±ê Ìâ:תÌû¡¾ÃÎÐÑʱ·Öt0db.myetang.com¡¿·ÒëµÄ£º¡¾ÆƽâAutodesk AUTOCAD 14 ¹·¼ÓÃÜ ¡¿
ÔõÑùÆƽâAutodesk AUTOCAD 14 ·¨Óï°æµÄ¹·¼ÓÃÜ
--------------------------------------------------------------------------------
translate by ÃÎÐÑʱ·Ö
yinqun2000@263.net
http://t0db.myetang.com
¼¶±ð:Öм¶-¸ß¼¶
ËùÐ蹤¾ß:
Soft ice 3.x
Äã×Ô¼º×îϲ»¶µÄ ±à¼Æ÷ (ÎÒÒ»Ö±Óà Hexworkshop)
»ã±à֪ʶ (ÖÁÉÙÊÇ»ù´¡)
Wdasm89 (²¢²»ÌرðÐèÒª)
´óÄÔ (ÄãÓÐÒ»¸ö , ÊÇÂð ? :p )
һЩơ¾Æ :O ( ÒòΪÆƽâÕâ¸öÈí¼þÊÇÒªºÜ³¤Ê±¼äµÄ!)
һЩÒôÀÖ ;)
ÀúÊ·:
ÎÒÊǺܾÃÒÔÇ°ÆƽâÕâ¸öÈí¼þµÄ... ;O
Ëü¶ÔÎÒÀ´ËµºÜÄÑ,¶øÇÒÀË·ÑÁËÎÒ¼¸Ììʱ¼ä.×îÄѵIJ¿·Ö¾ÍÊÇÕÒµ½¼ì²é¹·µÄµØ·½¶øÇÒÎÒ²»ÊÇÓÃÏÂÃæÎÒ
½ÌÄãµÄ·½·¨×öµÄ!ÄÇÊÇÒ»Öֺܸ´Ôӵķ½·¨...ÎҺܴÀµÄÆƽâÁËËü,¶øÇÒ»¹³£³£±ÀÀ£!¼¸ÌìÇ°,ÎÒÍê³ÉÁË
ÁíÒ»¸ö×¢²á»úʱ¾õµÃºÜ·³.ËùÒÔ,ÎÒÏëµ½³ýÁË×¢²á»úµÄÆƽâ.ÄÇôÄǸö¹·±£»¤µÄAutocad 14?!°¡!ÄÇ
Êǹ·±£»¤!ÎÒÌÖÑá¹·,¶øÇÒÔÚÕâ·½Ã漸ºõûÐʲô¾Ñ?..
¹·±£»¤ÊÇ×î¹óµÄ±£»¤·½·¨,Õâ¸öÈí¼þµÄÊÛ¼ÛÊÇ$7000×óÓÒ!(¹»¿ªÒ»¸öÍø°ÉµÄÁË)
ÈÃÎÒÃÇÀ´ÆƽâËü°É:)
BTW,ÎÒÓú÷½·¨ÆƽâËü´ó¸ÅÓÃÁË 2 Сʱ (°üÀ¨ ·´»ã±à: ×µÄ²¿·Ö :p) ÕâÆÚ¼äûÓÐËÀ»ú ;)
1)ÔËÐÐÈí¼þ :)
ºÃµÄ.. ÈÃÎÒÃÇÀ´¿´¿´Õâ¸öÄ¿±ê,ÎÒ°²×°Õâ¸öÈí¼þ·Ç³£Âý.. ¸ÃËÀµÄ¹âÅÌ!¼ÙÉèËü·Ç³£¿ì°É!°²×°ºÃºó,ÕÒ
µ½°²×°Ä¿Â¼.ÓÐÒ»¸ö Acad.exe µÄ¿ÉÖ´ÐÐÎļþºÍÆäËüºÜ¶àdllÎļþ...ÎÒÔËÐÐÕâ¸öÈí¼þ,Ìø³öÒ»¸ö¶Ô»°¿ò:
"ERREUR FATALE : Le system de securit?verrouillage materiel..."
ÕâÊÇ·¨Óï, Òâ˼ÊÇ:
"FATAL ERROR : security system is missing! blablabla"
ºÃµÄ,Ëü¾ÍÊǸæËßÎÒÃÇ×îÖØÒªµÄÓ²¼þ(*¹·*)¶ªÊ§!¹þ¹þ¹þ
ÄÇô... ÈÃÎÒÃǸüÉî²ãµÄ¿´¿´ ;) ÎÒʹÓÃsofticeÉèÖÃÁËÔÚ LPT1ÉÏ×î³£ÓõĶϵã: (BPIO -H 378 R).
ÎÒÃÇÍ£ÔÚÁËÕâ¶ù:
0028:CE5AA885 88442405 MOV [ESP+05],AL ; Õâ¶ù.
