EBPIG
6̽Ë÷ÔÓÖ¾6
MHJDQ
֪ʶ¹²ÏíJ×ÊÔ´¹²ÏíJ×ÊÁϹ²Ïí
¡¾·¢ÐÐʱ¼ä¡¿2000-11-15
¡¾ÆÚ¿¯ºÅÂë¡¿Ôö¿¯Ê®¾Å
¡¾ÍøÕ¾µØÖ·¡¿http://programhunter.myetang.com
¡¾°æȨÉùÃ÷¡¿
´ËÔÓÖ¾ÓɳÌʽÁÔÈ˱༭¡¢ÖÆ×÷¼°·¢ÐУ»ÔÓÖ¾¿ÉÒÔ×ÔÓÉתÔØ¡¢·Ö·¢ºÍ´«²¥£»ÈκθöÈË»òÍÅÌå²»µÃÔÚδ¾­±¾ÈËÊÚȨµÄÇé¿öÏÂÐÞ¸ÄÔÓÖ¾µÄÍâ¹Û¼°ÄÚÈÝ£»ÔÓÖ¾µÄ½âÊÍȨ¹é³ÌʽÁÔÈËËùÓС£

¡¾±à¼­¼ÄÓï¡¿

    
   {~._.~} 
    ( Y )  
   ()~*~() 
   (_)-(_) 
ÿÇ°ËÄÆÚµÄÔÓÖ¾ºÍÔö¿¯¶¼ÊÇÓ¢ÎĵIJÄÁÏ£¬ÓеÄÍøÓÑ˵ΪʲôÄØ£¿ÎÒÏë˵Èç¹ûÄã×Ðϸ¿´ÁËÄǼ¸ÆÚÔÓÖ¾Äã»á·¢ÏÖÕâЩ²ÄÁ϶¼ÊDz»¿ÉÒÔ¶àµÃµÄºÃÎÄÕ£¬¿ÉÄܶÔÓÚÓÐЩÍøÓÑÀ´Ëµ£¨Ö÷ÒªÊÇÓ¢ÎÄ·½Ãæ²îµÄÍøÓÑ£©£¬ÊÇÒ»¸öºÜ²»ºÃµÄÊÂÇ飬µ«ÊÇÈç¹ûÄãÓ¢ÎĺõĻ°£¬»á¶Ô½âÃÜÔںܴóµÄ°ïÖúµÄ¡£¶ÔÓÚ¹ØÓÚPEµÄÎÄÕÂÎÒÒѾ­·­ÒëÇ°ËÄƪÁË£¬½«ÔÚ±¾ÖܵÄÔÓÖ¾Öз¢ÐУ¬Ï£Íû´ó¼ÒÄܹ»Ö¸µ¼Ò»Ï¡£
 
¡¾Ä¿ ÿÿ ¼¡¿
ÿÿÿÿ&ÆƽâÐĵÃ
J¡­¡­chinaIRC V1.0 ³ÌʽÁÔÈË
K¡­¡­Win98 µÄÆÁÄ»±£»¤ÃÜÂëÆƽⷽ·¨ ³ÌʽÁÔÈË
L¡­¡­Tag&Rename 1.7  
ÿÿÿÿ,ÔÓÖ¾ÐÅÏä
 
&¡¾ÆƽâÐĵá¿
               chinaIRC V1.0
                      ³ÌʽÁÔÈË
¼ò½é£ºÖÐÎĵÄIRCÁÄÌìÈí¼þ
×·×Ù£ºÕâ¸ö³ÌÐòÔÚ°ïÖúÖÐÌáµ½ÁËÓÐЧÆÚÔÚ1999.9.15-2000.9.15£¬ÎÒ×òÌì´ÓÍøÉÏÏÂÔغó£¬ÔË
Ðз¢ÏÖËüµÄÕâ¸öÓÐЧÆÚµÄÎÊÌ⣬ºÃÁË£¬½ñÌì¾Í×·×ÙÕâ¸öÈí¼þµÄÓÐЧÆÚµÄÎÊÌ⣬½«Ëü½â¾öµô¡£

  ͨ³£×·×ÙÕâÑùµÄ³ÌÐòÒ²±È½Ï¼òµ¥µÄ£¬ËüÒ»¶¨ÓÐÒ»¸ö±È½Ïʱ¼äµÄµØ·½£¬Èç¹ûÔÚÕâ¸ö·¶Î§¾ÍÔË
ÐÐÈí¼þ£¬·ñÔò¾Í²»ÔËÐÐËü¡£ÒÔÇ°µÄ¾­ÑéÊÇÕÒµ½³ö´íµÄµØ·½¾Í¿ÉÒÔÁË¡£½ñÌ쿪ʼʱÎÒÒ²ÊÇ°´ÕÕ
Õâ¸öÏë·¨À´ÆƽâµÄ¡£¿ÉÊÇȴûÓÐ×·×Ù³öÀ´¹Ø¼üµÄ±È½ÏµØ·½£¬ÄÇô»¹µÃÁíѰ˼·¡£
  ÎÒ½«ÏµÍ³µÄʱ¼äµ÷µ½1999ºó£¬³ÌÐò¿ÉÒÔÔËÐÐÁË¡£ÄÇôÎÒÃǾʹÓϵͳµÄʱ¼äÀ´ÈëÊÖ°É¡£ÎÒÏÈ
ʹÓÃW32DASMÀ´·´»ã±àÕâ¸ö³ÌÐò¡£¿ÉÒԵõ½ÏÂÃæËüËùµ÷Óõĺ¯Êý¡£
   Import Module 007: kernel32.dll
 Addr:0007AF4C hint(0000) Name: GetLocalTime
  ³ÌÐòʹÓÃÁËÕâ¸öº¯ÊýÀ´µ÷ÓÃϵͳµÄʱ¼ä£¬ÄÇôÎÒ¾ÍÏÈÉè¶ÏÔÚÕâ¸öº¯Êý£¬ÔÙÔËÐгÌÐò±»À¹ÏÂ
À´ÁË£¬³É¹¦Ò»°ëÁË¡£
:00407EE8 83C4E8                  add esp, FFFFFFE8
:00407EEB 8D442408                lea eax, dword ptr [esp+08]
:00407EEF 50                      push eax

* Reference To: kernel32.GetLocalTime, Ord:0000h
                                  |
:00407EF0 E8B3D7FFFF              Call 004056A8
:00407EF5 668B4C240E              mov cx, word ptr [esp+0E]
:00407EFA 668B54240A              mov dx, word ptr [esp+0A]
:00407EFF 668B442408              mov ax, word ptr [esp+08]
:00407F04 E81FFEFFFF              call 00407D28
:00407F09 DD1C24                  fstp qword ptr [esp]
:00407F0C 9B                      wait
:00407F0D DD0424                  fld qword ptr [esp]
:00407F10 83C418                  add esp, 00000018
:00407F13 C3                      ret
  ÎÒÃǾͽ«ÔÚÉÏÃæµÄµØ·½±»À¹ÏÂÀ´£¬ÏÖÔÚ¿ÉÒÔ¿´Ò»ÏÂÁË¡£ÉÏÃægetlocaltimeº¯ÊýÔËÐк󽫵Ã
µ½Èý¸öÖµ£¬cx£¬dx£¬ax£¬ÕâÀïcxΪÌìÊý£¬dxΪÔÂÊý£¬axΪÄê¡£ÕâÑù´ó¼Ò¾ÍÖªµÀÁË°É¡£
  ÕâÀïÊDZȽϵĵط½µÃÏòÏ£º
:00473450 E8934AF9FF              call 00407EE8  µ÷ÓÃgetlocaltimeµÄº¯Êý
:00473455 DC5DF8                  fcomp qword ptr [ebp-08]
:00473458 DFE0                    fstsw ax
:0047345A 9E                      sahf
:0047345B 7616                    jbe 00473473  ¹Ø¼üµÄ±È½ÏµØ·½
:0047345D B890374700              mov eax, 00473790
:00473462 E89977FCFF              call 0043AC00
:00473467 A19C7E4700              mov eax, dword ptr [00477E9C]
:0047346C 8B00                    mov eax, dword ptr [eax]
:0047346E E88D01FBFF              call 00423600

* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:0047345B(C)
|
:00473473 A19C7E4700              mov eax, dword ptr [00477E9C]
  ÉÏÃæ¾ÍÊǹؼüµÄ±È½ÏµØ·½£¬Èç¹û²»ÈÃËüÌøÔ¾¾Í³öÏÖʧЧµÄÌáʾ¡£³ÌÐòÒ²ÎÞ·¨¼ÌÐøÔËÐÐÁË¡£
ÄÇô¾Í½«Ëü¸ÄΪÎÞÌõ¼þÌøÔ¾¾Í¿ÉÒÔÁË¡£


               ******************************
               * ²éÕÒ£ºDF E0 9E 76 16 B8 90 *
               * Ìæ»»£º-- -- -- EB -- -- -- *
               ******************************


                          Win98 µÄÆÁÄ»±£»¤ÃÜÂëÆƽⷽ·¨
                                       ³ÌʽÁÔÈË
  ½ñÌìûÓÐʲôÊÂÇ飬ÔÓÖ¾ÖÆ×÷Íê³Éºó¿´Ò»¿´´ÓÅóÓѽèµÄ¹âÅÌ£¬´ÓÖп´µ½ÁËÒ»¸ö¹ØÓÚÆƽâwi
n98ÆÁÄ»±£»¤µÄÃÜÂ룬ÕâÀï½éÉÜÈçÏ£º

ÆÁÄ»±£»¤ÃÜÂë
      ÀûÓÃϵͳµÄÆÁÄ»±£»¤¹¦ÄÜ¿ÉÒÔ·ÀÖ¹ËûÈËÔÚ×Ô¼º²»ÔÚµÄÇé¿öÏÂ͵ÓÃ×Ô¼ºµÄ¼ÆËã»ú£¬´Ó¶ø
Æðµ½±£»¤Êý¾Ý°²È«µÄ×÷Óᣲ»¹ýÔÚ²»ÅäºÏÆäËüÏÞÖƹ¦ÄܵÄÇé¿öÏ£¬ÏµÍ³µÄÆÁÄ»±£»¤ÃÜÂëÊÇ·Ç
³£´àÈõµÄ¡£ÎÒÃÇÔÚÒÅÍüÃÜÂëÖ®ºóÖ»ÐèʹÓá°¸´Î»¡±¼üÇ¿ÐÐÆô¶¯¼ÆËã»ú£¨Ä³Ð©Éè¼Æ²»ÍêÉƵÄÆÁ
Ä»±£»¤³ÌÐòÉõÖÁ¿ÉÒÔʹÓÃCtrl£«Alt£«DelÇ¿Ðйرգ¬Æä²Ù×÷¾Í¸ü¼òµ¥ÁË£©£¬È»ºóÓÒ»÷×ÀÃæ¿Õ
°×´¦²¢´Óµ¯³öµÄ¿ì½Ý²Ëµ¥ÖÐÖ´ÐС°ÊôÐÔ¡±ÃüÁ´ò¿ª¡°ÏÔʾÊôÐÔ¡±ÉèÖÿò²¢µ¥»÷¡°ÆÁÄ»±£»¤
¡±Ñ¡Ï£¬×îºóÈ¡Ïû¡°ÃÜÂë±£»¤¡±Ñ¡Ïî¼´¿É£¨È¡Ïû¸ÃÑ¡ÏîʱÎÞÐèÈ·ÈÏÃÜÂ룩¡£ÁíÍ⣬¾Ý˵Ŀ
Ç°ÊÐÃæÉÏ»¹³öÏÖÁËÒ»ÖÖרÃÅÓÃÓÚÆƽâÆÁÄ»±£»¤ÃÜÂëµÄ¹âÅÌ¡£²åÈë¸Ã¹âÅÌÖ®ºó£¬Ëü¾Í»áÀûÓÃWi
ndows 98µÄ×Ô¶¯ÔËÐй¦ÄÜÆô¶¯±£´æÔÚ¹âÅÌÉϵÄÆÁÄ»±£»¤ÃÜÂëÆƽâ³ÌÐò£¬¶ÔÆÁÄ»±£»¤¹¦ÄܵÄÃÜ
Âë½øÐзÖÎö¡¢ÆÆÒ룬×îºóÔÙ½«ÃÜÂëÏÔʾÔÚÆÁÄ»ÉÏ»òдµ½ÈíÅÌÉÏ£¬Õâ¾Í¸ü·½±ãÁË£¨¶Ô²»Æ𣬸Ã
¹¦ÄÜÖ»ÊǵÀÌý;˵£¬±¾È˲¢Ã»ÓÐÇ×ÑÛ¼ûµ½ÕâÑùµÄ¹âÅÌ£©¡£

  ÉÏÃæ¾ÍÊÇÕâ¸öÎÄÕµÄ×÷ÕßÌṩµÄÆƽⷽ·¨£¬µ«ÊÇÎÒ¸öÈËÈÏΪ¿ÉÒÔ¶Ôwin98µÄÆÁÄ»±£»¤ÃÜÂë
½øÐÐÑо¿Ò»Ï£¬ÕâÑù¾Í¿ÉÒÔÖªµÀwin98ÊÇʹÓÃʲôÎļþÀ´ÑéÖ¤ÃÜÂëµÄ¡£

  ÏÖÔÚÏÈʹÓÃRegsnapÀ´¶Ô×¢²á±í½øÐÐÅÄÕÕ£¬È»ºó½«ÆÁÄ»±£»¤ÃÜÂëÉèΪÓУ¬ÕâÑù¾Í¿ÉÒÔ·ÖÎö
µ½win98ÊÇÈçºÎ½«ÆÁ±£ÃÜÂë·ÅÔÚ×¢²á±íµÄÄĸöµØ·½ÁË¡£ÕâÑù·ÖÎöºóµÃµ½ÁËÕâÑùµÄ½á¹û¡£
HKEY_USERS\.DEFAULT\Control Panel\desktop\ScreenSaveUsePassword=0x00000001(1)
ÕâÀï¾ÍÊÇwin½«ÃÜÂëÏî´ò¿ªµÄÑ¡ÏÈç¹ûÄ㽫Õâ¸ö0x00000001(1)±äΪ0x00000000(0)ºó¾Íû
ÓÐÆÁ±£ÃÜÂëÁË¡£Ò²¾ÍÊÇÕâ¸öÆÁ±£ÃÜÂë²»ÔÙÆð×÷ÓÃÁË¡£

