-
Notifications
You must be signed in to change notification settings - Fork 283
/
微信基址-2.8.0.121.txt
4118 lines (3996 loc) · 194 KB
/
微信基址-2.8.0.121.txt
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
558
559
560
561
562
563
564
565
566
567
568
569
570
571
572
573
574
575
576
577
578
579
580
581
582
583
584
585
586
587
588
589
590
591
592
593
594
595
596
597
598
599
600
601
602
603
604
605
606
607
608
609
610
611
612
613
614
615
616
617
618
619
620
621
622
623
624
625
626
627
628
629
630
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645
646
647
648
649
650
651
652
653
654
655
656
657
658
659
660
661
662
663
664
665
666
667
668
669
670
671
672
673
674
675
676
677
678
679
680
681
682
683
684
685
686
687
688
689
690
691
692
693
694
695
696
697
698
699
700
701
702
703
704
705
706
707
708
709
710
711
712
713
714
715
716
717
718
719
720
721
722
723
724
725
726
727
728
729
730
731
732
733
734
735
736
737
738
739
740
741
742
743
744
745
746
747
748
749
750
751
752
753
754
755
756
757
758
759
760
761
762
763
764
765
766
767
768
769
770
771
772
773
774
775
776
777
778
779
780
781
782
783
784
785
786
787
788
789
790
791
792
793
794
795
796
797
798
799
800
801
802
803
804
805
806
807
808
809
810
811
812
813
814
815
816
817
818
819
820
821
822
823
824
825
826
827
828
829
830
831
832
833
834
835
836
837
838
839
840
841
842
843
844
845
846
847
848
849
850
851
852
853
854
855
856
857
858
859
860
861
862
863
864
865
866
867
868
869
870
871
872
873
874
875
876
877
878
879
880
881
882
883
884
885
886
887
888
889
890
891
892
893
894
895
896
897
898
899
900
901
902
903
904
905
906
907
908
909
910
911
912
913
914
915
916
917
918
919
920
921
922
923
924
925
926
927
928
929
930
931
932
933
934
935
936
937
938
939
940
941
942
943
944
945
946
947
948
949
950
951
952
953
954
955
956
957
958
959
960
961
962
963
964
965
966
967
968
969
970
971
972
973
974
975
976
977
978
979
980
981
982
983
984
985
986
987
988
989
990
991
992
993
994
995
996
997
998
999
1000
小号
wxid_vju0phxgdhgp22
大号
Lemonice-cheng
能强
wxid_sbrnzc86ibft22
资料:
hook基址:441894
call 54594B70
0f080000
0F4F7A37 8945 EC mov dword ptr ss:[ebp-0x14],eax
0F4F7A3A C745 F0 0000000>mov dword ptr ss:[ebp-0x10],0x0
0F4F7A41 FF15 34722710 call dword ptr ds:[<&KERNEL32.EnterCriti>; ntdll.RtlEnterCriticalSection
0F4F7A47 8D45 08 lea eax,dword ptr ss:[ebp+0x8]
0F4F7A4A C645 FC 01 mov byte ptr ss:[ebp-0x4],0x1
0F4F7A4E 8D9E 84000000 lea ebx,dword ptr ds:[esi+0x84]
0F4F7A54 50 push eax
0F4F7A55 8BCB mov ecx,ebx
0F4F7A57 E8 449EBDFF call WeChatWi.0F0D18A0
0F4F7A5C 8BF0 mov esi,eax
0F4F7A5E 3B33 cmp esi,dword ptr ds:[ebx]
0F4F7A60 74 1F je short WeChatWi.0F4F7A81
0F4F7A62 8B46 10 mov eax,dword ptr ds:[esi+0x10]
0F4F7A65 85C0 test eax,eax
0F4F7A67 74 06 je short WeChatWi.0F4F7A6F
0F4F7A69 66:8338 00 cmp word ptr ds:[eax],0x0
0F4F7A6D 75 05 jnz short WeChatWi.0F4F7A74
0F4F7A6F B8 A0A64910 mov eax,WeChatWi.1049A6A0
0F4F7A74 50 push eax
0F4F7A75 8D4D 08 lea ecx,dword ptr ss:[ebp+0x8]
//hook下面这行
0F4F7A78 E8 D3540600 call WeChatWi.0F55CF50
0F4F7A7D 85C0 test eax,eax
头像:
基址:57320000
5747B751 8BEC mov ebp,esp
5747B753 6A FF push -0x1
5747B755 68 6F7F1558 push WeChatWi.58157F6F
5747B75A 64:A1 00000000 mov eax,dword ptr fs:[0]
5747B760 50 push eax
5747B761 83EC 08 sub esp,0x8
5747B764 53 push ebx
5747B765 56 push esi
5747B766 57 push edi
5747B767 A1 C4805258 mov eax,dword ptr ds:[0x585280C4]
5747B76C 33C5 xor eax,ebp
5747B76E 50 push eax
5747B76F 8D45 F4 lea eax,dword ptr ss:[ebp-0xC]
5747B772 64:A3 00000000 mov dword ptr fs:[0],eax
5747B778 8BF9 mov edi,ecx
5747B77A 8B75 0C mov esi,dword ptr ss:[ebp+0xC]
5747B77D 8D87 54010000 lea eax,dword ptr ds:[edi+0x154]
5747B783 50 push eax
5747B784 56 push esi
5747B785 8D87 80040000 lea eax,dword ptr ds:[edi+0x480]
5747B78B 50 push eax
5747B78C FF15 ACC72058 call dword ptr ds:[<&USER32.IntersectRec>; user32.IntersectRect
5747B792 85C0 test eax,eax
5747B794 0F84 ED010000 je WeChatWi.5747B987
5747B79A 56 push esi
5747B79B 8B75 08 mov esi,dword ptr ss:[ebp+0x8]
5747B79E 8BCF mov ecx,edi
5747B7A0 56 push esi
5747B7A1 E8 2C7D5800 call WeChatWi.57A034D2
5747B7A6 8D45 EC lea eax,dword ptr ss:[ebp-0x14]
5747B7A9 6A 00 push 0x0
5747B7AB 50 push eax
5747B7AC E8 1F719200 call WeChatWi.57DA28D0
5747B7B1 A1 B8DF5858 mov eax,dword ptr ds:[0x5858DFB8]
5747B7B6 83C4 08 add esp,0x8
5747B7B9 85C0 test eax,eax
5747B7BB 75 27 jnz short WeChatWi.5747B7E4
5747B7BD 6A 3C push 0x3C
5747B7BF E8 26F58E00 call WeChatWi.57D6ACEA
5747B7C4 83C4 04 add esp,0x4
5747B7C7 8945 0C mov dword ptr ss:[ebp+0xC],eax
5747B7CA 8BC8 mov ecx,eax
5747B7CC C745 FC 0000000>mov dword ptr ss:[ebp-0x4],0x0
