AdBin V1.2 ³ÌʽÁÔÈË ¼ò½é£ºÕâ¸öÊÇÒ»¸öÉÏÍø¼ÓËÙµÄÈí¼þ£¬Ëü¿ÉÒÔ½«Äã·ÃÎʵÄÍøվʱ£¬¿ÉÒÔ½«¹ã¸æ½øÐÐÆÁÕϵô£¬Ëù ÒÔÕâÑù¾Í¿ÉÒÔÔö¼ÓµÄÉÏÍøËٶȡ£ ×·×Ù£ºRN£º01234567 ¶ÔÓÚ×·×ÙÕâ¸öÈí¼þ£¬¿ÉÊÇ»¨ÁËÎÒ¼¸ÌìµÄʱ¼ä²Å½«Ëü×·×Ù³öÀ´¡£ÔÚÇ°¼¸Ì죬ûÓн«Ëü×·×Ù ³öÀ´£¬ÒòΪÕâ¸öÈí¼þÔÚÆƽâ¹ý³ÌÖеÄÈ·ÓÐÒ»¶¨µÄÄѶȣ¬ËùÒÔÄǼ¸ÌìûÓн«Ëü×·×Ù³öÀ´¡£ µ«ÊÇ×òÌìÎÒÓÖ½«ËüÄóöÀ´½øÐÐÆƽ⣬ÒòΪÎÒ×òÌìÓÐÒ»ÖÖ²»ËÀ²»¹éµÄ¸Ð¾õ¡£ÖÕÓÚ½«Õâ¸öÈí¼þ¸ø Æƽâ³öÀ´ÁË£¬ÄÇôÏÖÔÚÔÙÏëһϣ¬Õâ¸öÈí¼þÈç¹ûÒª¶¨Î»µÄ»°£¬ËüÓ¦µ±ÊôÓÚÖÐÉÏˮƽ¡£ÏÖÔÚ¾Í À´Ïò´ó¼Ò½éÉÜÈçºÎÔÚÇ°¼¸ÌìûÓн«Ëü×·×Ù³öÀ´µÄÇé¿ö¡£ :00402676 E8D6080000 call 00402F51 :0040267B A180564100 mov eax, dword ptr [00415680] :00402680 53 push ebx
* Possible StringData Ref from Code Obj ->"VWhxVA" | :00402681 6852734000 push 00407352 :00402686 57 push edi * Possible Reference to Dialog: DialogID_006C | :00402687 6A6C push 0000006C :00402689 50 push eax :0040268A E883F1FFFF call 00401812 :0040268F 83F801 cmp eax, 00000001 :00402692 0F85A8000000 jne 00402740 :00402698 8D45A4 lea eax, dword ptr [ebp-5C] :0040269B 50 push eax :0040269C E8DF870000 call 0040AE80 :004026A1 83F80A cmp eax, 0000000A **** :004026A4 59 pop ecx :004026A5 7225 jb 004026CC :004026A7 8D45A4 lea eax, dword ptr [ebp-5C] :004026AA 50 push eax :004026AB E8D0870000 call 0040AE80 :004026B0 83F814 cmp eax, 00000014 *** :004026B3 59 pop ecx :004026B4 7716 ja 004026CC :004026B6 8D45A4 lea eax, dword ptr [ebp-5C] :004026B9 50 push eax * Reference To: ABKernel.SetLic, Ord:001Dh | :004026BA FF1500104100 Call dword ptr [00411000] :004026C0 6A01 push 00000001 * Reference To: ABKernel.SetEnabled, Ord:001Ch | :004026C2 FF151C104100 Call dword ptr [0041101C] :004026C8 59 pop ecx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:004025D4(U) | :004026C9 59 pop ecx :004026CA EB74 jmp 00402740 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:004026A5(C), :004026B4(C) | :004026CC 53 push ebx * Possible StringData Ref from Data Obj ->"Adbin" | :004026CD 6890414100 push 00414190 * Possible StringData Ref from Data Obj ->"The licence code you entered has " ->"been generated illegally." | :004026D2 6870424100 push 00414270 :004026D7 FFD6 call esi ÏÖÔÚÎÒÃǵ±È»ÊÇÊ×ÏÈ°´Õý³£µÄÆƽâ¹ý³ÌÀ´ÆƽâËü£¬Õâ¸öÈí¼þÔÚÎÒ¸Õ¸ÕÆƽâʱ¾Í·¢ÏÖÁËËüÊÇ Ò»¸ö±È½ÏÌØÊâµÄ×¢²á¹ý³Ì¡£ÔÚÉÏÃæ¾ÍÊÇÕâ¸öÈí¼þµÄÊäÈë×¢²áÂëºóËù½øÐеŤ×÷¡£ÔÚÕâÀïÎÒÃÇ ½«Äܵõ½Ê²Ã´ÄØ£¿Èç¹û°´ÕÕÕý³£µÄ×¢²á±È½Ï¹ý³ÌµÄ»°£¬ËüÔÚÉÏÃæÓ¦µ±ÓбȽϵĵط½£¬µ«ÊÇÔÚ ÕâÀïÎÒÃǽ«ÎÞ·¨µÃµ½±È½ÏµÄµØ·½£¬½öÄܵõ½µÄÊDZȽÏÄãËùÊäÈë×¢²áÂëµÄλÊýÖµ£¬ÔÚÕâÀïÎÒÃÇ ¿ÉÒÔÇáËɵĵõ½Õâ¸öÈí¼þËùÒªÇóµÄλÊý£¬ÊäÈëµÄ×¢²áÂëÒ»¶¨ÒªÂú×ãA(H)<=RN<=14(H)£¬Èç¹û ÄãûÓÐÂú×ãÉÏÃæµÄÒªÇ󣬳ÌÐò»áÌáʾÄãÊäÈëµÄ×¢²áÂë²»ÕýÈ·¡£ÎÒÏÖÔÚÊäÈëµÄRN£º0123456789 ºó£¬³ÌÐòûÓгöÏÖÌáʾÁË¡£µ«ÊÇÎÒ×·×Ùºó·¢ÏÖÔÚÕâÀïËüÒ²½ö½öÊDZȽÏλÊý£¬Ã»ÓнøÐÐ×¢²áÂë µÄ±È½Ï¡£ÄÇôÕâ¸öÈí¼þ¾Í³ÉÁËÔÚ¿ªÊ¼Ê±±È½Ï×¢²áÂ뷽ʽµÄ×¢²á·½·¨ÁË¡£ÕâÖÖÈí¼þµÄÆƽâ¹Ø¼ü ´óÓÚÕÒµ½Èí¼þÔÚÄÇÀï½øÐбȽϵĵط½¡£ÓÚÊǾÍʹÓÃW32DASM½øÐз´»ã±à£¬ÏëÒªÕÒµ½¹Ø¼üµÄ±È ½ÏµØ·½£¬Èç¹ûÒªÈÃÎÒÕâôÇáËɾÍÕÒµ½ÁË£¬ÄÇôÕâ¸öÈí¼þµÄÄѶÈÒ²¾ÍÎÞ·¨³ÆΪÖÐÉÏˮƽÁË¡£ ÔÚWÖз¢ÏÖÁË * Possible StringData Ref from Data Obj ->"Software\Paw-Print\Adbin" ³ÌÐòʹÓÃ×¢²á±íÑ¡Ï²éÕÒÏàÓ¦µÄÑ¡Ï·¢ÏÖÁËÏÂÃæ±È½ÏÃô¸ÐµÄÑ¡Ïî¡£ RegistrationEval:VZYmhL4l39KA RegistrationKey:0123456789 ÒÔÎÒ¸öÈ˵ľÑéÀ´Ëµ£¬Ö»Òª·¢ÏÖÕâ¸ö¹Ø¼üµÄµØ·½¾Í¿ÉÒԳɹ¦Ò»°ëÁË¡£ÕâÑùµÄÈí¼þͨ³£ÔÚ³Ì ÐòÖÐʹÓÃÏàÓ¦µÄ×¢²á¼üÖµÀ´½øÐÐÔËËã¡£ÎÒÓÚÊǾÍÔÚWÖжÔRegistrationKey½øÐвéÕÒ£¬´ó¼ÒÒ» ¶¨»áÏëµ½ÁËÕâ¸ö½á¹û¾ÍÊÇûÓвéÕÒµ½¡£ÄÇôÎÒûÓвéÕÒµ½Õâ¸ö¼üÖµ£¬ÎÒ¿ÉÒÔ²éÕÒµ½ÄãʹÓöÁ È¡Õâ¸ö¼üµÄº¯Êý£¬ÎÒ²éÕÒ¶Áȡע²á±íµÄº¯Êý,µ«ÊÇËüûÓÐʲôÓô¦£¬ËüÒ²ÎÞ·¨½«Òýµ¼ÎÒÏò³É ¹¦µÄ±Ë°¶£¬Ã»Óа취ÁË¡£ÒÔÉϾÍÊÇÎÒÇ°¼¸ÌìûÓн«Õâ¸öÈí¼þÆƽâ³öÀ´µÄ¹ý³Ì¡£×òÌìÎÒÏëÔÙ³¢ ÊÔÒ»ÏÂÆƽâÕâ¸öÈí¼þ£¬Õâ»ØÎҵõ½Ê¹ÓÃÇ°¼¸ÌìûÓÐÓùý·½·¨¶ÔËü½øÐÐÆƽ⡣ ÏÖÔÚÎÒÃÇÔÙ˵һЩÆƽⷽÃæµÄÊÂÇ飬¶ÔÓÚÄÇÖÖʹÓÃÏÈÊäÈë×¢²áÂ룬ÔÙÖØÐÂÆô¶¯ºó½øÐÐ±È½Ï µÄ×¢²á¹ý³Ì£¬¶ÔÓÚÎÒÃÇÕâЩÆƽâÕßÀ´Ëµ£¬ÆƽâËüÃDZÈÆƽâÄÇÖÖÖ±½Ó½øÐÐ×¢²áÂë±È½ÏµÄÈí¼þÔö ¼ÓÁËÒ»¶¨µÄÄѶȣ¬Í¨³£¾ÍÊÇÕâµãÄѶÈʹÓÃÄÇЩ³õѧÕß»òÕßÊÇÕÆÎÕÁËÒ»¶¨µÄÆƽⷽ·¨ºÍ¼¼ÒÕµÄ ÈËÒ²²»ºÃÆƽ⡣¶ÔÓÚÕâÖÖÈí¼þµÄÆƽâ¹Ø¼ü¾ÍÊÇÕÒµ½³ÌÐòÔÚÆô¶¯Ê±£¬ÔÚÄǸöº¯ÊýÖжÔÎÒÃÇÊäÈë µÄ×¢²áÂë½øÐбȽϵġ£ÎÒÃÇÆƽâÕßÃæ¶ÔÊǼ¸Ç§¸öÉõÖÁÊǼ¸Íò¸öº¯Êý£¬ÎÒÃǽ«ÈçºÎÕÒµ½ËüµÄ±È ½ÏµØ·½ÄØ¡£¶ÔÓÚ²»Í¬µÄÈí¼þÓ¦µ±ÓÐ×Ų»Í¬µÄÆƽⷽ·¨£¬µ«ÊÇËüÓÐ׿¸¸öÏàËƵÄÆƽⷽ·¨¡£ÄÇ Ã´ÎÒÔÚÕâÀïʹÓõľÍÊǹýÆÚµÄÆƽⷽ·¨¡£ ´ó¼ÒÏÖÔÚÏòÉÏ¿´£¬ÄãÃǻᷢÏÖÔÚ×¢²á±íÖв»½öÓÐRegistrationKeyÕâ¸ö¼üÖµ£¬¶øÇÒ»¹ÓÐReg istrationEvalÕâ¸ö¼üÖµ£¬ÄÇôËüÓÐʲôÓô¦ÄØ¡£ÎÒ²»ÊÇÉè¼ÆÕߣ¬ËùÒÔÎÒÒ²²»ÖªµÀ£¬µ«ÊÇÆÆ ½â¾Ñé¸æËßÎÒ£¬Õâ¸ö¼üÖµÒ»¶¨Óë×¢²áÓйأ¬¾ßÌåʲô¹ØϵÎÒÒ²Ö»ÓÐÊÔÒ»ÊÔ²ÅÖªµÀ¡£ÓÚÊÇÎÒ½« Õâ¸ö¼üÖµÖеÄVZYmhL4l39KAÉèΪ¿Õ£¬ÔÙÖØÐÂÆô¶¯Èí¼þ£¬ÏÖÔÚÈí¼þ¸æËßÄãËüÒѾ¹ýÆÚÁË¡£ÄÇô Õâ¾Í˵Ã÷ËüµÄֵͬע²á¿Ï¶¨ÓйØϵ£¬ÎÒÓÖ½«Ëücopy»Ø×¢²á±íÖУ¬ÖØÐÂÆô¶¯Èí¼þ£¬ËüûÓгöÏÖ Ìáʾ¹ýÆÚ¡£ÏÖÔÚÎҾͽ«Õâ¸ö×÷ΪÎÒÏòËü·¢Æð¹¥»÷µÄÍ»ÆƵ㡣 ÏÖÔÚµ÷³ötrw£¬ÓÃËü¶ÔÕâ¸öÈí¼þ½øÐÐ×·×Ù¡£ :0040B4A6 FF1504124100 Call dword ptr [00411204] :0040B4AC 50 push eax :0040B4AD E8FF7AFFFF call 00402FB1 <-³ö´í£¬½øÈë :0040B4B2 8945A0 mov dword ptr [ebp-60], eax :0040B4B5 50 push eax ÔÚÖ¸³öµÄµØ·½³ö´í£¬Í¨³£ÎÒÃÇʹÓÃÕâÖÖ·½·¨½øÐÐ×·×ٵĹؼüÊÇÕÒµ½Äܲ»ÄÜÌø¹ý´ËcallµÄµØ ·½£¬ÏòÉÏ¿´Ã»Óз¢ÏÖ£¬ÓÚÊǾͽøÈëcallÖС£ÏÂͬ£º :00403035 8BCB mov ecx, ebx :00403037 E8A0180000 call 004048DC <-³ö´í£¬½øÈë :0040303C A10C584100 mov eax, dword ptr [0041580C] :00404921 8BCF mov ecx, edi :00404923 E84BC9FFFF call 00401273 <-³ö´í£¬½øÈë :004012C9 8D8D4CFFFFFF lea ecx, dword ptr [ebp+FFFFFF4C] :004012CF E824010000 call 004013F8 <-³ö´í£¬½øÈë :0040152B FFD7 call edi * Reference To: ABKernel.GetStat, Ord:0015h :0040152D FF1514104100 Call dword ptr [00411014] <-³ö´í£¬½øÈë :00401533 83F801 cmp eax, 00000001 :00401536 7405 je 0040153D
ÎÒÀ´µ½ÕâÀï¾Í³öÏÖµØÖ·µÄ±ä»¯£¬ÒòΪÔÚͨ³£ÎÒÃǵĵØÖ·ÊÇ004?????£¬¶øÏÖÔÚ½øÈëµ½00C??? ??£¬Õâ¸öµØÖ·ÖС£ÎÒÒ²ÊÇÏÖÔÚ²ÅÃ÷°×£¬Õâʱ½øÈëÁ˳ÌÐòÖе÷ÓõÄdll³ÌÐòÁË¡£ÄÇôËü½øÈëÄÇ ¸ödllÖУ¬ÉÏÃæ¾ÍÓд𰸣¬ * Reference To: ABKernel.GetStat, Ord:0015h Õâ¸ö¾ÍÊǹؼü£¬ËüÒ»¶¨½øÈëABKernel.dllÖУ¬ÒòΪÔÚWÖпÉÒÔ·¢ÏÖ³ÌÐòÓÐÕâÑùÒ»¸ödllÎļþ ¡£ÒòΪÎÒʹÓÃNuÀ´×·×Ù£¬ËùÒÔµ±Ê±²»ÖªµÀËü½øÈëÁËÄǸödll£¬ÎÒÖ»ÖªµÀÕÒµ½±È½ÏµÄµØ·½£¬£¬E xported fn(): GetStat - Ord:0016h :10003088 E851E0FFFF call 100010DE <-³ö´í£¬½øÈë :1000308D A158160110 mov eax, dword ptr [10011658] :10003092 C3 ret ½øÈëcallÖÐÈçÏ£º :100010DE E85E1E0000 call 10002F41 :100010E3 85C0 test eax, eax :100010E5 740E je 100010F5 :100010E7 83251416011000 and dword ptr [10011614], 00000000 :100010EE 83253416011000 and dword ptr [10011634], 00000000 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:100010E5(C) | :100010F5 E900000000 jmp 100010FA * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:100010F5(U) | :100010FA 833D3416011000 cmp dword ptr [10011634], 00000000 :10001101 750A jne 1000110D :10001103 B920160110 mov ecx, 10011620 :10001108 E8E3410000 call 100052F0 <-³ö´í£¬½øÈë * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:10001101(C) | :1000110D 833D1416011000 cmp dword ptr [10011614], 00000000 :10001114 750A jne 10001120 :10001116 B900160110 mov ecx, 10011600 :1000111B E8D0410000 call 100052F0 <-³ö´í£¬½øÈë * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:10001114(C) | :10001120 833D3416011000 cmp dword ptr [10011634], 00000000 :10001127 740D je 10001136 :10001129 833D1416011000 cmp dword ptr [10011614], 00000000 :10001130 7404 je 10001136 :10001132 33C0 xor eax, eax :10001134 EB03 jmp 10001139 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:10001127(C), :10001130(C) | :10001136 6A01 push 00000001 :10001138 58 pop eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:10001134(U) | :10001139 50 push eax :1000113A E89B1F0000 call 100030DA :1000113F 59 pop ecx :10001140 C3 ret µ±ÎÒ×·×Ùµ½ÉÏÃæʱ£¬ÎÒÖÕÓÚ¶Ô×Ô¼ºËµ£¬Õâ¸öÈí¼þ¿ÉÄÜÒªÆƽâ³É¹¦ÁË¡£ÒòΪÏÖÔÚÎÒÒѾÄܹ» ¿´µ½Ê¤ÀûµÄÊï¹âÁË¡£ÉÏÃæÓÐpush 01;pop eaxÕâÁ½¸öÃüÁËùÒÔËüÓпÉÄܱíʾע²á³É¹¦¡£ÏÖ ÔڵŤ×÷»¹ÊǽøÈëcallÖÐ :100052F0 B8D6D50010 mov eax, 1000D5D6 :100052F5 E8EA150000 call 100068E4 :100052FA 81EC10080000 sub esp, 00000810 :10005300 56 push esi :10005301 8BF1 mov esi, ecx :10005303 57 push edi :10005304 8975E8 mov dword ptr [ebp-18], esi :10005307 833E00 cmp dword ptr [esi], 00000000 :1000530A 0F8561020000 jne 10005571 :10005310 6A01 push 00000001 :10005312 5F pop edi :10005313 6A00 push 00000000 :10005315 893E mov dword ptr [esi], edi :10005317 E8B0FCFFFF call 10004FCC <-³ö´í£¬½øÈë :1000531C 85C0 test eax, eax :1000531E 59 pop ecx :1000531F 0F844C020000 je 10005571 :10005325 53 push ebx ÉÏÃæÓÐÒ»¸ö±È½ÏµÄµØ·½£¬Ò²ÊÇÕâ¸öÈí¼þ³ö´íµÄµØ·½£¬¹Ê½øÈëcallÖС£ :1000516C 8D45C0 lea eax, dword ptr [ebp-40] <-0123456789 :1000516F 50 push eax :10005170 E83B100000 call 100061B0 :10005175 83F80A cmp eax, 0000000A :10005178 59 pop ecx :10005179 7213 jb 1000518E :1000517B 8D45C0 lea eax, dword ptr [ebp-40] :1000517E 50 push eax :1000517F E82C100000 call 100061B0 :10005184 83F814 cmp eax, 00000014 *** :10005187 59 pop ecx :10005188 0F86AC000000 jbe 1000523A * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:10005179(C) | :1000518E 6A00 push 00000000 * Possible StringData Ref from Data Obj ->"Adbin Licence" | :10005190 6830070110 push 10010730 * Possible StringData Ref from Data Obj ->"This version of Adbin from Paw-Print " ->"Software has been tampered with." | :10005195 6888060110 push 10010688 * Reference To: USER32.GetActiveWindow, Ord:00DDh | :1000519A FF1584E10010 Call dword ptr [1000E184] :100051A0 50 push eax * Reference To: USER32.MessageBoxA, Ord:01BEh | :100051A1 FF1580E10010 Call dword ptr [1000E180] :100051A7 C7055816011004000000 mov dword ptr [10011658], 00000004 :100051B1 EB3D jmp 100051F0 µ±ÎÒÀ´ÕâÀïÎÒÖÕÓÚ¶Ô×Ô¼ºËµ£¬³É¹¦Ò»°ëÁË£¬ÎªÊ²Ã´£¿ÄãÃÇ¿´µ½Ã»ÓÐÔÚÕâÀïÎÒÃÇÒѾ¿ÉÒÔ¿´ µ½ÎÒÊäÈëµÄ×¢²áÂëÁË£¬Ëü¿ªÊ¼¼ì²é×¢²áÂëµÄλÊýÁË¡£Í¬ÎÒÃÇÔÚÊäÈë×¢²áÂëʱµÄÒ»Ñù£¬Õâ¾Í˵ Ã÷ÎÒÒѾÀë±È½ÏµÄµØ·½²»Ô¶ÁË¡£ÏòÏÂÎÒ¾ÍÓ¦µ±¿ÉÒÔ·¢ÏֱȽϵĵط½¡£ :1000523A 6A01 push 00000001 :1000523C 8D45C0 lea eax, dword ptr [ebp-40] :1000523F 5F pop edi :10005240 57 push edi :10005241 50 push eax <-RN£º0123456789 :10005242 E8A9FCFFFF call 10004EF0 :10005247 59 pop ecx :10005248 59 pop ecx :10005249 33C9 xor ecx, ecx :1000524B 3D85050000 cmp eax, 00000585 *** :10005250 0F9DC1 setnl cl :10005253 41 inc ecx :10005254 8BC1 mov eax, ecx :10005256 3BC7 cmp eax, edi :10005258 A358160110 mov dword ptr [10011658], eax :1000525D 0F8586000000 jne 100052E9 :10005263 6A03 push 00000003 µ½´ïÕâÀïÎÒ¾ÍÖªµÀÒѾµ½´ïÕâ¸öÈí¼þµÄ±È½ÏºËÐÄÁË¡£ÒòΪÕâÀïÓÐËùÓÐÎÒÏëµÃµ½µÄ¶«Î÷£¬Ò» ÊÇRN£¬¶þÊDZȽÏÃüÁî¡£ÏÖÔÚµÄÈÎÎñ¾ÍÊÇÕÒµ½Êµ¼Ê×¢²áÂëÁË£¬½øÈëcallÖУº :10004EF0 55 push ebp :10004EF1 8BEC mov ebp, esp :10004EF3 83EC28 sub esp, 00000028 :10004EF6 834DF8FF or dword ptr [ebp-08], FFFFFFFF :10004EFA 53 push ebx :10004EFB 56 push esi :10004EFC 57 push edi :10004EFD 8B7D08 mov edi, dword ptr [ebp+08] :10004F00 33DB xor ebx, ebx :10004F02 895DFC mov dword ptr [ebp-04], ebx :10004F05 8A07 mov al, byte ptr [edi] :10004F07 84C0 test al, al :10004F09 747A je 10004F85 * Possible StringData Ref from Data Obj ->"n61O0rRxdkVHt5ZwqYUzoNDmCybcghfaMLj4liT8pQ3J2I" ->"vWP9euS7BKFGEAXs" | :10004F0B BEB0040110 mov esi, 100104B0 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:10004F83(C) | :10004F10 0FBEC0 movsx eax, al :10004F13 50 push eax :10004F14 56 push esi :10004F15 E856130000 call 10006270 :10004F1A 59 pop ecx :10004F1B 85C0 test eax, eax :10004F1D 59 pop ecx :10004F1E 0F8490000000 je 10004FB4 :10004F24 2BC3 sub eax, ebx :10004F26 2BC6 sub eax, esi :10004F28 48 dec eax :10004F29 8BC8 mov ecx, eax :10004F2B 7903 jns 10004F30 :10004F2D 83C13E add ecx, 0000003E * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:10004F2B(C) | :10004F30 8D5C0B01 lea ebx, dword ptr [ebx+ecx+01] :10004F34 83FB3E cmp ebx, 0000003E :10004F37 7C0A jl 10004F43 :10004F39 8BC3 mov eax, ebx :10004F3B 6A3E push 0000003E :10004F3D 99 cdq :10004F3E 5B pop ebx :10004F3F F7FB idiv ebx :10004F41 8BDA mov ebx, edx * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:10004F37(C) | :10004F43 837DF8FF cmp dword ptr [ebp-08], FFFFFFFF :10004F47 7505 jne 10004F4E :10004F49 894DF8 mov dword ptr [ebp-08], ecx :10004F4C EB10 jmp 10004F5E * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:10004F47(C) | :10004F4E 83F907 cmp ecx, 00000007 :10004F51 7F61 jg 10004FB4 :10004F53 8B45FC mov eax, dword ptr [ebp-04] :10004F56 6BC007 imul eax, 00000007 :10004F59 03C1 add eax, ecx :10004F5B 8945FC mov dword ptr [ebp-04], eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:10004F4C(U) | :10004F5E 47 inc edi :10004F5F 837D0C00 cmp dword ptr [ebp+0C], 00000000 :10004F63 741A je 10004F7F :10004F65 0FBE07 movsx eax, byte ptr [edi] :10004F68 50 push eax :10004F69 56 push esi :10004F6A 47 inc edi :10004F6B E800130000 call 10006270 :10004F70 59 pop ecx :10004F71 2BC6 sub eax, esi :10004F73 59 pop ecx :10004F74 6A02 push 00000002 :10004F76 99 cdq :10004F77 59 pop ecx :10004F78 F7F9 idiv ecx :10004F7A 85D2 test edx, edx :10004F7C 7401 je 10004F7F :10004F7E 47 inc edi * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:10004F63(C), :10004F7C(C) | :10004F7F 8A07 mov al, byte ptr [edi] :10004F81 84C0 test al, al :10004F83 758B jne 10004F10 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:10004F09(C) | :10004F85 FF75FC push [ebp-04] :10004F88 8D45D8 lea eax, dword ptr [ebp-28] * Possible StringData Ref from Data Obj ->"%d" | :10004F8B 68F4040110 push 100104F4 :10004F90 50 push eax * Reference To: USER32.wsprintfA, Ord:02ACh | :10004F91 FF1570E10010 Call dword ptr [1000E170] :10004F97 8D45D8 lea eax, dword ptr [ebp-28] :10004F9A 50 push eax :10004F9B E810120000 call 100061B0 :10004FA0 83C410 add esp, 00000010 :10004FA3 83F809 cmp eax, 00000009 :10004FA6 7310 jnb 10004FB8 :10004FA8 8D45D8 lea eax, dword ptr [ebp-28] :10004FAB 50 push eax :10004FAC E8FF110000 