¡¾Ô´´¡¿Turbo PhotoµÄÆƽ⼰²»ÍêÈ«Ëã·¨·ÖÎö
Turbo PhotoÊÇÒ»¸öÒÔÊýÂëÓ°ÏñΪ±³¾°£¬ÃæÏòÊýÂëÏà»úÆÕͨÓû§ºÍ׼רҵÓû§¶øÉè¼ÆµÄÒ»Ì×¼¯Í¼Æ¬¹ÜÀí£¬ä¯ÀÀ£¬´¦Àí£¬Êä³öΪһÉíµÄÈí¼þϵͳ¡£Ëý°üÀ¨Á½¸ö²¿·Ö:Turbo Photo Ïà²áºÍTurbo Photo ±à¼Æ÷¡£
¡¾×÷Õß¡¿WindayJiang
¡¾ÆƽâÉùÃ÷¡¿´¿´âѧϰ
¡¾Æƽ⹤¾ß¡¿WDSM£¬OLLDBG, eXeScopE, PEID£¬
¡¾ÆƽâÄѶȡ¿EASY
¡¾Èí¼þ±£»¤¡¿SN+TIME
¡¾Èí¼þÏÂÔØ¡¿http://www.stepok.com/chs/index.htm
ÔËÐÐÈí¼þ£¬³ÌÐòÒª¹Ø±ÕÄÇÒ»¿Ì²Å»áµ¯³ö×¢²á¿ò£¬´íÎó×¢²á»áÓÐÌáʾ
¿ª¹¤£¡ÏȲé¿Ç°É£¬VC±àµÄ£¬Ã»Óмӿǡ£
ÓÃOD¼ÓÔØ£¬CTRL+N²é¿´Ò»Ï£¬ÕÒ²»µ½GETWINDOWTEXTAÖ®ÀàµÄ³£¹æº¯Êý£¬ÄÇô¾ÍÊÔÒ»ÏÂÄÚ´æµÄ°É£¬¡¡µ÷³ö×¢²á´°¿Ú£¬ÊäÈ룱£²£³£´£µ-£µ£´£³£²£±-£¸£¸£¸£¸£¸£¸££¹£¸£·£¶£µ£¬°´½âËø£¬ÕâʱÌáʾÐòÁкŴíÎ󣬲»Òª¹Ø±ÕËü£¬»Øµ½OD£¬ÔÚDUMPÀïCTRL+B£¬²éÕÒHEX31¡¡32¡¡33¡¡34¡¡35, ÈçÏ£º
004BB52C 31 32 33 34 35 00 35 34 33 32 31 00 38 38 38 38 12345.54321.8888
004BB53C 38 38 00 39 38 37 36 35 00 00 00 00 80 22 1D 40 88.98765......€" @
ÔÚ004BB52CÏÂÓ²¼þ¶Ïµã£¬ÔٴνâËø¾Í»áÀ´µ½ÕâÀ
00453430 |. 8BC8 MOV ECX,EAX
00453432 |. 33C0 XOR EAX,EAX
00453434 |. 83E1 03 AND ECX,3
00453437 |. F3:A4 REP MOVS BYTE PTR ES:[EDI],BYTE PTR DS:[>
.