5747B7D3 E8 180A0000 call WeChatWi.5747C1F0
5747B7D8 C745 FC FFFFFFF>mov dword ptr ss:[ebp-0x4],-0x1
5747B7DF A3 B8DF5858 mov dword ptr ds:[0x5858DFB8],eax
5747B7E4 8D9F 4C090000 lea ebx,dword ptr ds:[edi+0x94C]
5747B7EA 8BC8 mov ecx,eax
5747B7EC 53 push ebx
5747B7ED E8 5E270000 call WeChatWi.5747DF50
5747B7F2 84C0 test al,al
5747B7F4 0F85 0C010000 jnz WeChatWi.5747B906
5747B7FA 837B 04 00 cmp dword ptr ds:[ebx+0x4],0x0
5747B7FE 0F9EC0 setle al
5747B801 84C0 test al,al
5747B803 0F85 FD000000 jnz WeChatWi.5747B906
5747B809 83BF D8090000 0>cmp dword ptr ds:[edi+0x9D8],0x0
5747B810 7F 37 jg short WeChatWi.5747B849
5747B812 8D87 88090000 lea eax,dword ptr ds:[edi+0x988]
5747B818 50 push eax
5747B819 8D8F D4090000 lea ecx,dword ptr ds:[edi+0x9D4]
5747B81F 53 push ebx
5747B820 51 push ecx
5747B821 E8 9AE5F7FF call WeChatWi.573F9DC0
5747B826 8BC8 mov ecx,eax
5747B828 E8 F3FC1400 call WeChatWi.575CB520
5747B82D 84C0 test al,al
5747B82F 74 18 je short WeChatWi.5747B849
5747B831 83EC 08 sub esp,0x8
5747B834 8D87 D4090000 lea eax,dword ptr ds:[edi+0x9D4]
5747B83A 8BCC mov ecx,esp
5747B83C 50 push eax
5747B83D E8 BE473200 call WeChatWi.577A0000 ; 调用这行后,取ebx
5747B842 8BCF mov ecx,edi
5747B844 E8 97FBFFFF call WeChatWi.5747B3E0
5747B849 83BF E0090000 0>cmp dword ptr ds:[edi+0x9E0],0x0
5747B850 0F8F B0000000 jg WeChatWi.5747B906
5747B856 80BF CC090000 0>cmp byte ptr ds:[edi+0x9CC],0x0
5747B85D 0F84 A3000000 je WeChatWi.5747B906
5747B863 E8 4847EFFF call WeChatWi.5736FFB0
5747B868 8BCB mov ecx,ebx
5747B86A E8 E17E1100 call WeChatWi.57593750
5747B86F 84C0 test al,al
5747B871 0F85 8F000000 jnz WeChatWi.5747B906
5747B877 0F1005 D03D3258 movups xmm0,dqword ptr ds:[0x58323DD0]
5747B87E 83EC 10 sub esp,0x10
5747B881 8DB7 9C090000 lea esi,dword ptr ds:[edi+0x99C]
5747B887 8BC4 mov eax,esp
5747B889 8BCE mov ecx,esi
5747B88B 83EC 10 sub esp,0x10
5747B88E 0F1100 movups dqword ptr ds:[eax],xmm0
5747B891 8BC4 mov eax,esp
5747B893 83EC 10 sub esp,0x10
5747B896 0F1100 movups dqword ptr ds:[eax],xmm0
5747B899 8BC4 mov eax,esp
5747B89B 83EC 10 sub esp,0x10
5747B89E 0F1100 movups dqword ptr ds:[eax],xmm0
5747B8A1 8BC4 mov eax,esp
5747B8A3 0F1100 movups dqword ptr ds:[eax],xmm0
5747B8A6 E8 C5D0EFFF call WeChatWi.57378970
5747B8AB 83EC 10 sub esp,0x10
5747B8AE 8BCC mov ecx,esp
5747B8B0 C601 02 mov byte ptr ds:[ecx],0x2
5747B8B3 8941 08 mov dword ptr ds:[ecx+0x8],eax
5747B8B6 8BCB mov ecx,ebx
5747B8B8 E8 B3D0EFFF call WeChatWi.57378970
5747B8BD 83EC 10 sub esp,0x10
5747B8C0 BA 58C43658 mov edx,WeChatWi.5836C458 ; ASCII "01_ui\common\HeadImgUI.cpp"
5747B8C5 8BCC mov ecx,esp
5747B8C7 68 1CC53658 push WeChatWi.5836C51C ; ASCII "DoPaint user: %s, url: %s"
5747B8CC 68 A8C43658 push WeChatWi.5836C4A8 ; ASCII "HeadImgUI"
5747B8D1 C601 02 mov byte ptr ds:[ecx],0x2
5747B8D4 8941 08 mov dword ptr ds:[ecx+0x8],eax
5747B8D7 B9 02000000 mov ecx,0x2
5747B8DC 68 D4C43658 push WeChatWi.5836C4D4 ; ASCII "HeadImgUI::DoPaint"
5747B8E1 68 1B010000 push 0x11B
5747B8E6 E8 55533200 call WeChatWi.577A0C40
5747B8EB 83C4 6C add esp,0x6C
5747B8EE 8D87 DC090000 lea eax,dword ptr ds:[edi+0x9DC]
5747B8F4 56 push esi
5747B8F5 53 push ebx
5747B8F6 50 push eax
5747B8F7 E8 C4E4F7FF call WeChatWi.573F9DC0
5747B8FC 8BC8 mov ecx,eax
5747B8FE E8 2D101500 call WeChatWi.575CC930
5747B903 8B75 08 mov esi,dword ptr ss:[ebp+0x8]
5747B906 80BF E4090000 0>cmp byte ptr ds:[edi+0x9E4],0x0
5747B90D 74 44 je short WeChatWi.5747B953
5747B90F 83EC 08 sub esp,0x8
5747B912 8BF4 mov esi,esp
5747B914 C706 00000000 mov dword ptr ds:[esi],0x0
5747B91A C746 04 0000000>mov dword ptr ds:[esi+0x4],0x0
5747B921 8B87 D4090000 mov eax,dword ptr ds:[edi+0x9D4]
5747B927 8B9F D8090000 mov ebx,dword ptr ds:[edi+0x9D8]
5747B92D 8945 0C mov dword ptr ss:[ebp+0xC],eax
5747B930 85C0 test eax,eax
5747B932 74 1A je short WeChatWi.5747B94E
5747B934 85DB test ebx,ebx
5747B936 7E 16 jle short WeChatWi.5747B94E
5747B938 53 push ebx
5747B939 8BCE mov ecx,esi
5747B93B E8 D0473200 call WeChatWi.577A0110
5747B940 53 push ebx
5747B941 FF75 0C push dword ptr ss:[ebp+0xC]
5747B944 FF36 push dword ptr ds:[esi]
5747B946 E8 65E5C800 call WeChatWi.58109EB0
5747B94B 83C4 0C add esp,0xC
5747B94E FF75 08 push dword ptr ss:[ebp+0x8]
个人ebx
036FF85C 0AFD6E28 UNICODE "wxid_8du0u27rttry22"
036FF860 00000013
036FF864 00000020
036FF868 00000000
036FF86C 00000000
036FF870 00000000
036FF874 00000000
036FF878 00000000
036FF87C 00000000
036FF880 00000000
036FF884 00000000
036FF888 00000000
036FF88C 00000000
036FF890 00000000
036FF894 00000000
036FF898 0AED82C8 UNICODE "http://wx.qlogo.cn/mmhead/ver_1/iaozoXP9ibb2XMWbH6"
