EBPIG
̽Ë÷ÔÓÖ¾
MHJDQ
֪ʶ¹²Ïí ×ÊÔ´¹²Ïí ×ÊÁϹ²Ïí
¡¾ÖÆ×÷³ÉÔ±¡¿³ÌʽÁÔÈË
¡¾·¢ÐÐʱ¼ä¡¿2000-9-13
¡¾ÆÚ¿¯ºÅÂë¡¿Ôö¿¯Ê®
¡¾ÍøÕ¾µØÖ·¡¿http://programhunter.home.china.com

¡¾±à¼­¼ÄÓï¡¿

    
    {~._.~} 
     ( Y )  
    ()~*~() 
    (_)-(_) 
ÿ½ñÌìÔÚÕâÀïÏÈ×£´ó¼ÒÖÐÇï¿ìÀÖ£¬ÖÐÇï±¾ÊÇÒ»¸öºÏ¼ÒÍž۵ÄÈÕ×Ó£¬¿ÉÊǾÍÓÐÐí¶àͬÎÒÒ»ÑùµÄÈËÔÚÀë¼ÒǧÀïÖ®Í⹤×÷»òѧϰ£¬ËùÒÔÔÚÕâÀïÏòÄÇЩûÓÐͬ¼ÒÈËÍž۵ÄÈËÒÔ¼°ËùÓÐÓû§µÀÒ»Éù×£¸££¬Ï£Íû´ó¼Ò¿ìÀÖ¡£Õâ¸öÔö¿¯µÄÄÚÈÝÂ𣬾ÍÊÇÍøÓÑpeterchenÌá³öÈçºÎ½øÐб©Á¦Æƽ⣬ËùÒÔÕâÆÚ¾ÍÏêϸ½éÉÜÈçºÎ½øÐб©Á¦ÆƽâµÄÇé¿ö¡£
¡¾Ä¿ ÿÿ ¼¡¿
ÿÿÿÿ&ÆƽâÐĵÃ
1¡­¡­±©Á¦ÆƽâµÄ·½·¨ºÍ¼¼ÇÉ ³ÌʽÁÔÈË
2¡­¡­NoteTab Pro Trial 4.81 xiA Qin
3¡­¡­PowerZip V5.2 xiA Qin
     