0028:CE5AA889 66C746680100 MOV WORD PTR [ESI+68],0001
0028:CE5AA88F 8A442405 MOV AL,[ESP+05]
0028:CE5AA893 884615 MOV [ESI+15],AL
0028:CE5AA896 884614 MOV [ESI+14],AL
0028:CE5AA899 5E POP ESI
0028:CE5AA89A 83C404 ADD ESP,04
0028:CE5AA89D C3 RET
0028:CE5AA89E CC INT 3
0028:CE5AA89F CC INT 3
0028:CE5AA8A0 83EC04 SUB ESP,04
0028:CE5AA8A3 56 PUSH ESI
0028:CE5AA8A4 8B74240C MOV ESI,[ESP+0C]
0028:CE5AA8A8 56 PUSH ESI
0028:CE5AA8A9 E832000000 CALL CE5AA8E0
0028:CE5AA8AE 668B465C MOV AX,[ESI+5C]
0028:CE5AA8B2 83C404 ADD ESP,04
0028:CE5AA8B5 6689442406 MOV [ESP+06],AX
0028:CE5AA8BA 8A4658 MOV AL,[ESI+58]
0028:CE5AA8BD 243F AND AL,3F
0028:CE5AA8BF 88442405 MOV [ESP+05],AL
0028:CE5AA8C3 8A442405 MOV AL,[ESP+05]
0028:CE5AA8C7 668B542406 MOV DX,[ESP+06]
0028:CE5AA8CC EE OUT DX,AL
0028:CE5AA8CD 5E POP ESI
0028:CE5AA8CE 83C404 ADD ESP,04
0028:CE5AA8D1 C3 RET
ÎÒÃÇÊÇÔÚ chat_to_dongle routine. ¶øÇÒÈç¹ûÎÒÃÇ¿´ÏÂÃæµÄdata²¿·Ö,ÎÒÃÇ¿´µ½:SENTINELXXX...
ÕâÊÇʲô°¡?! ÄãÓ¦¸ÃÖªµÀÓÐʲô¹«Ë¾ÌṩÕâÖÖ¼Ó¹·µÄ·þÎñÈç: Hasp, Sentinel, DesKEY,
Activator/Unikey »¹ÓÐÐí¶àÆäËüµÄ.
Òò´Ë,ÎÒÃÇ¿ÉÒÔÍƶÏÅöµ½µÄÊÇÒ»¸ö SENTINEL ¹·¼ÓÃÜ!ÎÒÃÇÏÖÔÚÔÚ SENTINEL.VXD Îļþ... »Øµ½ÎÄÕÂ
ÖÐÀ´,ÎÒÃÇÍ£ÔÚÕâ¶ù:
0028:CE5AA885 88442405 MOV [ESP+05],AL ; ͉˕..
0028:CE5AA889 66C746680100 MOV WORD PTR [ESI+68],0001
0028:CE5AA88F 8A442405 MOV AL,[ESP+05]
0028:CE5AA893 884615 MOV [ESI+15],AL
0028:CE5AA896 884614 MOV [ESI+14],AL
ÎÒÃÇÒª¿´ÊǹØÓÚ¿ÉÖ´ÐÐÎļþµÄCALL,ËùÒÔÎÒÃÇÒª°´ÈýËÄ´ÎF12,ÎÒÃÇ»áÔÚÕâ¶ù:
0028:CE5B35D6 50 PUSH EAX
0028:CE5B35D7 55 PUSH EBP
0028:CE5B35D8 57 PUSH EDI
0028:CE5B35D9 E8D2FEFFFF CALL CE5B34B0 ; ÎÒÃÇµÄ call :)
0028:CE5B35DE C06C241F01 SHR BYTE PTR [ESP+1F],01 ;»Øµ½Õâ¶ù.
0028:CE5B35E3 83C40C ADD ESP,0C
0028:CE5B35E6 0AD8 OR BL,AL
0028:CE5B35E8 664E DEC SI
0028:CE5B35EA 75E1 JNZ CE5B35CD
0028:CE5B35EC C0EB01 SHR BL,01
0028:CE5B35EF 6A64 PUSH 64
0028:CE5B35F1 57 PUSH EDI
0028:CE5B35F2 E8C979FFFF CALL CE5AAFC0
0028:CE5B35F7 8A44241B MOV AL,[ESP+1B]
0028:CE5B35FB 83C408 ADD ESP,08
0028:CE5B35FE 2401 AND AL,01
0028:CE5B3600 50 PUSH EAX
0028:CE5B3601 55 PUSH EBP
0028:CE5B3602 57 PUSH EDI
0028:CE5B3603 E8A8FEFFFF CALL CE5B34B0
0028:CE5B3608 83C40C ADD ESP,0C
0028:CE5B360B 0AD8 OR BL,AL
0028:CE5B360D 66BE0300 MOV SI,0003
0028:CE5B3611 6A64 PUSH 64
0028:CE5B3613 C06C241701 SHR BYTE PTR [ESP+17],01
0028:CE5B3618 57 PUSH EDI
ÔÚ CALL ÖÐ:
0028:CE5B35D6 50 PUSH EAX
0028:CE5B35D7 55 PUSH EBP