036FF89C 00000094
036FF8A0 00000100
036FF8A4 00000000
036FF8A8 00000000
036FF8AC 0AED7E78 UNICODE "http://wx.qlogo.cn/mmhead/ver_1/iaozoXP9ibb2XMWbH6"
036FF8B0 00000092
036FF8B4 00000100
036FF8B8 00000000
036FF8BC 00000000
036FF8C0 0ADB4DCC
036FF8C4 00000000
036FF8C8 00000000
036FF8CC 00000000
036FF8D0 00000000
036FF8D4 00000000
036FF8D8 00000003
群ebx
036F4F34 0AFD7198 UNICODE "9199093107@chatroom"
036F4F38 00000013
036F4F3C 00000020
036F4F40 00000000
036F4F44 00000000
036F4F48 00000000
036F4F4C 00000000
036F4F50 00000000
036F4F54 00000000
036F4F58 00000000
036F4F5C 00000000
036F4F60 00000000
036F4F64 00000000
036F4F68 00000000
036F4F6C 00000000
036F4F70 0AEDA998 UNICODE "http://wx.qlogo.cn/mmcrhead/xxib5HEohdRiaO26jEOkqq"
036F4F74 00000084
036F4F78 00000100
036F4F7C 00000000
036F4F80 00000000
036F4F84 00000000
036F4F88 00000000
036F4F8C 00000000
036F4F90 00000000
036F4F94 00000000
036F4F98 0ADB4DCC
036F4F9C 00000000
036F4FA0 00000000
036F4FA4 00000000
036F4FA8 00000000
036F4FAC 00000000
036F4FB0 00000003
公众号ebx
0AE05934 02ED4CE8 UNICODE "gh_3dfda90e39d6"
0AE05938 0000000F
0AE0593C 00000010
0AE05940 00000000
0AE05944 00000000
0AE05948 00000000
0AE0594C 00000000
0AE05950 00000000
0AE05954 00000000
0AE05958 00000000
0AE0595C 00000000
0AE05960 00000000
0AE05964 00000000
0AE05968 00000000
0AE0596C 00000000
0AE05970 04A59430 UNICODE "http://wx.qlogo.cn/mmhead/Q3auHgzwzM6CtTmrloqERDq5"
0AE05974 00000056
0AE05978 00000080
0AE0597C 00000000
0AE05980 00000000
0AE05984 04A59890 UNICODE "http://wx.qlogo.cn/mmhead/Q3auHgzwzM6CtTmrloqERDq5"
0AE05988 00000054
0AE0598C 00000080
0AE05990 00000000
0AE05994 00000000
0AE05998 0ADB4DCC
0AE0599C 00000000
0AE059A0 00000000
0AE059A4 00000000
0AE059A8 00000000
0AE059AC 00000000
0AE059B0 00000002
同意加好友请求:
消息类型:好友确认
收到好友消息:
好友wxid:
fmessage
v1_63a5c79810b2f39abe44093512a11d03de8b383ae9f83a539d559fe68e1b1544@stranger
v2_679c6c2dd446a8f2f8d78a8447887527c58deb9778c87900ebefa4bf9894f27df3f9f67f5c9e59c7c297f3ca75985bce44130a20ebbce742bc71dcf063e75ad6fc52e55b8227b00eabd0df846512d8d9@stranger
消息内容:
<msg fromusername="Lemonice-cheng" encryptusername="v1_63a5c79810b2f39abe44093512a11d03de8b383ae9f83a539d559fe68e1b1544@stranger" fromnickname="Lemonice" content="" fullpy="Lemonice" shortpy="LEMONICE" imagestatus="3" scene="6" country="CN" province="Guangdong" city="Guangzhou" sign="怎么样的人就有怎么样的故事。。。" percard="1" sex="1" alias="" weibo="" albumflag="0" albumstyle="0" albumbgimgid="" snsflag="273" snsbgimgid="http://mmsns.qpic.cn/mmsns/PiajxSqBRaEKINstXA9yy06n206ibnut057ribI40rib8lmKDMibs3pXC4qNibO23GZXuE/0" snsbgobjectid="11795503932415816424" mhash="312995dae082495f25daa5168e520716" mfullhash="312995dae082495f25daa5168e520716" bigheadimgurl="http://wx.qlogo.cn/mmhead/ver_1/VM4Xs3LB7QmicNWs7qicYaP0aFVZ1mA6L2iaPLTAPRFiccfbdLSaU9laySQHNzfnicPicgWibH3UE17XicnfFL48WOXoGhOic4HH1YrReLtlQyicAgXCQ/0" smallheadimgurl="http://wx.qlogo.cn/mmhead/ver_1/VM4Xs3LB7QmicNWs7qicYaP0aFVZ1mA6L2iaPLTAPRFiccfbdLSaU9laySQHNzfnicPicgWibH3UE17XicnfFL48WOXoGhOic4HH1YrReLtlQyicAgXCQ/96" ticket="v2_679c6c2dd446a8f2f8d78a8447887527c58deb9778c87900ebefa4bf9894f27df3f9f67f5c9e59c7c297f3ca75985bce44130a20ebbce742bc71dcf063e75ad6fc52e55b8227b00eabd0df846512d8d9@stranger" opcode="2" googlecontact="" qrticket="" chatroomusername="" sourceusername="" sourcenickname="" sharecardusername="" sharecardnickname="" cardversion=""><brandlist count="0" ver="698484744"></brandlist></msg>
基址:56F30000
570CDCE0 55 push ebp
570CDCE1 8BEC mov ebp,esp
570CDCE3 6A FF push -0x1
570CDCE5 68 E8330358 push WeChatWi.580333E8
570CDCEA 64:A1 00000000 mov eax,dword ptr fs:[0]
570CDCF0 50 push eax
570CDCF1 83EC 18 sub esp,0x18
570CDCF4 56 push esi
570CDCF5 57 push edi
570CDCF6 A1 942B4F58 mov eax,dword ptr ds:[0x584F2B94]
570CDCFB 33C5 xor eax,ebp
570CDCFD 50 push eax
570CDCFE 8D45 F4 lea eax,dword ptr ss:[ebp-0xC]
570CDD01 64:A3 00000000 mov dword ptr fs:[0],eax
570CDD07 8BF9 mov edi,ecx
570CDD09 8B8F F0060000 mov ecx,dword ptr ds:[edi+0x6F0]
570CDD0F FFB1 28040000 push dword ptr ds:[ecx+0x428]
570CDD15 83EC 14 sub esp,0x14
570CDD18 54 push esp
570CDD19 E8 32730000 call WeChatWi.570D5050 ; 传入v2
570CDD1E 8B8F F0060000 mov ecx,dword ptr ds:[edi+0x6F0]
570CDD24 8D45 DC lea eax,dword ptr ss:[ebp-0x24]
570CDD27 50 push eax
570CDD28 E8 93A8EAFF call WeChatWi.56F785C0 ; 传入v1
570CDD2D 8BF0 mov esi,eax
570CDD2F 83EC 08 sub esp,0x8
570CDD32 C745 FC 0000000>mov dword ptr ss:[ebp-0x4],0x0
570CDD39 8B0D E8CE5458 mov ecx,dword ptr ds:[0x5854CEE8] ; 参数地址
570CDD3F E8 7C7DF4FF call WeChatWi.57015AC0 ; 获取eax的值
570CDD44 8BD7 mov edx,edi