  Õâ¸ö¶ÔÆÁ±£ÃÜÂëµÄÑо¿ÊÇ×ʼ½×¶Î£¬ÏÂÒ»²½Êǽ«Ñо¿winÊÇʹÓÃÄĸö³ÌÐòÀ´ÑéÖ¤ÆÁ±£ÃÜ
ÂëµÄ¡£
  ÕâÀïÒÀÈ»»¹µÃ½èס¹¤¾ßÀ´·ÖÎö£¬ÏÈʹÓÃTRW2000À´·ÖÎö£¬½«ÆÁ±£Æô¶¯£¬³öÏÖÑéÖ¤ÃÜÂëµÄµØ
·½£¬ÔÚÕâÀïÏÈÊäÈëÈÎÒâµÄÃÜÂëºó£¬Éèbpx hmemcpyºóµã»÷OK£¬±»À¹ÏÂÀ´£¬ËüÕâʱÔÚϵͳÖÐken
ealÖУ¬°´F12¼¸´Î¾Í¿ÉÒÔµ½´ïÏÂÃæÏÔʾΪpassword!¡­¡­×ÖÑùµÄµØ·½£¬ÕâÀï¾ÍÊÇÎÒÃÇÏëÒªµÃµ½µÄµØ·½¡£
* Reference To: USER32.GetDlgItemTextA, Ord:00FDh
                                  |
:78054201 FF15DC720578            Call dword ptr [780572DC]
:78054207 85FF                    test edi, edi  <-³öÀ´
:78054209 751B                    jne 78054226
:7805420B 8D45FC                  lea eax, dword ptr [ebp-04]
:7805420E 8D8D78FFFFFF            lea ecx, dword ptr [ebp+FFFFFF78]
:78054214 50                      push eax
:78054215 51                      push ecx

* Reference To: MPR.WNetVerifyPasswordA, Ord:004Eh
                                  |
:78054216 E87F020000              Call 7805449A
:7805421B 85C0                    test eax, eax
:7805421D 7440                    je 7805425F
:7805421F B801000000              mov eax, 00000001
:78054224 EB79                    jmp 7805429F

* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:78054209(C)
|
:78054226 8D8574FEFFFF            lea eax, dword ptr [ebp+FFFFFE74]
:7805422C 8D8D78FFFFFF            lea ecx, dword ptr [ebp+FFFFFF78]
:78054232 50                      push eax
:78054233 51                      push ecx

* Reference To: KERNEL32.lstrlenA, Ord:02E7h
                                  |
:78054234 FF1558720578            Call dword ptr [78057258]
:7805423A 50                      push eax
:7805423B 8D8D78FFFFFF            lea ecx, dword ptr [ebp+FFFFFF78]
:78054241 51                      push ecx
:78054242 E89A010000              call 780543E1
:78054247 57                      push edi    ¼ÓÃܺóÄãÊäÈëµÄÃÜÂë
:78054248 8D8D74FEFFFF            lea ecx, dword ptr [ebp+FFFFFE74]
:7805424E 51                      push ecx   ¼ÓÃܺóÕæÕýµÄÃÜÂë

* Reference To: KERNEL32.lstrcmpiA, Ord:02DEh
                                  |
:7805424F FF1554720578            Call dword ptr [78057254]
:78054255 83F801                  cmp eax, 00000001
:78054258 1BC0                    sbb eax, eax
:7805425A F7D8                    neg eax
:7805425C 8945FC                  mov dword ptr [ebp-04], eax

* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:7805421D(C)
|
:7805425F 33FF                    xor edi, edi
:78054261 B801000000              mov eax, 00000001
:78054266 397DFC                  cmp dword ptr [ebp-04], edi
:78054269 7534                    jne 7805429F     ***¹Ø¼üÌøÔ¾µÄµØ·½
ÉÏÃæ¾ÍÊdzÌÐò±È½ÏÆÁ±£ÃÜÂë¹ý³Ì£¬ÉÏÃæÊǼÓÃܺóÔÙ½øÐбȽϵĹý³Ì£¬ËùÒÔÎÞ·¨¿´µ½ÕæÕýµÄÃÜ
Â룬µ«ÊÇÄã¿ÉÒÔÔÚ***´¦Ç¿ÐÐÌøÔ¾µÄ¾Í¿ÉÒÔÁË¡£ÕâÑù¾Í¿ÉÒԻص½winÖÐÁË¡£

ÏÖÔÚʹÓÃTRW¾Í¿ÉÒÔ½â¾öµôÆÁ±£ÃÜÂëÁË¡£µ«ÊÇ»¹ÊDz»Ðеģ¬ÎÒÃǵÃÕÒµ½winʹÓÃÄĸö³ÌÐòÀ´µ÷
ÓÃÑéÖ¤ÃÜÂëµÄ¹ý³Ì¡£

  ÏÖÔÚʹÓÃFile monitorÀ´²é¿´winµ÷ÓÃÁËʲô³ÌÐò¡£
  ¾­¹ý¼àÊÓ£¬·¢ÏÖwinµ÷ÓÃc:\windows\system\password.cpl³ÌÐòÀ´ÑéÖ¤ÃÜÂëµÄ¹ý³Ì¡£Æäʵ
Ò²Óõ½ÁËÆäËü³ÌÐò£¬µ«ÊÇÕâ¸ö¾ÍÊÇÎÒÃÇÒªÕҵijÌÐò¡£
 ʹÓÃW32DASMÀ´·´»ã±àÕâ¸ö³ÌÐò£¬·¢ÏÖ¾ÍÊÇÎÒÃÇÒªÕҵijÌÐò£¬ÓÚÊÇÎÒ½«
:78054266 397DFC                  cmp dword ptr [ebp-04], edi
:78054269 7534                    jne 7805429F     ***¹Ø¼üÌøÔ¾µÄµØ·½
ÕâÀï¸ÄΪ
:78054266 397DFC                  cmp dword ptr [ebp-04], edi
:78054269 EB34                    jmp 7805429F     ***¹Ø¼üÌøÔ¾µÄµØ·½
´æÅÌ£¬ÔÙ½øÐÐÆÁ±£ÃÜÂëÑéÖ¤¹ý³Ì£¬ÄãÖ»Òªµã»÷OK¾Í¿ÉÒÔÁË¡£winÒѾ­Ã»ÓÐÁËÆÁ±£ÃÜÂë±£»¤µÄ
¹¦ÄÜ¡£

