|
发表于 2011-12-4 17:18:53
|
显示全部楼层
- Private Function CallThreadFunc(ByVal UserFuncAddr As Long, ByVal lpParam As Long) As Long
- '写几句句用于被覆盖的垃圾代码 长度必须足够容纳下面的汇编
- MsgBox "YES"
- MsgBox "YES"
- MsgBox "YES"
- MsgBox "YES"
-
- '动态写入的汇编 手动调整堆栈 手动call
- '00402C10 58 pop eax
- '00402C11 5B pop ebx
- '00402C12 50 push eax
- '00402C13 FFE3 jmp ebx
- '00402C15 90 nop
- '00402C16 90 nop
- '00402C17 90 nop
- '585850 FF
- 'FF505858
- 'E3909090
- '909090E3
- End Function
复制代码 学飞,你的这个CallThreadFunc函数太牛了
|
|