call 100061B0 :10004FB1 59 pop ecx :10004FB2 EB07 jmp 10004FBB * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:10004F1E(C), :10004F51(C) | :10004FB4 33C0 xor eax, eax :10004FB6 EB0F jmp 10004FC7 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:10004FA6(C) | :10004FB8 6A09 push 00000009 :10004FBA 58 pop eax * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:10004FB2(U) | :10004FBB 2B45F8 sub eax, dword ptr [ebp-08] :10004FBE F7D8 neg eax :10004FC0 1BC0 sbb eax, eax :10004FC2 F7D0 not eax :10004FC4 2345FC and eax, dword ptr [ebp-04] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:10004FB6(U) | :10004FC7 5F pop edi :10004FC8 5E pop esi :10004FC9 5B pop ebx :10004FCA C9 leave :10004FCB C3 ret ÉÏÃæ¾ÍÊÇÕâ¸öÈí¼þÍêÕûµÄ×¢²áÂë±È½ÏµØ·½£¬ËüÔÚÕâÀï²»ÊÇͨ¹ýʹÓÃ×¢²áÂëÖ®¼äÏ໥±È½ÏµÄ £¬¶øÊÇͨ¹ýÄãÊäÈëµÄ×¢²áÂë¾¹ýÔËËãµÃµ½ÏàÓ¦µÄÖµ£¬ÔÙÔÚÇ°ÃæµÄ±È½ÏµØ·½½øÐбȽϣ¬ÄÇôÕâ ¸ö³ÌÐòÊÇÈçºÎÔËËãµÄÄØ£¿ Õâ¸öÈí¼þµÄÈ·²»ÊǼòµ¥µÄÈí¼þ£¨µ±È»ÕâÀïרָÆƽâËü£©¡£ÏÖÔÚÎÒ¾ÍÏò´ó¼Ò½éÉÜÈçºÎÆƽâ³ö Õâ¸öÈí¼þµÄ×¢²áÂë¡£ ÉÏÃæ¾ÍÊÇÕâ¸öÈí¼þÍêÕûµÄ×¢²á¹ý³Ì£¬ÎÒÃÇÈç¹ûÏëÒªÆƽâËü£¬Ê×ÏÈÓ¦µ±ÖªµÀÕâ¸öº¯ÊýÔÚ·µ»Ø ʱӦµ±·µ»ØʲôÑùµÄÖµ²ÅÄÜÂú×ãÎÒÃǵÄÒªÇó¡£ÏÖÔÚ¾ÍÓ¦µ±Ê×ÏÈÀ´¿´Ò»Ïµ÷ÓÃÕâ¸öº¯ÊýµÄÖ÷³Ì Ðò¡£ :10005242 E8A9FCFFFF call 10004EF0 :10005247 59 pop ecx :10005248 59 pop ecx :10005249 33C9 xor ecx, ecx :1000524B 3D85050000 cmp eax, 00000585 *** :10005250 0F9DC1 setnl cl ÔÚÕâÀïÎÒÖªµÀÈç¹û°´Õý³£µÄ»°£¬ÄǸö±È½ÏµÄµØ·½ÉÏeax=0£¬cl=0Ö»Óе±eaxµÄÖµ´óÓÚ585ʱ£¬ clµÄÖµ²ÅÄܱäΪ1£¬ÏÖÔÚÖªµÀÁËÏëÒªµÃµ½µÄÖµ£¬¾ÍÓ¦µ±»Øµ½ÉÏÃæµÄ¼ÆË㺯ÊýÖÐÁË¡£ :10004FBB 2B45F8 sub eax, dword ptr [ebp-08] :10004FBE F7D8 neg eax :10004FC0 1BC0 sbb eax, eax :10004FC2 F7D0 not eax :10004FC4 2345FC and eax, dword ptr [ebp-04] ÕâÀïÊǺ¯Êý·µ»ØÇ°µÄ¼ÆËã¹ý³Ì£¬Ò²ÊÇÕâ¸ö¼ÆËãµÄ¹Ø¼üÖ®ËùÔÚ¡£Èç¹ûÒªÈÃÄãÃÇÀ´·ÖÎöÉÏÃæµÄ ¹ý³ÌµÄ»°£¬ÄãÃÇ»áµÃµ½Ê²Ã´½á¹ûÄØ£¿Èç¹ûÄãÒªÏëµÃµ½eax²»µÈÓÚ0µÄÖµ£¬ÄǸöeaxºÍ[ebp-08] µÄÖµ¸ÃÓÐʲôÑùµÄ¹Øϵ¡£Èç¹ûËüÃÇÁ½¸ö²»ÏàµÈµÄ»°£¬½«ÔÚand´¦µÃµ½µÄeaxµÄÖµµÈÓÚ0£¬ÕâÑù ʹÓÃ0½øÐÐÓëÆäËüµÄÊý¾ùΪ0£¬ÄÇôֻÓÐʹÓÃeaxµÈÓÚ[ebp-08]µÄÖµÁË¡£ÄÇôÎÒ½«ÈçºÎÖªµÀ³Ì ÐòÈçºÎÔËËãÉÏÃæµÄÁ½¸öÖµµÄ¡£ÄÇÎÒÃÇ»¹µÃ¼ÌÐøÏòÉÏ¿´¡£ :10004F43 837DF8FF cmp dword ptr [ebp-08], FFFFFFFF :10004F47 7505 jne 10004F4E :10004F49 894DF8 mov dword ptr [ebp-08], ecx