EBPIG
̽Ë÷ÔÓÖ¾
MHJDQ
֪ʶ¹²Ïí ×ÊÔ´¹²Ïí ×ÊÁϹ²Ïí
¡¾ÖÆ×÷³ÉÔ±¡¿³ÌʽÁÔÈË
¡¾·¢ÐÐʱ¼ä¡¿2000-9-9
¡¾ÆÚ¿¯ºÅÂë¡¿µÚʮһÆÚ
¡¾ÍøÕ¾µØÖ·¡¿http://programhunter.home.china.com

¡¾±à¼­¼ÄÓï¡¿

    
    {~._.~} 
     ( Y )  
    ()~*~() 
    (_)-(_) 
ÿÕâÆÚÔÓÖ¾Ïò´ó¼Ò½éÉÜÒ»¸öÓÉ°ßÖñ±¾ÈËÆƽâµÄÒ»¸öÈí¼þ¡£Õâ¸öÈí¼þµÄÆƽ⻹ÊÇ·ÑÁ˲»ÉÙʱ¼ä £¬ËüµÄÄѶȿÉÒÔ¶¨ÔÚÄѼ¶°É¡£ÎÒÏë¶ÔÓÚÆƽâµÄÑо¿»áÓÐÒ»¶¨µÄ°ïÖú¡£ÔÚ½ñÌìµÄ³õѧÌìµØÀ¸Ä¿ÖÐÏò³õѧÕß¼ÌÐø½éÉÜÆƽⷽ·¨¼°»ã±à×éºÏÓï¾ä¡£ÔÚÍøÕ¾½éÉÜÖнñÌìÒªÏò¸÷λ½éÉܵÄÊÇÍѹìÆƽâÍøÕ¾¡£
¡¾Ä¿ ÿÿ ¼¡¿
ÿÿÿÿ&ÆƽâÐĵÃ
1¡­¡­AdBin V1.2 ³ÌʽÁÔÈË
ÿÿÿÿ%³õѧÌìµØ
ÿÿÿÿOÎÊÌâ´ðÒÉ
ÿÿÿÿ4ÍøÕ¾½éÉÜ
ÿÿÿÿ,ÔÓÖ¾ÐÅÏä
&¡¾ÆƽâÐĵá¿
                           AdBin V1.2
                                    ³ÌʽÁÔÈË
¼ò½é£ºÕâ¸öÊÇÒ»¸öÉÏÍø¼ÓËÙµÄÈí¼þ£¬Ëü¿ÉÒÔ½«Äã·ÃÎʵÄÍøվʱ£¬¿ÉÒÔ½«¹ã¸æ½øÐÐÆÁÕϵô£¬Ëù
ÒÔÕâÑù¾Í¿ÉÒÔÔö¼ÓµÄÉÏÍøËٶȡ£
×·×Ù£ºRN£º01234567
   ¶ÔÓÚ×·×ÙÕâ¸öÈí¼þ£¬¿ÉÊÇ»¨ÁËÎÒ¼¸ÌìµÄʱ¼ä²Å½«Ëü×·×Ù³öÀ´¡£ÔÚÇ°¼¸Ì죬ûÓн«Ëü×·×Ù
³öÀ´£¬ÒòΪÕâ¸öÈí¼þÔÚÆƽâ¹ý³ÌÖеÄÈ·ÓÐÒ»¶¨µÄÄѶȣ¬ËùÒÔÄǼ¸ÌìûÓн«Ëü×·×Ù³öÀ´¡£
µ«ÊÇ×òÌìÎÒÓÖ½«ËüÄóöÀ´½øÐÐÆƽ⣬ÒòΪÎÒ×òÌìÓÐÒ»ÖÖ²»ËÀ²»¹éµÄ¸Ð¾õ¡£ÖÕÓÚ½«Õâ¸öÈí¼þ¸ø
Æƽâ³öÀ´ÁË£¬ÄÇôÏÖÔÚÔÙÏëһϣ¬Õâ¸öÈí¼þÈç¹ûÒª¶¨Î»µÄ»°£¬ËüÓ¦µ±ÊôÓÚÖÐÉÏˮƽ¡£ÏÖÔÚ¾Í
À´Ïò´ó¼Ò½éÉÜÈçºÎÔÚÇ°¼¸ÌìûÓн«Ëü×·×Ù³öÀ´µÄÇé¿ö¡£

:00402676 E8D6080000              call 00402F51
:0040267B A180564100              mov eax, dword ptr [00415680]
:00402680 53                      push ebx
* Possible StringData Ref from Code Obj ->"VWhxVA"
                                  |
:00402681 6852734000              push 00407352
:00402686 57                      push edi
* Possible Reference to Dialog: DialogID_006C 
                                  |
:00402687 6A6C                    push 0000006C
:00402689 50                      push eax
:0040268A E883F1FFFF              call 00401812
:0040268F 83F801                  cmp eax, 00000001
:00402692 0F85A8000000            jne 00402740
:00402698 8D45A4                  lea eax, dword ptr [ebp-5C]
:0040269B 50                      push eax
:0040269C E8DF870000              call 0040AE80
:004026A1 83F80A                  cmp eax, 0000000A   ****
:004026A4 59                      pop ecx
:004026A5 7225                    jb 004026CC
:004026A7 8D45A4                  lea eax, dword ptr [ebp-5C]
:004026AA 50                      push eax
:004026AB E8D0870000              call 0040AE80
:004026B0 83F814                  cmp eax, 00000014   ***
:004026B3 59                      pop ecx
:004026B4 7716                    ja 004026CC
:004026B6 8D45A4                  lea eax, dword ptr [ebp-5C]
:004026B9 50                      push eax
* Reference To: ABKernel.SetLic, Ord:001Dh
                                  |
:004026BA FF1500104100            Call dword ptr [00411000]
:004026C0 6A01                    push 00000001
* Reference To: ABKernel.SetEnabled, Ord:001Ch
                                  |
:004026C2 FF151C104100            Call dword ptr [0041101C]
:004026C8 59                      pop ecx
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:004025D4(U)
|
:004026C9 59                      pop ecx
:004026CA EB74                    jmp 00402740
* Referenced by a (U)nconditional or (C)onditional Jump at Addresses:
|:004026A5(C), :004026B4(C)
|
:004026CC 53                      push ebx
* Possible StringData Ref from Data Obj ->"Adbin"
                                  |
:004026CD 6890414100              push 00414190
* Possible StringData Ref from Data Obj ->"The licence code you entered has "
                                        ->"been generated illegally."