0028:CE5B35D8 57 PUSH EDI
0028:CE5B35D9 E8D2FEFFFF CALL CE5B34B0
0028:CE5B35DE C06C241F01 SHR BYTE PTR [ESP+1F],01
0028:CE5B35E3 83C40C ADD ESP,0C
0028:CE5B35E6 0AD8 OR BL,AL
0028:CE5B35E8 664E DEC SI
0028:CE5B35EA 75E1 JNZ CE5B35CD
0028:CE5B35EC C0EB01 SHR BL,01
0028:CE5B35EF 6A64 PUSH 64
0028:CE5B35F1 57 PUSH EDI
0028:CE5B35F2 E8C979FFFF CALL CE5AAFC0
0028:CE5B35F7 8A44241B MOV AL,[ESP+1B]
0028:CE5B35FB 83C408 ADD ESP,08
0028:CE5B35FE 2401 AND AL,01
0028:CE5B3600 50 PUSH EAX
0028:CE5B3601 55 PUSH EBP
0028:CE5B3602 57 PUSH EDI
0028:CE5B3603 E8A8FEFFFF CALL CE5B34B0
0028:CE5B3608 83C40C ADD ESP,0C
0028:CE5B360B 0AD8 OR BL,AL
0028:CE5B360D 66BE0300 MOV SI,0003
0028:CE5B3611 6A64 PUSH 64
0028:CE5B3613 C06C241701 SHR BYTE PTR [ESP+17],01
0028:CE5B3618 57 PUSH EDI
0028:CE5B3619 E8A279FFFF CALL CE5AAFC0
0028:CE5B361E 83C408 ADD ESP,08
0028:CE5B3621 C0EB01 SHR BL,01
0028:CE5B3624 8A442413 MOV AL,[ESP+13]
0028:CE5B3628 2401 AND AL,01
0028:CE5B362A 50 PUSH EAX
0028:CE5B362B 55 PUSH EBP
0028:CE5B362C 57 PUSH EDI
0028:CE5B362D E87EFEFFFF CALL CE5B34B0
0028:CE5B3632 C06C241F01 SHR BYTE PTR [ESP+1F],01
0028:CE5B3637 83C40C ADD ESP,0C
0028:CE5B363A 0AD8 OR BL,AL
0028:CE5B363C 664E DEC SI
0028:CE5B363E 75E1 JNZ CE5B3621
0028:CE5B3640 6A05 PUSH 05
0028:CE5B3642 80E380 AND BL,80
0028:CE5B3645 68DF000000 PUSH 000000DF
0028:CE5B364A 57 PUSH EDI
0028:CE5B364B FF5718 CALL [EDI+18]
0028:CE5B364E 83C40C ADD ESP,0C
0028:CE5B3651 B900000000 MOV ECX,00000000
0028:CE5B3656 80FB01 CMP BL,01
0028:CE5B3659 5D POP EBP
0028:CE5B365A 83D1FF ADC ECX,-01
0028:CE5B365D 5F POP EDI
0028:CE5B365E 6683E103 AND CX,03
0028:CE5B3662 5E POP ESI
0028:CE5B3663 668BC1 MOV AX,CX
0028:CE5B3666 5B POP EBX
0028:CE5B3667 83C404 ADD ESP,04
0028:CE5B366A C3 RET
Ok,¿´¿´ÏÂÃæµÄ´úÂë²¢²»ÄÜ°ïÖúÎÒÃÇʲô :( ÎÒ¿´¹ý¼¸Æª¹ØÓÚ¹·¼ÓÃܵĽ̳Ì.ÎÒÃÇ×ö
µÄÕ⼸²½,Ó¦¸ÃÊÇÒѾÍê³ÉÁË.ÎÒÏë,ÔÚCALLºóÃæ,»áÓÐÒ»¸ö¹ØÓÚ¹·µÄ CMP ,Èç¹ûÖµÊÇ
ºÍ¹·Ïàͬ,ÄÇô¾Íͨ¹ý,·ñÔò¾Í»á¼ÓÉÏÒ»¸ö´íÎóµÄÆì±ê...... µ«ÊÇ,ÎÒÃÇÊDz»ÐÒÔ˵Ä,
ÕâÀï²»ÊÇÄÇô¼òµ¥!µÄ.ͨ¹ýºÍ´úÂëÓÎÏ·(¸ú×Ùcall,Ñ°ÕÒһЩ±È½ÏµÄ´úÂë),ÎÒ°´ºÜ¶à
´Î F12 ,µ«ÊÇÕÒ²»µ½Ò»µãºÃ¶«Î÷!
BTW,ÎÒÎÞ´ÓÕâ¸ÃËÀµÄSentinelµÄVXDÖгöÀ´!°´×¡ F12,¿ÉÊÇʲô¶¼Ã»Óбä!VDXʹÎÒ
ÏÝÈëÀ§¾³ÁË......ÎÒÏ£Íû»Øµ½ Acad.exe ÎļþÖÐ!ÎÒ²»Ï£ÍûÆƽ⹷Ӳ¼þ,´ó¶àÊýµÄʱºò,
¹·±£»¤µÄÈõµãÒ»°ã¶¼ÊÇÔÚÄ¿±ê±¾Éí!
ÎÒÊÔÁË BPIO -h 378 R
ÈÃÎÒÃÇÔÚ I/O-port ÉÏÊÔÊÔÆäËüµÄ¶Ïµã :
378 ÒѾÊÔ¹ýÁË
3BC Õâ¸ö ;)
278 Õâ¸öÒ²ÊÇ ;o)
OK,ÔËÐÐÈí¼þ,µ«ÊÇȴûÓÐÀ¹½Ø ;( ÎÒµÄÌì°¡!
