本帖最后由 十二 于 2011-1-24 12:19 编辑
- pushfd
- pushad
- push edx
- sgdt [esp-2]
- pop edx
- mov eax,edx
- mov ecx,120h
- mov byte ptr [edx],0c3h
- mov word ptr [edx+ecx],ax
- mov word ptr [edx+ecx+2],130h
- mov byte ptr [edx+ecx+4],00h
- mov byte ptr [edx+ecx+5],0ech
- shr eax,16
- mov word ptr [edx+ecx+6],ax
- mov word ptr [edx+ecx+16],0FFFFh
- mov word ptr [edx+ecx+18],00000h
- mov byte ptr [edx+ecx+20],000h
- mov word ptr [edx+ecx+21],0CF9Ah
- mov byte ptr [edx+ecx+23],000H
- popad
- popfd
复制代码 缩写还原,方便理解。  |