570CDD46 8D8F BC060000 lea ecx,dword ptr ds:[edi+0x6BC]
570CDD4C F7DA neg edx
570CDD4E 50 push eax ; 这个是上面的call回来的
570CDD4F 1BD2 sbb edx,edx
570CDD51 23D1 and edx,ecx
570CDD53 8D8F F4060000 lea ecx,dword ptr ds:[edi+0x6F4]
570CDD59 52 push edx ; 0x130大小的空缓冲区
570CDD5A 56 push esi ; v1结构体
570CDD5B E8 70BCFEFF call WeChatWi.570B99D0 ; 同意好友主要的call
570CDD60 8B45 DC mov eax,dword ptr ss:[ebp-0x24]
570CDD63 85C0 test eax,eax
570CDD65 74 10 je short WeChatWi.570CDD77
570CDD67 50 push eax
570CDD68 E8 C7C4F300 call WeChatWi.5800A234
570CDD6D 83C4 04 add esp,0x4
570CDD70 C745 DC 0000000>mov dword ptr ss:[ebp-0x24],0x0
570CDD77 8B45 E8 mov eax,dword ptr ss:[ebp-0x18] ; user32.73DE4F8A
570CDD7A C745 E4 0000000>mov dword ptr ss:[ebp-0x1C],0x0
570CDD81 C745 E0 0000000>mov dword ptr ss:[ebp-0x20],0x0
570CDD88 85C0 test eax,eax
570CDD8A 74 09 je short WeChatWi.570CDD95
570CDD8C 50 push eax
570CDD8D E8 A2C4F300 call WeChatWi.5800A234
570CDD92 83C4 04 add esp,0x4
570CDD95 B0 01 mov al,0x1
570CDD97 8B4D F4 mov ecx,dword ptr ss:[ebp-0xC]
570CDD9A 64:890D 0000000>mov dword ptr fs:[0],ecx
570CDDA1 59 pop ecx ; user32.73DE4F8A
570CDDA2 5F pop edi ; user32.73DE4F8A
570CDDA3 5E pop esi ; user32.73DE4F8A
570CDDA4 8BE5 mov esp,ebp
570CDDA6 5D pop ebp ; user32.73DE4F8A
570CDDA7 C3 retn
570CDDA8 CC int3
570CDDA9 CC int3
570CDDAA CC int3
570CDDAB CC int3
570CDDAC CC int3
570CDDAD CC int3
570CDDAE CC int3
570CDDAF CC int3
570CDDB0 55 push ebp
570CDDB1 8BEC mov ebp,esp
570CDDB3 6A FF push -0x1
570CDDB5 68 E8330358 push WeChatWi.580333E8
570CDDBA 64:A1 00000000 mov eax,dword ptr fs:[0]
570CDDC0 50 push eax
570CDDC1 83EC 1C sub esp,0x1C
570CDDC4 56 push esi
570CDDC5 A1 942B4F58 mov eax,dword ptr ds:[0x584F2B94]
570CDDCA 33C5 xor eax,ebp
570CDDCC 50 push eax
570CDDCD 8D45 F4 lea eax,dword ptr ss:[ebp-0xC]
570CDDD0 64:A3 00000000 mov dword ptr fs:[0],eax
570CDDD6 8BF1 mov esi,ecx
570CDDD8 83EC 14 sub esp,0x14
570CDDDB 8BCC mov ecx,esp
570CDDDD 6A FF push -0x1
570CDDDF C701 00000000 mov dword ptr ds:[ecx],0x0
570CDDE5 C741 04 0000000>mov dword ptr ds:[ecx+0x4],0x0
570CDDEC C741 08 0000000>mov dword ptr ds:[ecx+0x8],0x0
570CDDF3 68 08892958 push WeChatWi.58298908
570CDDF8 C741 0C 0000000>mov dword ptr ds:[ecx+0xC],0x0
570CDDFF C741 10 0000000>mov dword ptr ds:[ecx+0x10],0x0
570CDE06 E8 A5123400 call WeChatWi.5740F0B0
570CDE0B 83EC 14 sub esp,0x14
570CDE0E 8BCC mov ecx,esp
570CDE10 6A FF push -0x1
570CDE12 C701 00000000 mov dword ptr ds:[ecx],0x0
570CDE18 C741 04 0000000>mov dword ptr ds:[ecx+0x4],0x0
570CDE1F C741 08 0000000>mov dword ptr ds:[ecx+0x8],0x0
570CDE26 68 08892958 push WeChatWi.58298908
570CDE2B C741 0C 0000000>mov dword ptr ds:[ecx+0xC],0x0
570CDE32 C741 10 0000000>mov dword ptr ds:[ecx+0x10],0x0
570CDE39 E8 72123400 call WeChatWi.5740F0B0
570CDE3E 8B8E F0060000 mov ecx,dword ptr ds:[esi+0x6F0]
570CDE44 8D45 DC lea eax,dword ptr ss:[ebp-0x24]
570CDE47 50 push eax
570CDE48 E8 73A7EAFF call WeChatWi.56F785C0
570CDE4D 8BD0 mov edx,eax
570CDE4F C745 FC 0000000>mov dword ptr ss:[ebp-0x4],0x0
570CDE56 8B8E F0060000 mov ecx,dword ptr ds:[esi+0x6F0]
570CDE5C 6A 01 push 0x1
570CDE5E FFB1 28040000 push dword ptr ds:[ecx+0x428]
570CDE64 8B0D E8CE5458 mov ecx,dword ptr ds:[0x5854CEE8]
570CDE6A 6A 01 push 0x1
570CDE6C E8 4F7CF4FF call WeChatWi.57015AC0
570CDE71 8BCE mov ecx,esi
570CDE73 F7D9 neg ecx
570CDE75 50 push eax
570CDE76 1BC9 sbb ecx,ecx
570CDE78 8D86 BC060000 lea eax,dword ptr ds:[esi+0x6BC]
570CDE7E 23C8 and ecx,eax
570CDE80 51 push ecx
570CDE81 52 push edx
570CDE82 8D8E F4060000 lea ecx,dword ptr ds:[esi+0x6F4]
570CDE88 E8 B3B8FEFF call WeChatWi.570B9740
570CDE8D 8B45 DC mov eax,dword ptr ss:[ebp-0x24]
570CDE90 85C0 test eax,eax
加好友:
基址:56F30000
570B303D 8D95 3CFFFFFF lea edx,dword ptr ss:[ebp-0xC4]
570B3043 52 push edx
570B3044 8B01 mov eax,dword ptr ds:[ecx]
570B3046 FF50 04 call dword ptr ds:[eax+0x4]
570B3049 68 50372B58 push WeChatWi.582B3750 ; UNICODE "okbtn"
570B304E 8BC8 mov ecx,eax
570B3050 E8 2B916800 call WeChatWi.5773C180
570B3055 50 push eax
570B3056 E8 B38FF400 call WeChatWi.57FFC00E
570B305B 83C4 08 add esp,0x8
570B305E 8D8D 3CFFFFFF lea ecx,dword ptr ss:[ebp-0xC4]
570B3064 85C0 test eax,eax
570B3066 0F94C3 sete bl
570B3069 E8 AB916800 call WeChatWi.5773C219
570B306E 84DB test bl,bl
570B3070 0F84 8C010000 je WeChatWi.570B3202
570B3076 83BE 44030000 0>cmp dword ptr ds:[esi+0x344],0x0
570B307D 0F84 57030000 je WeChatWi.570B33DA
570B3083 6A FF push -0x1
570B3085 68 08892958 push WeChatWi.58298908
570B308A 8D8D 28FFFFFF lea ecx,dword ptr ss:[ebp-0xD8]
570B3090 E8 1BBD3500 call WeChatWi.5740EDB0
570B3095 C745 FC 0000000>mov dword ptr ss:[ebp-0x4],0x0