ÒòΪËüÊÇÒ»¸ö VDX ,ËùÒÔÎÒÒ²ÊÔÁË bpx CreateFileA ,µ«ÊÇ×ß²»Á˶à¾Ã......
ÄÇô,Ϊʲô²»·´»ã±àËüÄØ?ÔËÆøºÃ˵²»¶¨ÄÜÕÒµ½Ò»Ð©ÔÚ×Ö·û´®ÖÐÕÒµ½Ò»Ð©¹ØÓÚ³ö´í
µÄÐÅÏ¢(²»Òª×öÃÎÁË,ÄÇÊDz»¿ÉÄÜÓеÄ!!:p)ÏÖÔÚÄãÄÜÓù¤¾ßÖеÄÆ¡¾ÆÁË ;) ÒòΪÎÒÃÇ
Òª»¨ºÜ³¤Ê±¼äÈ¥·´»ã±à!!!! ÄǾÍÊÇÎÒΪʲô²»ÓÃIDAµÄÔÒòÁË! BTW, ÎÒÃǵÄÄ¿±ê¿É
Ö´ÐÐÎļþ´ó¸ÅÊÇ 7.24 mb!ºÃÁË,ÏÖÔÚÄãÖªµÀΪʲôҪ»¨Õâô¶àʱ¼äÁË°É..
ºÈ¹ý¾Æºó,Ò»¾õÐÑÀ´.
¾¹ýÕâô³¤µÄʱ¼ä,ÖÕÓÚ·´»ã±àºÃÁË! Ê×ÏÈ,±£´æ½á¹û!ÎÒÃDz»Ï£ÍûÔÙµÈÄÇô¶àʱ¼ä,²»ÊÇ
Âð?Èç¹ûÄãµÄµçÄÔËÀ»ú»òÕßÆäËüÔÒò,ÄãÖ»ÓÐÔÙµÈÄÇô¶àʱ¼äÁË!ÔÙºÈÒ»´Î¾Æ,ºÇºÇ!
ÍêÁËÂð? Ok!
ÎÒÃÇÓÞ´ÀµÄÏë·¨ÊÇÈ¥ÕÒ×Ö·û´®,ÔËÆø²»¼Ñ,ûÓÐ,ÆäʵÊÇÒâÁÏÖ®ÖÐ :p ÄÇôÈÃÎÒÃÇÏëÏë!
ÎÒÃÇÔõÑù¹¥»÷ËüÄØ? ÎÒÃÇ¿´¿´ Import ±í°É!¿´¿´¹·µ½µ×µ÷ÓÃÁËʲôº¯Êý :) ÎÒÃÇ¿ÉÒÔÕÒ
µ½Ò»¸ö "l33t0" API º¯Êý!¹þ¹þ,ÎÒÏë»áÓÐһЩºÃ¶«Î÷ÁË, ÎÒÃÇÀ´¿´¿´ÄÚºË......
Ì«Ì«Ì«ºÃÁË :) ÎÒÕÒµ½Ò»Ð©ÓÐȤµÄ¶«Î÷ÁË:
DeviceIoControl
´ÓûÓп´¹ý,µ«ÊÇÃû³Æ,ÌýÆðÀ´·Ç³£ºÃ,²»ÊÇÂð?
ºÇºÇ!È¥³ýËùÓеĶϵãÖ»ÔÚsofticeÖÐÊäÈë: 'bc *' ºÍ: 'BPX DeviceIocontrol'
ÏÖÔÚÔËÐÐÎÒÃǵÄÈí¼þ! ¹þ¹þ,ËüÀ¹½ØÏÂÀ´ÁË :) °´F12,ÎÒÃÇÌø³öÁËdllÎļþÀ´µ½ÁËACAD.exe
:) ÈÃÎÒÃǺʹúÂëÍæË£°É.......
ÏÈ¿´´úÂë, ÎÒ°´F12¼¸´ÎÖ±µ½ÔÚÒ»¸öºÃλÖÃ.ÏÂÃæÊÇÀ´×ÔÎÒµÄwinice.log µÄÒ»²¿·Ö:
:bl
00) BPX KERNEL32!DeviceIoControl // Damn good :)
Break due to BPX KERNEL32!DeviceIoControl
Break due to BPX KERNEL32!DeviceIoControl
Break due to BPX KERNEL32!DeviceIoControl
Break due to BPX KERNEL32!DeviceIoControl
Break due to BPX KERNEL32!DeviceIoControl
Break due to BPX KERNEL32!DeviceIoControl
// ÄãÔÚÕâ¿ÉÒÔ¿´µ½ÎÒÔÚÕÒµ½ºÃµØ·½Ö®Ç°±»À¹½ØÏÂÀ´¶àÉÙ´Î
// ÄãÓÃÕâ¸ö bpx µÄʱºò,Äã°´ F5 3 ´Î,Ò»»áÓÐÀ¹½ØÏÂÀ´,
// ÄãÔÙ°´Á½´ÎºóÍ£ÔÚÁËÕâ¶ù :
025F:0098B1AF 668B442402 MOV AX,[ESP+02] ; EAX = һЩֵ
025F:0098B1B4 83C404 ADD ESP,04
025F:0098B1B7 C20800 RET 0008
025F:0098B1BA 8D9B00000000 LEA EBX,[EBX+00000000]
025F:0098B1C0 33C0 XOR EAX,EAX
025F:0098B1C2 8A442408 MOV AL,[ESP+08]
025F:0098B1C6 83F801 CMP EAX,01
025F:0098B1C9 7415 JZ 0098B1E0
025F:0098B1CB 83F802 CMP EAX,02
025F:0098B1CE 7456 JZ 0098B226
025F:0098B1D0 83F803 CMP EAX,03
025F:0098B1D3 0F8497000000 JZ 0098B270
025F:0098B1D9 C20800 RET 0008
// ͨ¹ý RET ºó,ÎÒÃÇÂäÔÚÕâ¶ù:
025F:006ABE9A 0FBFC0 MOVSX EAX,AX ; ºÇºÇ :)
025F:006ABE9D 83F8FF CMP EAX,-01 ; EAX = FFFF ?!
