- UID
- 31985
注册时间2007-5-6
阅读权限40
最后登录1970-1-1
独步武林
该用户从未签到
|
发表于 2007-5-20 03:24:18
|
显示全部楼层
我试着脱壳后用od找字符来到这里
00405F36 53 PUSH EBX
00405F37 56 PUSH ESI
00405F38 6A 01 PUSH 1
00405F3A 8BD9 MOV EBX,ECX
00405F3C E8 29AD0000 CALL 1_.00410C6A
00405F41 8B43 64 MOV EAX,DWORD PTR DS:[EBX+64]
00405F44 8D5424 08 LEA EDX,DWORD PTR SS:[ESP+8]
00405F48 2BD0 SUB EDX,EAX
00405F4A 8A08 MOV CL,BYTE PTR DS:[EAX]
00405F4C 880C02 MOV BYTE PTR DS:[EDX+EAX],CL
00405F4F 40 INC EAX
00405F50 84C9 TEST CL,CL
00405F52 ^ 75 F6 JNZ SHORT 1_.00405F4A
00405F54 8B43 60 MOV EAX,DWORD PTR DS:[EBX+60]
00405F57 8D5424 48 LEA EDX,DWORD PTR SS:[ESP+48]
00405F5B 2BD0 SUB EDX,EAX
00405F5D 8A08 MOV CL,BYTE PTR DS:[EAX]
00405F5F 880C02 MOV BYTE PTR DS:[EDX+EAX],CL
00405F62 40 INC EAX
00405F63 84C9 TEST CL,CL
00405F65 ^ 75 F6 JNZ SHORT 1_.00405F5D
00405F67 68 5C814100 PUSH 1_.0041815C ; ether.dll
00405F6C FF15 C8304100 CALL DWORD PTR DS:[4130C8]
00405F72 8BF0 MOV ESI,EAX
00405F74 68 AC834100 PUSH 1_.004183AC ; reg_code
00405F79 56 PUSH ESI
00405F7A FF15 C4304100 CALL DWORD PTR DS:[4130C4]
00405F80 8D8C24 88000000 LEA ECX,DWORD PTR SS:[ESP+88]
00405F87 8D5424 08 LEA EDX,DWORD PTR SS:[ESP+8]
00405F8B 51 PUSH ECX
00405F8C 52 PUSH EDX
00405F8D FFD0 CALL EAX
00405F8F 83C4 08 ADD ESP,8
00405F92 56 PUSH ESI
00405F93 FF15 C0304100 CALL DWORD PTR DS:[4130C0]
00405F99 8D8424 88000000 LEA EAX,DWORD PTR SS:[ESP+88]
00405FA0 8D4C24 48 LEA ECX,DWORD PTR SS:[ESP+48]
00405FA4 50 PUSH EAX
00405FA5 51 PUSH ECX
00405FA6 E8 35F8FFFF CALL 1_.004057E0 根据以往的经验 在这里做内存注册机 用EAX做寄存器 竟然成功了 可能是运气比较好吧 呵呵
00405FAB 83C4 08 ADD ESP,8
00405FAE 85C0 TEST EAX,EAX
00405FB0 0F85 DF000000 JNZ 1_.00406095
00405FB6 8A4C04 08 MOV CL,BYTE PTR SS:[ESP+EAX+8]
00405FBA 8888 08964100 MOV BYTE PTR DS:[EAX+419608],CL
00405FC0 40 INC EAX
00405FC1 84C9 TEST CL,CL
00405FC3 ^ 75 F1 JNZ SHORT 1_.00405FB6
00405FC5 33C0 XOR EAX,EAX
00405FC7 8A4C04 48 MOV CL,BYTE PTR SS:[ESP+EAX+48]
00405FCB 8888 C0914100 MOV BYTE PTR DS:[EAX+4191C0],CL
00405FD1 40 INC EAX
00405FD2 84C9 TEST CL,CL
00405FD4 ^ 75 F1 JNZ SHORT 1_.00405FC7/:09
