ÆƽâºìÍâÒ£¿Ø±àÂë·ÖÎöÒÇ3.0
Passion
Ç°²»¾ÃһͬѧʹÓúìÍâÒ£¿Ø±àÂë·ÖÎöÒÇ3.0£¬ËµÊÇδע²á°æ±¾½ö½ö¿ÉÊä³öºìÍâÏß½Ó¿ÚÊý¾Ý3´Î£¨3´ÎµÄȷҲ̫ÉÙÁ˵㣩£¬ÓÚÊÇÕÒÎÒÅöÅöÔËÆø¿´Äܲ»ÄÜÆÆ¡£ÎÒÇÆÕâÈí¼þ˵Ã÷£¬ËµÒªÏò×÷Õ߸¶¡°Ò»¶ÖÎç·¹¡±×¢²á£¬Ìì°¡£¡ÒªÀÕ½ô¿ã´øÉÙ³Ô¶àÉٶٲÅÄÜ´Õ×ãÕâÒ»¶Ö£¿¡°ÃñÒÔʳΪÌ족£¬ÆÆ°É£¡
Õâ¸ö¶«Î÷¼ÓÁË¿Ç£¬ÓÉÓÚÎÒÍѿǾÑé²»×㣬ÔÚÕâÀïµ¢¸éÁËÁ½Ìì¡£Fileinfo²é²»³öÊÇʲô¿Ç£¬ºóÀ´ÏÂÁ˸öGTW£¬ËµÊÇASPack 1.083£¬ÓÚÊÇÓÃPROCDUMPµÄunpack£¬ÍѳöÀ´µÄÎļþÈ´²»ÄÜÔËÐУ¬³öʲôEAccessVoilation¡£ÕÒ¸öרÃÅÍÑËüµÄ¹¤¾ß£¬ÕÕÑù·Ç·¨²Ù×÷¡£¿´À´Ö»ÓÐÊÖ¹¤ÍÑÁË¡£»¹ºÃ£¬ÎÒÃÇÓÐÖйúÈËÖµµÃ½¾°ÁµÄTRW2000¡£
ÕÒÈë¿ÚµãÕÒµÃÎÒÍ·ÔΣ¬£¨´Ë´¦Ê¡ÂÔ²»³É¹¦Íѿǹý³ÌXXXX´Î£©¡£ºóÀ´ÖÕÓÚÅöÉÏÁËÒ»¸ö¶Îת»»µÄRET£¬Ö´ÐÐÍêRETºóÀ´µ½ÒÔÏ´¦£º
A1BCA34800 mov eax, dword
ptr [0048A3BC] ;ÕâÌõ¾ÓÈ»ÊÇÈë¿Ú£¡²»ÊÇPUSH EBP?
C1E002 shl eax,
02
A3C0A34800 mov dword ptr [0048A3C0],
eax
57
push edi
51
push ecx
ÔÚMOV EAX, dword ptr [0048A3BC]´¦À´¸öPEDUMP£¬ºÙºÙ£¬Íѿdzɹ¦¡£
½Ó×űãÊÇÆÆ×¢²áµÄ¹ý³ÌÁË¡£³ÌÐòÔËÐÐʱ»áÉú³ÉÒ»¸ö±¾»úºÅ£¬¹À¼ÆÊǰѵçÄԵĸ÷ÖÖ²ÎÊý¶¼¼ÆËã³öÀ´´Õ³ÉÒ»¿é¶ùµÄ¡£Ëã·¨¸´Ôӵúܡ£¡ª¡ªÏÈÊÔÊÔÔÙ˵¡£ÔËÐгÌÐòIRVIEWER.EXE£¬Å¾µØ³öÀ´¸ö´°¿Ú¸æËßÄãûע²á£¬»¹°Ñ±¾»úºÅ¶àÉÙ¶àÉÙ¶àÉÙ¸æËßÄã¡£°´È·¶¨ºóµã²Ëµ¥ÖеÄ×¢²á³öÏÖ×¢²áÊäÈë¿ò¡£Ëæ±ãÂÒÌîºó°´È·¶¨£¬´°ÌåÏÈÏûʧ£¬È»ºó¸æËßÄã´íÎó¡£Ã»µÄ˵£¬¸ú°É¡£Ï¶Ï
bpx hmemcpy£¬¶Ïºópmodule£¬Çå¶Ïµã°´F10¸ú×Ù£¬ÔÚIRVIEWERºÍCOMCTL32.DLLºÍkernerl¡¢userµÈÖ®¼äÌøÁ˼¸´ÎºóÖÕÓÚÀ´µ½ÒÔÏ´¦£º
:00402A7A 8B0D50354900 mov ecx, dword
ptr [00493550]
:00402A80 8B01
mov eax, dword ptr [ecx]
:00402A82 8B80E8020000 mov eax, dword
ptr [eax+000002E8]
:00402A88 E80B210400 call
00444B98
:00402A8D 8D45FC
lea eax, dword ptr [ebp-04]