   ÏÖÔÚwin98µÄÆÁ±£ÃÜÂë¼ÓÃܹý³ÌÔÙÑо¿Ò»ÏÂÁË£¬winµÄÆÁ±£ÃÜÂë¼ÓÃܹý³ÌÆäʵÊÇÒ»¸öºÜ¼ò
µ¥µÄ¹ý³Ì£¬ËüµÄ¾ßÌåËã·¨ºÜ¼òµ¥µÄ¡£ÈçÏ£º
:780510AF 0FB6442413              movzx eax, byte ptr [esp+13]  ³õʼֵΪ0£¬ÒÔºó
ÿ´Î¼Ó1£¬¾ÍΪµÃµ½ÏÂÃæµÄclÖµ£¬ËùÒÔclֵֻͬλÊýÖµÓйأ¬²»Í¬ÃÜÂëÓйء£
:780510B4 40                      inc eax
:780510B5 99                      cdq
:780510B6 33C2                    xor eax, edx
:780510B8 2BC2                    sub eax, edx
:780510BA 25FF000000              and eax, 000000FF
:780510BF 33C2                    xor eax, edx
:780510C1 2BC2                    sub eax, edx
:780510C3 88442413                mov byte ptr [esp+13], al
:780510C7 0FB6C0                  movzx eax, al
:780510CA 8D0C38                  lea ecx, dword ptr [eax+edi]
:780510CD 8A19                    mov bl, byte ptr [ecx]
:780510CF 0FB6442412              movzx eax, byte ptr [esp+12]
:780510D4 0FB6F3                  movzx esi, bl
:780510D7 03C6                    add eax, esi
:780510D9 99                      cdq
:780510DA 33C2                    xor eax, edx
:780510DC 2BC2                    sub eax, edx
:780510DE 25FF000000              and eax, 000000FF
:780510E3 33C2                    xor eax, edx
:780510E5 2BC2                    sub eax, edx
:780510E7 88442412                mov byte ptr [esp+12], al
:780510EB 0FB6C0                  movzx eax, al
:780510EE 8D1438                  lea edx, dword ptr [eax+edi]
:780510F1 8A02                    mov al, byte ptr [edx]
:780510F3 8801                    mov byte ptr [ecx], al
:780510F5 881A                    mov byte ptr [edx], bl
:780510F7 0FB601                  movzx eax, byte ptr [ecx]
:780510FA 03C6                    add eax, esi
:780510FC 99                      cdq
:780510FD 33C2                    xor eax, edx
:780510FF 2BC2                    sub eax, edx
:78051101 25FF000000              and eax, 000000FF
:78051106 33C2                    xor eax, edx
:78051108 2BC2                    sub eax, edx
:7805110A 8A0C07                  mov cl, byte ptr [edi+eax]
:7805110D 8B442420                mov eax, dword ptr [esp+20]
:78051111 300C28                  xor byte ptr [eax+ebp], cl
:78051114 45                      inc ebp
:78051115 3B6C241C                cmp ebp, dword ptr [esp+1C]
:78051119 7C94                    jl 780510AF
  winµÄ¼ÓÃܹý³ÌÊÇÏÈʹÓôÓ0¿ªÊ¼½«´Ó780510AF¿ªÊ¼¼ÆËãÒ»Ö±µ½7805110A¼ÆËã½áÊø£¬µÃµ½cl
ÖµÕâ¸öÖµ²»ÓÚÕýÈ·µÄÃÜÂëÓйأ¬ËùÒÔËüֻͬÃÜÂëµÄλÊýÓйصģ¬¾ßÌå¹ØϵÈçÏ£º
 λÊý£º 1  2  3  4  5  6  7  8  9  10 11 12 13 14 15 16 ¡­¡­
 ÃÜÎÄ£º 48 EE 76 1D 67 69 A1 1B 7A 8C 47 F8 54 95 97 5F ¡­¡­
 winµÄ¼ÓÃܹý³Ì¾ÍÊǽ«ÉÏÃæµÄÃÜÎÄͬÄãÊäÈëµÄÃÜÂë½øÐÐxorÔËË㣬µÃµ½µÄ¼ÓÃÜÃÜÎĺóÔÙͬÒÔ
Ç°±£´æµÄÃÜÂë±È½Ï£¬Èç¹û¡­¡­¡£ÕýÔھͲ»ÓÃ˵ÁË¡£
 win½«ÃÜÂëµÄ¼ÓÃÜÃÜÎÄ·ÅÔÚÕâÀï
HKEY_USERS\.DEFAULT\Control Panel\desktop\ScreenSave_Data
 Ëüµ±È»ÊÇ×îºóµÄÃÜÎÄÁË¡£ÄãÔÚÕâÀï¿ÉÒԵõ½Ê®ÁùλµÄÃÜÎÄ¡£Èç¹ûÄãÉèµÄÃÜÂëΪ£º????(Õâ¸ö
ÊÇÑÝʾʹÓõģ©£¬ÔÚÕâÀïÄ㽫µÃµ½ÈçϵÄÊý¾Ý£º
0000   37 38 44 46 34 34 32 45  78DF442E
0001   00
ÕâÀï×îºóµÄ00¾ÍÊÇÃÜÂëµÄ½áÊø±êÖ¾£¬ÉÏÃæ²ÅÊÇÃÜÎĵġ£Ëü½«ÊÇÄãÊäÈëÃÜÂëµÄÁ½±¶£¬Õâ¸öºÜÈÝ
Ò×Àí½â£¬ÏÖÔÚ´ó¼Ò¾Í¿ÉÒÔʹÓôÓλÊýµÃµ½µÄÃÜÎÄÀ´¶ÔÕâ¸ö¼ÓÃܵÄÃÜÂë½øÐнâÃÜ´¦Àí¡£
¾ßÌå²Ù×÷Ϊ£ºÆÁ±£¼ÓÃÜÃÜÂë=ÆÁ±£Î»ÊýÃÜÎÄXORÆÁ±£Ã÷ÎÄ
      ÆÁ±£Î»ÊýÃÜÎÄ£º  48  EE  76  1D
 XOR  ÆÁ±£Ã÷ÎÄ£º                    
   =  ÆÁ±£¼ÓÃÜÃÜÂ룺  78  DF  44  2E
  ͨ¹ýÉÏÃæµÄ·´xorÔËËã¿ÉÒԵõ½ÆÁ±£ÃÜÂëµÄÃ÷ÎÄÁË¡£ÔËËã½á¹ûΪ£º30 31 32 33£¬ÔòÃ÷ÎľÍ
Ϊ£º0123¡£ÕâÏÂÆÁ±£µÄÃÜÂëÆƽâ¹ý³Ì¾ÍÍêÈ«Ñо¿³É¹¦ÁË¡£

  ÏÖÔÚ¿ÉÒԺܼòµ¥µÄÖÆ×÷³öwin98µÄÆÁ±£ÃÜÂëÆƽâÈí¼þÁË¡£µ±È»ÄãµÃÊäÈë¼ÓÃܺóµÄÃÜÎÄÁË¡£
ÕâÑù¾Í¿ÉÒԵõ½Ã÷ÎÄÁË¡£¾ßÌåÖÆ×÷¹ý³ÌºÜ¼òµ¥µÄ£¬´ó¼ÒʹÓÃC¾Í¿ÉÒÔ½â¾öÁË¡£

ºÃÁË£¬ÏÖÔÚ×ܽáһϰɣ¬Èç¹ûÄãÏë´ò¿ªÆÁ±£±£»¤µÄÃÜÂ룬ʹÓÃ×îºóÒ»ÖÖ·½·¨±È½ÏºÃ£¬¿ÉÒÔÔÚ
Áíһ̨µçÄÔÖн«password.cplÐÞ¸ÄΪÉÏÃæµÄÄÇÑù£¬ÖØÐÂÆô¶¯µçÄԾͿÉÒÔ½«Ëü¿½±´µ½ÏàÓ¦µÄÄ¿
¼Ï¾ͿÉÒÔÁË¡£ÕâÑù½øÐÐwinÖоÍÊÇ¿ªÊ¼»¹ÓÐÃÜÂë±£»¤Ò²Äܵã»÷OK»Øµ½winÖÐÀ´¡£
 