570B309C C745 E4 0000000>mov dword ptr ss:[ebp-0x1C],0x0
570B30A3 C745 E8 0000000>mov dword ptr ss:[ebp-0x18],0x0
570B30AA C745 EC 0000000>mov dword ptr ss:[ebp-0x14],0x0
570B30B1 8D45 E4 lea eax,dword ptr ss:[ebp-0x1C]
570B30B4 C645 FC 01 mov byte ptr ss:[ebp-0x4],0x1
570B30B8 8B8E 44030000 mov ecx,dword ptr ds:[esi+0x344]
570B30BE 50 push eax
570B30BF E8 BCE8F2FF call WeChatWi.56FE1980
570B30C4 8B4D E8 mov ecx,dword ptr ss:[ebp-0x18] ; user32.73DE4F8A
570B30C7 B8 398EE338 mov eax,0x38E38E39
570B30CC 8B7D E4 mov edi,dword ptr ss:[ebp-0x1C] ; user32.73DE895C
570B30CF 2BCF sub ecx,edi
570B30D1 F7E9 imul ecx
570B30D3 C1FA 03 sar edx,0x3
570B30D6 8BC2 mov eax,edx
570B30D8 C1E8 1F shr eax,0x1F
570B30DB 03C2 add eax,edx
570B30DD 74 14 je short WeChatWi.570B30F3
570B30DF 833F 01 cmp dword ptr ds:[edi],0x1
570B30E2 75 0F jnz short WeChatWi.570B30F3
570B30E4 8D47 04 lea eax,dword ptr ds:[edi+0x4]
570B30E7 50 push eax
570B30E8 8D8D 28FFFFFF lea ecx,dword ptr ss:[ebp-0xD8]
570B30EE E8 EDC13500 call WeChatWi.5740F2E0
570B30F3 8BBD 28FFFFFF mov edi,dword ptr ss:[ebp-0xD8]
570B30F9 8D8E 48030000 lea ecx,dword ptr ds:[esi+0x348]
570B30FF 85FF test edi,edi
570B3101 74 08 je short WeChatWi.570B310B
570B3103 66:833F 00 cmp word ptr ds:[edi],0x0
570B3107 8BC7 mov eax,edi
570B3109 75 05 jnz short WeChatWi.570B3110
570B310B B8 08892958 mov eax,WeChatWi.58298908
570B3110 FFB5 2CFFFFFF push dword ptr ss:[ebp-0xD4]
570B3116 50 push eax
570B3117 E8 94BF3500 call WeChatWi.5740F0B0
570B311C 8D9E 24030000 lea ebx,dword ptr ds:[esi+0x324]
570B3122 8BCB mov ecx,ebx
570B3124 E8 47E85800 call WeChatWi.57641970
570B3129 84C0 test al,al
570B312B 74 3A je short WeChatWi.570B3167
570B312D 6A 00 push 0x0
570B312F 8D86 68030000 lea eax,dword ptr ds:[esi+0x368]
570B3135 50 push eax
570B3136 8D4D C4 lea ecx,dword ptr ss:[ebp-0x3C]
570B3139 E8 C2BD3500 call WeChatWi.5740EF00
570B313E 8D45 C4 lea eax,dword ptr ss:[ebp-0x3C]
570B3141 C645 FC 02 mov byte ptr ss:[ebp-0x4],0x2
570B3145 50 push eax
570B3146 8D85 28FFFFFF lea eax,dword ptr ss:[ebp-0xD8]
570B314C 50 push eax
570B314D 53 push ebx
570B314E E8 BD5DEFFF call WeChatWi.56FA8F10
570B3153 8BC8 mov ecx,eax
570B3155 E8 36F85800 call WeChatWi.57642990
570B315A 8D4D C4 lea ecx,dword ptr ss:[ebp-0x3C]
570B315D E8 3E9EECFF call WeChatWi.56F7CFA0
570B3162 E9 83000000 jmp WeChatWi.570B31EA
570B3167 83EC 18 sub esp,0x18
570B316A 8BCC mov ecx,esp
570B316C 89A5 24FFFFFF mov dword ptr ss:[ebp-0xDC],esp
570B3172 68 949C2958 push WeChatWi.58299C94 ; 参数地址
570B3177 E8 D4F3ECFF call WeChatWi.56F82550 ; 调用1
570B317C 83EC 18 sub esp,0x18
570B317F C645 FC 03 mov byte ptr ss:[ebp-0x4],0x3
570B3183 8D86 68030000 lea eax,dword ptr ds:[esi+0x368]
570B3189 89A5 1CFFFFFF mov dword ptr ss:[ebp-0xE4],esp
570B318F 8BCC mov ecx,esp
570B3191 50 push eax
570B3192 E8 79B7EEFF call WeChatWi.56F9E910 ; 调用2
570B3197 FFB6 64030000 push dword ptr ds:[esi+0x364]
570B319D 85FF test edi,edi
570B319F 74 06 je short WeChatWi.570B31A7
570B31A1 66:833F 00 cmp word ptr ds:[edi],0x0
570B31A5 75 05 jnz short WeChatWi.570B31AC
570B31A7 BF 08892958 mov edi,WeChatWi.58298908
570B31AC 83EC 14 sub esp,0x14
570B31AF 8BCC mov ecx,esp
570B31B1 89A5 18FFFFFF mov dword ptr ss:[ebp-0xE8],esp
570B31B7 6A FF push -0x1
570B31B9 57 push edi
570B31BA E8 F1BB3500 call WeChatWi.5740EDB0 ; 调用3
570B31BF FFB6 5C030000 push dword ptr ds:[esi+0x35C]
570B31C5 83EC 14 sub esp,0x14
570B31C8 8BCC mov ecx,esp
570B31CA 89A5 20FFFFFF mov dword ptr ss:[ebp-0xE0],esp
570B31D0 53 push ebx
570B31D1 E8 1ABC3500 call WeChatWi.5740EDF0 ; 调用4
570B31D6 C645 FC 06 mov byte ptr ss:[ebp-0x4],0x6
570B31DA E8 41B5ECFF call WeChatWi.56F7E720 ; 调用5
570B31DF 8BC8 mov ecx,eax
570B31E1 C645 FC 01 mov byte ptr ss:[ebp-0x4],0x1
570B31E5 E8 867D1200 call WeChatWi.571DAF70 ; 调用6
570B31EA 8D4D E4 lea ecx,dword ptr ss:[ebp-0x1C]
570B31ED E8 2E2AF3FF call WeChatWi.56FE5C20
570B31F2 8D8D 28FFFFFF lea ecx,dword ptr ss:[ebp-0xD8]
570B31F8 E8 A39DECFF call WeChatWi.56F7CFA0
570B31FD E9 D8010000 jmp WeChatWi.570B33DA
570B3202 8B8F 08010000 mov ecx,dword ptr ds:[edi+0x108] ; ntdll.770B562E
570B3208 8D95 3CFFFFFF lea edx,dword ptr ss:[ebp-0xC4]
570B320E 52 push edx
570B320F 8B01 mov eax,dword ptr ds:[ecx]
570B3211 FF50 04 call dword ptr ds:[eax+0x4]
570B3214 68 04212B58 push WeChatWi.582B2104 ; UNICODE "cancelbtn"
570B3219 8BC8 mov ecx,eax
570B321B E8 608F6800 call WeChatWi.5773C180
570B3220 50 push eax
570B3221 E8 E88DF400 call WeChatWi.57FFC00E
570B3226 83C4 08 add esp,0x8
570B3229 8D8D 3CFFFFFF lea ecx,dword ptr ss:[ebp-0xC4]
570B322F 85C0 test eax,eax
570B3231 0F94C3 sete bl