                                  |
:004026D2 6870424100              push 00414270
:004026D7 FFD6                    call esi
  ÏÖÔÚÎÒÃǵ±È»ÊÇÊ×ÏÈ°´Õý³£µÄÆƽâ¹ý³ÌÀ´ÆƽâËü£¬Õâ¸öÈí¼þÔÚÎÒ¸Õ¸ÕÆƽâʱ¾Í·¢ÏÖÁËËüÊÇ
Ò»¸ö±È½ÏÌØÊâµÄ×¢²á¹ý³Ì¡£ÔÚÉÏÃæ¾ÍÊÇÕâ¸öÈí¼þµÄÊäÈë×¢²áÂëºóËù½øÐеŤ×÷¡£ÔÚÕâÀïÎÒÃÇ
½«Äܵõ½Ê²Ã´ÄØ£¿Èç¹û°´ÕÕÕý³£µÄ×¢²á±È½Ï¹ý³ÌµÄ»°£¬ËüÔÚÉÏÃæÓ¦µ±ÓбȽϵĵط½£¬µ«ÊÇÔÚ
ÕâÀïÎÒÃǽ«ÎÞ·¨µÃµ½±È½ÏµÄµØ·½£¬½öÄܵõ½µÄÊDZȽÏÄãËùÊäÈë×¢²áÂëµÄλÊýÖµ£¬ÔÚÕâÀïÎÒÃÇ
¿ÉÒÔÇáËɵĵõ½Õâ¸öÈí¼þËùÒªÇóµÄλÊý£¬ÊäÈëµÄ×¢²áÂëÒ»¶¨ÒªÂú×ãA(H)<=RN<=14(H)£¬Èç¹û
ÄãûÓÐÂú×ãÉÏÃæµÄÒªÇ󣬳ÌÐò»áÌáʾÄãÊäÈëµÄ×¢²áÂë²»ÕýÈ·¡£ÎÒÏÖÔÚÊäÈëµÄRN£º0123456789
ºó£¬³ÌÐòûÓгöÏÖÌáʾÁË¡£µ«ÊÇÎÒ×·×Ùºó·¢ÏÖÔÚÕâÀïËüÒ²½ö½öÊDZȽÏλÊý£¬Ã»ÓнøÐÐ×¢²áÂë
µÄ±È½Ï¡£ÄÇôÕâ¸öÈí¼þ¾Í³ÉÁËÔÚ¿ªÊ¼Ê±±È½Ï×¢²áÂ뷽ʽµÄ×¢²á·½·¨ÁË¡£ÕâÖÖÈí¼þµÄÆƽâ¹Ø¼ü
´óÓÚÕÒµ½Èí¼þÔÚÄÇÀï½øÐбȽϵĵط½¡£ÓÚÊǾÍʹÓÃW32DASM½øÐз´»ã±à£¬ÏëÒªÕÒµ½¹Ø¼üµÄ±È
½ÏµØ·½£¬Èç¹ûÒªÈÃÎÒÕâôÇáËɾÍÕÒµ½ÁË£¬ÄÇôÕâ¸öÈí¼þµÄÄѶÈÒ²¾ÍÎÞ·¨³ÆΪÖÐÉÏˮƽÁË¡£
  ÔÚWÖз¢ÏÖÁË
* Possible StringData Ref from Data Obj ->"Software\Paw-Print\Adbin"
  ³ÌÐòʹÓÃ×¢²á±íÑ¡Ï²éÕÒÏàÓ¦µÄÑ¡Ï·¢ÏÖÁËÏÂÃæ±È½ÏÃô¸ÐµÄÑ¡Ïî¡£
RegistrationEval:VZYmhL4l39KA
RegistrationKey:0123456789
  ÒÔÎÒ¸öÈ˵ľ­ÑéÀ´Ëµ£¬Ö»Òª·¢ÏÖÕâ¸ö¹Ø¼üµÄµØ·½¾Í¿ÉÒԳɹ¦Ò»°ëÁË¡£ÕâÑùµÄÈí¼þͨ³£ÔÚ³Ì
ÐòÖÐʹÓÃÏàÓ¦µÄ×¢²á¼üÖµÀ´½øÐÐÔËËã¡£ÎÒÓÚÊǾÍÔÚWÖжÔRegistrationKey½øÐвéÕÒ£¬´ó¼ÒÒ»
¶¨»áÏëµ½ÁËÕâ¸ö½á¹û¾ÍÊÇûÓвéÕÒµ½¡£ÄÇôÎÒûÓвéÕÒµ½Õâ¸ö¼üÖµ£¬ÎÒ¿ÉÒÔ²éÕÒµ½ÄãʹÓöÁ
È¡Õâ¸ö¼üµÄº¯Êý£¬ÎÒ²éÕÒ¶Áȡע²á±íµÄº¯Êý,µ«ÊÇËüûÓÐʲôÓô¦£¬ËüÒ²ÎÞ·¨½«Òýµ¼ÎÒÏò³É
¹¦µÄ±Ë°¶£¬Ã»Óа취ÁË¡£ÒÔÉϾÍÊÇÎÒÇ°¼¸ÌìûÓн«Õâ¸öÈí¼þÆƽâ³öÀ´µÄ¹ý³Ì¡£×òÌìÎÒÏëÔÙ³¢
ÊÔÒ»ÏÂÆƽâÕâ¸öÈí¼þ£¬Õâ»ØÎҵõ½Ê¹ÓÃÇ°¼¸ÌìûÓÐÓùý·½·¨¶ÔËü½øÐÐÆƽ⡣
  ÏÖÔÚÎÒÃÇÔÙ˵һЩÆƽⷽÃæµÄÊÂÇ飬¶ÔÓÚÄÇÖÖʹÓÃÏÈÊäÈë×¢²áÂ룬ÔÙÖØÐÂÆô¶¯ºó½øÐбȽÏ
µÄ×¢²á¹ý³Ì£¬¶ÔÓÚÎÒÃÇÕâЩÆƽâÕßÀ´Ëµ£¬ÆƽâËüÃDZÈÆƽâÄÇÖÖÖ±½Ó½øÐÐ×¢²áÂë±È½ÏµÄÈí¼þÔö
¼ÓÁËÒ»¶¨µÄÄѶȣ¬Í¨³£¾ÍÊÇÕâµãÄѶÈʹÓÃÄÇЩ³õѧÕß»òÕßÊÇÕÆÎÕÁËÒ»¶¨µÄÆƽⷽ·¨ºÍ¼¼ÒÕµÄ
ÈËÒ²²»ºÃÆƽ⡣¶ÔÓÚÕâÖÖÈí¼þµÄÆƽâ¹Ø¼ü¾ÍÊÇÕÒµ½³ÌÐòÔÚÆô¶¯Ê±£¬ÔÚÄǸöº¯ÊýÖжÔÎÒÃÇÊäÈë
