- UID
- 32342
注册时间2007-6-1
阅读权限10
最后登录1970-1-1
周游历练

该用户从未签到
|

楼主 |
发表于 2007-8-10 22:37:09
|
显示全部楼层
004C34AA |. E8 5121F8FF call 00445600
004C34AF |. 8B4D FC mov ecx, dword ptr [ebp-4]
004C34B2 |. BA 54354C00 mov edx, 004C3554 ; reguser
004C34B7 |. 8BC3 mov eax, ebx
004C34B9 |. E8 CE84FAFF call 0046B98C
004C34BE |. 8D55 F8 lea edx, dword ptr [ebp-8]
004C34C1 |. 8B86 3C030000 mov eax, dword ptr [esi+33C]
004C34C7 |. E8 3421F8FF call 00445600
004C34CC |. 8B4D F8 mov ecx, dword ptr [ebp-8]
004C34CF |. BA 64354C00 mov edx, 004C3564 ; regno
004C34D4 |. 8BC3 mov eax, ebx
004C34D6 |. E8 B184FAFF call 0046B98C
004C34DB |. 8BC3 mov eax, ebx
004C34DD |. E8 FA00F4FF call 004035DC
004C34E2 |. 6A 40 push 40
004C34E4 |. B9 6C354C00 mov ecx, 004C356C ; 提示
004C34E9 |. BA 74354C00 mov edx, 004C3574 ; 注册完成,请重新运行程序!
004C34EE |. A1 E8964C00 mov eax, dword ptr [4C96E8]
004C34F3 |. 8B00 mov eax, dword ptr [eax]
004C34F5 |. E8 7E2EFAFF call 00466378
004C34FA |. A1 E8964C00 mov eax, dword ptr [4C96E8]
004C34FF |. 8B00 mov eax, dword ptr [eax]
004C3501 |. E8 CE2DFAFF call 004662D4
以上是最新的2.97的反汇编代码:004C34DD 应该是关键CALL了吧?跟入后如下
004035DC /$ 85C0 test eax, eax
004035DE 74 07 je short 004035E7
004035E0 |. B2 01 mov dl, 1
004035E2 |. 8B08 mov ecx, dword ptr [eax]
004035E4 |. FF51 FC call dword ptr [ecx-4]
004035E7 \> C3 retn
把JE改成JNE后DUMP,无法运行,修复IAT不成功,有无效的地址.请帮忙研究下 |
|