025F:006ABEA0 7405 JZ 006ABEA7 ; Ìøתµ½ 6abea7
025F:006ABEA2 25FFFF0000 AND EAX,0000FFFF
025F:006ABEA7 5F POP EDI
025F:006ABEA8 C3 RET ; ·µ»Ø ....
// ÕâÊÇ×îÖØÒªµÄ²¿·Ö :
025F:006ABD94 83C404 ADD ESP,04
025F:006ABD97 85C0 TEST EAX,EAX
025F:006ABD99 7C36 JL 006ABDD1
025F:006ABD9B 8D44240C LEA EAX,[ESP+0C]
025F:006ABD9F 50 PUSH EAX
025F:006ABDA0 E8DB000000 CALL 006ABE80
025F:006ABDA5 83C404 ADD ESP,04
025F:006ABDA8 85C0 TEST EAX,EAX
025F:006ABDAA 7C25 JL 006ABDD1
025F:006ABDAC 686071A700 PUSH 00A77160
025F:006ABDB1 E8CA000000 CALL 006ABE80
025F:006ABDB6 83C404 ADD ESP,04
025F:006ABDB9 85C0 TEST EAX,EAX
025F:006ABDBB 7C14 JL 006ABDD1
025F:006ABDBD 68F470A700 PUSH 00A770F4
025F:006ABDC2 E8B9000000 CALL 006ABE80
025F:006ABDC7 83C404 ADD ESP,04
025F:006ABDCA 3DFDDC0000 CMP EAX,0000DCFD ; eax= DCFD?
025F:006ABDCF 7408 JZ 006ABDD9 ; ºÃ! ¹·
025F:006ABDD1 47 INC EDI ; ËøסÁË :)
025F:006ABDD2 83FF04 CMP EDI,04
025F:006ABDD5 7EA3 JLE 006ABD7A
025F:006ABDD7 EB17 JMP 006ABDF0 ; ÖªµÀÂð?
025F:006ABDD9 8B0D8871A700 MOV ECX,[00A77188] ;¹·ÔÚÕâ¶ù
025F:006ABDDF 6633F6 XOR SI,SI
025F:006ABDE2 A18471A700 MOV EAX,[00A77184]
025F:006ABDE7 8B1481 MOV EDX,[EAX*4+ECX]
025F:006ABDEA C70202000000 MOV DWORD PTR [EDX],00000002
025F:006ABDF0 8B0D8471A700 MOV ECX,[00A77184] ;ûÓй·:/
025F:006ABDF6 A18871A700 MOV EAX,[00A77188]
025F:006ABDFB 8B1488 MOV EDX,[ECX*4+EAX]
025F:006ABDFE 8D0C88 LEA ECX,[ECX*4+EAX]
025F:006ABE01 8B1D8471A700 MOV EBX,[00A77184]
025F:006ABE07 8B02 MOV EAX,[EDX]
025F:006ABE09 35A9B50000 XOR EAX,0000B5A9
025F:006ABE0E 03C3 ADD EAX,EBX
025F:006ABE10 A3A471A700 MOV [00A771A4],EAX
025F:006ABE15 8B11 MOV EDX,[ECX]
025F:006ABE17 833A00 CMP DWORD PTR [EDX],00
025F:006ABE1A 752F JNZ 006ABE4B
025F:006ABE1C E81F010000 CALL 006ABF40
025F:006ABE21 35A9B50000 XOR EAX,0000B5A9
025F:006ABE26 3D564AFFFF CMP EAX,FFFF4A56
025F:006ABE2B 741E JZ 006ABE4B
--------------------------- 8< ---------------------- ½ØÈ¡ :p
Ok,ÎÒÊ×ÏÈÏëµ½µÄÊǸıä:
025F:006ABDCA 3DFDDC0000 CMP EAX,0000DCFD ; ÊÇ eax= DCFD ?
025F:006ABDCF 7408 JZ 006ABDD9 ; ºÃµÄ! ¹·ËøסÁË
³ÉΪ:
025F:006ABDCA 3DFDDC0000 CMP EAX,0000DCFD
025F:006ABDCF EB08 JMP 006ABDD9 ;²»¹Ü EAX ÁË,ÎÒÌø :p
µ«ÊÇ,EAX µÄÖµºÜÖØÒª,·ñÔòÊÇ»á±ÀÀ£µÄ:( ÎÒÃÇÒ²¿´µ½Á˺ܶദ¶¼µ÷ÓÃÁË EAX ¼Ä´æÆ÷
,¼ì²éÁ˺ü¸´ÎŶ!ÄÇô,ÎÒÃÇÖ»Óб©Á¦Ê¹ EAX µÄÖµµÈÓÚ DCFD ÁË!
