¡¾ÆÆÎÄ×÷Õß¡¿xu_wh (yuyu)
¡¾ËùÊô×éÖ¯¡¿PCG
¡¾×÷ÕßÖ÷Ò³¡¿
¡¾ E-mail ¡¿xu_wh@163.com
¡¾ ×÷ÕßQQ ¡¿
¡¾ÎÄÕÂÌâÄ¿¡¿¶ÔÆóÒµ¶ÌÐſ쳵1.7µÄÆÆ½â
¡¾Èí¼þÃû³Æ¡¿ÆóÒµ¶ÌÐſ쳵1.7
¡¾ÏÂÔØµØÖ·¡¿http://www.supcode.com/Soft/softdown/wangluogongju/lianluoliaotian/jianyiduanxinkuaicheEasySms1.7.sh
¡¾¼ÓÃÜ·½Ê½¡¿×¢²áÂë
¡¾¼Ó¿Ç·½Ê½¡¿ASPack 2.12 -> Alexey Solodovnikov
¡¾ÆÆ½â¹¤¾ß¡¿OD PE UltraEdit
¡¾Èí¼þÏÞÖÆ¡¿Win9x/Me/NT/2000/XP
¡¾ÆÆ½âƽ̨¡¿Win XP
=======================================================================================================
¡¾ÎÄÕ¼ò½é¡¿
=======================================================================================================
¡¾½âÃܹý³Ì¡¿
Ê×ÏÈÔËÐÐÕâ¸öÈí¼þ£¬¶ÔÕâ¸öÈí¼þÓÐÒ»¸ö»ù±¾µÄÁ˽⡣
ÓÃPE²âÊÔ¿Ç£ºASPack 2.12 -> Alexey Solodovnikov¡£ÓÃODÍÑÖ®¡£
ÍѿǺóµÄÈí¼þ3.5M£¬ÓÃPE¼ì²âΪDELPHI¡£
ÔËÐÐÕâ¸öÈí¼þ£¬µã×¢²á´°¿Ú£º¿ÉÒÔ¿´µ½ÎҵĻúÆ÷ÂëÊÇ£ºH-888066761¡£¿´À´Õâ¸öÓ¦¸ÃºÍ×îÖÕ×¢²áÂëµÄÑéÖ¤Óйأ¨µ«ÊÇ£¬ÊÂʵ֤Ã÷Õâ¸ö³ÌÐòÖ»ÊDzâÊÔ°æµÄ³ÌÐò£¬³ÌÐòÖÐûÓйý¶Ô×¢²áÂëµÄУÑé¡£³ÌÐò×¢²áÓë·ñµÄ±êÖ¾ÊÇдËÀÔÚ³ÌÐòµÄ¡££©ÎÒÃÇÊäÈëÊÔÑéÂ룺12345678900987654321¡£³ÌÐòÌáʾ£¬Ð»Ð»×¢²á£¬½«ÔÚÏÂ´ÎÆô¶¯Ê±¶Ô×¢²áÂë½øÐÐУÑé¡£
¹Ø±Õ³ÌÐò£¬ÔÚ³ÌÐòµÄĿ¼Ï£¬ÓÐÒ»¸öEasySms.iniµÄÎļþ£º
FONTNAME=ËÎÌå
FONTCHARSET=1
REGUSER=
REGSN=12345678900987654321
¿É¼û³ÌÐòÔÚÖØÆôºó£¬Òª·ÃÎÊÕâ¸öÎļþ£¬×Ö¶ÎÊÇREGSN¡£ÓÐÁ½´¦¡££¨µ±È»ÁË£¬Ò»´¦ÊdzÌÐò¿ªÊ¼ÔËÐÐʱ£¬Òª·ÃÎʵġ£ÁíÒ»´¦ÊÇÎÒÃÇÊäÈë×¢²áÂëʱ£¬³ÌÐòҪдÈëÎļþµÄ£©
ËùÒÔÒªÔÚODÖвéÕÒ¡°REGSN¡±£¬ÔÚ0062E8E5´¦Ï¶ϣ¬F9ÔËÐгÌÐò£¬¶ÔÎÒÃÇÊäÈëµÄ×¢²áÂë½øÐиú×Ù£º