µÄ×¢²áÂë½øÐбȽϵġ£ÎÒÃÇÆƽâÕßÃæ¶ÔÊǼ¸Ç§¸öÉõÖÁÊǼ¸Íò¸öº¯Êý£¬ÎÒÃǽ«ÈçºÎÕÒµ½ËüµÄ±È
½ÏµØ·½ÄØ¡£¶ÔÓÚ²»Í¬µÄÈí¼þÓ¦µ±ÓÐ×Ų»Í¬µÄÆƽⷽ·¨£¬µ«ÊÇËüÓÐ׿¸¸öÏàËƵÄÆƽⷽ·¨¡£ÄÇ
ôÎÒÔÚÕâÀïʹÓõľÍÊǹýÆÚµÄÆƽⷽ·¨¡£
  ´ó¼ÒÏÖÔÚÏòÉÏ¿´£¬ÄãÃǻᷢÏÖÔÚ×¢²á±íÖв»½öÓÐRegistrationKeyÕâ¸ö¼üÖµ£¬¶øÇÒ»¹ÓÐReg
istrationEvalÕâ¸ö¼üÖµ£¬ÄÇôËüÓÐʲôÓô¦ÄØ¡£ÎÒ²»ÊÇÉè¼ÆÕߣ¬ËùÒÔÎÒÒ²²»ÖªµÀ£¬µ«ÊÇÆÆ
½â¾­Ñé¸æËßÎÒ£¬Õâ¸ö¼üÖµÒ»¶¨Óë×¢²áÓйأ¬¾ßÌåʲô¹ØϵÎÒÒ²Ö»ÓÐÊÔÒ»ÊÔ²ÅÖªµÀ¡£ÓÚÊÇÎÒ½«
Õâ¸ö¼üÖµÖеÄVZYmhL4l39KAÉèΪ¿Õ£¬ÔÙÖØÐÂÆô¶¯Èí¼þ£¬ÏÖÔÚÈí¼þ¸æËßÄãËüÒѾ­¹ýÆÚÁË¡£ÄÇô
Õâ¾Í˵Ã÷ËüµÄֵͬע²á¿Ï¶¨ÓйØϵ£¬ÎÒÓÖ½«Ëücopy»Ø×¢²á±íÖУ¬ÖØÐÂÆô¶¯Èí¼þ£¬ËüûÓгöÏÖ
Ìáʾ¹ýÆÚ¡£ÏÖÔÚÎҾͽ«Õâ¸ö×÷ΪÎÒÏòËü·¢Æð¹¥»÷µÄÍ»ÆƵ㡣
  ÏÖÔÚµ÷³ötrw£¬ÓÃËü¶ÔÕâ¸öÈí¼þ½øÐÐ×·×Ù¡£
:0040B4A6 FF1504124100            Call dword ptr [00411204]
:0040B4AC 50                      push eax
:0040B4AD E8FF7AFFFF              call 00402FB1   <-³ö´í£¬½øÈë
:0040B4B2 8945A0                  mov dword ptr [ebp-60], eax
:0040B4B5 50                      push eax
  ÔÚÖ¸³öµÄµØ·½³ö´í£¬Í¨³£ÎÒÃÇʹÓÃÕâÖÖ·½·¨½øÐÐ×·×ٵĹؼüÊÇÕÒµ½Äܲ»ÄÜÌø¹ý´ËcallµÄµØ
·½£¬ÏòÉÏ¿´Ã»Óз¢ÏÖ£¬ÓÚÊǾͽøÈëcallÖС£ÏÂͬ£º
:00403035 8BCB                    mov ecx, ebx
:00403037 E8A0180000              call 004048DC     <-³ö´í£¬½øÈë
:0040303C A10C584100              mov eax, dword ptr [0041580C]
:00404921 8BCF                    mov ecx, edi
:00404923 E84BC9FFFF              call 00401273    <-³ö´í£¬½øÈë
:004012C9 8D8D4CFFFFFF            lea ecx, dword ptr [ebp+FFFFFF4C]
:004012CF E824010000              call 004013F8    <-³ö´í£¬½øÈë

:0040152B FFD7                    call edi
* Reference To: ABKernel.GetStat, Ord:0015h
:0040152D FF1514104100            Call dword ptr [00411014]   <-³ö´í£¬½øÈë
:00401533 83F801                  cmp eax, 00000001
:00401536 7405                    je 0040153D
  ÎÒÀ´µ½ÕâÀï¾Í³öÏÖµØÖ·µÄ±ä»¯£¬ÒòΪÔÚͨ³£ÎÒÃǵĵØÖ·ÊÇ004?????£¬¶øÏÖÔÚ½øÈëµ½00C???
