cb7d dd f8 04 00 f0 5e 05 00 5d c9 05 00 96 43 08 00 Ýø.ð^.]?.–c.
0057cb8d 89 93 05 00 00 c6 04 00 d9 08 07 00 22 74 02 00 ‰“..?.?."t.
0057cb9d 02 de 07 00 d7 32 01 00 d1 66 01 00 a2 17 03 00 ?.?.Ñf.?.
0057cbad 0f a8 07 00 9b 9a 01 00 9a 08 02 00 05 cc 00 00 ?.›š.?.?.
0057cbbd ff 96 06 00 26 11 08 00 67 60 03 00 c3 75 07 00 ÿ?.&.g`.Ãu.
0057cbcd 89 43 07 00 00 00 00 00 00 00 00 00 00 00 00 00 ‰c.............
......
0057cccd 55 32 00 00 63 32 00 00 69 32 00 00 6b 32 00 00 u2..c2..i2..k2.. ;ÓÃÁËsdkµÄ´óС
0057ccdd 6c 32 00 00 6d 32 00 00 6d 32 00 00 6e 32 00 00 l2..m2..m2..n2..
0057cced 7b 32 00 00 88 32 00 00 89 32 00 00 9b 32 00 00 {2..?..?..?..
0057ccfd 9b 32 00 00 9b 32 00 00 9b 32 00 00 9b 32 00 00 ?..?..?..?..
0057cd0d 9b 32 00 00 9b 32 00 00 9b 32 00 00 af 32 00 00 ?..?..?..?..
0057cd1d b2 32 00 00 b5 32 00 00 d5 32 00 00 da 32 00 00 ?..?..?..?..
0057cd2d da 32 00 00 e6 32 00 00 f8 32 00 00 3b 33 00 00 ?..?..?..;3..
0057cd3d cb 33 00 00 dc 64 00 00 f2 64 00 00 24 65 00 00 ?..Üd..òd..$e..
0057cd4d 27 65 00 00 8c 65 00 00 e2 65 00 00 1e 67 00 00 'e..Œe..âe..g..
0057cd5d ae 99 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ®™..............
sub_unknow1:
0058cfbf > 60 pushad ;¶ÔdelphiµÄ³ÌÐò£¬ÕâÀï»á²úÉúÒì³£
0058cfc0 f8 clc
0058cfc1 be 97b4bed0 mov esi,d0beb497
0058cfc6 e8 01000000 call 0058cfcc
0058cfcb ^ 72 83 jb short 0058cf50
0058cfcd c40481 les eax,fword ptr ds:[ecx+eax*4] ; modification of segment register
0058cfd0 cd d9 int 0d9
......
0058d16a > e8 91efffff call <sub_getebp >
0058d16f e8 580f0000 call 0058e0cc ; eaxËæ»ú²úÉúµÄÖµ
0058d174 0bc0 or eax,eax
0058d176 75 3d jnz short 0058d1b5 ; ûÓÐÒì³£ÔòÌø/?,ÎÒÕâ¸ö³ÌÐòÀïÌø
0058d178 90 nop
0058d179 90 nop
0058d17a 90 nop
0058d17b 90 nop
0058d17c ff95 6ffd4000 call dword ptr ss:[ebp+40fd6f] ; getcurrentthread
0058d182 50 push eax
0058d183 8db5 6ef74000 lea esi,dword ptr ss:[ebp+40f76e]
0058d189 56 push esi
0058d18a 56 push esi ; /pcontext = maincon.0058a76e
0058d18b 50 push eax ; |hthread = fffffffe
0058d18c ff95 67fd4000 call dword ptr ss:[ebp+40fd67] ; \getthreadcontext
0058d192 5f pop edi
0058d193 83c7 04 add edi,4
0058d196 2bc0 sub eax,eax
0058d198 b9 04000000 mov ecx,4
0058d19d f3:ab rep stos dword ptr es:[edi]
0058d19f 8db5 6ef74000 lea esi,dword ptr ss:[ebp+40f76e]
0058d1a5 58 pop eax
0058d1a6 56 push esi ; /pcontext
0058d1a7 50 push eax ; |hthread
0058d1a8 ff95 6bfd4000 call dword ptr ss:[ebp+40fd6b] ; \setthreadcontext
0058d1ae c685 bf1f4100 c3 mov byte ptr ss:[ebp+411fbf],0c3
0058d1b5 60 pushad ; °Ñ´úÂë¼ÓÃÜ»ØÈ¥
0058d1b6 e8 00000000