  ±êÌ⣺Tag&Rename 1.7 ÎÄÕÂÒ» £º¸ú×Ù£¬²¢ÇÒÖÆ×÷Loader¡££¨ÊʺϳõѧÕߣ©
                           mcny@work
Èí¼þ      £ºTag&Rename 1.7 
Èí¼þ¼ò½é  £ºÒ»¸ö¿ÉÒÔÐÞ¸ÄMP3 ºÍ VQF ÒôÀÖÎļþÖеÄTAG˵Ã÷µÄ³ÌÐò¡£Ä¿Ç°ÉÐδ֧³ÖMP3×îеÄID3v2 
            µ«ÊÇ£¬ÈÔÈ»ÊÇÒ»¸öºÜºÃÓõı༭¹¤¾ß¡£
ÏÂÔØ´¦    £ºÈí¼þÖ÷Ò³: http://www.softpointer.com/tr.htm 
          £º°æ±¾1.7£¨ÈôÕÒ²»µ½£©¿ÉÒÔÔÚÎÒÕâÀïÏÂÔØ:
            http://www.geocities.com/mcny_work/orgfile/2000/TagRename17.zip
            (888k bytes  ²»Ö§³Ö¶ÏµãÐø´« )
×¢²á·½·¨  £º×¢²áÂ루ÓëÃû×ÖÎÞ¹Ø,¶øÇÒÊDz»¿ÉÄæËã·¨£¬ÎÞ·¨¼ÆËã³ö×¢²áÂ룩 
·´¸ú×Ù±£»¤ £ºAsprotect 1.0 ¼Ó¿Ç 
========================================================================================
ÆƽâÄѶȠ       £ºÒ× £¨ÕâÀïÊÇÖ¸£ºÕÒ³ö¹Ø¼üÌøת£¬¸Ä±äËü£©
È¥·´¸ú×Ù±£»¤ÄѶȣºÒ× £¨ÕâÀïÊÇÖ¸£ºÊ¹ÓÃLoader,ÓÐÏֳɵĴúÂëÂ²»ÓÃ×Ô¼ºÐ´£¡
                      ÈôÒª×Ô¶¯ÍѿǵĻ°£¬ÓÐÏֳɵÄÍÑ¿Ç»ú(SACµÄ£¬ÎÒ»¹Ã»Óùý£¬²»ÖªÐ§¹ûÈçºÎ)¡£
                      ÈôÒªÊÖ¹¤ÍѿǵĻ°£¬¿ÉÒԲο¼http://toye.yeah.net
                      'Æƽâ½Ìѧ'ÉϵÄÏà¹ØÎÄÕ£¬ÄѶȣºÖУ©
ʹÓù¤¾ß        £º1) Trw2000 v1.22
                  2) TASM32 5.0(ÐèÒª3¸öÎļþ£ºimport32.lib ,tasm32.exe, tlink32.exe)
Ä¿±êÎļþ        £ºTagRename.exe
¹Ø¼ü            £ºÕÒ³ö¹Ø¼üÌøתµã£¬ÖÆ×÷Ò»¸öLoaderÀ´¸Ä±ä¸ÃÌøת£¨Ô­Òò£ºÒòΪÈí¼þ¾­¹ý¼Ó¿Ç£¬ÎÞ
                  ·¨Ö±½ÓÐÞ¸ÄÄ¿±êÎļþ£©
----------------------------------------------------------------------------------------
¡¾×¢1¡¿ £º¿´Ñ©ÂÛ̳ÖУ¬ÓÐÈËÔø¸æËßÎÒ£ºÆƽâÊÇÆƽ⣬ÍÑ¿ÇÊÇÍÑ¿Ç£¬²»ÄÜ»ìΪһ̸¡£ ¾õµÃºÜÓÐ
          µÀÀí£¬ËùÒÔÕâÀï¾Í·Ö³ÉÁ½¸öÄѶȶÈÁ¿£ºÆƽ⡢ȥ·´¸ú×Ù¡£
¡¾×¢2¡¿ £º±àÒëÁ¬½ÓLoaderʱ£¬±¾ÎÄûÓÐʹÓÃ'×ÊÔ´Îļþ'£¬ËùÒÔÖÆ×÷³öÀ´Loader²»»á°üº¬Í¼±ê¡£ÓÐ
          ÐËȤ£¬Äã¿ÉÒÔ×Ô¼º²¹ÉÏ¡£
¡¾×¢3¡¿ £º±¾ÎÄÒâÔÚ¸øÓè²»ÔøÖÆ×÷LoaderµÄÅóÓÑÒ»¸öLoaderµÄÖÆ×÷¾­Ñé¡£²¢²»ÊÇ˵£¬ÖÆ×÷Loader
          ²ÅÊÇÆƽⱾÈí¼þ×î¼Ñ·½·¨¡£
========================================================================================
±¾ÎÄ×÷ÕߣºMcNy@Work
ÈÕÆÚ     £º2000Äê11ÔÂ09ÈÕ
Email    £ºmcny_work@yahoo.com
        £¨ÓʼþÖ÷ÌâÇëÒÔ"WANTED:McNycn"¿ªÊ¼£¬×¢ÒâÓ¢ÎÄ×Öĸ´óСд£¬·ñÔòÎÒ»áÊÕ²»µ½à¸£¡£©
 
                ¡¾Ä¿Â¼¡¿ 
¡ì£½£½£½£½£½£½£½£½£½£½£½£½£½£½£½£½£½£½£½£½¡ì
¡ìµÚÒ»²¿·Ö£º³õ²½×·×Ù                    ¡ì
¡ìµÚ¶þ²¿·Ö£º½øÒ»²½×·×Ù£¬ÕÒµ½¹Ø¼ü±È½Ïµã    ¡ì
¡ìµÚÈý²¿·Ö£ºÖÆ×÷Loader£¬¸½£º³ÌÐòÔ´´úÂë    ¡ì
¡ì£½£½£½£½£½£½£½£½£½£½£½£½£½£½£½£½£½£½£½£½¡ì

