- UID
- 2
注册时间2004-12-1
阅读权限255
最后登录1970-1-1
总坛主
TA的每日心情 | 开心 2024-12-1 11:04 |
---|
签到天数: 12 天 [LV.3]偶尔看看II
|
发表于 2010-2-26 00:29:17
|
显示全部楼层
解1 and 2:
00494048 C3 retn ; 打开软件正上方广告(弹窗广告由此决定) Timer事件 修改为直接返回~
00494049 . 8BD8 mov ebx, eax
0049404B . 33D2 xor edx, edx
0049404D . 8B83 40030000 mov eax, dword ptr [ebx+340]
00494053 . E8 64B2F9FF call 0042F2BC
00494058 . BA 70404900 mov edx, 00494070 ; UNICODE "http://wdjpq.com/qqbegin.htm"
0049405D . 8B83 FC020000 mov eax, dword ptr [ebx+2FC]
00494063 . E8 C015FDFF call 00465628
00494068 . 5B pop ebx
00494069 . C3 retn
解3:
-----------------------------------------------------------------------------------
00493AB8 53 push ebx ; “帮助”按钮事件
00493AB9 8BD8 mov ebx, eax
00493ABB . 6A 01 push 1
00493ABD . 6A 00 push 0
00493ABF . 6A 00 push 0
00493AC1 . 68 D83A4900 push 00493AD8 ; ASCII "http://www.wdjpq.com/qqjpq.htm"
00493AC6 . 6A 00 push 0
00493AC8 . 8BC3 mov eax, ebx
00493ACA . E8 31F5FAFF call 00443000
00493ACF . 50 push eax ; |hWnd
00493AD0 . E8 1381F9FF call <jmp.&SHELL32.ShellExecuteA> ; \ShellExecuteA
00493AD5 . 5B pop ebx
00493AD6 . C3 retn
004932A0 . 53 push ebx ; “论坛”按钮事件,其他以此类推~~ 看一下资源内容
004932A1 . 8BD8 mov ebx, eax
004932A3 . 6A 01 push 1
004932A5 . 6A 00 push 0
004932A7 . 6A 00 push 0
004932A9 . 68 C0324900 push 004932C0 ; ASCII "http://bbs.wdjpq.com"
004932AE . 6A 00 push 0
004932B0 . 8BC3 mov eax, ebx
004932B2 . E8 49FDFAFF call 00443000
004932B7 . 50 push eax ; |hWnd
004932B8 . E8 2B89F9FF call <jmp.&SHELL32.ShellExecuteA> ; \ShellExecuteA
004932BD . 5B pop ebx
004932BE . C3 retn
-----------------------------------------------------------------------------------
解4:
00490DE5 /EB 24 jmp short 00490E0B ; 退出广告
00490DE7 |. |6A 07 push 7
00490DE9 |. |6A 00 push 0
00490DEB |. |6A 00 push 0
00490DED |. |A1 E07D4900 mov eax, dword ptr [497DE0]
00490DF2 |. |E8 5137F7FF call 00404548
00490DF7 |. |50 push eax
00490DF8 |. |68 380E4900 push 00490E38 ; ASCII "open"
00490DFD |. |8B45 FC mov eax, dword ptr [ebp-4]
00490E00 |. |E8 FB21FBFF call 00443000
00490E05 |. |50 push eax ; |hWnd
00490E06 |. |E8 DDADF9FF call <jmp.&SHELL32.ShellExecuteA> ; \ShellExecuteA
00490E0B \> \C3 retn |
|