CTRL+F9·µ»ØºóÀ´µ½ÕâÀ
00452EA3 . B9 7CB14B00 MOV ECX,TPhoto.004BB17C
00452EA8 . E8 53050000 CALL TPhoto.00453400¡¡¡¡¡¡¡¡¡¡¡¡¡¡//×¢²áÂëµÄ±È½ÏCALL
00452EAD . 85C0 TEST EAX,EAX¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//ÅжÏEAX
00452EAF . 75 1B JNZ SHORT TPhoto.00452ECC¡¡¡¡¡¡//Ìø¾Í³É¹¦×¢²áÁË£¬²»Ìø¾ÍÌáʾ´íÎó
00452EB1 . 50 PUSH EAX
ÓÚÊÇÐÞ¸Ä452EAFΪJMP¡¡SHORT TPhoto.00452ECC£¬µ«ÄãºÜ¿ì¾Í»á·¢ÏÖÕâÊDz»Öα¾µÄ£¬³ÌÐòÆô¶¯»áÔÙÅжÏÊÇ·ñ×¢²á£¬ÓÚÊǵã»÷452EAFÓÒ¼ü£¬Ñ¡FIND REFERENCES TO CALL DESTINATION£¬·¢ÏÖÓУ²¸öµØ·½µ÷Óã¬ÁíÒ»¸ö¾ÍÊÇ4535CC£¬ÔÚ´Ë϶ϣ¬ÖØÔËÐгÌÐò£¬¶ÏÏ£º
004535CC |. E8 2FFEFFFF CALL TPhoto.00453400
004535D1 \. C3 RETN¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//·µ»Ø4533A5
¡¡¡¡¡..
004533A5 |. F7D8 NEG EAX
004533A7 |. 5F POP EDI ; TPhoto.004BBC58
004533A8 |. 5E POP ESI
004533A9 |. 1BC0 SBB EAX,EAX
004533AB |. 5D POP EBP
004533AC |. F7D8 NEG EAX
004533AE |. 5B POP EBX
004533AF |. 59 POP ECX¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//ÉÏÃæÊǶÔEAX´¦Àí
004533B0 \. C3 RETN¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//·µ»Ø453A37
¡¡¡¡¡¡..
00453A37 |. 8986 64030000 MOV DWORD PTR DS:[ESI+364],EAX //½«EAXдÈëÄÚ´æ±ê־λ
00453A3D |. C786 68030000>MOV DWORD PTR DS:[ESI+368],1
00453A47 |. 5E POP ESI
00453A48 \. C3 RETN
ÓÉÉÏ£²´¦ÅжϿÉÖªÖ»ÒªÁî±êÖ¾·µ»Ø£±¾ÍOKÁË£¬ÏÂÃæÎÒÃÇ¿´¿´×¢²áÂëµÄ±È½ÏCALL£º
00453400 /$ >PUSH EBX
00453401 |. >MOV EBX,ECX
00453403 |. >PUSH EBP¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//"C:\WINNT\system32\tpflag.rg£¬×¢²áÐÅÏ¢Îļþ
00453404 |. >MOV EBP,DWORD PTR SS:[ESP+C]
00453408 |. >LEA EDX,DWORD PTR DS:[EBX+3B0] ¡¡¡¡//µÚÒ»¶Î×¢²áÂëµØÖ··Åµ½EDX /12345
0045340E |. >PUSH ESI
0045340F |. >CMP EDX,EBP
00453411 |. >PUSH EDI
00453412 |. >JE TPhoto.004534BE¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//ÕâÀï»áÌø
¡¡.