??£¬Õâ¸öµØÖ·ÖС£ÎÒÒ²ÊÇÏÖÔÚ²ÅÃ÷°×£¬Õâʱ½øÈëÁ˳ÌÐòÖе÷ÓõÄdll³ÌÐòÁË¡£ÄÇôËü½øÈëÄÇ
¸ödllÖУ¬ÉÏÃæ¾ÍÓд𰸣¬
* Reference To: ABKernel.GetStat, Ord:0015h
 Õâ¸ö¾ÍÊǹؼü£¬ËüÒ»¶¨½øÈëABKernel.dllÖУ¬ÒòΪÔÚWÖпÉÒÔ·¢ÏÖ³ÌÐòÓÐÕâÑùÒ»¸ödllÎļþ
¡£ÒòΪÎÒʹÓÃNuÀ´×·×Ù£¬ËùÒÔµ±Ê±²»ÖªµÀËü½øÈëÁËÄǸödll£¬ÎÒÖ»ÖªµÀÕÒµ½±È½ÏµÄµØ·½£¬£¬E
xported fn(): GetStat - Ord:0016h
:10003088 E851E0FFFF              call 100010DE  <-³ö´í£¬½øÈë
:1000308D A158160110              mov eax, dword ptr [10011658]
:10003092 C3                      ret
 ½øÈëcallÖÐÈçÏ£º
:100010DE E85E1E0000              call 10002F41
:100010E3 85C0                    test eax, eax
:100010E5 740E                    je 100010F5
:100010E7 83251416011000          and dword ptr [10011614], 00000000
:100010EE 83253416011000          and dword ptr [10011634], 00000000
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:100010E5(C)
|
:100010F5 E900000000              jmp 100010FA
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:100010F5(U)
|
:100010FA 833D3416011000          cmp dword ptr [10011634], 00000000
:10001101 750A                    jne 1000110D
:10001103 B920160110              mov ecx, 10011620  
:10001108 E8E3410000              call 100052F0  <-³ö´í£¬½øÈë
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10001101(C)
|
:1000110D 833D1416011000          cmp dword ptr [10011614], 00000000
:10001114 750A                    jne 10001120
:10001116 B900160110              mov ecx, 10011600
:1000111B E8D0410000              call 100052F0      <-³ö´í£¬½øÈë
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10001114(C)
|
:10001120 833D3416011000          cmp dword ptr [10011634], 00000000
:10001127 740D                    je 10001136
:10001129 833D1416011000          cmp dword ptr [10011614], 00000000
:10001130 7404                    je 10001136
:10001132 33C0                    xor eax, eax
:10001134 EB03                    jmp 10001139
* Referenced by a (U)nconditional or (C)onditional Jump at Addresses:
|:10001127(C), :10001130(C)
|
:10001136 6A01                    push 00000001
:10001138 58                      pop eax
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10001134(U)
|
:10001139 50                      push eax
:1000113A E89B1F0000              call 100030DA
:1000113F 59                      pop ecx
:10001140 C3                      ret
  µ±ÎÒ×·×Ùµ½ÉÏÃæʱ£¬ÎÒÖÕÓÚ¶Ô×Ô¼ºËµ£¬Õâ¸öÈí¼þ¿ÉÄÜÒªÆƽâ³É¹¦ÁË¡£ÒòΪÏÖÔÚÎÒÒѾ­Äܹ»
¿´µ½Ê¤ÀûµÄÊï¹âÁË¡£ÉÏÃæÓÐpush 01;pop eaxÕâÁ½¸öÃüÁËùÒÔËüÓпÉÄܱíʾע²á³É¹¦¡£ÏÖ
ÔڵŤ×÷»¹ÊǽøÈëcallÖÐ
:100052F0 B8D6D50010              mov eax, 1000D5D6
:100052F5 E8EA150000              call 100068E4
:100052FA 81EC10080000            sub esp, 00000810
:10005300 56                      push esi
:10005301 8BF1                    mov esi, ecx
:10005303 57                      push edi
:10005304 8975E8                  mov dword ptr [ebp-18], esi
:10005307 833E00                  cmp dword ptr [esi], 00000000
:1000530A 0F8561020000            jne 10005571
:10005310 6A01                    push 00000001
:10005312 5F                      pop edi
:10005313 6A00                    push 00000000
:10005315 893E                    mov dword ptr [esi], edi
:10005317 E8B0FCFFFF              call 10004FCC   <-³ö´í£¬½øÈë
:1000531C 85C0                    test eax, eax
:1000531E 59                      pop ecx
:1000531F 0F844C020000            je 10005571
:10005325 53                      push ebx
  ÉÏÃæÓÐÒ»¸ö±È½ÏµÄµØ·½£¬Ò²ÊÇÕâ¸öÈí¼þ³ö´íµÄµØ·½£¬¹Ê½øÈëcallÖС£
:1000516C 8D45C0                  lea eax, dword ptr [ebp-40]  <-0123456789
:1000516F 50                      push eax
:10005170 E83B100000              call 100061B0
:10005175 83F80A                  cmp eax, 0000000A
:10005178 59                      pop ecx
:10005179 7213                    jb 1000518E
:1000517B 8D45C0                  lea eax, dword ptr [ebp-40]
:1000517E 50                      push eax
:1000517F E82C100000              call 100061B0
:10005184 83F814                  cmp eax, 00000014   ***
:10005187 59                      pop ecx
:10005188 0F86AC000000            jbe 1000523A
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10005179(C)
|
:1000518E 6A00                    push 00000000
* Possible StringData Ref from Data Obj ->"Adbin Licence"
                                  |
:10005190 6830070110              push 10010730
* Possible StringData Ref from Data Obj ->"This version of Adbin from Paw-Print "
                                        ->"Software has been tampered with."