ÿÿÿÿ%³õѧÌìµØ
ÿÿÿÿOÎÊÌâ´ðÒÉ
ÿÿÿÿ4ÍøÕ¾½éÉÜ
ÿÿÿÿ,ÔÓÖ¾ÐÅÏä
&¡¾ÆƽâÐĵá¿
           ±©Á¦ÆƽâµÄ·½·¨ºÍ¼¼ÇÉ
                          ³ÌʽÁÔÈË
  Ç°¼¸ÌìÍøÓÑpeterchen˵£¬Ó¦ÔÚÔÓÖ¾ÖнéÉÜһϱ©Á¦ÆƽⷽÃæµÄ֪ʶ£¬ÎÒÏë½ñÌì¾ÍÏò´ó¼Ò
½éÉÜһϹØÓÚÕâ·½ÃæµÄ֪ʶºÍÆƽ⾭Ñé¡£Õâ¸öµ±È»Ò²ÊÇÎÒ¸öÈ˵ľ­Ñ飬µ«ÊǶÔÓÚ¸ßÊÖÀ´ËµÓ¦
»¹ÓÐÆäËü·½ÃæµÄ¾­Ñ飬Èç¹ûÄãÈÏΪÎҵľ­Ñé²»×ãµÄ»°£¬Ï£ÍûÄܹ»À´ÐŲ¹³äһϡ£
  ÏÖÔھͿªÊ¼½éÉܱ©Á¦ÆƽâµÄÔ­Àí¡£¶ÔÓÚ±©Á¦Æƽâͨ³£ÊÇÎÞ·¨µÃµ½×¢²áÂë»òÊÇ×¢²áÂëµÄÔËËã
¹ý³ÌÌ«¸´ÔÓ£¬ÎÞ·¨Í¨³£¼ÆËãµÃµ½£¨ÕâÀïָʹÓ÷´ÍÆ·¨À´¼ÆËã×¢²áÂ룩ËùÒÔ¾ÍÄܹ»Ê¹ÓÃÐ޸ijÌ
ÐòµÄ·½·¨À´ÆƽâÕâ¸öÈí¼þ£¬ÕâÑùͨ³£¾ÍÊDZ©Á¦Æƽ⡣
  ÏÖÔÚ½«Ê¹Óñ©Á¦ÆƽâµÄÈí¼þ·ÖÒ»ÏÂÀàÐÍ£¬Ò²ºÃÈôó¼ÒÀ´ÖªµÀÈçºÎ¶Ô²»Í¬µÄÈí¼þ½øÐÐ×¢²áÂë
Æƽ⻹ÊDZ©Á¦ÆƽâÁË¡£
  1 ²âÊÔ°æÈí¼þ
    ÕâÖÖÈí¼þÊÇÊôÓÚ²âÊÔʹÓõģ¬Í¨³£ÎÞ·¨×¢²á£¬ÕâÑùËüÖ»ÓÐÒ»¸ötime bombÏÞÖÆ£¬¶ÔÓÚÆÆ
½âËüÖ»ÄÜʹÓñ©Á¦Æƽⷽ·¨ÁË¡£Ö»Òª½«ËüµÄʱ¼äÕ¨µ¯½â³ý¾ÍÐÐÁË¡£
  2 ¹²ÏíÈí¼þÖв»ÐèҪע²áÂëÊäÈëµÄÐÎʽ
    ÕâÖÖÈí¼þÊDZȽϳÉÊìµÄÈí¼þ£¬µ«ÊÇ×÷Õßͨ³£Ã»ÓÐʹÓÃ×¢²áÂë±£»¤Èí¼þ£¬¶øÊǽö×öÒ»¸öti
me bomb£¬Í¬ÉÏÃæµÄÒ»Ñù£¬ËùÒÔÆƽâ¾ÍͬÉÏÃæÏàͬÁË¡£
  3 ¹²ÏíÈí¼þÖÐ×¢²áÂëÔËËã¹ý³Ì¹ýÓÚ¸´ÔÓÇé¿ö
    ÕâÑùµÄÈí¼þÊÇ×÷ÕßÉè¼ÆʱʹÓÃÁËÊ®·Ö¸´ÔÓµÄÔËËã¹ý³Ì£¬ÄãʹÓ÷´ÍÆÎÞ·¨µÃµ½ËüµÄ×¢²áÂë
£¬ËùÒÔËüÒ²Ö»ÄÜʹÓñ©Á¦Æƽâ²ÅÄÜʹÓÃÕâ¸öÈí¼þ¡£
  4 ¹²ÏíÈí¼þµÄÌáʾ´°¿Ú
   ͨ³£ÕâÖÖÈí¼þÊÇÔÚ¿ªÊ¼ÔËÐеÄʱºòÓÐÒ»¸öÌáʾ´°¿Ú£¬×îΪ¿ÉÆøÊÇÓеÄÈí¼þÌáʾ´°¿ÚÓÐÒ»
¶¨µÄʱ¼äÒªÇó£¬Äã±ØÒªµÈ10Ãë²ÅÄÜÔËÐÐÕâ¸öÈí¼þ£¬ËùÒÔͨ³£ÆƽâËü¾ÍʹÓñ©Á¦ÆƽâÁË¡££¨Õâ
²»°üÀ¨Æƽâ³ö×¢²áÂëµÄÇé¿ö£©
  5 ¹²ÏíÈí¼þʹÓÃkey file±£»¤µÄÐÎ?
   ¶ÔÓÚÕâÖÖÈí¼þÀ´Ëµ£¬Í¨³£µÄ½âÃÜÈËÊDZȽÏÄÑÆƽâµÄ£¬µ«ÊÇʹÓñ©Á¦Æƽâ¾ÍÏ൱µÄÇáËÉÁË
£¬ÄãÖ»ÒªÕҶԵط½¾Í¿ÉÒÔÆƽâËüÁË¡£
  6 ¹²ÏíÈí¼þ¼Ó¿Ç´¦Àí
   ÕâÖÖÆƽâÊÇÊôÓÚ±©Á¦ÆƽâÖÐ×îÄѵÄÒ»ÖÖÁË£¬ÒòΪÈç¹ûÄãûÓÐÍÑ¿Ç֪ʶµÄ»°£¬Ä㽫ÎÞ·¨Ê¹
Óñ©Á¦ÆƽâÀ´µÃµ½Õâ¸öÈí¼þµÄÆƽâ¹ý³Ì¡£ËùÒÔ¶ÔÓÚÕâÖÖÀ´Ëµ£¬Ò»¶¨ºÃºÃѧϰÍÑ¿Ç֪ʶ²ÅÄܶÔ
¸¶Õâ¸öÆƽ⡣
  ºÃÁË£¬ÏÖÔھͿªÊ¼Í¨³£¹ýÀý×ÓÀ´½éÉÜÈçºÎ½øÐб©Á¦ÆƽâÁË¡£


