0040ED85 2BDB sub ebx,ebx //停在这里0040ED87 64:8F03 pop dword ptr fs:[ebx]0040ED8A 58 pop eax0040ED8B 5D pop ebp0040ED8C 2BFF sub edi,edi0040ED8E EB 01 jmp short pespin1_.0040ED910040ED90 C466 81 les esp,fword ptr ds:[esi-7F]
0040ED85 2BDB sub ebx,ebx //停在这里0040ED87 64:8F03 pop dword ptr fs:[ebx]0040ED8A 58 pop eax0040ED8B 5D pop ebp0040ED8C 2BFF sub edi,edi0040ED8E EB 01 jmp short pespin1_.0040ED910040ED90 C466 81 les esp,fword ptr ds:[esi-7F]
然后下断HW 0012F9C0 ,F9运行,来到这里
0040D8FB 61 popad0040D8FC 55 push ebp0040D8FD EB 01 jmp short pespin1_.0040D900 //停在这里0040D8FF 318B ECEB01AC xor dword ptr ds:[ebx+AC01EBEC],ecx0040D905 83EC 44 sub esp,440040D908 EB 01 jmp short pespin1_.0040D90B0040D90A 72 56 jb short pespin1_.0040D9620040D90C EB 01 jmp short pespin1_.0040D90F0040D90E 95 xchg eax,ebp0040D90F FF15 6CF34000 call dword ptr ds:[40F36C]0040D915 EB 01 jmp short pespin1_.0040D918