Winsock fd_set Structure (0x104 Signature)
On 32-bit Windows, the fd_set structure from Winsock (winsock2.h) is exactly 260 bytes, or 0x104. That makes 0x104 a useful signature when reverse engineering.
Structure breakdown:
typedef struct fd_set {
u_int fd_count; // 4 bytes
SOCKET fd_array[FD_SETSIZE]; // 64 × 4 bytes = 256 bytes
} fd_set; // total = 260 = 0x104
When you see assembly like:
lea eax, [ebp+writefds]
push 104h
push esi
push eax
call _memset
It is very likely clearing a fd_set for select():
memset(&writefds, 0, sizeof(fd_set)); // i.e. FD_ZERO(&writefds);
Common fd_set variable names in disassembly are readfds, writefds, and exceptfds. Combined with timeout and a socket-like argument, this is the classic setup for the select() API.
This is a pattern recognition shortcut, not a guarantee: always verify the calling convention and argument order, and treat 0x104 as a strong clue rather than proof.
Related: x86 CDECL Calling Convention