                                  |
:10005195 6888060110              push 10010688
* Reference To: USER32.GetActiveWindow, Ord:00DDh
                                  |
:1000519A FF1584E10010            Call dword ptr [1000E184]
:100051A0 50                      push eax
* Reference To: USER32.MessageBoxA, Ord:01BEh
                                  |
:100051A1 FF1580E10010            Call dword ptr [1000E180]
:100051A7 C7055816011004000000    mov dword ptr [10011658], 00000004
:100051B1 EB3D                    jmp 100051F0
  µ±ÎÒÀ´ÕâÀïÎÒÖÕÓÚ¶Ô×Ô¼ºËµ£¬³É¹¦Ò»°ëÁË£¬ÎªÊ²Ã´£¿ÄãÃÇ¿´µ½Ã»ÓÐÔÚÕâÀïÎÒÃÇÒѾ­¿ÉÒÔ¿´
µ½ÎÒÊäÈëµÄ×¢²áÂëÁË£¬Ëü¿ªÊ¼¼ì²é×¢²áÂëµÄλÊýÁË¡£Í¬ÎÒÃÇÔÚÊäÈë×¢²áÂëʱµÄÒ»Ñù£¬Õâ¾Í˵
Ã÷ÎÒÒѾ­Àë±È½ÏµÄµØ·½²»Ô¶ÁË¡£ÏòÏÂÎÒ¾ÍÓ¦µ±¿ÉÒÔ·¢ÏֱȽϵĵط½¡£
:1000523A 6A01                    push 00000001
:1000523C 8D45C0                  lea eax, dword ptr [ebp-40]
:1000523F 5F                      pop edi
:10005240 57                      push edi
:10005241 50                      push eax    <-RN£º0123456789
:10005242 E8A9FCFFFF              call 10004EF0
:10005247 59                      pop ecx
:10005248 59                      pop ecx
:10005249 33C9                    xor ecx, ecx
:1000524B 3D85050000              cmp eax, 00000585    ***
:10005250 0F9DC1                  setnl cl
:10005253 41                      inc ecx
:10005254 8BC1                    mov eax, ecx
:10005256 3BC7                    cmp eax, edi
:10005258 A358160110              mov dword ptr [10011658], eax
:1000525D 0F8586000000            jne 100052E9
:10005263 6A03                    push 00000003
  µ½´ïÕâÀïÎÒ¾ÍÖªµÀÒѾ­µ½´ïÕâ¸öÈí¼þµÄ±È½ÏºËÐÄÁË¡£ÒòΪÕâÀïÓÐËùÓÐÎÒÏëµÃµ½µÄ¶«Î÷£¬Ò»
ÊÇRN£¬¶þÊDZȽÏÃüÁî¡£ÏÖÔÚµÄÈÎÎñ¾ÍÊÇÕÒµ½Êµ¼Ê×¢²áÂëÁË£¬½øÈëcallÖУº
:10004EF0 55                      push ebp
:10004EF1 8BEC                    mov ebp, esp
:10004EF3 83EC28                  sub esp, 00000028
:10004EF6 834DF8FF                or dword ptr [ebp-08], FFFFFFFF
:10004EFA 53                      push ebx
:10004EFB 56                      push esi
:10004EFC 57                      push edi
:10004EFD 8B7D08                  mov edi, dword ptr [ebp+08]
:10004F00 33DB                    xor ebx, ebx
:10004F02 895DFC                  mov dword ptr [ebp-04], ebx
:10004F05 8A07                    mov al, byte ptr [edi]
:10004F07 84C0                    test al, al
:10004F09 747A                    je 10004F85
* Possible StringData Ref from Data Obj ->"n61O0rRxdkVHt5ZwqYUzoNDmCybcghfaMLj4liT8pQ3J2I"
                                        ->"vWP9euS7BKFGEAXs"
                                  |
:10004F0B BEB0040110              mov esi, 100104B0
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10004F83(C)
|
:10004F10 0FBEC0                  movsx eax, al
:10004F13 50                      push eax
:10004F14 56                      push esi
:10004F15 E856130000              call 10006270
:10004F1A 59                      pop ecx
:10004F1B 85C0                    test eax, eax
:10004F1D 59                      pop ecx
:10004F1E 0F8490000000            je 10004FB4
:10004F24 2BC3                    sub eax, ebx
:10004F26 2BC6                    sub eax, esi
:10004F28 48                      dec eax
:10004F29 8BC8                    mov ecx, eax
:10004F2B 7903                    jns 10004F30
:10004F2D 83C13E                  add ecx, 0000003E
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10004F2B(C)
|
:10004F30 8D5C0B01                lea ebx, dword ptr [ebx+ecx+01]
:10004F34 83FB3E                  cmp ebx, 0000003E
:10004F37 7C0A                    jl 10004F43
:10004F39 8BC3                    mov eax, ebx
:10004F3B 6A3E                    push 0000003E
:10004F3D 99                      cdq
:10004F3E 5B                      pop ebx
:10004F3F F7FB                    idiv ebx
:10004F41 8BDA                    mov ebx, edx
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10004F37(C)
|
:10004F43 837DF8FF                cmp dword ptr [ebp-08], FFFFFFFF
:10004F47 7505                    jne 10004F4E
:10004F49 894DF8                  mov dword ptr [ebp-08], ecx
:10004F4C EB10                    jmp 10004F5E