Ä㻹²»Çå³ýÂð,ÐÂÊÖ?EAXµÄֵΪʲôҪµÈÓÚ DCFD?Äãû¿´µ½:CMP EAX,0000DCFD
Âð?ÏÈÔÚ´ó¼Ò¶¼Çå³þÁË°É!
ÎÒÃǵ½ÄÄÈ¥ÐÞ¸ÄÄ¿±êÄØ?ÏëÏëʲôʱºò¶Ô AX ¸³ÖµµÄ?ÎÒÇåÀíÒ»ÏÂÄÚ´æ,ÕûÀí³öÏÂÃæÕâ¶Î
´úÂë:
025F:0098B1AF 668B442402 MOV AX,[ESP+02] ; EAX = һЩֵ.
025F:0098B1B4 83C404 ADD ESP,04
025F:0098B1B7 C20800 RET 0008
025F:0098B1BA 8D9B00000000 LEA EBX,[EBX+00000000]
025F:0098B1C0 33C0 XOR EAX,EAX
025F:0098B1C2 8A442408 MOV AL,[ESP+08]
025F:0098B1C6 83F801 CMP EAX,01
025F:0098B1C9 7415 JZ 0098B1E0
025F:0098B1CB 83F802 CMP EAX,02
025F:0098B1CE 7456 JZ 0098B226
025F:0098B1D0 83F803 CMP EAX,03
025F:0098B1D3 0F8497000000 JZ 0098B270
025F:0098B1D9 C20800 RET 0008
'ÊǵÄ!¾ÍÊÇÄã˵¹ýµÄÄǸöµØ·½! *SLAP*!!
ºÇºÇ,ÎÒÃÇֻҪʹEAXµÄÖµÓÀÔ¶µÈÓÚDCFD¾ÍÐÐÁË,´úÂë¾Í±ä³É:
66B8FDDC MOV AX,DCFD ; ÄãÖªµÀÕâÊǸÉʲô,¶ÔÂð? ;)
90 NOP ; Ò»¸ö NOP ¾ÍÊÇʲô¶¼²»¸É!
C20800 RET 0008 ; ²»±ä
Ok,ºÜ¼òµ¥°É? BTW µ±ÄãÐ޸ĵÄʱºò²»ÒªÍüÁË°Ñ´úÂëµ¹Ò»ÏÂ,±ÈÈç: B8FDCD ÊÇ CDFD,
ÄãÓ¦¸ÃÖªµÀÎÒÊÇʲôÒâ˼,¶ÔÂð?²»??
ÏÖÔÚ¸øÄãµÄÄ¿±ê´òÉϲ¹¶¡,ÔËÐÐÊÔÊÔ¿´!
ÏÂÃæ¾ÍÊÇ˵Èí¼þÆƽâµÄ·Ç³£³É¹¦,ÎҾͲ»·ÒëÁË.
ÔÎÄ×÷Õß:ACiD BuRN [ECLiPSE / Immortal Descendants]
-=-=-=-=-=-=-=-=-=-=-=-[EOF]-=-=-=-=-=-=-=-=-=--=ÃξµÚËÄÆÚ-=-=-=-=-=-=-=-=-=-=
|
Õý°æ¡°Ã˾ü¸ÒËÀ¶Ó¡±Ãܳ׹âÅ̼ÓÃÜÆƽâʵ¼ Write By liangs
ÉùÃ÷£º±¾ÎIJ»ÊǽÐÄãÔõôȥµÁ°æ£¬¶ø½ö½öÊÇ×÷ΪһÖÖCrack¼¼Êõ½»Á÷¡£ ʹÓù¤¾ß£ºTrw2000; W32Dasm; UltraEdit ºÃ¾ÃûдµãʲôÁË£¬Ö»ÒòΪ×î½ü¼ÒÀï¸Õ¸ÕÌíÁ˸öСBaby,æµÄÒªËÀ¡£ ¾Í°ÑÇ°²»¾Ã¸Õ¸ÕÆƽâµÄÃ˾ü¸ÒËÀ¶Ó¹âÅ̼ÓÃܵļǼÕûÀíÁËһϣ¬ ȨÇҳ䵱һƪÎÄÕ°ɡ£ ÔÚ¿´ÕâƪÎÄÕÂ֮ǰ£¬½¨Òé´ó¼ÒÏȺúÿ´¿´¿´Ñ©ÐÖÕûÀíµÄ¡°ÂÛ̳¾«»ª2¡± ÖйØÓÚCD-CHECKµÄÁ½ÆªÒëÎÄ£¬¶Ô´ó¼Ò»áÓкܴóµÄ°ïÖú£¬ÄÇÀïÃæ½éÉÜµÄ ¹âÅ̼ÓÃÜ·½Ê½ºÜÓÐͨÓÃÐÔ¡£ ÏÈÓÃ×ÊÔ´¹ÜÀíÆ÷²é¿´Ô¹âÅÌ£¬·¢ÏÖ¹âÅÌÈÝÁ¿¾ÓÈ»ÓÐ3.05GB£¡ ÆäÖйâÅ̸ùĿ¼ÏµÄBbvn.afp£¬Btbw.afp£¬Etao.afp£¬Tbtp.afp µÈËĸöÎļþ¸ö¸ö¶¼ÓÐ680MBÒÔÉÏ£¬²»ÓÃ˵¿ÉÄÜÓÖÊÇSafeDiskÖ®ÀàµÄ¹âÅÌ ¼ÓÃÜ·½Ê½¡£ ¶Ô¸¶ÉÏÊö¹âÅ̼ÓÃÜ·½Ê½£¬ÎÒÃÇͨ³£¶¼´ÓÅÌÉϵÄÄǼ¸¸ö680MBÒÔÉϵÄÎļþ ÈëÊÖ£¬ÕâÀïÊÇTbtp.afp£¬Bbvn.afp£¬Btbw.afp£¬Etao.afpµÈËĸöÎļþ¡£ Ê×ÏÈÔËÐÐComandos.exe£¬ÔÙÔËÐÐTrw2000£¬ÏÂbpx GetDriveTypeAÖ¸Á »Øµ½ÓÎÏ·ÖУ¬Ñ¡ÔñÓÎÏ·²Ëµ¥ÖÐNew GameϵÄSingle PlayerÑ¡Ïî¡£ * Reference To: KERNEL32.GetDriveTypeA, Ord:00CEh | :00494A01 8B3514266600 mov esi, dword ptr [00662614] * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:00494A8C(C) | :00494A07 8D44240C lea eax, dword ptr [esp+0C] :00494A0B 885C240C mov byte