- UID
- 59939
注册时间2009-3-1
阅读权限10
最后登录1970-1-1
周游历练
该用户从未签到
|
小生最近偶然发现了一款库管软件,但是是共享版本的 ,小生也学习了几天飘云偶像的 追吗教程,但偶苦求无果,特怀着一份与大家共同学习,请教的心态 上来发个帖子,请求大家的帮助,谢谢了
OD载入程序:
查找ASCII 中找到注册码错误!请与我们联系!点击来到005F10D7
看代码:
005F10D0 . 6A 00 PUSH 0
005F10D2 > B9 EC105F00 MOV ECX,projshop.005F10EC ; 警告框
005F10D7 . BA F4105F00 MOV EDX,projshop.005F10F4 ; 注册码错误!请与我们联系!
005F10DC . A1 043D7500 MOV EAX,DWORD PTR DS:[753D04]
005F10E1 . 8B00 MOV EAX,DWORD PTR DS:[EAX]
005F10E3 . E8 44AEEBFF CALL projshop.004ABF2C 我判断这个可能是算法,F7进去看看
005F10E8 . C3 RETN
005F10E9 00 DB 00
005F10EA 00 DB 00
005F10EB 00 DB 00
005F10EC BE DB BE
005F10ED AF DB AF
005F10EE B8 DB B8
005F10EF E6 DB E6
005F10F0 BF DB BF
005F10F1 F2 DB F2
005F10F2 00 DB 00
005F10F3 00 DB 00
005F10F4 D7 DB D7
005F10F5 A2 DB A2
005F10F6 B2 DB B2
005F10F7 E1 DB E1
005F10F8 . C2 EBB4 RETN 0B4EB
005F10FB ED DB ED
005F10FC CE DB CE
005F10FD F3 DB F3
005F10FE 21 DB 21 ; CHAR '!'
005F10FF C7 DB C7
005F1100 EB DB EB
005F1101 D3 DB D3
005F1102 .^ EB CE JMP SHORT projshop.005F10D2
我不知道为什么我的都是从下往上走的 这个1102却调转到了005F10D2
005F1104 D2 DB D2
005F1105 . C3 RETN
005F1106 C7 DB C7
005F1107 C1 DB C1
005F1108 AA DB AA
005F1109 CF DB CF
005F110A B5 DB B5
005F110B 21 DB 21 ; CHAR '!'
005F110C 00 DB 00
005F110D 00 DB 00
005F110E 00 DB 00
005F110F 00 DB 00
005F10E3 F7进去后来到
00748199 |. 8BEC MOV EBP,ESP
0074819B |. 83C4 EC ADD ESP,-14
0074819E |. 53 PUSH EBX
0074819F |. 56 PUSH ESI
007481A0 |. 33C0 XOR EAX,EAX
007481A2 |. 8945 EC MOV DWORD PTR SS:[EBP-14],EAX
007481A5 |. B8 D8797400 MOV EAX,projshop.007479D8
007481AA |. E8 09EECBFF CALL projshop.00406FB8
007481AF |. BE 60737500 MOV ESI,projshop.00757360
007481B4 |. 33C0 XOR EAX,EAX
007481B6 |. 55 PUSH EBP
007481B7 |. 68 E8827400 PUSH projshop.007482E8
007481BC |. 64:FF30 PUSH DWORD PTR FS:[EAX]
007481BF |. 64:8920 MOV DWORD PTR FS:[EAX],ESP
007481C2 |. 6A 00 PUSH 0 ; /Title = NULL
007481C4 |. 68 F8827400 PUSH projshop.007482F8 ; |Class = "Tfrmjxclogin"
007481C9 |. E8 C2FACBFF CALL <JMP.&user32.FindWindowA> ; \FindWindowA
007481CE |. 85C0 TEST EAX,EAX
007481D0 |. 74 18 JE SHORT projshop.007481EA
007481D2 |. 6A 00 PUSH 0 ; /Style = MB_OK|MB_APPLMODAL
007481D4 |. 68 08837400 PUSH projshop.00748308 ; |Title = "运行"
007481D9 |. 68 10837400 PUSH projshop.00748310 ; |Text = "该程序已经有一个在运行中!"
007481DE |. 6A 00 PUSH 0 ; |hOwner = NULL
007481E0 |. E8 4BFDCBFF CALL <JMP.&user32.MessageBoxA> ; \MessageBoxA
007481E5 |. E8 96C5CBFF CALL projshop.00404780
007481EA |> A1 043D7500 MOV EAX,DWORD PTR DS:[753D04]
007481EF |. 8B00 MOV EAX,DWORD PTR DS:[EAX]
007481F1 |. E8 0E3BD6FF CALL projshop.004ABD04
007481F6 |. A1 043D7500 MOV EAX,DWORD PTR DS:[753D04]
007481FB |. 8B00 MOV EAX,DWORD PTR DS:[EAX]
007481FD |. BA 34837400 MOV EDX,projshop.00748334
00748202 |. E8 B536D6FF CALL projshop.004AB8BC
00748207 |. 6A 01 PUSH 1 ; /String2 = 00000001 ???