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10004F47(C)
|
:10004F4E 83F907                  cmp ecx, 00000007
:10004F51 7F61                    jg 10004FB4
:10004F53 8B45FC                  mov eax, dword ptr [ebp-04]
:10004F56 6BC007                  imul eax, 00000007
:10004F59 03C1                    add eax, ecx
:10004F5B 8945FC                  mov dword ptr [ebp-04], eax
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10004F4C(U)
|
:10004F5E 47                      inc edi
:10004F5F 837D0C00                cmp dword ptr [ebp+0C], 00000000
:10004F63 741A                    je 10004F7F
:10004F65 0FBE07                  movsx eax, byte ptr [edi]
:10004F68 50                      push eax
:10004F69 56                      push esi
:10004F6A 47                      inc edi
:10004F6B E800130000              call 10006270
:10004F70 59                      pop ecx
:10004F71 2BC6                    sub eax, esi
:10004F73 59                      pop ecx
:10004F74 6A02                    push 00000002
:10004F76 99                      cdq
:10004F77 59                      pop ecx
:10004F78 F7F9                    idiv ecx
:10004F7A 85D2                    test edx, edx
:10004F7C 7401                    je 10004F7F
:10004F7E 47                      inc edi
* Referenced by a (U)nconditional or (C)onditional Jump at Addresses:
|:10004F63(C), :10004F7C(C)
|
:10004F7F 8A07                    mov al, byte ptr [edi]
:10004F81 84C0                    test al, al
:10004F83 758B                    jne 10004F10
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10004F09(C)
|
:10004F85 FF75FC                  push [ebp-04]
:10004F88 8D45D8                  lea eax, dword ptr [ebp-28]
* Possible StringData Ref from Data Obj ->"%d"
                                  |
:10004F8B 68F4040110              push 100104F4
:10004F90 50                      push eax
* Reference To: USER32.wsprintfA, Ord:02ACh
                                  |
:10004F91 FF1570E10010            Call dword ptr [1000E170]
:10004F97 8D45D8                  lea eax, dword ptr [ebp-28]
:10004F9A 50                      push eax
:10004F9B E810120000              call 100061B0
:10004FA0 83C410                  add esp, 00000010
:10004FA3 83F809                  cmp eax, 00000009
:10004FA6 7310                    jnb 10004FB8
:10004FA8 8D45D8                  lea eax, dword ptr [ebp-28]
:10004FAB 50                      push eax
:10004FAC E8FF110000              call 100061B0
:10004FB1 59                      pop ecx
:10004FB2 EB07                    jmp 10004FBB
* Referenced by a (U)nconditional or (C)onditional Jump at Addresses:
|:10004F1E(C), :10004F51(C)
|
:10004FB4 33C0                    xor eax, eax
:10004FB6 EB0F                    jmp 10004FC7
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10004FA6(C)
|
:10004FB8 6A09                    push 00000009
:10004FBA 58                      pop eax
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10004FB2(U)
|
:10004FBB 2B45F8                  sub eax, dword ptr [ebp-08]
:10004FBE F7D8                    neg eax
:10004FC0 1BC0                    sbb eax, eax
:10004FC2 F7D0                    not eax
:10004FC4 2345FC                  and eax, dword ptr [ebp-04]
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10004FB6(U)
|
:10004FC7 5F                      pop edi
:10004FC8 5E                      pop esi
:10004FC9 5B                      pop ebx
:10004FCA C9                      leave
:10004FCB C3                      ret
  ÉÏÃæ¾ÍÊÇÕâ¸öÈí¼þÍêÕûµÄ×¢²áÂë±È½ÏµØ·½£¬ËüÔÚÕâÀï²»ÊÇͨ¹ýʹÓÃ×¢²áÂëÖ®¼äÏ໥±È½ÏµÄ
£¬¶øÊÇͨ¹ýÄãÊäÈëµÄ×¢²áÂë¾­¹ýÔËËãµÃµ½ÏàÓ¦µÄÖµ£¬ÔÙÔÚÇ°ÃæµÄ±È½ÏµØ·½½øÐбȽϣ¬ÄÇôÕâ
¸ö³ÌÐòÊÇÈçºÎÔËËãµÄÄØ£¿
  Õâ¸öÈí¼þµÄÈ·²»ÊǼòµ¥µÄÈí¼þ£¨µ±È»ÕâÀïרָÆƽâËü£©¡£ÏÖÔÚÎÒ¾ÍÏò´ó¼Ò½éÉÜÈçºÎÆƽâ³ö
Õâ¸öÈí¼þµÄ×¢²áÂë¡£
 ÉÏÃæ¾ÍÊÇÕâ¸öÈí¼þÍêÕûµÄ×¢²á¹ý³Ì£¬ÎÒÃÇÈç¹ûÏëÒªÆƽâËü£¬Ê×ÏÈÓ¦µ±ÖªµÀÕâ¸öº¯ÊýÔÚ·µ»Ø
ʱӦµ±·µ»ØʲôÑùµÄÖµ²ÅÄÜÂú×ãÎÒÃǵÄÒªÇó¡£ÏÖÔÚ¾ÍÓ¦µ±Ê×ÏÈÀ´¿´Ò»Ïµ÷ÓÃÕâ¸öº¯ÊýµÄÖ÷³Ì
Ðò¡£
:10005242 E8A9FCFFFF              call 10004EF0
:10005247 59                      pop ecx
:10005248 59                      pop ecx
:10005249 33C9                    xor ecx, ecx
:1000524B 3D85050000              cmp eax, 00000585    ***