ptr [esp+0C], bl :00494A0F 50 push eax :00494A10 FFD6 call esi GetDriveTypeAÖ¸Áî·µ»ØʱÎÒÃÇÍ£ÔÚÕâ¡£ :00494A12 83F805 cmp eax, 00000005 ÕâÌõÖ¸ÁîÊDz»ÊǺÜÑÛÊì°¡£¡ :00494A15 7570 jne 00494A87 Èç¹ûû·Å¹âÅÌ£¬½«Ìø×ß¡£ * Possible StringData Ref from Data Obj ->"rb" | :00494A17 68900F5F00 push 005F0F90 :00494A1C 881D10266000 mov byte ptr [00602610], bl * Possible StringData Ref from Data Obj ->"d:\TBTP.AFP" ´ó¼Ò×¢ÒâÁË£¬¿´¼ûÉÏÃæµÄ"d:\TBTP.AFP"ûÓУ¬ÏÂÃæµÄÅжϾÍÊǹØÓÚËüµÄ¡£ | :00494A22 6810266000 push 00602610 :00494A27 881D20266000 mov byte ptr [00602620], bl :00494A2D 881D30266000 mov byte ptr [00602630], bl :00494A33 881D40266000 mov byte ptr [00602640], bl :00494A39 E8D2A81300 call 005CF310 ¼ì²é¹âÅÌÊÇ·ñÓС°TBTP.AFP¡±Õâ¸öÎļþ :00494A3E 83C408 add esp, 00000008 :00494A41 8BF8 mov edi, eax :00494A43 85FF test edi, edi :00494A45 750A jne 00494A51 Èç¹û¹âÅÌÓС°TBTP.AFP¡±Õâ¸öÎļþ£¬¾ÍÌøµ½ÏÂÒ»¸öµØÖ·¼ÌÐø¼ì²é :00494A47 C744241000000000 mov [esp+10], 00000000 :00494A4F EB2E jmp 00494A7F * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:00494A45(C) | :00494A51 6A00 push 00000000 :00494A53 6800A08329 push 2983A000 ±£´æÆ«ÒƵØÖ·¡°2983A000¡± :00494A58 57 push edi :00494A59 E8C2AD1300 call 005CF820 Ö¸ÕëÖ¸ÏòÎļþÖеÄÆ«ÒƵØÖ· :00494A5E 83C40C add esp, 0000000C :00494A61 57 push edi :00494A62 E879AD1300 call 005CF7E0 È¡Æ«ÒƵØÖ·´¦µÄÎļþÊý¾Ý :00494A67 83C404 add esp, 00000004 :00494A6A 33C9 xor ecx, ecx :00494A6C 83F829 cmp eax, 00000029 ÎļþÆ«ÒƵØÖ·¡°2983A000¡±´¦µÄÖµÊÇ·ñµÈÓÚ¡°00000029¡± :00494A6F 0F94C1 sete cl :00494A72 894C2410 mov dword ptr [esp+10], ecx :00494A76 57 push edi :00494A77 E8F4A71300 call 005CF270 :00494A7C 83C404 add esp, 00000004 * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:00494A4F(U) | :00494A7F 8B442410 mov eax, dword ptr [esp+10] :00494A83 85C0 test eax, eax :00494A85 7514 jne 00494A9B Èç¹û¼ì²éÌõ¼þÂú×㣬¾ÍÌø×ß¡£ * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:00494A15(C) | :00494A87 FEC3 inc bl :00494A89 80FB5A cmp bl, 5A :00494A8C 0F8E75FFFFFF jle 00494A07 :00494A92 33C0 xor eax, eax EAX±êÖ¾Çå0£¬±íʾûÓзŹâÅÌ :00494A94 5F pop edi :00494A95 5E pop esi :00494A96 5B pop ebx :00494A97 83C408 add esp, 00000008 :00494A9A C3 ret * Referenced