570B3234 E8 E08F6800 call WeChatWi.5773C219
570B3239 84DB test bl,bl
570B323B 75 3F jnz short WeChatWi.570B327C
570B323D 8B8F 08010000 mov ecx,dword ptr ds:[edi+0x108] ; ntdll.770B562E
570B3243 8D95 3CFFFFFF lea edx,dword ptr ss:[ebp-0xC4]
570B3249 52 push edx
570B324A 8B01 mov eax,dword ptr ds:[ecx]
570B324C FF50 04 call dword ptr ds:[eax+0x4]
570B324F 68 10E32158 push WeChatWi.5821E310 ; UNICODE "closebtn"
570B3254 8BC8 mov ecx,eax
570B3256 E8 258F6800 call WeChatWi.5773C180
570B325B 50 push eax
570B325C E8 AD8DF400 call WeChatWi.57FFC00E
570B3261 83C4 08 add esp,0x8
570B3264 8D8D 3CFFFFFF lea ecx,dword ptr ss:[ebp-0xC4]
570B326A 85C0 test eax,eax
570B326C 0F94C3 sete bl
570B326F E8 A58F6800 call WeChatWi.5773C219
570B3274 84DB test bl,bl
570B3276 0F84 56010000 je WeChatWi.570B33D2
570B327C 8B46 E0 mov eax,dword ptr ds:[esi-0x20] ; WeChatWi.57741459
570B327F 8D4E E0 lea ecx,dword ptr ds:[esi-0x20]
570B3282 6A 02 push 0x2
570B3284 FF10 call dword ptr ds:[eax]
570B3286 E9 4F010000 jmp WeChatWi.570B33DA
570B328B 68 1CE72958 push WeChatWi.5829E71C ; UNICODE "textchanged"
570B3290 8BCF mov ecx,edi
570B3292 E8 E98E6800 call WeChatWi.5773C180
570B3297 50 push eax
570B3298 E8 718DF400 call WeChatWi.57FFC00E
570B329D 83C4 08 add esp,0x8
570B32A0 85C0 test eax,eax
570B32A2 0F85 2A010000 jnz WeChatWi.570B33D2
570B32A8 8B8F 08010000 mov ecx,dword ptr ds:[edi+0x108] ; ntdll.770B562E
570B32AE 8D95 3CFFFFFF lea edx,dword ptr ss:[ebp-0xC4]
570B32B4 52 push edx
570B32B5 8B01 mov eax,dword ptr ds:[ecx]
570B32B7 FF50 04 call dword ptr ds:[eax+0x4]
570B32BA 68 68EB2958 push WeChatWi.5829EB68 ; UNICODE "contendEdit"
570B32BF 8BC8 mov ecx,eax
570B32C1 E8 BA8E6800 call WeChatWi.5773C180
570B32C6 50 push eax
570B32C7 E8 428DF400 call WeChatWi.57FFC00E
570B32CC 83C4 08 add esp,0x8
570B32CF 8D8D 3CFFFFFF lea ecx,dword ptr ss:[ebp-0xC4]
570B32D5 85C0 test eax,eax
570B32D7 0F94C3 sete bl
570B32DA E8 3A8F6800 call WeChatWi.5773C219
570B32DF 84DB test bl,bl
570B32E1 0F84 EB000000 je WeChatWi.570B33D2
570B32E7 8B8E 44030000 mov ecx,dword ptr ds:[esi+0x344]
570B32ED 8D95 3CFFFFFF lea edx,dword ptr ss:[ebp-0xC4]
570B32F3 52 push edx
570B32F4 8B01 mov eax,dword ptr ds:[ecx]
570B32F6 FF50 3C call dword ptr ds:[eax+0x3C]
570B32F9 6A FF push -0x1
570B32FB 8BC8 mov ecx,eax
570B32FD E8 7E8E6800 call WeChatWi.5773C180
570B3302 50 push eax
570B3303 8D8D 28FFFFFF lea ecx,dword ptr ss:[ebp-0xD8]
570B3309 E8 A2BA3500 call WeChatWi.5740EDB0
570B330E 8D8D 3CFFFFFF lea ecx,dword ptr ss:[ebp-0xC4]
570B3314 C745 FC 0700000>mov dword ptr ss:[ebp-0x4],0x7
570B331B E8 F98E6800 call WeChatWi.5773C219
570B3320 8B9D 2CFFFFFF mov ebx,dword ptr ss:[ebp-0xD4]
570B3326 83FB 14 cmp ebx,0x14
570B3329 0F8E 91000000 jle WeChatWi.570B33C0
570B332F 83EC 14 sub esp,0x14
570B3332 8D85 28FFFFFF lea eax,dword ptr ss:[ebp-0xD8]
570B3338 8BCC mov ecx,esp
570B333A 50 push eax
570B333B E8 B0BA3500 call WeChatWi.5740EDF0
570B3340 E8 0BFCFFFF call WeChatWi.570B2F50
570B3345 83C4 14 add esp,0x14
570B3348 83F8 28 cmp eax,0x28
570B334B 7E 73 jle short WeChatWi.570B33C0
570B334D 8B85 28FFFFFF mov eax,dword ptr ss:[ebp-0xD8]
570B3353 85C0 test eax,eax
570B3355 74 06 je short WeChatWi.570B335D
570B3357 66:8338 00 cmp word ptr ds:[eax],0x0
570B335B 75 05 jnz short WeChatWi.570B3362
570B335D B8 08892958 mov eax,WeChatWi.58298908
570B3362 50 push eax
570B3363 8D4D C0 lea ecx,dword ptr ss:[ebp-0x40]
570B3366 E8 6591EEFF call WeChatWi.56F9C4D0
570B336B C645 FC 08 mov byte ptr ss:[ebp-0x4],0x8
570B336F 8D4D C0 lea ecx,dword ptr ss:[ebp-0x40]
570B3372 8B45 D0 mov eax,dword ptr ss:[ebp-0x30]
570B3375 48 dec eax
570B3376 50 push eax
570B3377 6A 00 push 0x0
570B3379 8D45 D8 lea eax,dword ptr ss:[ebp-0x28]
570B337C 50 push eax
570B337D E8 7E5FFAFF call WeChatWi.57059300
570B3382 8BD0 mov edx,eax
570B3384 C645 FC 09 mov byte ptr ss:[ebp-0x4],0x9
570B3388 837A 14 08 cmp dword ptr ds:[edx+0x14],0x8
570B338C 72 02 jb short WeChatWi.570B3390
570B338E 8B12 mov edx,dword ptr ds:[edx]
570B3390 8B8E 44030000 mov ecx,dword ptr ds:[esi+0x344]
570B3396 52 push edx
570B3397 8B01 mov eax,dword ptr ds:[ecx]
570B3399 FF50 40 call dword ptr ds:[eax+0x40]
570B339C 8D4D D8 lea ecx,dword ptr ss:[ebp-0x28]
570B339F C645 FC 08 mov byte ptr ss:[ebp-0x4],0x8
570B33A3 E8 58B6EEFF call WeChatWi.56F9EA00
570B33A8 8B8E 44030000 mov ecx,dword ptr ds:[esi+0x344]
获取好友详情:22905167168@chatroom
基址:56F30000
571556D9 33C5 xor eax,ebp
571556DB 8945 F0 mov dword ptr ss:[ebp-0x10],eax
571556DE 53 push ebx
571556DF 56 push esi
571556E0 57 push edi
571556E1 50 push eax
571556E2 8D45 F4 lea eax,dword ptr ss:[ebp-0xC]
