挂钩Windows API(14) .codepublic disasm_mainpublic _disasm_mainpublic @disasm_mainpublic DISASM_MAINdisasm_main:_disasm_main:@disasm_main:DISASM_MAIN:; __fastcall EAX; __cdecl [ESP+4];这是我的第一处修改,它只是这个函数的声明get_instr_len: mov ecx, [esp+4] ; ECX = opcode ptr xor edx, edx ; 标志 xor eax, eax@@prefix: and dl, not C_PREFIX mov al, [ecx] inc ecx