by a (U)nconditional or (C)onditional Jump at Address: |:00494A85(C) | :00494A9B B801000000 mov eax, 00000001 EAX±êÖ¾ÖÃ1£¬±íʾ·ÅÈëÁ˹âÅÌ£¬²¢Í¨¹ýÁË¡°TBTP.AFP¡±ÎļþµÄ¼ì²é¡£ :00494AA0 5F pop edi :00494AA1 5E pop esi :00494AA2 5B pop ebx :00494AA3 83C408 add esp, 00000008 :00494AA6 C3 ret ------------------------------------------------------------------- ´ÓÉÏÃæµÄret·µ»Øºó£¬ÎÒÃÇÀ´µ½0044CB04´¦£¬ * Referenced by a CALL at Addresses: |:00447E9C , :00448015 | :0044CAF0 83EC0C sub esp, 0000000C :0044CAF3 A1980A5F00 mov eax, dword ptr [005F0A98] :0044CAF8 85C0 test eax, eax :0044CAFA 90 nop :0044CAFB 53 push ebx :0044CAFC 56 push esi :0044CAFD 7413 je 0044CB12 :0044CAFF E8EC7E0400 call 004949F0 Õâ¾ÍÊÇÉÏÃæµÄ¹âÅ̼°¡°TBTP.AFP¡±Îļþ¼ì²éÅÐ¶Ï :0044CB04 85C0 test eax, eax :0044CB06 740A je 0044CB12 Ìø¾ÍÍêµ°ÁË£¡ :0044CB08 C705980A5F0000000000 mov dword ptr [005F0A98], 00000000 * Referenced by a (U)nconditional or (C)onditional Jump at Addresses: |:0044CAFD(C), :0044CB06(C) ÏÂÃæÊǹâÅÌÉÏÄǼ¸¸ö*.AFPÎļþµÄÅбð£¬ÓëÉÏÃæ¡°TBTP.AFP¡±ÎļþµÄ ·ÖÎöÒ»Ñù¡£ ......²¿·ÖÏàͬ´úÂëÂÔ * Possible StringData Ref from Data Obj ->"rb" | :0044CB59 68900F5F00 push 005F0F90 * Possible StringData Ref from Data Obj ->"d:\BBVN.AFP" ¶Ô¡°BBVN.AFP¡±ÎļþµÄ¼ì²é | :0044CB5E 6820266000 push 00602620 :0044CB63 E8A8271800 call 005CF310 :0044CB68 83C408 add esp, 00000008 :0044CB6B 8BF0 mov esi, eax :0044CB6D 85F6 test esi, esi :0044CB6F 750A jne 0044CB7B :0044CB71 C744241000000000 mov [esp+10], 00000000 :0044CB79 EB2E jmp 0044CBA9 ......²¿·ÖÏàͬ´úÂëÂÔ °´F12·µ»Ø¸üÉÏÒ»¼¶Call,À´µ½ÈçϵØÖ·£º :00448015 E8D64A0000 call 0044CAF0 ÉÏÃæËùÓеÄÅж϶¼ÔÚÕâ¸öCallÀïÃæ :0044801A 85C0 test eax, eax :0044801C 7418 je 00448036 ÎÒÃǵÄÄ¿µÄ¾ÍÊÇҪʹ£¬eax=1£¬Ê¹je 00448036²»Ìøת£¬ Òò´Ë£¬Ö»Òª½«0044801C´¦µÄje 00448036¸ÄΪNOP¾Í¿ÉÒÔÁË¡£ ÖØÐÂÔËÐÐÓÎÏ·£¬New GameϵÄSingle PlayerÑ¡ÏîÒѾ¿ÉÒÔÍæÁË£¬ ²»ÔÙÐèÒª¹âÅÌ¡£²»ÒªÒÔΪÕâÑù¾ÍÒѾÆƽâÍêÁË£¬Èç¹ûÄãÔÙÊÔÊÔLoad Game£¬ ¾Í»á·¢ÏÖ»¹ÒªÌáʾ²åÈë¹âÅÌ£¬ËµÃ÷»¹Ã»Æƽâ¸É¾»¡£ ÔÚ°´ÏÂLoad Game²Ëµ¥Ç°ÔÙÏÂbpx GetDriveTypeAÖ¸Áî ÖжϺó£¬ÎÒÃÇ»¹ÊÇ»á»Øµ½ÉÏÃæµÄ00494A12´¦£¬ °´F12·µ»ØÉÏÒ»¼¶µ÷Óã¬À´µ½0044CB06´¦ ÔÙ°´F12·µ»Ø¸üÉÏÒ»¼¶µ÷Óã¬À´µ½00447EA3´¦ Ö»ÒªÔÙ½«00447EA3µÄÌøת¶¼¸Ä³ÉNOP¾Í¿ÉÒÔÁË£¬ÖÁ´Ë£¬¡°Ã˾ü¸ÒËÀ¶Ó¡± Ãܳ׹âÅ̼ÓÃܾÍÍêÈ«ÆƽâÍêÁË¡£
|