0062E8E5 |. B9 90EC6200 mov ecx,11.0062EC90 ; ASCII "REGSN"
0062E8EA |. BA 90EB6200 mov edx,11.0062EB90 ; ASCII "SMS"
0062E8EF |. 8BC3 mov eax,ebx
0062E8F1 |. 8B38 mov edi,dword ptr ds:[eax]
0062E8F3 |. FF17 call near dword ptr ds:[edi] ; ·ÃÎÊÎļþ,Äõ½PASSWORD
0062E8F5 |. 8B55 C8 mov edx,dword ptr ss:[ebp-38] ; edx=01089728,password
0062E8F8 |. A1 30C46300 mov eax,dword ptr ds:[63C430] ; eax=0063DF58,Õâ¸öµØÖ·µÄÖµÊÇ 00000000
0062E8FD |. E8 B65FDDFF call 11.004048B8
0062E902 |. 6A 01 push 1
0062E904 |. B9 A0EC6200 mov ecx,11.0062ECA0 ; ASCII "COM"
0062E909 |. BA 90EB6200 mov edx,11.0062EB90 ; ASCII "SMS"
0062E90E |. 8BC3 mov eax,ebx
0062E910 |. 8B38 mov edi,dword ptr ds:[eax]
0062E912 |. FF57 08 call near dword ptr ds:[edi+8]
ºÇºÇ£¬Äõ½×¢²áÂëÁË£¬´æ·ÅÔÚEDX£¬01089728ÖУº
01089718 94 97 08 01 26 00 00 00 01 00 00 00 14 00 00 00 ”—&.........
01089728 31 32 33 34 35 36 37 38 39 30 30 39 38 37 36 35 1234567890098765
01089738 34 33 32 31 00 00 08 01 E4 6A 08 01 74 97 08 01 4321..äjt?
×¢Ò⣺³¤¶È·ÅÔÚ01089724£¬Îª 0x14 = 20 ÎÒÃǶԳ¤¶ÈºÍ¼Ù×¢²áÂë¶¼ÏÂÓ²¼þ·ÃÎʶϵ㣨ÒÔÃâ³ÌÐòÏȶԳ¤¶È½øÐÐÅжϣ©¡£ºÃÁËF9£¬µÈ´ýÎÒÃǵÄÊdzÌÐòÔËÐÐÁË£¬Ææ¹Ö£¬ÔõôûÓжÔ×¢²áÂë½øÐÐУÑ飿 ¾¹ýÈô¸É´ÎÊÔÑ飬¶¼·¢ÏÖ¸ú±¾¾ÍûÓзÃÎʵ½ÎÒÊäÈëµÄ×¢²áÂë¡£×÷Ϊ²ËÄñµÄÎÒ£¬ÒѾÇ¿¼¼ÇîÁË¡£
ÄѵÀÊÇ×÷ÕßÔÚÆÈË£¿ ÔÚÊäÈë¼Ù×¢²áÂëµÄʱºò¾Í¶ÔÕâ¸ö×¢²áÂë½øÐÐÅжÏÁË£¿ ÕÒÕÒ¿´ÁË£¬Êµ¼ùÊǼìÑéÕæÀíµÄΨһ±ê×¼¡£
µ«ÊÇÎÒÃÇÊäÈë×¢²áÂëºó£¬³ÌÐòʲô×öÈκÎУÑéµÄ¶¯×÷£¬¾ÍÁ¬ÎÒÊäÈëµÄ×¢²áÂëºÍ×¢²áÂëµÄ³¤¶ÈÀí¶¼²»Àí¡£ÓôÃÆing....