571556E5 64:A3 00000000 mov dword ptr fs:[0],eax
571556EB 8BF1 mov esi,ecx
571556ED C745 FC 0000000>mov dword ptr ss:[ebp-0x4],0x0
571556F4 8B86 480A0000 mov eax,dword ptr ds:[esi+0xA48]
571556FA 85C0 test eax,eax
571556FC 74 10 je short WeChatWi.5715570E
571556FE B2 01 mov dl,0x1
57155700 C680 890B0000 0>mov byte ptr ds:[eax+0xB89],0x0
57155707 32C9 xor cl,cl
57155709 E8 825DE5FF call WeChatWi.56FAB490
5715570E 8B8E AC0B0000 mov ecx,dword ptr ds:[esi+0xBAC]
57155714 6A 00 push 0x0
57155716 8B01 mov eax,dword ptr ds:[ecx]
57155718 FF90 EC000000 call dword ptr ds:[eax+0xEC]
5715571E 8B5D 0C mov ebx,dword ptr ss:[ebp+0xC]
57155721 85DB test ebx,ebx
57155723 0F9EC0 setle al
57155726 84C0 test al,al
57155728 0F85 FC020000 jnz WeChatWi.57155A2A
5715572E A1 14625558 mov eax,dword ptr ds:[0x58556214]
57155733 85C0 test eax,eax
57155735 74 06 je short WeChatWi.5715573D
57155737 66:8338 00 cmp word ptr ds:[eax],0x0
5715573B 75 05 jnz short WeChatWi.57155742
5715573D B8 08892958 mov eax,WeChatWi.58298908
57155742 50 push eax
57155743 8D4D 08 lea ecx,dword ptr ss:[ebp+0x8]
57155746 E8 C59C2B00 call WeChatWi.5740F410
5715574B 8B7D 08 mov edi,dword ptr ss:[ebp+0x8]
5715574E 85C0 test eax,eax
57155750 0F84 4F020000 je WeChatWi.571559A5
57155756 85FF test edi,edi
57155758 74 08 je short WeChatWi.57155762
5715575A 66:833F 00 cmp word ptr ds:[edi],0x0
5715575E 8BC7 mov eax,edi
57155760 75 05 jnz short WeChatWi.57155767
57155762 B8 08892958 mov eax,WeChatWi.58298908
57155767 50 push eax
57155768 B9 28625558 mov ecx,WeChatWi.58556228
5715576D E8 9E9C2B00 call WeChatWi.5740F410
57155772 85C0 test eax,eax
57155774 0F84 2B020000 je WeChatWi.571559A5
5715577A 85FF test edi,edi
5715577C 74 08 je short WeChatWi.57155786
5715577E 66:833F 00 cmp word ptr ds:[edi],0x0
57155782 8BC7 mov eax,edi
57155784 75 05 jnz short WeChatWi.5715578B
57155786 B8 08892958 mov eax,WeChatWi.58298908
5715578B 50 push eax
5715578C B9 3C625558 mov ecx,WeChatWi.5855623C
57155791 E8 7A9C2B00 call WeChatWi.5740F410
57155796 85C0 test eax,eax
57155798 0F84 07020000 je WeChatWi.571559A5
5715579E E8 7D8FE2FF call WeChatWi.56F7E720
571557A3 8D45 08 lea eax,dword ptr ss:[ebp+0x8]
571557A6 50 push eax
571557A7 E8 54930800 call WeChatWi.571DEB00
571557AC 83F8 02 cmp eax,0x2
571557AF 0F84 EA010000 je WeChatWi.5715599F
571557B5 8DBE 500C0000 lea edi,dword ptr ds:[esi+0xC50]
571557BB 57 push edi
571557BC 83EC 14 sub esp,0x14
571557BF 8D45 08 lea eax,dword ptr ss:[ebp+0x8]
571557C2 8BCC mov ecx,esp
571557C4 8965 D4 mov dword ptr ss:[ebp-0x2C],esp
571557C7 50 push eax
571557C8 E8 23962B00 call WeChatWi.5740EDF0 ; call1
571557CD C645 FC 01 mov byte ptr ss:[ebp-0x4],0x1
571557D1 E8 4A8FE2FF call WeChatWi.56F7E720 ; call2
571557D6 C645 FC 00 mov byte ptr ss:[ebp-0x4],0x0
571557DA E8 A1720800 call WeChatWi.571DCA80 ; call3
571557DF 84C0 test al,al
571557E1 0F84 43020000 je WeChatWi.57155A2A
571557E7 81EC E0030000 sub esp,0x3E0
571557ED 8BCC mov ecx,esp
571557EF 57 push edi
571557F0 E8 1B51EDFF call WeChatWi.5702A910
571557F5 8BCE mov ecx,esi
571557F7 E8 84020000 call WeChatWi.57155A80
571557FC 8D45 C0 lea eax,dword ptr ss:[ebp-0x40]
571557FF 8BCF mov ecx,edi
57155801 50 push eax
57155802 E8 B968E5FF call WeChatWi.56FAC0C0
57155807 8DBE 58100000 lea edi,dword ptr ds:[esi+0x1058]
5715580D 50 push eax
5715580E 8BCF mov ecx,edi
57155810 E8 7BA02B00 call WeChatWi.5740F890
57155815 8D4D C0 lea ecx,dword ptr ss:[ebp-0x40]
57155818 E8 8377E2FF call WeChatWi.56F7CFA0
5715581D 6A 00 push 0x0
5715581F 8BCE mov ecx,esi
57155821 E8 BA1A0000 call WeChatWi.571572E0
57155826 8BCF mov ecx,edi
57155828 E8 23780800 call WeChatWi.571DD050
5715582D 84C0 test al,al
5715582F 0F84 01010000 je WeChatWi.57155936
57155835 8D45 D8 lea eax,dword ptr ss:[ebp-0x28]
57155838 50 push eax
57155839 E8 72CBE2FF call WeChatWi.56F823B0
5715583E 8BC8 mov ecx,eax
57155840 E8 FB962100 call WeChatWi.5736EF40
57155845 6A 00 push 0x0
57155847 50 push eax
57155848 8D4D C0 lea ecx,dword ptr ss:[ebp-0x40]
5715584B E8 B0962B00 call WeChatWi.5740EF00
57155850 8D4D D8 lea ecx,dword ptr ss:[ebp-0x28]
57155853 C645 FC 02 mov byte ptr ss:[ebp-0x4],0x2
57155857 E8 047AE2FF call WeChatWi.56F7D260
5715585C E8 DF0AE4FF call WeChatWi.56F96340
57155861 8D45 C0 lea eax,dword ptr ss:[ebp-0x40]
57155864 50 push eax
57155865 57 push edi
57155866 E8 35A20700 call WeChatWi.571CFAA0
5715586B 84C0 test al,al
5715586D 74 1E je short WeChatWi.5715588D
5715586F 57 push edi
57155870 8BCE mov ecx,esi
57155872 E8 19140000 call WeChatWi.57156C90
57155877 6A 05 push 0x5
57155879 8BCE mov ecx,esi
5715587B E8 90270000 call WeChatWi.57158010
