我们最终会发现,此处的值递减时,剩余的画面越来越少。
于是分析实现慢慢吞噬主程序的代码
mugen.exe+B404A - mov eax,[mugen.exe+B5518]
mugen.exe+B404F - mov ebx,[mugen.exe+B551C]
mugen.exe+B4055 - sub dword ptr [eax+04],02
mugen.exe+B4059 - sub dword ptr [ebx+04],02
mugen.exe+B405D - nop
mugen.exe+B405E - nop
mugen.exe+B405F - nop
mugen.exe+B4060 - nop
mugen.exe+B4061 - nop
mugen.exe+B4062 - nop
mugen.exe+B4063 - nop
mugen.exe+B4064 - nop
mugen.exe+B4065 - nop
mugen.exe+B4066 - nop
mugen.exe+B4067 - push 00000100
mugen.exe+B406C - call dword ptr [mugen.exe+9F128] { ->kernel32.Sleep }
mugen.exe+B4072 - jmp mugen.exe+B404A
mugen.exe+B4074 - nop
这是此处的代码