        INF-Tool V5.2c
                      ³ÌʽÁÔÈË
¼ò½é£ºÒ»¸öÖÆ×÷Èí¼þ°²×°³ÌÐò,¿ÉÒÔÖÆ×÷·Ç³£Ð¡ÇɵݲװÎļþ£¬²¢ÇÒÖ§³ÖWin95/98/NT£¬
ÓÃËüËùÖÆ×÷³öÀ´µÄÎļþ·Ç³£Ð¡Ö»ÓÐ2-3K£¬¶øÇÒ²»ÐèÒªSETUP.EXEÎļþ£¬Ö»Òªµã»÷Êó±êÓÒ¼ü
Ñ¡ÔñInstall¼´¿É£¬²»¹ýÄãÒ²¿ÉÒÔÓÃËüÖÆ×÷Ò»¸ö°üº¬SETUP.EXEÎļþµÄINFÎļþ°ü¡£¿ÉÉú³É
һƬ»ò¶àƬµÄZIP»òEXEÎļþ£¬ËüʹÓÃINI file£¬¿ÉÒÔÍƳö¶à¹úÓïÑÔ°ü×°¡£
×·×Ù£ºÓÉÓÚÕâ¸öÈí¼þÎÒÔÚ×°ÈëºóËü֪ͨÎÒÕâ¸öÈí¼þÒѾ­¹ýÆÚÁË£¬ËùÒÔ¾ÍÏȽâ¾öÕâ¸ö¹ýÆÚµÄ
ÎÊÌâ¡£ÎÒ¸Õ¿ªÊ¼Ê±Ê¹ÓÃsofticeÀ´ÔØÈëËü£¬µ«ÊÇûÓн«Ëü·ÖÎö³öÀ´£¬ËùÒÔÓÖʹÓÃw32dasmÕâ
¸ö¹¤¾ßÀ´·ÖÎöËü£¬Ê¹ÓÃÕâ¸öÈí¼þÀ´·ÖÎöÕâÖÖ¹ýÆÚ·½ÃæµÄÈí¼þÊÇÓÐÏ൱µÄˮƽµÄ¡£ËùÒÔ´ó¼Ò
×÷Ϊһ¸ö½âÃÜÕßÒ»¶¨ÒªÓÐÕâÑùÒ»¸öºÃµÄ¹¤¾ß¡£
  
 ÈçÏ£º

:004B3882 D805E04A4B00            fadd dword ptr [004B4AE0]
:004B3888 DB7DC8                  fstp tbyte ptr [ebp-38]
:004B388B 9B                      wait
:004B388C E8D366F5FF              call 00409F64
:004B3891 DB6DC8                  fld tbyte ptr [ebp-38]
:004B3894 DED9                    fcompp
:004B3896 DFE0                    fstsw ax
:004B3898 9E                      sahf
:004B3899 7321                    jnb 004B38BC
:004B389B 6A00                    push 00000000
:004B389D 668B0DE44A4B00          mov cx, word ptr [004B4AE4]
:004B38A4 B202                    mov dl, 02

* Possible StringData Ref from Code Obj ->"This version of INF-Tool Lite "
                                        ->"is outdated."
                                  |
:004B38A6 B8F04A4B00              mov eax, 004B4AF0
:004B38AB E8383BFAFF              call 004573E8
:004B38B0 A180C74C00              mov eax, dword ptr [004CC780]
:004B38B5 8B00                    mov eax, dword ptr [eax]
:004B38B7 E894AAF9FF              call 0044E350

* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:004B3899(C)
|
:004B38BC C605ADFC4C0000          mov byte ptr [004CFCAD], 00
:004B38C3 C605ACFC4C0000          mov byte ptr [004CFCAC], 00
:004B38CA B201                    mov dl, 01
:004B38CC A120F44000              mov eax, dword ptr [0040F420]
:004B38D1 E8FAF7F4FF              call 004030D0
:004B38D6 898644160000            mov dword ptr [esi+00001644], eax

    ÄãÃÇÊÇ·ñ¿´µ½ÁËÈí¼þ¹ýÆÚµÄ×ÖÑùÁË°É£¬ÏòÉÏ¿´ÓÐÒ»¸ö¿ÉÒÔÌø¹ýÕâÀïµÄjneµÄÃüÁ
¹À¼ÆËü¾ÍÊDZȽÏÊÇ·ñ¹ýÆڵĵط½£¬µ«ÊÇÎÒÃÇ»¹ÒªÈ·¶¨Ò»ÏÂËü£¬½«Ëü¸ÄÖ®¡£ºÙ£¬¹ûÈ»¾ÍÊÇ
Ëü£¬ÄãÃÇÒ»ÊÔ¾ÍÖªµÀÁË¡£Õâ¸öÈí¼þ½øÈëºó·¢ÏÖҲûÓÐÊäÈë×¢²áÂëµÄµØ·½£¬ËùÒÔÆƽâ³É
ÕâÑù¾ÍËãÊÇÆƽâÁË¡£Õâ¸öÈí¼þµÄÆƽâÒ²Êdzɹ¦ÁË¡£


                   ********************************
                   *   ²éÕÒ£º9E 73 21 6A 00       *
                   *   Ìæ»»£º9E EB 21 6A 00       * 
                   ********************************
  Õâ¸öÈí¼þ¾ÍÊÇʹÓñ©Á¦·½·¨ÆƽâµÄ£¬ÏÖÔÚÀ´·ÖÎöÒ»ÏÂͨ³£ÈçºÎ½øÐб©Á¦ÆƽâµÄ¡£
  ¶ÔÓÚ±©Á¦Æƽâ×îºÃʹÓÃW32DASMÕâÖÖ·´»ã±àµÄÈí¼þ£¬ÎªÊ²Ã´ÄØ£¿Õâ¸öÖ÷ÒªÊDZ©Á¦ÆƽâµÄÈí
¼þͨ³£¶¼ÓÐÒ»¸ö¹ØÓÚʹÓÃʱ¼ä»òʹÓôÎÊýµÄÌáʾ´°¿Ú£¬ËùÒÔÄã¿ÉÒÔ¼ÇסÄǸöÌáʾ´°¿ÚºóʹÓÃ
W32²éÕÒÏàÓ¦µÄÓï¾ä¾Í¿ÉÒԵõ½Á˳ö´íµØ·½£¬ÔÙ²éÕÒÈçºÎ±Ü¿ªÕâ¸öµØ·½µÄÌøÔ¾Ö®´¦¾Í¿ÉÒÔÆÆ
½âÕâÑùµÄÈí¼þÁË¡£Í¨³£Õâ¸ö¾ÍÊDZ©Á¦ÆƽâµÄ·½·¨¡£
  ´ó¼ÒºÃºÃ·ÖÎöÉÏÃæµÄÀý×Ó£¬ÎÒÏ뱩Á¦Æƽâͨ³£¶¼Ê¹ÓÃÕâÖÖ·½·¨£¬¾ßÌåÈçºÎÆƽâÎÒÏëÓ¦µ±Ê¹
ÓÃÈçϼ¸ÖÖ·½·¨¡£