:10005250 0F9DC1                  setnl cl
 ÔÚÕâÀïÎÒÖªµÀÈç¹û°´Õý³£µÄ»°£¬ÄǸö±È½ÏµÄµØ·½ÉÏeax=0£¬cl=0Ö»Óе±eaxµÄÖµ´óÓÚ585ʱ£¬
clµÄÖµ²ÅÄܱäΪ1£¬ÏÖÔÚÖªµÀÁËÏëÒªµÃµ½µÄÖµ£¬¾ÍÓ¦µ±»Øµ½ÉÏÃæµÄ¼ÆË㺯ÊýÖÐÁË¡£
:10004FBB 2B45F8                  sub eax, dword ptr [ebp-08]
:10004FBE F7D8                    neg eax
:10004FC0 1BC0                    sbb eax, eax
:10004FC2 F7D0                    not eax
:10004FC4 2345FC                  and eax, dword ptr [ebp-04]
  ÕâÀïÊǺ¯Êý·µ»ØÇ°µÄ¼ÆËã¹ý³Ì£¬Ò²ÊÇÕâ¸ö¼ÆËãµÄ¹Ø¼üÖ®ËùÔÚ¡£Èç¹ûÒªÈÃÄãÃÇÀ´·ÖÎöÉÏÃæµÄ
¹ý³ÌµÄ»°£¬ÄãÃÇ»áµÃµ½Ê²Ã´½á¹ûÄØ£¿Èç¹ûÄãÒªÏëµÃµ½eax²»µÈÓÚ0µÄÖµ£¬ÄǸöeaxºÍ[ebp-08]
µÄÖµ¸ÃÓÐʲôÑùµÄ¹Øϵ¡£Èç¹ûËüÃÇÁ½¸ö²»ÏàµÈµÄ»°£¬½«ÔÚand´¦µÃµ½µÄeaxµÄÖµµÈÓÚ0£¬ÕâÑù
ʹÓÃ0½øÐÐÓëÆäËüµÄÊý¾ùΪ0£¬ÄÇôֻÓÐʹÓÃeaxµÈÓÚ[ebp-08]µÄÖµÁË¡£ÄÇôÎÒ½«ÈçºÎÖªµÀ³Ì
ÐòÈçºÎÔËËãÉÏÃæµÄÁ½¸öÖµµÄ¡£ÄÇÎÒÃÇ»¹µÃ¼ÌÐøÏòÉÏ¿´¡£
:10004F43 837DF8FF                cmp dword ptr [ebp-08], FFFFFFFF
:10004F47 7505                    jne 10004F4E
:10004F49 894DF8                  mov dword ptr [ebp-08], ecx
 ÕâÀォµÃµ½[ebp-08]µÄÖµ£¬ÔÚ¿ªÊ¼Ê±[ebp-08]µÄÖµµÈÓÚffffffff£¬ÔÚ³ÌÐò½øÐеÚÒ»´ÎÔËËã
ºó£¬½«ÆäÔËËãÖµ´¢´æÔÚÕâÀÒÔºóµÄÖµ¾ùͨ¹ýÏÂÃæµÄÔËËã´¢´æÔÚ[ebp-04]ÖÐ
:10004F4E 83F907                  cmp ecx, 00000007
:10004F51 7F61                    jg 10004FB4
:10004F53 8B45FC                  mov eax, dword ptr [ebp-04]
:10004F56 6BC007                  imul eax, 00000007
:10004F59 03C1                    add eax, ecx
:10004F5B 8945FC                  mov dword ptr [ebp-04], eax
 ÄÇôÎÒÃÇÏÖÔÚÈçºÎµÃµ½¸ÃÈí¼þµÄ×¢²áÂëÄØ£¿
* Possible StringData Ref from Data Obj ->"n61O0rRxdkVHt5ZwqYUzoNDmCybcghfaMLj4liT8pQ3J2I"
                                        ->"vWP9euS7BKFGEAXs"
¿´µ½ÉÏÃæµÄ×Ö·û´®Ã»ÓУ¬ÎÒÃǼÆËã×¢²áÂë¾ÍÒªÓõ½Õâ¸ö×Ö·û´®£¬Ëü¾ßÌå±È½Ï¹ý³ÌÈçÏ£º
 È¡ÊäÈë×¢²áÂëµÄÊ×룬¼ÆËã³öËüÔÚÕâ¸ö×Ö·û´®ÖеÄλÖÃÖµ£¬Èç0µÄλÖÃΪ4£¨´Ó0¿ªÊ¼¼ÆÊý£©
½«ËüµÄÖµ-ebx£¨ÕâʱµÄebx=0£©£¬ÔÙ-esi£¨esi×Ö·û´®µÄ³õʼµØÖ·Öµ£©ºó£¬ÔÙ½«Õâ¸öÖµ-1ºó£¬
ÕâÑùÎÒÃǾͿÉÒԵõ½[ebp-08]µÄÖµ¡£
  ÏÖÔÚÎÒÃǽ«ÒªÖªµÀÈçºÎµÃµ½[ebp-04]µÄÖµÁË£¬ÄÇôËüµÄÖµ½«ÈçºÎµÃµ½£¬ÉÏÃæÎÒ˵¹ýÁË£¬µ«
ÊÇÕâÀïËü»¹ÓÐÒ»¸öÒªÇ󣬾ÍÊÇÏÂÃ棺
:10004F4E 83F907                  cmp ecx, 00000007
:10004F51 7F61                    jg 10004FB4
ÕâÀïµÄecxµÄÖµ×÷ÓÃÊÇʲôÄØ£¿ËüµÄ×÷ÓÃÊDZȽÏÇ°ºóÏÖÔÚÏàÁÚ×¢²áÂëµÄλÖÃÖµÊÇ·ñ´óÓÚ7Èç¹û
´óÓÚ7ÔòÈÏΪ²»ÕýÈ·µÄ×¢²áÂë¡£ÏÖÔÚÎÒÃÇÔٻص½·µ»ØeaxµÄµØ·½£¬ÎÒÃÇÏÖÔÚÖªµÀÁË[ebp-08],[
ebp-04]µÄÖµÁË£¬ÄÇôeaxµÄÖµµ½µ×ÈçºÎµÃµ½µÄ£¬ËüµÄÖµ¾ÍÊdzÌÐò¼ÆËã×¢²áÂëµÄ¸öÊý£¬ÔÚÕâÀï
ÓÖÒªÏò´ó¼Ò˵Ã÷Ò»µã£¬ÎÒÃÇÊäÈëµÄ×¢²áÂë²»ÊÇÿһλ¶¼¼ÆËãµÄ£¬ÒòΪÓÐÏÂÃæµÄÃüÁËùÒÔͨ
³£ËüÊǸôһλ¼ÆËãµÄ¡£
:10004F74 6A02                    push 00000002
:10004F76 99                      cdq
:10004F77 59                      pop ecx
:10004F78 F7F9                    idiv ecx
:10004F7A 85D2                    test edx, edx
:10004F7C 7401                    je 10004F7F
:10004F7E 47                      inc edi
* Referenced by a (U)nconditional or (C)onditional Jump at Addresses:
|:10004F63(C), :10004F7C(C)
|
:10004F7F 8A07                    mov al, byte ptr [edi]
:10004F81 84C0                    test al, al
:10004F83 758B                    jne 10004F10
  ÉÏÃæ¾ÍÊdzÌÐò¼ì²éµÄÇé¿ö£¬Ëüͨ³£ÊÇÿ¸ôһλ¼ÆËãÒ»¸ö¡£
  ÏÖÔÚÎÒÃÇÔٻص½ÈçºÎµÃµ½×¢²áÂëµÄ»°ÌâÉÏÀ´¡£ÏÖÔÚÎÒÃÇÖªµÀÁË£¬eaxΪ¼ÆËã×¢²áÂëµÄ¸öÊý
£¬ÕâÀï²»°üÀ¨µÚһλ¼ÆËãµÄÖµ¡£[ebp-08]ΪµÚһλµÄÔËËãÖµ£¬¶ø[ebp-04]ΪÆäËüλµÄ¼ÆËãÖµ
£¬ÏÖÔھͿÉÒÔÖªµÀ×¢²áÂëÁË£¬Í¨¹ýÎÒµÄÑо¿£¬Èç¹ûÒªÂú×ã´óÓÚ585µÄ»°£¬Ò»¶¨Òª¼ÆËã4´ÎÒÔÉÏ
£¬ÔÚÕâÀïÎÒ¾ÍÑ¡ÔñÁ˼ÆËã4´Î£¬ÒòΪËüÊǸôһλ¼ÆËãÒ»¸ö£¬²¢ÇÒÏàÁÚµÄ×¢²áÂëµÄλÊý²»Ó¦´ó
ÓÚ7ËùÒÔÑ¡ÔñÏÂÃæµÄ×ÖĸΪע²áÂ룬ÌîÈëºó£¬×¢²á³É¹¦¡£
    RN£ºrRdvtZqUoDCb
  ÏÖÔÚÎÒÏëÎÒ¶ÔÕâ¸öÈí¼þµÄÆƽâÊÇÍê³ÉÁË£¬µ«ÊǶÔÓÚ´ó¼ÒÏë±Ø¾ÍûÓÐÀí½âÊÇÈçºÎ×¢²áµÄ£¬ÄÇ
ôֻºÃ´ó¼ÒÔÙ×Ô¼ºÓù¦Ñо¿Ñо¿ËüÁË¡£ÎÒÖ»ÊÇÒ»¸öÒý·ÈË£¬¾ßÌåÔõô×ß»¹Òª¿´´ó¼ÒµÄ¡£
                  ********************************
                  *       RN:rRdvtZqUoDCb        *
                  ********************************
·µ»Ø
%¡¾³õѧÌìµØ¡¿
            ½âÃ̳ܽ̾Å
               ³ÌʽÁÔÈË
  ÏÖÔÚÓÖµ½ÁËÎÒÃdzõѧÌìµØµÄʱ¼äÁË£¬½ñÌìÎÒÏëÏò´ó¼Ò¼ÌÐø½éÉÜÆƽⷽÃæµÄÒ»¸ö¹Ì¶¨±È½Ï¸ñ
ʽ£¬´ó¼ÒÈç¹ûÄܹ»±È½ÏºÃµÄÕÆÎÕÎÒ˵µÄ¼¸ÖֱȽϸñʽµÄ»°£¬ÎÒÏàÐŶÔÓÚÌá¸ß´ó¼ÒµÄÆƽâˮƽ
ÊÇ»áÔÚÒ»¶¨µÄ°ïÖúµÄ¡£ÒòΪÕâЩ¶¼ÎÒ¸öÈË´ÓÆƽâÖеõ½µÄ¾­Ñé¡£ÎÒÒ²ÊÇ´ÓÒ»¸öÒ»ÎÞËùÖª²Å´ï
µ½ÏÖÔÚµÄˮƽ¡£ÕâÀﶼÊÇÎÒ¸öÈ˵ľ­Ñ飬ÏÖÔھͿªÊ¼½éÉÜÇ°Ò»½Ú¿Î½éÉܵÄ×îºóÒ»¸ö±È½Ï¸ñʽ
£¬ÈçÏ£º
call 00??????  ***
     push eax (ebx,ecx¡­)
     ¡­¡­
     ¡­¡­
     call 00??????