004534BE |>>MOV EDI,TPhoto.004B795C ; ASCII "DDGTM"¡¡¡¡//×Ö´®DDGTMµ½EDI
004534C3 |.>MOV ESI,EDX¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//µÚÒ»¶Î×¢²áÂëµ½ESI 12345
004534C5 |>>/MOV CL,BYTE PTR DS:[ESI]¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//µÚ£±¸ö×¢²áÂëµ½CL ¡°1¡±
004534C7 |.>|MOV DL,BYTE PTR DS:[EDI]¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//¡°D¡±
004534C9 |.>|MOV AL,CL¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//µÚ£±¸ö×¢²áÂëµ½AL
004534CB |.>|CMP CL,DL¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//µÚ£±¸ö×¢²áÊDz»ÊÇ¡°D¡±
004534CD |.>|JNZ SHORT TPhoto.004534ED¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//²»ÊÇÌø×ß
004534CF |.>|TEST AL,AL¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//ALÊDz»ÊÇ0
004534D1 |.>|JE SHORT TPhoto.004534E9 ¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//0¾ÍÌøµ½4534E9
004534D3 |.>|MOV DL,BYTE PTR DS:[ESI+1]¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//µÚ£²¸ö×¢²áÂëµ½CL ¡°2¡±
004534D6 |.>|MOV CL,BYTE PTR DS:[EDI+1]¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//µÚ¶þ¸ö¡°D¡±
004534D9 |.>|MOV AL,DL
004534DB |.>|CMP DL,CL
004534DD |.>|JNZ SHORT TPhoto.004534ED¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//²»ÊÇÌø×ß
004534DF |.>|ADD ESI,2
004534E2 |.>|ADD EDI,2
004534E5 |.>|TEST AL,AL
004534E7 |.>\JNZ SHORT TPhoto.004534C5¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//ÏòÉÏÑ»·
004534E9 |>>XOR EAX,EAX ¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//EAXÇå0
004534EB |.>JMP SHORT TPhoto.004534F2¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//Ìøµ½4534F2
004534ED |>>SBB EAX,EAX¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//½èλ¼õ
004534EF |.>SBB EAX,-1
004534F2 |>>TEST EAX,EAX
004534F4 |.>JNZ SHORT TPhoto.004534FD¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//Èç¹û²»Ìø±êÖ¾Öµ¾Í²»ÄÜÉèΪ£±
004534F6 |.>POP EDI
004534F7 |.>POP ESI
004534F8 |.>POP EBP
004534F9 |.>POP EBX
004534FA |.>RETN 10
¡¡¡¡¡¡
004534FD |> \8B>MOV EAX,DWORD PTR SS:[ESP+20]¡¡¡¡¡¡¡¡¡¡¡¡¡¡//µÚ4¶Î×¢²áÂë
00453501 |. 8B>MOV ECX,DWORD PTR SS:[ESP+1C] ¡¡¡¡¡¡¡¡¡¡¡¡//µÚ£³¶Î×¢²áÂë
00453505 |. 8B>MOV EDX,DWORD PTR SS:[ESP+18] ¡¡¡¡¡¡¡¡¡¡//µÚ£²¶Î×¢²áÂë
00453509 |. 50 PUSH EAX ¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//µÚ4¶Î×¢²áÂëÈëÕ»
0045350A |. 51 PUSH ECX¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡ //µÚ£³¶Î×¢²áÂëÈëÕ»
0045350B |. 52 PUSH EDX¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//µÚ£²¶Î×¢²áÂëÈëÕ»
0045350C |. 55 PUSH EBP¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//µÚ£±¶Î×¢²áÂëÈëÕ»
0045350D |. 8D>LEA ECX,DWORD PTR DS:[EBX+204] ; |
00453513 |. E8>CALL TPhoto.0048E210¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//¿´À´Õâ¸ö×îÖյıȽÏCALLÁË
00453518 |. >TEST EAX,EAX¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//±êÖ¾ÊÇ·ñΪ0
0045351A |. >JNZ SHORT TPhoto.00453523¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//0µÄ»°¾ÍÊÇ×¢²á²»³É¹¦ÁË
¡¡¡¡¡¡¡¡
00453523 |> >LEA EAX,DWORD PTR SS:[ESP+20]
00453527 |. >PUSH EAX
00453528 |. >CALL <JMP.&MFC42.#3811>
0045352D |. >PUSH 0
0045352F |. >MOV ECX,EAX
00453531 |. >CALL <JMP.&MFC42.#3337>
00453536 |. >MOV ECX,DWORD PTR DS:[EAX+14]
00453539 |. >ADD ECX,76C
0045353F |. >CMP ECX,7D5¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//ÊÇ·ñ2005Äꣿ
00453545 |. >JLE SHORT TPhoto.0045358F
¡¡¡¡..
