov edi, edi 762a2e32 55 push ebp 762a2e33 8bec mov ebp, esp 762a2e35 51 push ecx 762a2e36 53 push ebx 762a2e37 56 push esi 762a2e38 57 push edi 762a2e39 8b3d0400fe7f mov edi, dword ptr ds:[7FFE0004h] 762a2e3f ba2403fe7f mov edx, 7FFE0324h 762a2e44 897dfc mov dword ptr [ebp-4], edi 762a2e47 be2003fe7f mov esi, 7FFE0320h 762a2e4c bf2803fe7f mov edi, 7FFE0328h 762a2e51 8b02 mov eax, dword ptr [edx] 762a2e53 8b1e mov ebx, dword ptr [esi] 762a2e55 8b0f mov ecx, dword ptr [edi] 762a2e57 3bc1 cmp eax, ecx 762a2e59 7525 jne KERNELBASE!_GetTickCount64@0+0x50 (762a2e80) 762a2e5b f765fc mul eax, dword ptr [ebp-4] 762a2e5e 5f pop edi 762a2e5f 8bc8 mov ecx, eax 762a2e61 8bf2 mov esi, edx 762a2e63 8bc3 mov eax, ebx 762a2e65 f765fc mul eax, dword ptr [ebp-4] 762a2e68 0fa4ce08 shld esi, ecx, 8 762a2e6c 0facd018 shrd eax, edx, 18h 762a2e70 c1e108 shl ecx, 8 762a2e73 c1ea18 shr edx, 18h 762a2e76 03c1 add eax, ecx 762a2e78 13d6 adc edx, esi 762a2e7a 5e pop esi 762a2e7b 5b pop ebx 762a2e7c 8be5 mov esp, ebp 762a2e7e 5d pop ebp 762a2e7f c3 ret 762a2e80 f390 pause 762a2e82 ebcd jmp KERNELBASE!_GetTickCount64@0+0x21 (762a2e51)
|