[Asm] 纯文本查看 复制代码 000007FEFE3C4730 | 4 | sub rsp,58 |
000007FEFE3C4734 | 4 | mov rax,qword ptr ss:[rsp+A0] | [rsp+A0]:L"C:\\Windows\\winsxs\\amd64_microsoft-windows-registry-editor_31bf3856ad364e35_6.1.7600.16385_none_5023a70bf589ad3e\\regedit.exe"
000007FEFE3C473C | 4 | mov qword ptr ss:[rsp+40],rax |
000007FEFE3C4741 | 4 | mov rax,qword ptr ss:[rsp+98] |
000007FEFE3C4749 | 4 | mov qword ptr ss:[rsp+38],rax |
000007FEFE3C474E | 4 | mov rax,qword ptr ss:[rsp+90] |
000007FEFE3C4756 | 4 | mov qword ptr ss:[rsp+30],rax |
000007FEFE3C475B | 8 | mov eax,dword ptr ss:[rsp+88] |
000007FEFE3C4762 | 8 | mov dword ptr ss:[rsp+28],eax |
000007FEFE3C4766 | 8 | mov eax,dword ptr ss:[rsp+80] |
000007FEFE3C476D | 8 | mov dword ptr ss:[rsp+20],eax |
000007FEFE3C4771 | E | call <JMP.&RegCreateKeyExA> |
000007FEFE3C4776 | 4 | add rsp,58 |
000007FEFE3C477A | C | ret |
000007FEFE3C4700 | F | jmp qword ptr ds:[<&RegCreateKeyExA>] |
000007FEFE3C4706 | 4 | mov dword ptr ds:[r13],esi |
000007FEFE3C470A | E | jmp advapi32.7FEFE3C446D |
因为这边有个IAT数据,只要改写他的值,跳转到哪他说了算 |