-------------------------------¡¾µÚÒ»²¿·Ö£º³õ²½×·×Ù¡¿-----------------------------------
    Ê×ÏÈÔËÐÐ Trw2000 £¬ÓÃËüÔØÈëTagRename.exe ¡£°´ÏÂ'Load'½¡ºó£¬ÎÒÃÇÀ´µ½trw2000µÄµ÷ÊÔ¿òÖУ¬ 
°´F5,³ÌÐò¼ÌÐøÔËÐС£È»ºó£¬TagRename »á³öÏÖÒ»¸öÌáʾ¿ò¸æÊöÄãÒѾ­Ê¹ÓÃÁ˼¸Ì죬»¹½ÐÄã×¢²á¡£Ñ¡Ôñ
'Unlock'£¬ÔÚYournameÖÐÌíÈëÐÕÃû£¬ÔÚCodeÖÐÌíÈëÈÎÒâÎı¾¡£(eg, Name: McNy@Work    Code:a )
ÔÝʱ²»Òª°´ÏÂOK°´Å¥¡£
    È»ºó,°´Ctrl+N, À´µ½trw2000µ÷ÊÔ¿òÖС£ÉèÖöϵ㣬¼üÈ룺bpx hmemcpy  £¬»Ø³µ¡££¨<--Õâ¿ÉÊÇ 
¾­µä¶¯×÷à¸!£©°´F5,ÈóÌÐò¼ÌÐøÔËÐС£ÎÒÃÇ»á»Øµ½windows ÖУ¬°´Ï¸ղÅû°´ÏµÄOK¼ü¡£
    ³ÌÐòÓÖ±»Öжϣ¬ÎÒÃÇÓÖÀ´µ½trw2000µ÷ÊÔ¿òÖС£ÏÖÔÚ£¬ÎÒÃDz»¶ÏµÄ°´F10 £¬Ò»Ö±µ½Error¶Ô»°¿ò³ö 
ÏÖ£¨F10 ÊÇÖ𲽸ú×Ù£©¡£ÆäÖÐÒ»¸öret´¦°´ÏÂF10ºó»áÀ´µ½µØÖ· 00508B49¡£¼ÌÐø¸ú×Ù£¬µ±ÓÃF10Ô½¹ý
00508B76  call 004646EC ºó£¬Error ¿ò³öÏÖ£¬¸æËßÄã×¢²áÂë²»¶Ô£¡ °´OK £¬»á»Øµ½Trw2000µ÷ÊÔ¿ò¡£
    ºÜÃ÷ÏÔ£¬00508B76 ´¦µÄcall »áÏÔʾerror¶Ô»°¿ò¡£ÒªÈçºÎ±Ü¿ªËüÄØ£¿ÎÒÃÇÏòÉÏÕÒ£¬·¢ÏÖ00508B80 
´¦µÄJZÓлú»á±Ü¿ªError¿ò£¬Ìõ¼þÊÇAL=1¡££¨µ±È»£¬ÎÒÃǵ½ÕâÀïʱµÄAL<>1£¬ÒòΪע²áÂë²»¶ÔÂ£©
        
            ...
        ==>    017F:00508B49    MOV EAX,[EBP-08]        file://ijһ¸öret»á·µ»Øµ½´Ë¡£
        017F:00508B4C    LEA EDX,[EBP-04]
                017F:00508B4F    CALL 0408EBC
                017F:00508B54    MOV EAX,[EBP-04]
      **(A1)**  017F:00508B57    CALL 00456510          file://´¦Àí¡¢¼ÆËã¡¢±È½Ï×¢²áÂë!!!
                                                        file://×¢²áÂëÕýȷʱ£¬·µ»ØAL=1¡£
      **(A2)**  017F:00508B5C    CMP AL,01        
    ==>    017F:00508B5E    JZ 0508B80        file://ÈôAL=1£¬Ôò¿ÉÒԱܿªerror¶Ô»°¿ò!
                017F:00508B60    LEA ECX,[EBP-0C]
                017F:00508B63    MOV EAX,[00541A98]
                017F:00508B68    MOV EAX,[EAX]
                017F:00508B6A    MOV DX,01D9
                017F:00508B6E    CALL 0046DE40
                017F:00508B73    MOV EAX,[EBP-0C]
        ==>    017F:00508B76    CALL 004646EC          file://»á³öÏÖerror¶Ô»°¿ò
                017F:00508B7B    JMP 00508C56
            ...

    ´ÏÃ÷µÄÄ㣬һ¶¨»áÏëµ½¸Ä±ä 00508B5C µÄ±È½ÏÖ¸Áî »òÕß ¸Ä±ä 00508B5E µÄÌõתָÁîÀ´´ïµ½
±Ü¿ªerror¶Ô»°¿òµÄÄ¿µÄ¡£µ«ÊÇ£¬ÕâÑù×öµÄ»°Ö»¶ÔÁËÒ»°ë£¡ÒòΪ³ÌÐò²»Ö¹ÔÚÒ»µØ·½µ÷Óà call 00456510 ¡£
£¨ÎÒµ±È»ÊÇÊÔ¹ý²ÅÖªµÀÂ£©ËùÒÔʹ call 00456510 µÄ·µ»Ø½á¹û±Ø¶¨ AL=01²ÅÊÇÒ»ÀÍÓÀÒݵķ½·¨¡£
    ËùÒÔ£¬ÎÒÃÇÒ²¿ÉÒÔÐÞ¸Ä 00465610 ´¦µÄ´úÂ룬ʹ֮±ä³É mov al,01 ¡£ ret¡££¨ÖÃAL=1,²¢ÂíÉÏ·µ»Ø£© 
µ«ÎÒÃDz»ÕâÑù×ö£¬ÒòΪÕâÑù×öÒѸıäÁËÕû¸öCallµÄ×÷Ó㬿ÉÄÜ»á´øÀ´Ç±ÔڵijÌÐò´íÎó¡£ÎÒÏë¶Ôԭʼ³Ì
ÐòÓÃ×îÉÙ¡¢×ȫµÄÐÞ¸ÄÀ´´ïµ½ÎÒÃǵÄÄ¿µÄ¡£
    ÓÚÊÇ£¬ÎÒÃDZ¾×ÅÕâÑùµÄ˼·À´½øÐÐ×·×Ù£ºÊÇʲôÔì³ÉAL=1£¿Ô­À´ÊǵØÖ·xxxxxxxx ´¦µÄ EBX=1 ʱ¡£ 
ÄÄÓÖÊÇʲôÔì³É xxxxxxxx ʱµÄEBX=1?Ô­À´ÊǵØÖ·yyyyyyyy´¦µÄ EAX<>0 £¬... ¾ÍÕâÑù£¬Ò»Ö±µ½±È½Ï
×¢²áÂëµÄµØµã¡£
---------------------------------µÚÒ»²¿·ÖÍê----------------------------------------------- 
 
-------------------------------¡¾µÚ¶þ²¿·Ö£º½øÒ»²½×·×Ù£¬ÕÒµ½¹Ø¼ü±È½Ïµã¡¿------------------- 
    ÎÒÃÇÖØÐÂÉèÖÃËùÓжϵã,¶øжϵãÉèÖÃÔÚÉÏÊö´úÂëÖÐÓÐ×¢Ã÷**(A1)**´¦£¬ËùcallµÄµØÖ·¡£ 
¼´ bc * , »Ø³µ¡£bpx 00456510 £¬»Ø³µ ¡£ °´ÏÂF5 ¡£TagRename³ÌÐò¼ÌÐøÔËÐС£
    °´'Unlock'¼ü£¬'OK'¼ü¡£³ÌÐòÓÖ±»Öжϣ¬ÎÒÃÇÀ´µ½µ÷ÊÔ¿òÖУ¬µØÖ·ÊÇÎÒÃǸղÅÉèÖõĶϵ㴦£¬¼´ 
00456510 ¡£²»¶Ï°´F10Ò»Ö±µ½¹ýÁ˵ÚÒ»¸öRET £¨ÏÂÃæ´úÂëµÄ **(A4)** ´¦£©¡£ÓÉÓÚµÚ¶þ¸öRET ²ÅÊÇÕæ
ÕýµÄRET£¬ËùÒÔÎÒÃÇÖªµÀµØÖ·004565BD´¦µÄEBX ¾ö¶¨Á˼´½«·µ»ØµÄEAXÖµ£¨ÎÒÃÇҪʹEAX=1£©£¡
    