:00402A90 E8DB360000 call
00406170
:00402A95 50
push eax
:00402A96 E8212F0000 call
004059BC ;ÕâÀïÑé֤ע²áÂëÊÇ·ñÕýÈ·¡£
:00402A9B 59
pop ecx
:00402A9C 3B0548BD4900 cmp eax, dword
ptr [0049BD48] ;ÕýÈ·±êÖ¾
:00402AA2 0F95C2
setne dl ;¶ÔÔòDLΪ0£¬·ñÔò¡¡
:00402AA5 83E201
and edx, 00000001 ;·ñÔòΪ1
:00402AA8 52
push edx
:00402AA9 FF4DD4
dec [ebp-2C]
:00402AAC 8D45FC
lea eax, dword ptr [ebp-04]
:00402AAF BA02000000 mov edx,
00000002
:00402AB4 E8E3600800 call
00488B9C
:00402AB9 59
pop ecx
:00402ABA 84C9
test cl, cl
:00402ABC 7429
je 00402AE7
;ÕâÀï²»ÌøÔò³ö´í¡£
:00402ABE 6A00
push 00000000
µ«Èç¹û¸Ä00402ABC´¦µÄJE£¬¾ÓÈ»ÎÞЧ¡£Ö»ÓиÄ00402AA2´¦ÁË¡£°Ñsetne dlºÍAND EDX,00000001¸Ä³ÉMOV EDX,0ºÍNOP¼´¿É¡£
Ò²¾ÍÊÇ°Ñ
0F 95 C2 83 E2 01 52
¸ÄΪ£º
BA 00 00 00 00 90 ..
¸ÄµôÍѿǺóµÄEXEÎļþºóÔÙÔËÐУ¬Ñ¡²Ëµ¥ÖеÄ×¢²á£¬ÔÚ×¢²á¿òÖÐÂÒÌîÒ»Æø£¬°´È·¶¨¡£¡¡àÅ£¿Ê²Ã´¶¼Ã»ÓУ¿
ÄÇÕâÑùËã²»Ëã×¢²á³É¹¦£¿¹Ø±Õ³ÌÐòÔÙÔËÐУ¬ÈÔÈ»Ìáʾδע²á¡£¿´À´²»ÐС£
²»¹ý×¢Òâµ½Ò»µã£¬ÂÒÌîÒ»ÆøµÄ×¢²áÂëÔÚ³ÌÐòÔÙ¶ÈÔËÐкóÔÚ×¢²á¿òÖÐÈÔÈ»´æÔÚ£¬¿´À´×¢²áÕâÒ»²½Ó¦¸ÃÊÇͨ¹ýÁË£¬µ«³ÌÐòÆô¶¯µÄʱºò»¹ÓÐÒ»²½¼ìÑéµÄ¹ý³Ì£¬ÄǶùͨ²»¹ý£¬¾ÍµÃÿ´ÎÔËÐгÌÐò¶¼µÃ×¢²áÒ»´ÎÁË¡£
ÓÃFILEmonitorºÍregmonitor¼àÊÓ³ÌÐòÔËÐÐÖÐ×¢²á±íºÍÎļþµÄ±ä»¯£¬ÖÕÓÚ´ÓǧͷÍòÐ÷Öп´µ½ÁËC:\WINDOWS\IRVIEW.INIÎļþ¡£×¢²á¿òµÄ¼ìÑéͨ¹ýºó¹Ø±Õ³ÌÐòʱ»á°Ñ¡°ÕýÈ·¡±µÄ×¢²áÂëдÈëC:\WINDOWS\IRVIEW.INIÎļþ¡£ÆäÄÚÈÝΪ£º
[Register]
SerialNum=0987654321