00405FD6 C705 A4994100 0>MOV DWORD PTR DS:[4199A4],1
00405FE0 8B53 64 MOV EDX,DWORD PTR DS:[EBX+64]
00405FE3 57 PUSH EDI
00405FE4 52 PUSH EDX
00405FE5 8D8424 D0010000 LEA EAX,DWORD PTR SS:[ESP+1D0]
00405FEC 68 D88A4100 PUSH 1_.00418AD8 ; 此副本授权给:%s
00405FF1 50 PUSH EAX
00405FF2 FF15 B4354100 CALL DWORD PTR DS:[4135B4]
00405FF8 83C4 0C ADD ESP,0C
00405FFB 8D8C24 CC010000 LEA ECX,DWORD PTR SS:[ESP+1CC]
00406002 6A 40 PUSH 40
00406004 68 CC8A4100 PUSH 1_.00418ACC ; 感谢
00406009 51 PUSH ECX
0040600A 8BCB MOV ECX,EBX
0040600C E8 A5AB0000 CALL 1_.00410BB6
00406011 8D9424 CC000000 LEA EDX,DWORD PTR SS:[ESP+CC]
00406018 52 PUSH EDX
00406019 E8 D2D0FFFF CALL 1_.004030F0
0040601E 8DBC24 D0000000 LEA EDI,DWORD PTR SS:[ESP+D0]
00406025 83C9 FF OR ECX,FFFFFFFF
00406028 33C0 XOR EAX,EAX
0040602A 83C4 04 ADD ESP,4
0040602D F2:AE REPNE SCAS BYTE PTR ES:[EDI]
0040602F BA 68884100 MOV EDX,1_.00418868 ; option.ini
00406034 8D8424 CC000000 LEA EAX,DWORD PTR SS:[ESP+CC]
0040603B F7D1 NOT ECX
0040603D 49 DEC ECX
0040603E 2BC2 SUB EAX,EDX
00406040 03C8 ADD ECX,EAX
00406042 5F POP EDI
00406043 8A02 MOV AL,BYTE PTR DS:[EDX]
00406045 880411 MOV BYTE PTR DS:[ECX+EDX],AL
00406048 42 INC EDX
00406049 84C0 TEST AL,AL
0040604B ^ 75 F6 JNZ SHORT 1_.00406043
0040604D 8B35 D4304100 MOV ESI,DWORD PTR DS:[4130D4]
00406053 8D8C24 C8000000 LEA ECX,DWORD PTR SS:[ESP+C8]
0040605A 51 PUSH ECX
0040605B 68 08964100 PUSH 1_.00419608
00406060 68 CC834100 PUSH 1_.004183CC ; 用户名
00406065 68 84824100 PUSH 1_.00418284 ; 注册
0040606A FFD6 CALL ESI
0040606C 8D9424 C8000000 LEA EDX,DWORD PTR SS:[ESP+C8]
00406073 52 PUSH EDX
00406074 68 C0914100 PUSH 1_.004191C0
00406079 68 B8834100 PUSH 1_.004183B8 ; 注册码
0040607E 68 84824100 PUSH 1_.00418284 ; 注册
00406083 FFD6 CALL ESI
00406085 8BCB MOV ECX,EBX
00406087 E8 7AA90000 CALL 1_.00410A06
0040608C 5E POP ESI
0040608D 5B POP EBX
0040608E 81C4 C0020000 ADD ESP,2C0
00406094 C3 RETN
00406095 6A 40 PUSH 40
00406097 68 C48A4100 PUSH 1_.00418AC4 ; 抱歉
0040609C 68 9C8A4100 PUSH 1_.00418A9C ; 无效用户名和注册码
004060A1 8BCB MOV ECX,EBX
希望楼主能分享下破解的心得 先谢谢了 /:09 |
|