    ÓÚÊÇÎÒÃÇ°Ñ×¢ÒâÁ¦×ªÒƵ½EBX¡£ÔÙÍùÉÏÃ漸Ðп´¿´£¬·¢ÏÖ00456598 ´¦½«1 ¸³Öµ¸øBL¡£µ«ÊÇΪʲô
ÎÒÃǵÄÊÇEBX=0 ? ÕâÊÇÒòΪ 00456594 ´¦µÄJZ Ìøת³É¹¦£¡£¨ÏÂÃæ´úÂëµÄ**(A3)** £©
    ºÜÃ÷ÏÔ00456594¾ÍÊÇÎÒÃÇÒª¸ÄµÄµØ·½ÁË¡£Ö»Òª½« JZ 00456598 È¥µô¼´¿É£¨¼´£¬²»¹ÜÕæÕý½á¹ûÈç 
ºÎ£¬ÎÒÃǶ¼Áî×¢²áÂëÕýÈ·(BL=1) £©¡£¼üÈë code on,»Ø³µ¡£ÏÈÓÃÖ½¼ÇÏÂ00456594´¦¿ªÊ¼µÄ10 Bytes
µÄ´úÂ루ÖÆ×÷LOADERʱ»áÓõ½:¼´74 02 B3 01 8B 45 F8 E8 C8 C9£©¡£
   
    ÏÖÔÚ£¬ÓÃÁ½¸önopÈ¡´ú00456594µÄJZ 00456598¡£ÎÒÃǼüÈëa 456594£¬»Ø³µ¡£nop£¬»Ø³µ¡£nop£¬Á½
¸ö»Ø³µ¡£¿ÉÒÔ¿´¼û£¬00456594´¦µÄ´úÂë±ä³ÉÁ½¸önop ÁË¡£
    ÈóÌÐò¼ÌÐøÔËÐÐÇ°£¬ÎÒÃÇÓ¦¸ÃÇå³ýËùÓжϵ㡣¹Ê¼üÈëbc * £¬»Ø³µ¡£°´ÏÂF5¡£TagRename³ÌÐò¼ÌÐø 
ÔËÐС£³ÌÐò³öÏÖError¿ò£¨ÎÒÃǵÄÐÞ¸ÄÔÚÏÂÒ»´Î²ÅÉúЧ£©¡£
    °´'Unlock'¼ü£¬'OK'¼ü¡£³öÏÖÒ»¸ö¶Ô»°¿ò¸ÐлÎÒÃÇ×¢²á 8^)  ¡£ÎÒÃǵÄ×·×ÙÒ²µ½´Ë½áÊøÁË¡£Ñ¡Ôñ 
TagRename ³ÌÐòÖеÄHELP > ABOUT£¬³öÏÖµÄABOUT¶Ô»°¿ò»áÏÔʾ Register to: McNy@Work ¡£

            ...
        ==>    017F:00456510    PUSH EBP                file://´ËΪ¶Ïµã´¦£¬³ÌÐòÔÚÕâÀïÔÝÍ£¡£
                017F:00456511    MOV EBP,ESP
            ...
            ...
                017F:0045655F    MOV EAX,ESI
                017F:00456561    CALL 00402F68
                017F:00456566    LEA EDX,[EBP-04]
                017F:00456569    LEA EAX,[EBP-18]
                017F:0045656C    CALL 00456460          file://ÓÉÊäÈëS/N£¬²úÉú"ÊäÈëÂëÉú³É´®"µÄ
                                                        file://Ö÷Òªµ÷Óá£
                017F:00456571    MOV DL,01
                017F:00456573    MOV EAX,[00410060]
                017F:0045657D    MOV [EBP-08],EAX
                017F:00456580    LEA EAX,[EBP-08]
                017F:00456583     CALL 00456404
                017F:00456588    MOV EDX,[EBP-04]
                017F:0045658B    MOV EAX,[EBP-08]
                017F:0045658E    MOV ECX,[EAX]
                017F:00456590    CALL NEAR [ECX+50]  file://±È½Ï"×¢²áÂëÉú³É´®'ºÍÁ½°ÙÓà¸ö
                                                    file://"ÕýÈ·µÄ´®"¡£
                                                    file://ÈôÈ«²¿²»Æ¥Åä·µ»ØEAX=FFFFFFFF
                                                    file://£¨ÄÚ²¿»áµ÷Óà Kernel32!CompareStringA£©
                017F:00456593    INC EAX            
      **(A3)**  017F:00456594    JZ 0456598              file://EAX=0 ʱÌøת¡£ÎÒÃǸÄÕâÀï!!!
        ==>    017F:00456598    MOV BL,01              file://ÈôÉÏÒ»Ðв»Ìøת£¬Ôò×¢²áÂëÕýÈ·¡£
                017F:0045659B    CALL 00402F68
                017F:004565A0    XOR EAX,EAX
                017F:004565A2     POP EDX
                017F:004565A3    POP ECX
                017F:004565A4    POP ECX
                017F:004565A5    MOV [FS:EAX],EDX
                017F:004565A8    PUSH DWORD 004565BD
                017F:004565AD    LEA EAX,[EBP-04]
                017F:004565B0    CALL 00403CEC
        ==>    017F:004565B5    RET                    file://È¥017f:004565BD  !!!
                017F:004565B6    JMP 004036C8
                017F:004565BB    JMP SHORT 004565AD
      **(A4)**  017F:004565BD    MOV EAX,EBX            file://¹þ£¡Ô­À´Êǽ«EBX¸³Öµ¸øEAX¡£
                017F:004565BF    POP ESI
                017F:004565C0    POP EBX
                017F:004565C1    POP ESP,EBP
                017F:004565C3    POP EBP
                017F:004565C4    RET                    file://·µ»Øµ½**(A2)**´¦

---------------------------------µÚ¶þ²¿·ÖÍê-----------------------------------------------

-------------------------------¡¾µÚÈý²¿·Ö£ºÖÆ×÷Loader¡¿-----------------------------------
±¾ÎIJÉÓÃR!SC µÄLoaderÔ´´úÂ룬²¢¸Ä±äÏàÓ¦µÄµØ·½£º 
£¨Ò»£©ÎÒÃÇÏÈÕûÀíÓɵÚÒ»¡¢¶þ²¿·ÖµÄ¸ú×ÙËùµÃµÄһЩÊý¾Ý£º 
    Ä¿±ê³ÌÐòÃû£ºTAGRENAME.EXE
    Ð޸ĵĵØÖ·£º00456594h         £¨h ´ú±íÊ®Áù½øÖÆÊý£©
    Ëù×÷Ð޸Ġ £º7402 ==> 9090        £¨nopµÄ´úÂëÊÇ90£©
    ÐÞ¸Ä×Ö½ÚÊý£º2             
    ´Ó00456594ÆðµÄ10¸ö×Ö½ÚΪ£º74,02,B3,01,8B,45,F8,E8,C8,C9
£¨¶þ£©²½Ö裺 
        1£©ÔÚTASMµÄĿ¼ÖУ¬½¨Á¢Ò»¸öÎļþÃûΪloader.asm µÄÎı¾Îļþ£¨.asmÊÇÎļþÀ©Õ¹Ãû£©
        2£©½«ÏÂÃæÁ½ÐÐ ;+++++++++++++ Ö®¼äµÄ´úÂëÈ«²¿¿½±´Õ³Ìùµ½loader.asmÖУ¬±£´æÎļþ¡£ 
    