ÕâÑù¾ÍÐèÒª¸ú×Ù³ÌÐò¿ªÊ¼¶ÁÎļþµÄ²¿·Ö¡£ÎÒÓÚÊǾÍÓÃTRW2000À´LOADËü£¬Ï¶ÏCreatefileaÒ²ºÃ£¬ÏÂgetprivateprofilestringÒ²ºÃ£¬ÏÂgetprivateprofileintÒ²ºÃ£¬ÏÂreadfileÒ²ºÃ£¬ÏÂopenfileºÍÆäexÒ²ºÃ£¬¾ÓȻҪôÊÇʲô¶¼À¹²»×¡£¨ÕâÊÇʲôÔÒò»¹Çë¸÷λָµã£©£¬ÒªÃ´¾ÍÊÇÔÚµ¯³öÌáʾδע²á¿òºóÖжϡ£ÎÒ¼¸ºõ¾õµÃɽÇîË®¾¡ÁË¡£ºóÀ´×ÐϸÏëÏëÓÖÕÒµ½ÁË·¨×Ó¡£¡ª¡ª³ÌÐò²»ÊÇ»á°ÑÕâ¸ö¡°ÕýÈ·¡±µÄ×¢²áÂë¶Á½øÀ´Âð£¿ÎҾͲéËü¾ÍÐÐÁË¡£
ÔÚµ¯³ö×¢²á¿òʱ°´Ctrl+MÇÐÈëTRW2000£¬s 0 ffffffff '0987654321'£¬ÕæµÄÕÒµ½Ò»¸öµØÖ·47B490¡£
Í˳ö³ÌÐòÖØÐÂload£¬ÏÂbpm 47b490 w£¬ºóÀ´Öжϼ¸´Î£¬¿´¿´ÄÄ´Î47b490´¦»á³öÏÖ0987654321¡£
¹þ¹þ£¬ÕâÀ¡ª¡ªÕâÀïÖжÏÒѾÀëÄ¿±ê²»Ô¶ÁË¡£
£¨¾ÝREGMON·ÖÎö£¬³ÌÐòÊÇÏȶÁÐí¶à×¢²á±í²ÎÊýÔÙ¶ÁµÄIRVIEW.INIÎļþ£¬Ò²¾ÍÊÇ˵ºÜ¿ÉÄܱ¾»úºÅµÄ¼ÆËãÔÚ×¢²áÂëµÄ¶Á³ö֮ǰ´¦Àí£¬¿ÉÒÔÌø¹ýÐí¶àÂé·³µÄËã·¨³ÌÐòÁË¡££©
²»¶à¾ÃÀ´µ½´Ë´¦£º
:0040325B E80C270000 call
0040596C
:00403260 A348BD4900 mov dword
ptr [0049BD48], eax
:00403265 B850BD4900 mov eax,
0049BD50
:0040326A E8012F0000 call
00406170
:0040326F 50
push eax
:00403270 E847270000 call
004059BC ;ÕâÀïÊÇÑéÖ¤¹ý³Ì
:00403275 59
pop ecx
:00403276 3B0548BD4900 cmp eax, dword
ptr [0049BD48] ;ÕâÀïÊǹؼü±È¶Ô
:0040327C 0F849E000000 je 00403320
;ÕýÈ·ÔòÌø£¬·ñÔò³ö´í¡£
:00403282 66C7459C5000 mov [ebp-64],
0050
:00403288 8D45D0
lea eax, dword ptr [ebp-30]
:0040328B E8B02E0000 call
00406140
:00403290 8BD0
mov edx, eax
:00403292 FF45A8
inc [ebp-58]
:00403295 A148BD4900 mov eax,
dword ptr [0049BD48]
:0040329A E89D2F0000 call
0040623C
:0040329F 8D55D0
lea edx, dword ptr [ebp-30]
:004032A2 52
push edx
:004032A3 8D45CC
lea eax, dword ptr [ebp-34]
:004032A6 E8952E0000 call
00406140
:004032AB 50
push eax
:004032AC FF45A8
inc [ebp-58]
* Possible StringData Ref from Data Obj ->"¸ÃÈí¼þûÓÐ×¢²á,ÇëÏò×÷Õß×¢²á.