0045358F |> >MOV EAX,1¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡//ÖÕÓÚ¿´µ½Õâ¸öÁË£¬µÈµÃ²»¾ÍÊÇÕâ¸öÂºÇºÇ
00453594 |. >POP EDI
00453595 |. >POP ESI
00453596 |. >MOV DWORD PTR DS:[EBX+368],EAX
0045359C |. >POP EBP
0045359D |. >POP EBX
0045359E \. >RETN 10
ƪ·ùÓÐÏÞ£¬ÄÄЩJUMP¸ÃÐÞ¸ÄÎҾͲ»ËµÁË£¬¸ÄÍêºóµ±ÄãÔÙ´ÎÔËÐгÌÐò»áÌáʾ£º×¢²áºÅÊÇ·Ç·¨µÄ´°¿Ú£¬ÐèÒªÔٴνâËø£¬ÄóöEXESCOPE£¬ÕÒµ½¸Ã¶Ô»°¿ò274,¡¡»»ËãHEXÊÇ112,¡¡ÔÙÀ´WDASM¿´¿´£º
* Possible Reference to Dialog: DialogID_0112
:00453B31 6812010000 push 00000112¡¡¡¡¡¡¡¡¡¡¡¡//µ½ODÉè¶ÏÕâÀï
:00453B36 89742418 mov dword ptr [esp+18], esi
CTRL+K VIEW CALL TREE£¬¿´¿´ÊÇ´ÓʲôµØ·½µ÷Óõģ¨ÕâÀïÒª¿´£²´Î£¬Æª·ùÎÊÌâÎÒÖ»ÄÜÊ¡ÂÔÁË£©£¬À´µ½Õ⣺
0042E79F . E8 3C4E0200 CALL TPhoto.004535E0
0042E7A4 . 3BC5 CMP EAX,EBP
0042E7A6 . A1 E0B44B00 MOV EAX,DWORD PTR DS:[4BB4E0]/ºÜÃæÊì°É£¬ÔÚ×¢²áÂë±È½ÏÄǼû¹ý
0042E7AB . 7F 4D JG SHORT TPhoto.0042E7FA¡¡¡¡//±ØÐëÌø·ñÔò˵·Ç·¨
¡¡¡¡¡.
0042E7FA > \3BC5 CMP EAX,EBP
0042E7FC . 75 68 JNZ SHORT TPhoto.0042E866¡¡¡¡//±ØÐëÌø£¬·ñÔòÊÇÊÔÓðæ
¡¡¡¡¡
ÐÞ¸Äһϣ¬Ò»¸ö·Ç³£ºÃÓõÄÈí¼þ¾Í´Ë¸æÆÆ£¡
×ܽáһϣººÜ³¤Ê±¼äûдÆÆÎÄÁË£¬×Ô¼º¸Ð¾õÒ²ºÜÀÛ£¬±ÈÆƵÄʱ¼ä»¹Òª³¤£ºP£¬¡¡ÆƵÄʱºòûÓÐÓÃÆäËûһЩ¿ÉÄܸüÓÐЧ¸ü¿ì½ÝµÄ¶Ïµã£¬¶øÊÇÓü¸¸öÈí¼þ½»²æÅäºÏ£¬ÈøÕѧÆƽâµÄNEWBIESÊìÁ·ÓÃÓÃÈí¼þ£¬Ð´µÃ²»ºÃ»¹Íû´ó¼Ò¶à¶àÔÁÂÁË¡£ÁíÍâÎÒûÓÐʱ¼äÔÙ¸ú½ø×¢²áËã·¨£¬TPhoto.0048E210Õâ¸öCALL¹À¼Æ¾ÍÊÇËã·¨µÄ¹Ø¼üCALL£¬ÓÐÐËȤµÄÅóÓÑ¿ÉÒÔÔÙÈ¥¿´¿´¡£»¹ÓоÍÊÇTurboPhotoAlbum.exeÊÇÏà²á£¬Í¬ÑùÐèÒªÆƽâµÄ£¬µ«¸úÉÏÃæ˼·һÑù£¬ÎÒ¾ÍÀÁµÃдÁË£ºP
////////////////////////////////////////////////////////////////
If you want to crack well, learn ASM well !
WiNDaYJiANg 2005-12-18
////////////////////////////////////////////////////////////////