ÄѵÀÊÇÔÚÍ˳öʱ½øÐÐУÑ飿 ÔÙÊÔÊÔ¡£Í˳ö³ÌÐò£¬ÔÚÏÂÃæµÄ¶ÏµãÖжϣºÖ»ÊÇдÎļþʱҪ·ÃÎÊÎÒÊäÈëµÄ×¢²áÂë¡£MY GOD£¡£¡£¡
0062EE5B |. FF56 0C call near dword ptr ds:[esi+C]
0062EE5E |. A1 30C46300 mov eax,dword ptr ds:[63C430]
0062EE63 |. 8B00 mov eax,dword ptr ds:[eax]
0062EE65 |. 50 push eax
0062EE66 |. B9 80EF6200 mov ecx,11.0062EF80 ; ASCII "REGSN"
0062EE6B |. BA E8EE6200 mov edx,11.0062EEE8 ; ASCII "SMS"
0062EE70 |. 8BC3 mov eax,ebx
0062EE72 |. 8B30 mov esi,dword ptr ds:[eax]
0062EE74 |. FF56 04 call near dword ptr ds:[esi+4]
0062EE77 |. 8BC3 mov eax,ebx ; Í˳öʱ,ҪдÎļþ
0062EE79 |. E8 F64ADDFF call 11.00403974
ÄÇÕæµÄ¾ÍûÓа취ÁËÂ𣿠ÎÒ¾ÍÊÇҪע²á£¡ÏÂÃæ¾Í»»¸ö˼·£º
ÎÒÃÇÊ×Ïȵã»÷³ÌÐòµÄ°ïÖú->¹ØÓÚ£¬´°¿ÚÏÔʾĿǰµÄ°æ±¾ÊÇ¡°ÆóÒµ¶ÌÐſ쳵ÊÔÓð桱
ÆôÓÃOD£¬ËÑË÷×Ö·û´®¡°ÆóÒµ¶ÌÐſ쳵ÊÔÓð桱£¬ÔÚµØÖ· 00618AEC ´¦£¬ÕÒµ½ÈçÏÂÐÅÏ¢£º
00618AEC C6 F3 D2 B5 B6 CC D0 C5 BF EC B3 B5 D5 FD CA BD ÆóÒµ¶ÌÐſ쳵Õýʽ
00618AFC B0 E6 20 56 65 72 20 00 FF FF FF FF 17 00 00 00 °æ Ver .ÿÿÿÿ...
00618B0C C6 F3 D2 B5 B6 CC D0 C5 BF EC B3 B5 CA D4 D3 C3 ÆóÒµ¶ÌÐſ쳵ÊÔÓÃ
00618B1C B0 E6 20 56 65 72 20 00 6A 01 6A 00 6A 00 68 48 °æ Ver .jj.j.hH
00618B2C 8B 61 00 68 60 8B 61 00 A1 68 C5 63 00 8B 00 8B ‹a.h`‹a.¡hÅc.?
00618B3C 40 30 50 E8 10 84 E2 FF C3 00 00 00 68 74 74 70 @0P?„âÿ?..http
00618B4C 3A 2F 2F 77 77 77 2E 64 61 69 6C 79 70 69 6D 2E ://www.dailypim.
00618B5C 63 6F 6D 00 6F 70 65 6E 00 00 00 00 6A 01 6A 00 com.open....jj.
ÎÒÃÇ¿ÉÒÔÍÆ¶Ï£¬³ÌÐòÔÚÏÔʾÕâ¸ö¹ØÓÚ´°¿ÚµÄʱºò£¬¸ù¾ÝÒ»¸öÌõ¼þ£¬ÅжÏÊÇ×¢²á°æ£¬»òÊÔÓð档
ÓÃODÔÚµØÖ·00618B0C ´¦ÏÂÓ²¼þ·ÃÎʶϵ㡣 ÖØÐµ㠰ïÖú->¹ØÓÚ¡£³ÌÐòÔÚ
00618A2C /. 55 push ebp
00618A2D |. 8BEC mov ebp,esp
00618A2F |. 6A 00 push 0
00618A31 |. 6A 00 push 0
00618A33 |. 6A 00 push 0
00618A35 |. 53 push ebx
00618A36 |. 8BD8 mov ebx,eax
00618A38 |. 33C0 xor eax,eax
00618A3A |. 55 push ebp
00618A3B |. 68 D78A6100 push 11.00618AD7
00618A40 |. 64:FF30 push dword ptr fs:[eax]
00618A43 |. 64:8920 mov dword ptr fs:[eax],esp
00618A46 |. A1 6CC56300 mov eax,dword ptr ds:[63C56C] ; EAXµÄÖµÊÇ0063DF90£¬ÆäÖдæ·ÅµÄÊÇÊýÖµ2