00748209 |. E8 42F2CBFF CALL <JMP.&kernel32.GetCurrentProcessId> ; |[GetCurrentProcessId
0074820E |. 50 PUSH EAX ; |String1
0074820F |. E8 94F7FFFF CALL <JMP.&kernel32.lstrcpyA> ; \lstrcpyA
00748214 |. 6A 00 PUSH 0 ; /Relation = GW_HWNDFIRST
00748216 |. A1 043D7500 MOV EAX,DWORD PTR DS:[753D04] ; |
0074821B |. 8B00 MOV EAX,DWORD PTR DS:[EAX] ; |
0074821D |. 8B40 30 MOV EAX,DWORD PTR DS:[EAX+30] ; |
00748220 |. 50 PUSH EAX ; |hWnd
00748221 |. E8 F2FBCBFF CALL <JMP.&user32.GetWindow> ; \GetWindow
00748226 |. 8BD8 MOV EBX,EAX
00748228 |. 85DB TEST EBX,EBX
0074822A |. 74 46 JE SHORT projshop.00748272
0074822C |> 68 FF000000 /PUSH 0FF ; /Count = FF (255.)
00748231 |. 56 |PUSH ESI ; |Buffer
00748232 |. 53 |PUSH EBX ; |hWnd
00748233 |. E8 08FCCBFF |CALL <JMP.&user32.GetWindowTextA> ; \GetWindowTextA
00748238 |. 85C0 |TEST EAX,EAX
0074823A |. 7E 28 |JLE SHORT projshop.00748264
0074823C |. 8D55 EC |LEA EDX,DWORD PTR SS:[EBP-14]
0074823F |. 8BC6 |MOV EAX,ESI
00748241 |. E8 8A33CCFF |CALL projshop.0040B5D0
00748246 |. 8B55 EC |MOV EDX,DWORD PTR SS:[EBP-14]
00748249 |. B8 4C837400 |MOV EAX,projshop.0074834C ; ASCII "DeDe"
0074824E |. E8 C5CCCBFF |CALL projshop.00404F18
00748253 |. 85C0 |TEST EAX,EAX
00748255 |. 74 0D |JE SHORT projshop.00748264
00748257 |. 6A 00 |PUSH 0 ; /Enable = FALSE
00748259 |. 53 |PUSH EBX ; |hWnd
0074825A |. E8 E9F9CBFF |CALL <JMP.&user32.EnableWindow> ; \EnableWindow
0074825F |. E8 1CC5CBFF |CALL projshop.00404780
00748264 |> 6A 02 |PUSH 2 ; /Relation = GW_HWNDNEXT
00748266 |. 53 |PUSH EBX ; |hWnd
00748267 |. E8 ACFBCBFF |CALL <JMP.&user32.GetWindow> ; \GetWindow
0074826C |. 8BD8 |MOV EBX,EAX
0074826E |. 85DB |TEST EBX,EBX
00748270 |.^ 75 BA \JNZ SHORT projshop.0074822C
00748272 |> 68 54837400 PUSH projshop.00748354 ; /Arg3 = 00748354
00748277 |. 6A 00 PUSH 0 ; |Arg2 = 00000000
00748279 |. 6A 00 PUSH 0 ; |Arg1 = 00000000
0074827B |. E8 00F1CBFF CALL projshop.00407380 ; \projshop.00407380
00748280 |. 8BD8 MOV EBX,EAX
00748282 |. E8 19F2CBFF CALL <JMP.&kernel32.GetLastError> ; [GetLastError
00748287 |. 3D B7000000 CMP EAX,0B7
0074828C |. 74 26 JE SHORT projshop.007482B4
0074828E |. 8B0D E03A7500 MOV ECX,DWORD PTR DS:[753AE0] ; projshop.00756FE8
00748294 |. A1 043D7500 MOV EAX,DWORD PTR DS:[753D04]
00748299 |. 8B00 MOV EAX,DWORD PTR DS:[EAX]
0074829B |. 8B15 C0345F00 MOV EDX,DWORD PTR DS:[5F34C0] ; projshop.005F350C
007482A1 |. E8 763AD6FF CALL projshop.004ABD1C
007482A6 |. A1 043D7500 MOV EAX,DWORD PTR DS:[753D04]
007482AB |. 8B00 MOV EAX,DWORD PTR DS:[EAX]
007482AD |. E8 EA3AD6FF CALL projshop.004ABD9C
007482B2 |. EB 18 JMP SHORT projshop.007482CC
007482B4 |> 6A 00 PUSH 0
007482B6 |. B9 64837400 MOV ECX,projshop.00748364
007482BB |. BA 6C837400 MOV EDX,projshop.0074836C
007482C0 |. A1 043D7500 MOV EAX,DWORD PTR DS:[753D04]
007482C5 |. 8B00 MOV EAX,DWORD PTR DS:[EAX]
007482C7 |. E8 603CD6FF CALL projshop.004ABF2C
007482CC |> 53 PUSH EBX ; /hMutex
007482CD |. E8 FEF2CBFF CALL <JMP.&kernel32.ReleaseMutex> ; \ReleaseMutex
007482D2 |. 33C0 XOR EAX,EAX
007482D4 |. 5A POP EDX
007482D5 |. 59 POP ECX
007482D6 |. 59 POP ECX
007482D7 |. 64:8910 MOV DWORD PTR FS:[EAX],EDX
007482DA |. 68 EF827400 PUSH projshop.007482EF
007482DF |> 8D45 EC LEA EAX,DWORD PTR SS:[EBP-14]
007482E2 |. E8 2DC6CBFF CALL projshop.00404914
007482E7 \. C3 RETN
进来这了 我F8一步一步的来 但走到我就不知道怎么走了那位能知道下 谢谢!~~~我找不出来了啊 呵呵 谢谢
[ 本帖最后由 cylaban 于 2009-3-31 16:49 编辑 ] |
|