  1 µ÷ºóÈÕÆÚ£¬Í¨³£µ÷ºóÒ»Ä꣬ÕâÑùÓÐʱ¼äÏÞÖƵÄÈí¼þ¾ÍÌáʾÄãÈí¼þÒѾ­¹ýÆÚÁË£¬ÕâÑù´ó¼Ò
¾Í¿ÉÒÔͨ³£W32·ÖÎö»òʹÓÃTRW»òSIÀ´ÔØÈë·ÖÎöÁË¡£
  2 ²éÕÒ×¢²á±íÖйؼü¼üÖµ£¬É¾³ýµôºóÌáʾ¹ýÆÚ»òÒªÇó×¢²áµÈÒªÇó£¬Äã¾Í¿ÉÒÔÏÂÊÖÁË¡£
  3 ¶ÔÓÚÓÐʹÓôÎÊýÒªÇóµÄÈí¼þ¿ÉÒÔ²éÕÒÏàÓ¦µÄ×¢²á±í»òÎļþÖµ£¬ÕâÑùÒ²¿ÉÒÔÆƽâÕâ¸öÈí¼þ
¡£
  ÏÖÔÚÔÚÏÂÃæ¸ø´ó¼Ò½éÉܵĶ¼ÊÇʹÓñ©Á¦ÆƽâµÄÈí¼þ£¬Ï£Íû³õѧÕßÄܹ»´ÓÖÐѧµ½Ò»¶¨µÄ±©Á¦
Æƽâ֪ʶÁË¡£
·µ»Ø
±ê Ìâ:Æƽâʵ¼£¨ËÄ£©Ö® NoteTab Pro Trial 4.81 (3ǧ×Ö)
·¢ÐÅÈË:xiA Qin
ʱ ¼ä:2000-7-18 16:45:24 
ÏêϸÐÅÏ¢:

Æƽâʵ¼£¨ËÄ£©Ö® NoteTab Pro Trial 4.81 


Èí¼þÃû³Æ£ºNoteTab Pro Trial 4.81    -->(30ÌìÊÔÓÃ) 
¼ò    ½é£º³¬¼¶µÄÎÄ×ֱ༭Æ÷£¬³ý¿ÉÈ¡´úWindowsµÄNotepadÍ⣬Ëü¿É±à¼­´óµÄÎļþ£¬ÔÚ´òÁÐ
·½ÃæÒ²Äܵ÷Õû±ß½ç¡¢Ò³ÂëµÈ£¬ËüÒà¿É¶ÁдDOS ASCII and UNIXµÈ¸ñʽÎļþ£¬¶ÔHtmL¸üÌṩÁË
¶àÖֵŤ¾ß£¬¿ÉÇáÒ׿ìËٵıàд¡£ 


×÷    ÕߣºxiA Qin 
¼¶    ±ð£ºÔ­Ê¼Éç»á 
½âÃÜÈÕÇ°£º2000Äê7ÔÂ18ÈÕ 
½âÃܹ¤¾ß£ºTrw2000 1.22 
ÆƽâÄ¿µÄ£ºÑ§Ï°NAG´°¿ÚµÄÈ¥³ýµÄÆƽ⡣(¼òµ¥) 

˵    Ã÷£º 
        ±¾ÎÄÊÇÔÚÎÒµÄÈí¼þÆƽâ¼Ç¼ÉÏÕûÀí³öÀ´µÄ¡£Ö»×÷¼¼Êõ½»Á÷¡£ÈçÈôÓÐç¢Â©£¬Çë¸÷λ´ó
ÏÀ¶àÖ¸½Ì£¡ 



