- UID
- 54124
注册时间2008-7-1
阅读权限10
最后登录1970-1-1
周游历练

该用户从未签到
|
PEID查壳,发现是VB写的,我们利用C32查找UNICODE,发现
0043E911 PUSH 433B40 \->: 已注册
好!找到关键了
我们OD载入来到0043E911 SRN:!-
0043E8F8 /0F85 3D010000 jnz 0043EA3B ; 关键跳,NOP就KO了
0043E8FE . |FF91 B4030000 call dword ptr [ecx+3B4]
0043E904 . |8D55 D4 lea edx, dword ptr [ebp-2C] Cl
0043E907 . |50 push eax
0043E908 . |52 push edx
0043E909 . |FF15 B0104000 call dword ptr [<&MSVBVM60.__vbaObjSe>; MSVBVM60.__vbaObjSet n ?%3=~9
0043E90F . |8BD8 mov ebx, eax
0043E911 . |68 403B4300 push 00433B40 ; ASCII "騗鑜孮"
0043E916 . |53 push ebx J ,fXXi)J
0043E917 . |8B03 mov eax, dword ptr [ebx]
0043E919 . |FF50 54 call dword ptr [eax+54]
0043E91C . |3BC7 cmp eax, edi
0043E91E . |DBE2 fclex |
|