设计到程序部分如下:
F878A261
8365D400
AND
DWORD PTR [EBP-2C],00
F878A265
F6400CA4
TEST
BYTE PTR [EAX+0C],A4
--->b[2b]是否是混杂模式等
F878A269
741E
JZ
F878A289
不是:B,是的时候是2B
F878A26B
8B502A
MOV
EDX,[EAX+2A] ;
F878A26E
3B5102
CMP
EDX,[ECX+02] ;比较MAC地址是否是本机的
F878A271
750F
JNZ
F878A282
;
F878A273
668B5028
MOV
DX,[EAX+28] ;
F878A277
663B11
CMP
DX,[ECX]
;
F878A27A
7506
JNZ
F878A282
;
F878A27C
8365D400
AND
DWORD PTR [EBP-2C],00 ;是本机的标志
F878A280
EB07
F878A265
F878A269
F878A26B
F878A26E
F878A271
F878A273
F878A277
F878A27A
F878A27C
F878A280