Ê×ÏȽ«ÏµÍ³µÄʱ¼äµ÷¿ìÒ»¸öÔ¡£ 

Ctrl+N½øÈëTrw2000 

ÏÂÖ¸Áîbpx createwindowex      //ÏÂÖÐ¶Ïµã  

°´X¼ü»Øµ½×ÀÃæÔËÐгÌÐò£¬Õâʱ»á±»Trw2000À¹½Øµ½¡£ 

ÏÂÖ¸Áîbc *                  //Çå³ý¶Ïµã 

ÏÂÖ¸Áîpmodule                //Ö±½ÓÌøµ½³ÌÐòµÄÁì¿Õ 

°´F10À´µ½ÏÂÃæ 

015F:0054B240 8B45EC          MOV      EAX,[EBP-14] 
015F:0054B243 8D4DF0          LEA      ECX,[EBP-10] 
015F:0054B246 BA7CB45400      MOV      EDX,0054B47C 
015F:0054B24B E84402F2FF      CALL    0046B494 
015F:0054B250 8B55F0          MOV      EDX,[EBP-10] 
015F:0054B253 A18CDD5400      MOV      EAX,[0054DD8C] 
015F:0054B258 E8DF8BEBFF      CALL    00403E3C 
015F:0054B25D 8B0D8CDD5400    MOV      ECX,[0054DD8C] 
015F:0054B263 8B09            MOV      ECX,[ECX] 
015F:0054B265 B201            MOV      DL,01 
015F:0054B267 A16CDE4600      MOV      EAX,[0046DE6C] 
015F:0054B26C E8EF2FF2FF      CALL    0046E260 
015F:0054B271 8B1538E15400    MOV      EDX,[0054E138] 
015F:0054B277 8902            MOV      [EDX],EAX 
015F:0054B279 33D2            XOR      EDX,EDX 
015F:0054B27B B001            MOV      AL,01 
015F:0054B27D E8AA73FCFF      CALL    0051262C 
015F:0054B282 A110E25400      MOV      EAX,[0054E210] 
015F:0054B287 803800          CMP      BYTE [EAX],00 
015F:0054B28A 751A            JNZ      0054B2A6            
015F:0054B28C E8077FFCFF      CALL    00513198              //¹Ø¼üCALL 

µ±×ßµ½ÕâÀïʱ¾Í»áµ¯³öÊÔÓùýÆڵĶԻ°¿ò¡£ 

¿´¿´ÄÇÀï¿ÉÒÔÌø¹ýÕâÀï¡£ 

ÉÏÃæ0054B28A 751A  JNZ  0054B2A6 ºÃÏñ¿ÉÒÔÌø¹ýËüÒ®!!!! 

ÖØÐÂ϶ϵãbpx 0054b287 

°´X¼ü»Øµ½×ÀÃæÔËÐгÌÐò£¬Õâʱ±»Trw2000À¹½Øµ½¡£ 

µ±¹â±ê×ßµ½0054B28A 751A  JNZ  0054B2A6 £¬ 

´òÈëÃüÁî CODE ON  ¼ÇÏÂÖ¸ÁîÂë 


ÏÂÖ¸ÁîA  дÈë»ã±à´úÂë 
½« 0054B28A 751A        JNZ  0054B2A6  
¸Ä 0054B28A 741A        JZ  0054B2A6 

ºÃÒ®£¡ÓÖ¿ÉÒÔ½øÈë³ÌÐòÁË£¬³É¹¦ÁË¡£ 



015F:0054B291 84C0            TEST    AL,AL 
015F:0054B293 7411            JZ      0054B2A6 
015F:0054B295 A138E15400      MOV      EAX,[0054E138] 
015F:0054B29A 8B00            MOV      EAX,[EAX] 
015F:0054B29C E8937FEBFF      CALL    00403234 
015F:0054B2A1 E8128AEBFF      CALL    00403CB8 
015F:0054B2A6 A1F8E25400      MOV      EAX,[0054E2F8] 
015F:0054B2AB 8B00            MOV      EAX,[EAX] 
015F:0054B2AD 66BAEDFF        MOV      DX,FFED 
015F:0054B2B1 E8DAB3EEFF      CALL    00436690 
015F:0054B2B6 A110E25400      MOV      EAX,[0054E210] 
015F:0054B2BB 803800          CMP      BYTE [EAX],00 
015F:0054B2BE 740D            JZ      0054B2CD 
015F:0054B2C0 A180E05400      MOV      EAX,[0054E080] 
015F:0054B2C5 C70007000000    MOV      DWORD [EAX],07 
015F:0054B2CB EB5F            JMP      SHORT 0054B32C 
015F:0054B2CD E84AF8FFFF      CALL    0054AB1C 
015F:0054B2D2 A1DCE05400      MOV      EAX,[0054E0DC] 
015F:0054B2D7 8B00            MOV      EAX,[EAX] 
015F:0054B2D9 BA88B45400      MOV      EDX,0054B488 
015F:0054B2DE E875CBEEFF      CALL    00437E58 
015F:0054B2E3 6A11            PUSH    BYTE +11 
015F:0054B2E5 E846C4EBFF      CALL    `USER32!GetAsyncKeyState` 
015F:0054B2EA 6685C0          TEST    AX,AX 
015F:0054B2ED 0F9CC2          SETL    DL 
015F:0054B2F0 A138E15400      MOV      EAX,[0054E138] 
015F:0054B2F5 8B00            MOV      EAX,[EAX] 
015F:0054B2F7 B101            MOV      CL,01 
015F:0054B2F9 E8CA38F2FF      CALL    0046EBC8 