00618A4B |. 8338 01 cmp dword ptr ds:[eax],1 ; Èç¹ûÊÇ×¢²á¹ýµÄ£¬Õâ¸öÖµÓ¦¸ÃÊÇ 1
00618A4E |. 75 25 jnz short 11.00618A75 ; ¹Ø¼üÌø×ª
00618A50 |. 8B0D B8C663>mov ecx,dword ptr ds:[63C6B8] ; 11.0063DF4C
00618A56 |. 8B09 mov ecx,dword ptr ds:[ecx]
00618A58 |. 8D45 FC lea eax,dword ptr ss:[ebp-4]
00618A5B |. BA EC8A6100 mov edx,11.00618AEC ; ÆóÒµ¶ÌÐſ쳵Õýʽ°æ
00618A60 |. E8 13C1DEFF call 11.00404B78
00618A65 |. 8B55 FC mov edx,dword ptr ss:[ebp-4]
00618A68 |. 8B83 140300>mov eax,dword ptr ds:[ebx+314]
00618A6E |. E8 E96DE3FF call 11.0044F85C
00618A73 |. EB 23 jmp short 11.00618A98
00618A75 |> 8B0D B8C663>mov ecx,dword ptr ds:[63C6B8] ; 11.0063DF4C
00618A7B |. 8B09 mov ecx,dword ptr ds:[ecx]
00618A7D |. 8D45 F8 lea eax,dword ptr ss:[ebp-8]
00618A80 |. BA 0C8B6100 mov edx,11.00618B0C ; ÆóÒµ¶ÌÐſ쳵ÊÔÓðæ
00618A85 |. E8 EEC0DEFF call 11.00404B78
00618A8A |. 8B55 F8 mov edx,dword ptr ss:[ebp-8]
00618A8D |. 8B83 140300>mov eax,dword ptr ds:[ebx+314]
00618A93 |. E8 C46DE3FF call 11.0044F85C
00618A98 |> 8D55 F4 lea edx,dword ptr ss:[ebp-C]
00618A9B |. 8B83 140300>mov eax,dword ptr ds:[ebx+314]
00618AA1 |. E8 866DE3FF call 11.0044F82C
00618AA6 |. 8B55 F4 mov edx,dword ptr ss:[ebp-C]
00618AA9 |. 8B83 1C0300>mov eax,dword ptr ds:[ebx+31C]
00618AAF |. E8 A86DE3FF call 11.0044F85C
00618AB4 |. 33C0 xor eax,eax
00618AB6 |. 5A pop edx
00618AB7 |. 59 pop ecx
00618AB8 |. 59 pop ecx
00618AB9 |. 64:8910 mov dword ptr fs:[eax],edx
00618ABC |. 68 DE8A6100 push 11.00618ADE
00618AC1 |> 8D45 F4 lea eax,dword ptr ss:[ebp-C]
00618AC4 |. E8 9BBDDEFF call 11.00404864
00618AC9 |. 8D45 F8 lea eax,dword ptr ss:[ebp-8]
00618ACC |. BA 02000000 mov edx,2
00618AD1 |. E8 B2BDDEFF call 11.00404888
00618AD6 \. C3 retn
ÔÚÕâÀÈç¹ûÖ±½Ó½«µØÖ· 0063DF90 ´¦µÄÖµÐÞ¸ÄΪ£º00000001£¬½«»á¿´µ½³ÌÐòÒѾÊÇ×¢²á°æÁË¡£
ÏÂÃæÎÒÃǾÍÔÚµØÖ· 0063DF90 ´¦ÉèÖÃÓ²¼þдÈë¶Ïµã£¬È»ºóÖØÐÂÔËÐУº
ͨ¹ý¶Ô³ÌÐòµÄ¸ú×Ù£¬ÎÒÃÇ·¢ÏÖ£¬³ÌÐòÖ»ÓÐÔÚ0062E68A´¦£¬²Å»á¶Ô0063DF90´¦µÄ±äÁ¿¸³Öµ£¬Õâ¸öÖµÊÇ 0¡£Õâ¸öÁãÀ´×Ôxor edx,edx¡£Äܲ»ÊÇÁãÂð£¿Ê²Ã´Çé¿ö²»£¬²»¸³ÁãÄØ£¿ ÓÃUltraEditÄõ½³ÌÐòµÄ¾²Ì¬»ã±à´úÂ룬±éÀúËùÓжԵØÖ·0063DF90µÄ¸³ÖµÓï¾ä¡£Ö»ÓÐÁ½´¦£¬Ò»´¦¸³³õʼֵΪ 0£¬ ±ð´¦Ò»´¦¸³ÖµÎª2£¨2˵Ã÷ûÓÐ×¢²á£©
