- UID
- 33475
注册时间2007-8-6
阅读权限20
最后登录1970-1-1
以武会友
TA的每日心情 | 开心 2018-4-27 20:21 |
---|
签到天数: 2 天 [LV.1]初来乍到
|
今天在PYG发现一软件破解注册机,想下,没钱,穷啊!!没办法自己动手吧。软件加壳了ASPack 2.12 -> Alexey Solodovnikov好脱,脱壳就不说了。OD上,运行,点注册没提示。用API插件下内存短点。点注册后短下经过好多的返回到了5b6938向上到这里下短
005B6882 . 55 push ebp
005B6883 . 68 98695B00 push dumped_.005B6998
005B6888 . 64:FF30 push dword ptr fs:[eax]
005B688B . 64:8920 mov dword ptr fs:[eax],esp
005B688E . 8D55 F8 lea edx,dword ptr ss:[ebp-8]
005B6891 . 8B83 2C030000 mov eax,dword ptr ds:[ebx+32C]
005B6897 . E8 C421EDFF call dumped_.00488A60
005B689C . 8B45 F8 mov eax,dword ptr ss:[ebp-8]
005B689F . 8D55 FC lea edx,dword ptr ss:[ebp-4]
005B68A2 . E8 792FE5FF call dumped_.00409820
005B68A7 . 8B45 FC mov eax,dword ptr ss:[ebp-4]
005B68AA . 50 push eax
005B68AB . A1 30FA5C00 mov eax,dword ptr ds:[5CFA30]
005B68B0 . 8B00 mov eax,dword ptr ds:[eax]
005B68B2 . B9 E4695B00 mov ecx,dumped_.005B69E4 ; ASCII "RegID"
005B68B7 . BA F4695B00 mov edx,dumped_.005B69F4
005B68BC . 8B38 mov edi,dword ptr ds:[eax]
005B68BE . FF57 04 call dword ptr ds:[edi+4]
005B68C1 . 8B06 mov eax,dword ptr ds:[esi]
005B68C3 . E8 C87C0000 call dumped_.005BE590 F7进去
到这里
005BE590 $ 55 push ebp
005BE591 . 8BEC mov ebp,esp
005BE593 . B9 05000000 mov ecx,5
005BE598 > 6A 00 push 0
005BE59A . 6A 00 push 0
005BE59C . 49 dec ecx
005BE59D .^ 75 F9 jnz short dumped_.005BE598
005BE59F . 53 push ebx
005BE5A0 . 56 push esi
005BE5A1 . 57 push edi
005BE5A2 . 8BD8 mov ebx,eax
005BE5A4 . 33C0 xor eax,eax
005BE5A6 . 55 push ebp
005BE5A7 . 68 E2E65B00 push dumped_.005BE6E2
005BE5AC . 64:FF30 push dword ptr fs:[eax]
005BE5AF . 64:8920 mov dword ptr fs:[eax],esp
005BE5B2 . 33C0 xor eax,eax
005BE5B4 . 55 push ebp
005BE5B5 . 68 BDE65B00 push dumped_.005BE6BD
005BE5BA . 64:FF30 push dword ptr fs:[eax]
005BE5BD . 64:8920 mov dword ptr fs:[eax],esp
005BE5C0 . 8D45 FC lea eax,dword ptr ss:[ebp-4]
005BE5C3 . 50 push eax
005BE5C4 . E8 5F74FFFF call dumped_.005B5A28
005BE5C9 . 8BD0 mov edx,eax
005BE5CB . 8D45 F4 lea eax,dword ptr ss:[ebp-C]
005BE5CE . E8 D966E4FF call dumped_.00404CAC
005BE5D3 . 8B45 F4 mov eax,dword ptr ss:[ebp-C]
005BE5D6 . 8D55 F8 lea edx,dword ptr ss:[ebp-8]
005BE5D9 . E8 42B2E4FF call dumped_.00409820
005BE5DE 8B45 F8 mov eax,dword ptr ss:[ebp-8]
005BE5E1 . 33C9 xor ecx,ecx
005BE5E3 . 8B15 60335D00 mov edx,dword ptr ds:[5D3360]
005BE5E9 . E8 6EEFFEFF call dumped_.005AD55C
005BE5EE . 8B45 FC mov eax,dword ptr ss:[ebp-4] ; 注册码
005BE5F1 . 50 push eax
005BE5F2 . 68 F8E65B00 push dumped_.005BE6F8
005BE5F7 . 8D45 F0 lea eax,dword ptr ss:[ebp-10]
005BE5FA . 50 push eax
005BE5FB . B9 04E75B00 mov ecx,dumped_.005BE704 ; ASCII "RegID"
005BE600 . BA 14E75B00 mov edx,dumped_.005BE714
005BE605 . A1 B4315D00 mov eax,dword ptr ds:[5D31B4]
005BE60A . 8B30 mov esi,dword ptr ds:[eax]
005BE60C . FF16 call dword ptr ds:[esi]
005BE60E 8B55 F0 mov edx,dword ptr ss:[ebp-10] 这里改成mov edx,dword ptr ss:[ebp-4]
005BE611 . 58 pop eax
005BE612 . E8 A968E4FF call dumped_.00404EC0
005BE617 . 74 4E je short dumped_.005BE667 关键跳
[ 本帖最后由 yuxinlcj 于 2007-11-19 16:16 编辑 ] |
|