ÔÚNotePro.exeÓÃUltraedtÕÒµ½ 

      75 1A E8 07 7F FC FF 84 
¸Ä³É  74 1A E8 07 7F FC FF 84 
--------------------------------------------------------------------------------
·µ»Ø
±ê Ìâ:²ËÄñѧÆƽ⣨Æߣ©Ö® PowerZip V5.2 (3ǧ×Ö)
·¢ÐÅÈË:xiA Qin
ʱ ¼ä:2000-7-21 9:43:54 
ÏêϸÐÅÏ¢:

²ËÄñѧÆƽ⣨Æߣ©Ö® PowerZip V5.2 


Èí¼þÃû³Æ£ºPowerZip      -->(60ÌìÊÔÓÃ) 
°æ    ±¾£º5.2      
¼ò    ½é£º·Ç³£Ç¿º·µÄѹËõ¡¢½âѹËõ¹¤¾ß£¬¼¸ºõÖ§³ÖËùÓÐѹËõ¸ñʽ£¡¸Ð¾õÆðÀ´×÷ÕßËƺõÊÇÒÔ
WinZip ΪÀ¶±¾À´¿ª·¢ PowerZip£¬ÒòΪ³ÌÐò½éÃæÓëʹÓ÷½·¨·Ç³£µÄÏñ£¬¶øÇÒÔÚÎļþÉÏ°´Êó±ê
ÓÒ¼üµÄpop menu ÉÏÒ²ÓÐ[Add to Zip]ºÍ[Extract to...]µÄÑ¡Ï²¢ÇÒÒàÖ§³ÖÖÆ×÷ EXE ×Ô
½âѹËõµµ¡£Ö§³Ö¸ñʽ£ºZIP¡¢A¡¢ARJ¡¢TAR¡¢GZ¡¢TGZ¡¢Z¡¢RAR¡¢CAB¡¢LHA¡¢EXE 

×÷    ÕߣºxiA Qin 
¼¶    ±ð£ººÜ²Ë...ºÜ²Ë.... 
½âÃÜÈÕÇ°£º2000Äê7ÔÂ21ÈÕ 
½âÃܹ¤¾ß£ºTrw2000 1.22 
ÆƽâÄ¿µÄ£ºÑ§Ï°NAG´°¿ÚµÄÈ¥³ýµÄÆƽ⡣(¼òµ¥) 

˵    Ã÷£º 
        ±¾ÎÄÊÇÔÚÎÒµÄÈí¼þÆƽâ¼Ç¼ÉÏÕûÀí³öÀ´µÄ¡£Ö»×÷¼¼Êõ½»Á÷¡£ÈçÈôÓÐç¢Â©£¬Çë¸÷λ´óÏÀ¶àÖ¸½Ì£¡ 



Ê×ÏȽ«ÏµÍ³µÄʱ¼äµ÷¿ì60Ìì¡£ 


Ctrl+N½øÈëTrw2000 

ÏÂÖ¸Áîbpx createwindowex      //ÏÂÖÐ¶Ïµã  

°´X¼ü»Øµ½×ÀÃæÔËÐгÌÐò£¬Õâʱ»á±»Trw2000À¹½Øµ½¡£ 

ÏÂÖ¸Áîbc *                  //Çå³ý¶Ïµã 

ÏÂÖ¸Áîpmodule                //Ö±½ÓÌøµ½³ÌÐòµÄÁì¿Õ 

°´F10À´µ½ÏÂÃæ, 

......................... 