57155880 8D4D C0 lea ecx,dword ptr ss:[ebp-0x40]
57155883 E8 1877E2FF call WeChatWi.56F7CFA0
57155888 E9 9D010000 jmp WeChatWi.57155A2A
5715588D 8B8E 7C0A0000 mov ecx,dword ptr ds:[esi+0xA7C]
57155893 6A 00 push 0x0
57155895 8B01 mov eax,dword ptr ds:[ecx]
57155897 FF90 EC000000 call dword ptr ds:[eax+0xEC]
5715589D 6A 00 push 0x0
5715589F 8BCE mov ecx,esi
571558A1 E8 3A1A0000 call WeChatWi.571572E0
571558A6 8B8E 900A0000 mov ecx,dword ptr ds:[esi+0xA90]
571558AC 6A 00 push 0x0
571558AE 8B01 mov eax,dword ptr ds:[ecx]
571558B0 FF90 EC000000 call dword ptr ds:[eax+0xEC]
571558B6 8B8E A80B0000 mov ecx,dword ptr ds:[esi+0xBA8]
571558BC 6A 00 push 0x0
571558BE 8B01 mov eax,dword ptr ds:[ecx]
571558C0 FF90 EC000000 call dword ptr ds:[eax+0xEC]
571558C6 8B8E 080B0000 mov ecx,dword ptr ds:[esi+0xB08]
571558CC 85C9 test ecx,ecx
571558CE 74 0A je short WeChatWi.571558DA
571558D0 8B01 mov eax,dword ptr ds:[ecx]
571558D2 6A 00 push 0x0
571558D4 FF90 EC000000 call dword ptr ds:[eax+0xEC]
571558DA 8B8E 7C0A0000 mov ecx,dword ptr ds:[esi+0xA7C]
571558E0 6A 01 push 0x1
571558E2 8B01 mov eax,dword ptr ds:[ecx]
571558E4 FF90 EC000000 call dword ptr ds:[eax+0xEC]
571558EA 8BCE mov ecx,esi
571558EC E8 AF150000 call WeChatWi.57156EA0
571558F1 83EC 14 sub esp,0x14
571558F4 BA 22040000 mov edx,0x422
571558F9 8BCC mov ecx,esp
571558FB 8965 D4 mov dword ptr ss:[ebp-0x2C],esp
571558FE 32DB xor bl,bl
57155900 E8 DBA32B00 call WeChatWi.5740FCE0
57155905 83EC 14 sub esp,0x14
57155908 C645 FC 03 mov byte ptr ss:[ebp-0x4],0x3
5715590C BA 0E040000 mov edx,0x40E
57155911 8BCC mov ecx,esp
57155913 E8 C8A32B00 call WeChatWi.5740FCE0
57155918 C645 FC 02 mov byte ptr ss:[ebp-0x4],0x2
5715591C 8AD3 mov dl,bl
5715591E 8B4E 04 mov ecx,dword ptr ds:[esi+0x4]
57155921 E8 7A5DF0FF call WeChatWi.5705B6A0
57155926 83C4 28 add esp,0x28
57155929 8D4D C0 lea ecx,dword ptr ss:[ebp-0x40]
5715592C E8 6F76E2FF call WeChatWi.56F7CFA0
57155931 E9 F4000000 jmp WeChatWi.57155A2A
57155936 8B8E 7C0A0000 mov ecx,dword ptr ds:[esi+0xA7C]
5715593C 6A 00 push 0x0
5715593E 8B01 mov eax,dword ptr ds:[ecx]
57155940 FF90 EC000000 call dword ptr ds:[eax+0xEC]
57155946 6A 00 push 0x0
57155948 8BCE mov ecx,esi
5715594A E8 91190000 call WeChatWi.571572E0
个人edi
0D589BB0 00000000
0D589BB4 00000000
0D589BB8 0D8CFDC0 UNICODE "wxid_ex8vs2ew6u5j12" 0x8
0D589BBC 00000013
0D589BC0 00000020
0D589BC4 00000000
0D589BC8 00000000
0D589BCC 0DB7B730 UNICODE "yfsx5201314" 0x1C
0D589BD0 0000000B
0D589BD4 00000010
0D589BD8 00000000
0D589BDC 00000000
0D589BE0 0D871910 UNICODE "v1_d0bebd57db3ead25fdc4c9632853fe0a6a11f06cc4c3b29" 0x30
0D589BE4 0000006C
0D589BE8 00000080
0D589BEC 00000000
0D589BF0 00000000
0D589BF4 00000000
0D589BF8 00000001
0D589BFC 00000000
0D589C00 0DB715A8 UNICODE "瓷肌-森贤" 0x50
0D589C04 00000005
0D589C08 00000008
0D589C0C 00000000
0D589C10 00000000
0D589C14 0DA15B40 UNICODE "雨雪纷飞" 0x64
0D589C18 00000004
0D589C1C 00000008
0D589C20 00000000
0D589C24 00000000
0D589C28 00000000
0D589C2C 00000000
0D589C30 00000000
0D589C34 00000000
0D589C38 00000000
0D589C3C 00000000
0D589C40 00000000
0D589C44 00000000
0D589C48 00000000
0D589C4C 00000000
0D589C50 00000001
0D589C54 0DA15A20 UNICODE "YXFF"
0D589C58 00000004
0D589C5C 00000008
0D589C60 00000000
0D589C64 00000000
0D589C68 0DA51A08 UNICODE "yuxuefenfei"
0D589C6C 0000000B
0D589C70 00000010
0D589C74 00000000
0D589C78 00000000
0D589C7C 0DC69890 UNICODE "CJSX"
0D589C80 00000004
0D589C84 00000004
0D589C88 00000000
0D589C8C 00000000
0D589C90 0DB7B7C0 UNICODE "cijisenxian"
0D589C94 0000000B
0D589C98 00000010
0D589C9C 00000000
0D589CA0 00000000
0D589CA4 0D842E90 UNICODE "http://wx.qlogo.cn/mmhead/ver_1/59RvVaxnaqKNgiaNT3"
0D589CA8 00000093
0D589CAC 00000100
0D589CB0 00000000
0D589CB4 00000000
0D589CB8 0DC2C2B0 UNICODE "http://wx.qlogo.cn/mmhead/ver_1/59RvVaxnaqKNgiaNT3" 0x108
0D589CBC 00000095
0D589CC0 00000100
0D589CC4 00000000
0D589CC8 00000000
0D589CCC 0DB929D0 ASCII "747e527aec4b24b1f1ca46779ddbd49a"
0D589CD0 01010101
0D589CD4 01010101
0D589CD8 01010101
0D589CDC 00000020
0D589CE0 0000002F
0D589CE4 00000000
群edi
0D589BB0 00000000
0D589BB4 00000000
0D589BB8 0D8CFDC0 UNICODE "22905167168@chatroom"
0D589BBC 00000014
0D589BC0 00000020
0D589BC4 00000000
0D589BC8 00000000
0D589BCC 0DB7BB20
0D589BD0 00000000
0D589BD4 00000000
0D589BD8 00000000
0D589BDC 00000000
0D589BE0 0D871910 UNICODE "v1_ea7731173e71074c543ba3ea16c35d5b30f48fed5b7a445"
0D589BE4 0000006C
0D589BE8 00000080
0D589BEC 00000000
0D589BF0 00000000
0D589BF4 00000000
0D589BF8 00000003
0D589BFC 00000000
0D589C00 0DB71228
0D589C04 00000000
0D589C08 00000000
0D589C0C 00000000
0D589C10 00000000