Tuesday, October 30, 2018

GetMessageW , waiting for WM_QUIT or termination

In assembly if you see pseudo code in windows similar to this

   call GetMessageW
   test eax, eax
   jg listenForMore

   call DoActionAfterTerminated

     call ds:TranslateMessage
     call ds:DispatchMessageW
     jmp top


Then it's listening for a message from a window.
GetMessageW returns 0 with the program gets shutdown
So as soon as the program is shut down it's going to perform whatever is at DoActionAfterTerminated

FYI this just me learning and documenting from the great Malware Hunter and his youtube video , none of this is my own


No comments:

Post a Comment