        3£©½«ÎÒÃÇ£¨Ò»£©ÖеÄËùÓÐ×ÊÁÏÌîÔÚloader.asmÖÐ**(B1)**´¦µÄÏàӦλÖá£
        ÔÚ**(B2)**´¦£¬ÌîÈëÑÓʱ£¬Ïȼٶ¨1000 °É¡£Èô²»ÄÜÕý³£Ê¹ÓÃÔòÔÚµ÷Õû¡£
        £¨µ÷ÕûÔ­Ôò£ºLoader ¿ÉÒÔÔØÈëTagRename£¬µ«³ÌÐòÒÀȻûע²á¡£ ==> ¼õÉÙÑÓʱ (eg: 800)
                Loader ²»ÄÜÕý³£ÔËÐУ¬³öÏÖERROR¿ò¡£          ==> Ôö¼ÓÑÓʱ (eg:1200)
         £©    
    
        4£©ÔÚDOS Prompt ÖÐ £¬½øÈëTASMµÄĿ¼ÖÐ(±ÊÕßµÄĿ¼Ϊ£ºe:\tasm5),ÒÀ´Î¼üÈëÒÔÏÂ
        Á½ÐÐÃüÁî¡£
        tasm32 /ml loader.asm                        £¨±àÒ룩
        tlink32 /Tpe /aa /c loader,loader,,e:\tasm5\import32.lib    £¨Á¬½Ó£©
       
        5£©³É¹¦µÄ»°£¬»áÔÚµ±Ç°Ä¿Â¼²úÉúÒ»¸öÃûΪloader.exeµÄÎļþ£¬½«Ëü¿½±´µ½Tag&RenameµÄ
        Ŀ¼ÖУ¬¼´¿É¡£ÔËÐÐLoader,¿´¿´Äܲ»ÄÜÕý³£Ê¹Ó㬲»ÄÜÔòÔٴε÷ÕûÑÓʱ£¬ÖØбàÒë¡£

;++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
; Requires Tasm 5.0 & import32.lib to compile
; tasm32 /ml loader.asm 
; tlink32 /Tpe /aa /c loader,loader,, <path to> import32.lib
; replace <path to> with whatever...
.386P 
Locals
jumps
.Model Flat ,StdCall 

;Define the needed external functions and constants here.
Extrn      MessageBoxA:PROC  
Extrn      WaitForInputIdle:PROC
Extrn      WriteProcessMemory:PROC 
Extrn      ReadProcessMemory:PROC
Extrn      CreateProcessA:PROC
Extrn      CloseHandle:PROC
Extrn      ExitProcess:PROC
;-=-Normal data-=-=-=-=-=-=-=-=-=-=-=-=-= 
.Data                                       
CSiR_Tag            db 'Tag&Rename 1.7 (Loader),by McNy@Work ',0
CSiR_Error          db 'Error!!!',0
CSiR_Error1        db 'Something wrong!!...',0
OpenERR_txt        db 'CreateProcess Error :(',0
ReadERR_txt        db 'ReadProcessMemory Error :(',0
WriteERR_txt        db 'WriteProcessMemory Error :P',0
VersionERR_txt      db 'Incorrect Version of application :(',0
CSiR_ProcessInfo    dd 4 dup (0)        ;process handles
CSiR_StartupInfo    db 48h dup (0)      ;startup info for the process were opening
CSiR_RPBuffer      db 10h dup (0)      ;read buffer, for checking data
;-=-Patch datas-=-=-=-=-=-=-=-=-=-=-=-=-= 
CSiR_AppName  db 'TAGRENAME.EXE',0          ; **(B1)** 
mcny          dd 00456594h                  ; address to read data from for version checking
sizeof        dd 10                        ; in the new process
checkbytes    db 074h,002h,0b3h,001h,08bh  ; the bytes to check for 
              db 045h,0f8h,0e8h,0c8h,0c9h  ; if there not there, we have the wrong version??
;-----
patch_data_1  db 90h,90h
patch_size_1  dd 2
patch_addr_1  dd 00456594h
.Code                                  
;-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Main:
    push    offset CSiR_Tag
    mov    dword ptr [CSiR_StartupInfo],44h ; (the size in bytes of the structure)
    push    offset CSiR_ProcessInfo          ; Typedef struct _PROCESS_INFORMATION
    push    offset CSiR_StartupInfo          ; Pointer to STARTUPINFO structure
    push    0
    push    0
    push    20h                              ; Creation flags
    push    0
    push    0
    push    0
    push    0
    push    offset CSiR_AppName              ; Pointer to name of executable mod
    call    CreateProcessA
    test    eax,eax
    jz      OpenERR
Wait4Depack: 
    push    1000                            ; **(B2)**   
                                            ; Timeout (in milliseconds, -1 = infinate)
                                            ; Ô­×÷ÕßΪ LARGE-1
                                            ; ÎÒµÄPCÉÏ¿ÉÒÔÓÃ800µ½1500¡£Äã×Ô¼ºÉèÒ»¸öÊý°É£¡
    push    dword ptr [CSiR_ProcessInfo]
    call    WaitForInputIdle
   
Check_Data:
    push    0                              ; BytesRead 
    push    dword ptr [sizeof]              ; Length
    push    offset CSiR_RPBuffer            ; Destination (to read them to)
    push    dword ptr [mcny]                ; Source
    push    dword ptr [CSiR_ProcessInfo]    ; Process whose memory we are to read
    call    ReadProcessMemory
    test    eax,eax
    jz      ReadERR
    ;...
    ;int 03 ;-)
    cld
    lea    esi, CSiR_RPBuffer
    lea    edi, checkbytes
    mov    ecx, 10
    rep    cmpsb
    jnz    VersionERR 
    ;...
Patch_the_mother:
    push    0                              ; Pointer to byteswritten (i like null though)
    push    dword ptr [patch_size_1]        ; Length
    push    offset patch_data_1            ; Source
    push    dword ptr [patch_addr_1]        ; Destination
    push    dword ptr [CSiR_ProcessInfo]    ; Process whose memory we are to patch
    call    WriteProcessMemory              ; Call Kernel32!WriteProcessMenory
    test    eax,eax
    jz      WriteERR
   
Close_This_app:
    push    dword ptr [CSiR_ProcessInfo]
    call    CloseHandle
    push    dword ptr [CSiR_ProcessInfo+4]
    call    CloseHandle
   
Exit_Proc:
    Push LARGE-1
    Call ExitProcess
;-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= 
VersionERR:
    lea    eax, VersionERR_txt
    jmp    abort
ReadERR:
    lea    eax, ReadERR_txt
    jmp    abort
OpenERR:
    lea    eax, OpenERR_txt
    jmp    abort
WriteERR:
    lea    eax, WriteERR_txt
abort:
    push 0
    push offset CSiR_Error                  ; Title
    push eax                                ; Message
    push 0
    call MessageBoxA
    jmp Close_This_app 
   
End Main
;++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
---------------------------------µÚÈý²¿·ÖÍê----------------------------------------------- 
========================================================================================== 
È«ÎĽáÊø£¨ÕâÊÇÎҵĴ¦Å®×÷£¬Óв»¶ÔµÄµØ·½£¬»¹Íû´ó¼Ò¶à¶àÖ¸ÕýÓë°üº­!£©
,¡¾ÔÓÖ¾ÐÅÏä¡¿
Ͷ¸åÐÅÏ䣺discoveredit@china.com
´ðÒÉÐÅÏ䣺discoveranswer@china.com
°ßÖñÐÅÏ䣺programhunter@china.com