|
根据PC=96cc5748(NK.EXE+0x0000d748)偏移地址0x0000d748。
SwitchToProcPtr:
98C0D6EC: E92D4030 stmdb sp!, {r4, r5, lr}
98C0D6F0: E1A05000 mov r5, r0
98C0D6F4: E3A03010 mov r3, #0x10
98C0D6F8: E2433DDE sub r3, r3, #0xDE, 26
98C0D6FC: E5933000 ldr r3, [r3]
98C0D700: E3A04014 mov r4, #0x14
98C0D704: E2444DDE sub r4, r4, #0xDE, 26
98C0D708: E5853008 str r3, [r5, #8]
98C0D70C: E5943000 ldr r3, [r4]
98C0D710: E3A02000 mov r2, #0
98C0D714: E5933014 ldr r3, [r3, #0x14]
98C0D718: E5852004 str r2, [r5, #4]
98C0D71C: E5852014 str r2, [r5, #0x14]
98C0D720: E585300C str r3, [r5, #0xC]
98C0D724: E5943000 ldr r3, [r4]
98C0D728: E5933018 ldr r3, [r3, #0x18]
98C0D72C: E5852018 str r2, [r5, #0x18]
98C0D730: E5853000 str r3, [r5]
98C0D734: E5943000 ldr r3, [r4]
98C0D738: E5835018 str r5, [r3, #0x18]
98C0D73C: E5943000 ldr r3, [r4]
98C0D740: E583100C str r1, [r3, #0xC]
98C0D744: E594E000 ldr lr, [r4]
98C0D748: E5912014 ldr r2, [r1, #0x14]
98C0D74C: E59E3014 ldr r3, [lr, #0x14]
98C0D750: E1833002 orr r3, r3, r2
98C0D754: E58E3014 str r3, [lr, #0x14]
98C0D758: E5940000 ldr r0, [r4]
98C0D75C: EBFFF3BE bl 98C0A65C
98C0D760: E5940000 ldr r0, [r4]
98C0D764: E3A01001 mov r1, #1
98C0D768: EBFFEE9D bl 98C091E4
98C0D76C: E5950008 ldr r0, [r5, #8]
98C0D770: E8BD4030 ldmia sp!, {r4, r5, lr}
98C0D774: E12FFF1E bx lr
SwitchToProcPtr是什么函数?估计是GWES.EXE切换电源管理的一个函数吧?还是想不出有什么问题!!! |
|