ÕâÀォµÃµ½[ebp-08]µÄÖµ£¬ÔÚ¿ªÊ¼Ê±[ebp-08]µÄÖµµÈÓÚffffffff£¬ÔÚ³ÌÐò½øÐеÚÒ»´ÎÔËË㠺󣬽«ÆäÔËËãÖµ´¢´æÔÚÕâÀÒÔºóµÄÖµ¾ùͨ¹ýÏÂÃæµÄÔËËã´¢´æÔÚ[ebp-04]ÖÐ :10004F4E 83F907 cmp ecx, 00000007 :10004F51 7F61 jg 10004FB4 :10004F53 8B45FC mov eax, dword ptr [ebp-04] :10004F56 6BC007 imul eax, 00000007 :10004F59 03C1 add eax, ecx :10004F5B 8945FC mov dword ptr [ebp-04], eax ÄÇôÎÒÃÇÏÖÔÚÈçºÎµÃµ½¸ÃÈí¼þµÄ×¢²áÂëÄØ£¿ * Possible StringData Ref from Data Obj ->"n61O0rRxdkVHt5ZwqYUzoNDmCybcghfaMLj4liT8pQ3J2I" ->"vWP9euS7BKFGEAXs" ¿´µ½ÉÏÃæµÄ×Ö·û´®Ã»ÓУ¬ÎÒÃǼÆËã×¢²áÂë¾ÍÒªÓõ½Õâ¸ö×Ö·û´®£¬Ëü¾ßÌå±È½Ï¹ý³ÌÈçÏ£º È¡ÊäÈë×¢²áÂëµÄÊ×룬¼ÆËã³öËüÔÚÕâ¸ö×Ö·û´®ÖеÄλÖÃÖµ£¬Èç0µÄλÖÃΪ4£¨´Ó0¿ªÊ¼¼ÆÊý£© ½«ËüµÄÖµ-ebx£¨ÕâʱµÄebx=0£©£¬ÔÙ-esi£¨esi×Ö·û´®µÄ³õʼµØÖ·Öµ£©ºó£¬ÔÙ½«Õâ¸öÖµ-1ºó£¬ ÕâÑùÎÒÃǾͿÉÒԵõ½[ebp-08]µÄÖµ¡£ ÏÖÔÚÎÒÃǽ«ÒªÖªµÀÈçºÎµÃµ½[ebp-04]µÄÖµÁË£¬ÄÇôËüµÄÖµ½«ÈçºÎµÃµ½£¬ÉÏÃæÎÒ˵¹ýÁË£¬µ« ÊÇÕâÀïËü»¹ÓÐÒ»¸öÒªÇ󣬾ÍÊÇÏÂÃ棺 :10004F4E 83F907 cmp ecx, 00000007 :10004F51 7F61 jg 10004FB4 ÕâÀïµÄecxµÄÖµ×÷ÓÃÊÇʲôÄØ£¿ËüµÄ×÷ÓÃÊDZȽÏÇ°ºóÏÖÔÚÏàÁÚ×¢²áÂëµÄλÖÃÖµÊÇ·ñ´óÓÚ7Èç¹û ´óÓÚ7ÔòÈÏΪ²»ÕýÈ·µÄ×¢²áÂë¡£ÏÖÔÚÎÒÃÇÔٻص½·µ»ØeaxµÄµØ·½£¬ÎÒÃÇÏÖÔÚÖªµÀÁË[ebp-08],[ ebp-04]µÄÖµÁË£¬ÄÇôeaxµÄÖµµ½µ×ÈçºÎµÃµ½µÄ£¬ËüµÄÖµ¾ÍÊdzÌÐò¼ÆËã×¢²áÂëµÄ¸öÊý£¬ÔÚÕâÀï ÓÖÒªÏò´ó¼Ò˵Ã÷Ò»µã£¬ÎÒÃÇÊäÈëµÄ×¢²áÂë²»ÊÇÿһλ¶¼¼ÆËãµÄ£¬ÒòΪÓÐÏÂÃæµÄÃüÁËùÒÔͨ ³£ËüÊǸôһλ¼ÆËãµÄ¡£ :10004F74 6A02 push 00000002 :10004F76 99 cdq :10004F77 59 pop ecx :10004F78 F7F9 idiv ecx :10004F7A 85D2 test edx, edx :10004F7C 7401 je 10004F7F :10004F7E 47 inc edi * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:10004F63(C), :10004F7C(C) | :10004F7F 8A07 mov al, byte ptr [edi] :10004F81 84C0 test al, al :10004F83 758B jne 10004F10 ÉÏÃæ¾ÍÊdzÌÐò¼ì²éµÄÇé¿ö£¬Ëüͨ³£ÊÇÿ¸ôһλ¼ÆËãÒ»¸ö¡£ ÏÖÔÚÎÒÃÇÔٻص½ÈçºÎµÃµ½×¢²áÂëµÄ»°ÌâÉÏÀ´¡£ÏÖÔÚÎÒÃÇÖªµÀÁË£¬eaxΪ¼ÆËã×¢²áÂëµÄ¸öÊý £¬ÕâÀï²»°üÀ¨µÚһλ¼ÆËãµÄÖµ¡£[ebp-08]ΪµÚһλµÄÔËËãÖµ£¬¶ø[ebp-04]ΪÆäËüλµÄ¼ÆËãÖµ £¬ÏÖÔھͿÉÒÔÖªµÀ×¢²áÂëÁË£¬Í¨¹ýÎÒµÄÑо¿£¬Èç¹ûÒªÂú×ã´óÓÚ585µÄ»°£¬Ò»¶¨Òª¼ÆËã4´ÎÒÔÉÏ £¬ÔÚÕâÀïÎÒ¾ÍÑ¡ÔñÁ˼ÆËã4´Î£¬ÒòΪËüÊǸôһλ¼ÆËãÒ»¸ö£¬²¢ÇÒÏàÁÚµÄ×¢²áÂëµÄλÊý²»Ó¦´ó ÓÚ7ËùÒÔÑ¡ÔñÏÂÃæµÄ×ÖĸΪע²áÂ룬ÌîÈëºó£¬×¢²á³É¹¦¡£ RN£ºrRdvtZqUoDCb ÏÖÔÚÎÒÏëÎÒ¶ÔÕâ¸öÈí¼þµÄÆƽâÊÇÍê³ÉÁË£¬µ«ÊǶÔÓÚ´ó¼ÒÏë±Ø¾ÍûÓÐÀí½âÊÇÈçºÎ×¢²áµÄ£¬ÄÇ Ã´Ö»ºÃ´ó¼ÒÔÙ×Ô¼ºÓù¦Ñо¿Ñо¿ËüÁË¡£ÎÒÖ»ÊÇÒ»¸öÒý·ÈË£¬¾ßÌåÔõô×ß»¹Òª¿´´ó¼ÒµÄ¡£ ******************************** * RN:rRdvtZqUoDCb * ********************************
|