ËùÒÔ£¬¾ÍÕâ¸ö³ÌÐò¶øÑÔ£¬ÊDz»»á¶Ô×¢²áÂë½øÐÐУÑéµÄ¡£¿´À´³ÌÐòȷʵ²»»á¶Ô×¢²áÂë½øÐмìÑ飡
Ö»ºÃʹÓñ©Á¦ÁË£¬Ö»ÄÜͨ¹ý±¬ÆÆµÄ·½·¨ÁË£¬ÔÚ³ÌÐòÔËÐÐʱ£¬µÚһʱ¼ä¶ÔÕâ¸ö0063DF90´¦µÄÖµ¸³Îª 1£¨1±íʾ³ÌÐòÒѾע²á£©¡££¨Èç¹ûÒѾÊÇ 1 µÄ»°£¬¾Í²»»á¶ÔÕâ¸öÖµ¸³ 2 £©
ÐÞ¸ÄǰµÄ´úÂ룺
0062E683 |. A1 6CC56300 mov eax,dword ptr ds:[63C56C]
0062E688 33D2 xor edx,edx
0062E68A 8910 mov dword ptr ds:[eax],edx
0062E68C A1 B8C66300 mov eax,dword ptr ds:[63C6B8]
0062E691 |. BA 38EB6200 mov edx,22.0062EB38 ; ASCII "1.7"
00634F00 0000 add byte ptr ds:[eax],al
00634F02 0000 add byte ptr ds:[eax],al
00634F04 0000 add byte ptr ds:[eax],al
00634F06 0000 add byte ptr ds:[eax],al
00634F08 0000 add byte ptr ds:[eax],al
00634F0A 0000 add byte ptr ds:[eax],al
00634F0C . 0000 add byte ptr ds:[eax],al
00634F0E . 0000 add byte ptr ds:[eax],al
00634F10 . 0000 add byte ptr ds:[eax],al
Ð޸ĺóµÄ´úÂ룺
0062E683 . A1 6CC56300 mov eax,dword ptr ds:[63C56C]
0062E688 . E9 73680000 jmp 33.00634F00
0062E68D 90 nop
0062E68E 90 nop
0062E68F 90 nop
0062E690 90 nop
0062E691 BA 38EB6200 mov edx,33.0062EB38 ; ASCII "1.7"
00634F00 . 33D2 xor edx,edx
00634F02 . 42 inc edx
00634F03 . 8910 mov dword ptr ds:[eax],edx
00634F05 . A1 B8C66300 mov eax,dword ptr ds:[63C6B8]
00634F0A .^ E9 8297FFFF jmp 33.0062E691
00634F0F . 90 nop
ÕæÊÇÓÐÁ¦ÎÞ´¦Ê¹£¡£¡£¡
¼ÈÈ»³ÌÐòûÓÐ×¢²áÂëµÄËã·¨£¬ÎÒÃÇ´ó¼Ò¾Í¿´¿´³ÌÐòÊÇÔõô¼ÆËã»úÆ÷ÂëµÄ°É¡£ºÃ´õÒ²ÒªÕÒ¸öËã·¨¿´¿´Ñ½¡£
0056D4A4 /$ 83C4 F4 add esp,-0C
0056D4A7 |. 6A 00 push 0 ; /pFileSystemNameSize = NULL
0056D4A9 |. 6A 00 push 0 ; |pFileSystemNameBuffer = NULL
0056D4AB |. 8D4424 10 lea eax,dword ptr ss:[esp+10] ; |
0056D4AF |. 50 push eax ; |pFileSystemFlags
0056D4B0 |. 8D4424 10 lea eax,dword ptr ss:[esp+10] ; |
0056D4B4 |. 50 push eax ; |pMaxFilenameLength
0056D4B5 |. 8D4424 10 lea eax,dword ptr ss:[esp+10] ; |
0056D4B9 |. 50 push eax ; |pVolumeSerialNumber
0056D4BA |. 6A 00 push 0 ; |MaxVolumeNameSize = 0
0056D4BC |. 6A 00 push 0 ; |VolumeNameBuffer = NULL