×¢²áºÅ: "
|
:004032AF BA01A84800 mov edx,
0048A801
¡¡¡¡ ;ϱ߾ÍÊ¡ÁË¡£
ºÜºÃ¡£°Ñje 00403320¸Ä³ÉJMP 00403320¾ÍÐС£
Ò²¾ÍÊÇ×öÒÔÏÂÐ޸ģº
0F 84 9E 00 00 00 66 C7
E9 9F 00 .. .. 90 .. ..
±£´æÎļþºóÔËÐУ¬ÍòÊ´󼪣¡¡ª¡ªÊµ¼ÊÉÏÖ»¸Ä´Ë´¦¾ÍÐС£
Õâ¸öÈí¼þÔÚ»ª¾üÉϵÄÈí¼þ·ÖÀàÖеġ°ÆäËûÀ¸Ä¿¡±ÖÐÓÐÏÂÔØ£¬²»ÊÇÁбíÖеĵÚÒ»¸öµØÖ·£¡ÄÇÊÇ´íµÄ£¬ËäȻҲÊÇÒ»¸öIR.EXE£¬È´ÊÇʲôInternetRadio¡£
^_^
Õâ¸ö¶«Î÷Èç¹ûÓþ²Ì¬·ÖÎö²éÕÒ×Ö´®ÒýÓõķ½·¨À´ÆÆ¿ÉÄÜ»¹»á¼òµ¥µÃ¶à£¬ÎÒûÕâÑù×ö£¬ÒòΪ¡¡»¹²»Ê죬ÕÒ×¢²áÂë¾Í¸üû±¾ÊÂÁË¡£ºÙºÙ£¡
ºó¼Ç£º
±¾ÎÄÔÚ´ò×Ö¹ý³ÌÖÐÍê³É50%×óÓÒʱÕý´ý±£´æ£¬È´³öÀ´¸ö±£´æ´íÎó£¬È»ºóUedit32±»ÖÐÖ¹£¬ÎÒ²îµãÆøÔΣ¬¸ÏæÆô¶¯TRW2000£¬²éÕÒÄÚ´æÖеÄ"IRVIEW.INI"£¬½á¹ûÍòÐÒ£¬ÕÒµ½ÁËÎÒÕâ¿ÉÁ¯µÄ°ëƪÎÄÕ¡£µ«VMMģʽϲ»¿ÉдÅÌ£¬ÎÒÓÚÊÇϸöBPX
HMEMCPY£¬ÔÝʱÍ˳ö£¬Ëæ±ãÔÚÄǸö³ÌÐòµÄ¿òÖÐÇÃÒ»×Ö·û£¬¶Ïʱ¾ÍÍÑÀëVMMģʽÁË£¬À´¸öw£¬ºÃ£¬×ÜËãûÀË·ÑÁ¦Æø¡£
¡ª¡ªPassionдÓÚÇéÈ˽ںóÁ½Ìì¡£
- ±ê Ì⣺ÆƽâºìÍâÒ£¿Ø±àÂë·ÖÎöÒÇ3.0¡ª¡ªÉÏ´ÎÎʹýµÄ£¬ÏÖÔÚÖÕÓÚÆÆÁË¡£ (6ǧ×Ö)
- ×÷ ÕߣºPassion
- ʱ ¼ä£º2001-2-16 10:43:57
- Á´ ½Ó£ºhttp://bbs.pediy.com