- UID
- 4497
注册时间2005-11-9
阅读权限10
最后登录1970-1-1
周游历练
该用户从未签到
|
发表于 2006-12-14 20:06:16
|
显示全部楼层
是这个程序吗?
如果是的话是明码比较
下断在(不要忘记先脱壳如果不过请在UPX解压完成后)
进去看看吧!~
004677B6 . FF15 40124000 CALL DWORD PTR DS:[<&MSVBVM60.__vbaStrCo>; MSVBVM60.__vbaStrCopy
004677BC . 8D55 D0 LEA EDX,DWORD PTR SS:[EBP-30]
004677BF . 8D85 40FFFFFF LEA EAX,DWORD PTR SS:[EBP-C0]
004677C5 . 8995 6CFFFFFF MOV DWORD PTR SS:[EBP-94],EDX
004677CB . 8D4D C8 LEA ECX,DWORD PTR SS:[EBP-38]
004677CE . 50 PUSH EAX
004677CF . 8D95 64FFFFFF LEA EDX,DWORD PTR SS:[EBP-9C]
004677D5 . 51 PUSH ECX
004677D6 . 52 PUSH EDX
004677D7 . C785 64FFFFFF>MOV DWORD PTR SS:[EBP-9C],4008
004677E1 . E8 0A61FFFF CALL DreamP.0045D8F0
004677E6 . 8BD0 MOV EDX,EAX
004677E8 . 8D4D C4 LEA ECX,DWORD PTR SS:[EBP-3C]
004677EB . FFD7 CALL EDI
004677ED . 50 PUSH EAX
004677EE . 8B45 E4 MOV EAX,DWORD PTR SS:[EBP-1C]
004677F1 . 50 PUSH EAX
004677F2 . FF15 34114000 CALL DWORD PTR DS:[<&MSVBVM60.__vbaStrCm>; MSVBVM60.__vbaStrCmp
这里上面应该出算法的地方还么仔细看!~
MSVBVM60.__vbaStrCmp
这里首次下断可以看见真码!~ |
|