0056D4BE |. 68 E8D45600 push 11.0056D4E8 ; |RootPathName = "c:\\"
0056D4C3 |. E8 009EE9FF call <jmp.&kernel32.GetVolumeInformati>; \GetVolumeInformationA
0056D4C8 |. 8B0424 mov eax,dword ptr ss:[esp] ; EAX=A865A81C,ÊÇÎÒCÅ̵ÄÐòÁкÅ
0056D4CB |. 05 85000000 add eax,85
0056D4D0 |. B9 22000000 mov ecx,22
0056D4D5 |. 33D2 xor edx,edx
0056D4D7 |. F7F1 div ecx ; EAX = ( EAX + 0x58 ) / 0x22
0056D4D9 |. 6BC0 29 imul eax,eax,29 ; eax * = 0x29
0056D4DC |. 890424 mov dword ptr ss:[esp],eax ; EAX=CB112D37
0056D4DF |. 8B0424 mov eax,dword ptr ss:[esp] ; ºóÃæÉú³ÉµÄ»úÆ÷ÂëºÍËüÓйØ
0056D4E2 |. 83C4 0C add esp,0C
0056D4E5 \. C3 retn
0040A5FC |. F7D8 neg eax ; ×¢Òâ´Ë´¦EAXµÄÖµ;ÔËËãǰEAX=CB112D37,ºóEAX=34EED2C9
0040A5FE |. E8 07000000 call 11.0040A60A ; ½«EAXµÄֵת»»³ÉÊ®½øÖÆÊý£¬Îª888066761
0040A603 |. B0 2D mov al,2D ; al=2D, '-'
0040A605 |. 41 inc ecx ; »úÆ÷ÂëµÄ³¤¶È + 1
0040A606 |. 4E dec esi ; ESI = ESI -1,Ö¸ÕëÇ°ÒÆ
0040A607 |. 8806 mov byte ptr ds:[esi],al ; Ç¿ÐÐÔÚ888066761ǰ²åÈë '-'
0040A609 |. C3 retn
00402A3B |. 89C1 mov ecx,eax
00402A3D |. 83E1 03 and ecx,3
00402A40 |. 83C6 03 add esi,3
00402A43 |. 83C7 03 add edi,3
00402A46 |. F3:A4 rep movs byte ptr es:[edi],byte ptr>; ½«0062ED10´¦µÄ'H'¸´ÖƵ½0108A6FC´¦
00402A48 |. FC cld
00402A49 |> 5F pop edi
00402A4A |. 5E pop esi
00402A4B \. C3 retn
ÓÃUltraEdit´ò¿ªÕâ¸ö¿ÉÖ´ÐÐÎļþ,ÔÚÆ«ÒÆ0062ED10µÄÖµ¾ÍÊÇ'H',ËùÒÔ,Õâ¸ö×Ö·ûÊÇд³ÉÁËÒ»¸öCONST±äÁ¿ÁË :)
ËùÒÔ,»úÆ÷Âë¾Í±ØÈ»ÊÇ"H-XXXXXXXX"
ÎÒÊÇÒ»¸öССµÄ²ËÄñ£¬Èç¹ûÄÄλÀÏÄñÄÜÕÒµ½ÕæÕýµÄËã×¢²áÂëµÄµØ·½£¬Çëͨ¸æÒ»Ï£¬²»Ê¤¸Ð¼¤£¡
=======================================================================================================
¡¾½âÃÜÐĵá¿
=======================================================================================================
¡¾ÆÆ½âÉùÃ÷¡¿ÎÒÊÇÒ»¸öСС²Ë³æ×Ó,ÎÄÕÂÈçÓдíÎó,Çë¸ßÊÖÖ¸Õý!
¡¾°æÈ¨ÉùÃ÷¡¿±¾ÎÄ´¿Êô¼¼Êõ½»Á÷, ×ªÔØÇë×¢Ã÷×÷Õß²¢±£³ÖÎÄÕµÄÍêÕû, лл!
=======================================================================================================
ÎÄÕÂÍê³ÉÓÚ2005-12-13 ÉÏÎç 16:33:38