015F:00504760  MOV      EDX,[ESP+28] 
015F:00504764  CMP      [EDX-08],EBX 
015F:00504767  JNZ      00504776 
015F:00504769  MOV      ECX,[ESI+20] 
015F:0050476C  PUSH    DWORD 0052133C 
015F:00504771  CALL    `MFC42!ord_00001837` 
015F:00504776  PUSH    EBX 
015F:00504777  PUSH    DWORD 00521330 
015F:0050477C  PUSH    DWORD 00521290 
015F:00504781  MOV      ECX,ESI 
015F:00504783  CALL    `MFC42!ord_00000DC1` 
015F:00504788  TEST    EAX,EAX 
015F:0050478A  JZ      00504790 
015F:0050478C  PUSH    BYTE +03 
015F:0050478E  JMP      SHORT 00504792 
015F:00504790  PUSH    BYTE +05 
015F:00504792  MOV      ECX,[ESI+20] 
015F:00504795  CALL    `MFC42!ord_00001847` 
015F:0050479A  MOV      EAX,[ESI+20] 
015F:0050479D  MOV      EAX,[EAX+20] 
015F:005047A0  PUSH    EAX 
015F:005047A1  CALL    `USER32!UpdateWindow` 
015F:005047A7  MOV      ECX,[ESI+20] 
015F:005047AA  PUSH    BYTE +01 
015F:005047AC  CALL    `MFC42!ord_000009FE` 
015F:005047B1  MOV      ECX,[005218D8] 
015F:005047B7  CMP      BYTE [ECX+E9],44 
015F:005047BE  JZ      NEAR 00504871                    //ÕâÀï¿ÉÒÔÌø¹ýÏÂÃæµÄCALL,ÎҸġ£ 
015F:005047C4  CALL    `DTUTIL!?DT_GetEvalDay@@YGIXZ` 
015F:005047CA  CMP      EAX,BYTE +0A 
015F:005047CD  JNA      NEAR 00504871 
015F:005047D3  LEA      ECX,[ESP+3C] 
015F:005047D7  CALL    `MFC42!ord_000009D2`              //ʱ¼ä¹ýÆÚ¶Ô»°¿ò 

µ±×ßµ½ÕâÀïʱ¾Í»áµ¯³öÊÔÓùýÆڵĶԻ°¿ò¡£ 

¿´¿´ÄÇÀï¿ÉÒÔÌø¹ýÕâÀï¡£ 

ÉÏÃæ005047BE  JZ  NEAR 00504871 ºÃÏñ¿ÉÒÔÌø¹ýËüÒ®!!!! 

ÖØÐÂ϶ϵãbpx 005047B7 

°´X¼ü»Øµ½×ÀÃæÔËÐгÌÐò£¬Õâʱ±»Trw2000À¹½Øµ½¡£ 

µ±¹â±ê×ßµ½005047BE  JZ    NEAR 00504871 

´òÈëÃüÁî CODE ON  ¼ÇÏÂÖ¸ÁîÂë 


ÏÂÖ¸ÁîA  дÈë»ã±à´úÂë 
½«015F:005047BE  JZ        NEAR 00504871 

¸Ä015F:005047BE  JNZ      NEAR 00504871 

ºÃÒ®£¡ÓÖ¿ÉÒÔ½øÈë³ÌÐòÁË£¬³É¹¦ÁË¡£ 


015F:005047DC  CMP      EAX,BYTE +0A 
015F:005047DF  JZ      NEAR 00504871 
015F:005047E5  LEA      ECX,[ESP+14] 
015F:005047E9  MOV      [ESP+0310],BL 
015F:005047F0  CALL    `MFC42!ord_00000269` 
015F:005047F5  LEA      ECX,[ESP+02FC] 
........................... 


ÕûÀïһϣ¬ÓÃUltraedt´ò¿ªPowerZip.exe 

ÕÒµ½OF 84 AD 00 00 00 

¸Ä³É0F 85 AD 00 00 00 

ÖØÐÂÔËÐгÌÐòÊÔÒ»ÊÔ¡£ 
--------------------------------------------------------------------------------
·µ»Ø
 
·µ»Ø
%¡¾³õѧÌìµØ¡¿
                 
·µ»Ø
O¡¾ÎÊÌâ´ðÒÉ¡¿
 
·µ»Ø
4¡¾ÍøÕ¾½éÉÜ¡¿
 
 
·µ»Ø
,¡¾ÔÓÖ¾ÐÅÏä¡¿
Ͷ¸åÐÅÏ䣺discoveredit@china.com
´ðÒÉÐÅÏ䣺discoveranswer@china.com
°ßÖñÐÅÏ䣺programhunter@china.com
·µ»Ø