     pop eax (ebx,ecx¡­)
     test eax eax
     jz(jnz)
ÕâÖֱȽϸñʽʹÓò»ÊǺܶ࣬µ«ÊÇÔÚһЩÈí¼þÖл¹ÊÇʹÓõIJ»ÉÙ£¬ÕâÖֱȽϷ½Ê½µÄÆƽâÓÐÒ»
¶¨µÄ¹æÂÉ¿ÉÑ­£¬ÕâÀï¾ÍÒªÇó´ó¼Ò¶ÔÕâ¸ö±È½Ï·½Ê½µÄÔ­ÀíËùÊìϤÁË¡£ËüµÄ±È½ÏÖصãÔÚtest eax
 eax £¬¶øeaxÖµÊÇ´Ópop eaxÕâÀïµÃµ½µÄ£¬ÄÇôÔÙÏòÉϲéÕÒÔںδ¦Ñ¹Èë¹æÄ£µÄµØ·½£¬ÔÚÉÏÃæ
ͨ³£Äã¿ÉÒÔ²éÕÒµ½ÕâÑùÒ»¸öµØ·½push eax Èç¹ûÄܹ»²éÕÒµ½ÕâÀï¾Í¿ÉÒÔÁË¡£ÄÇôÖصã¾ÍÊÇÔÚ
Õâ¸öÃüÁîÉÏÃæµÄÄǸöcallÁË£¬½øÈëÄǸöcall¾Í¿ÉÒÔÕÒµ½¹Ø¼üµÄ±È½ÏµØ·½ÁË¡£
 ÏÖÔÚ¸ø´ó¼Ò¾ÙÒ»¸öÀý×Ó£¬Õâ¸öÀý×Ó¾ÍÊÇÔÚµÚÊ®ÆÚÖнéÉܵÄnoteproÈí¼þ¡£ËüµÄÆƽâ¹ý³Ì¾ÍÊÇ
ÀûÓÃÁËÕâ¸ö±È½Ï·½Ê½²ÅÄܹ»±È½Ï¿ìµÄÆƽâ³öÀ´ÁË¡£
            Noterpro V1.1
                     ³ÌʽÁÔÈË
¼ò½é£ºÕâ¸öÈí¼þÊÇÒ»¸öСÐ͵ı༭Èí¼þ£¬¹¦ÄܱÈnoteÇ¿´ó¡£
×·×Ù£ºname:dahuilang
      RN:01234567
     
ÏÖÔÚÏÂbpx hmemcpyºóÄ㽫±»À¹Ï¡£ÌøÔ¾µ½Ö÷³ÌÐòÖУ¬ÈçÏ£º
0040b1f7  call 0049a768
          lea edx [ebp-08]  <-³öÀ´
          xor eax eax
          ¡­¡­
          ¡­¡­
0040b214  call 0049a768
          lea edx [ebp-08]
          mov edx [edx]
          mov eax [004e9c80]
          pop eax
          call 00406bb0
          push eax      ****
          ¡­¡­
          ¡­¡­
0040b245  call 004dccc
          pop ecx      ****
          test cl cl
          jz 0040b38b
  ÏÖÔÚÎÒÃǾÍ×·×Ùµ½ÕâÀÄ㽫Ê×ÏÈ´ÓÉÏÃæ±ê¼ÇµÄµØ·½³öÀ´£¬ÒòΪ³ÌÐòÒª¶ÁÈ¡Á½´Î£¬ËùÒÔËüʹ
ÓÃÁËcall 0049a768Á½´ÎµÄ£¬³ÌÐò¶ÁÈ¡ÍêºóÏÂÃæµÄÄǸöcall¾ÍÊǹؼüµÄµØ·½£¬ÎÒÔÚÕâÀïÏò
´ó¼Ò½âÊÍÒ»ÏÂΪʲô˵call 00406bb0¾ÍÊÇÖØÒªµÄµØ·½¡£
  ÒòΪÔÚÏÂÃæ0040b245´¦¿ªÊ¼£¬Èç¹û³ÌÐòÔÚÕâÀïÌøÔ¾µÄ»°£¬½«³öÏÖ´íÎóÌáʾ£¬ËùÒÔ˵Õâ¸öÌø
Ô¾ÊÇÒ»¸öÏ൱¹Ø¼üµÄµØ·½£¬ÄÇôecxµÄÖµ¾ö¶¨Õâ¸ö³ÌÐòÄܹ»×¢²á³É¹¦Óë·ñÁË¡£³ÌÐòµ÷ÓÃecxÊÇ
ʹÓóöÕ»µÄ·½·¨µÃµ½ecxµÄ£¬ÄÇô¾ÍÒª¿´ÔÚÄÇÀï½øÕ»ÁË£¬¹Û²ì³ÌÐò·¢ÏÖÖ»ÓÐ****´¦½øÈë¶ÑÕ»
£¬ËùÒÔÏÖÔÚ¾ÍÖªµÀcall 00406bb0ÊÇÒ»¸öÖØÒªµÄº¯ÊýÁË¡£
   ½øÈëcall 00406bb0ÖУ¬ÈçÏ£º
00406e6b  mov edx [ebp-08]
          call notepro!@stratil@xordecord$qqrx17
          lea edx [ebp-2c]
          lea eax [ebp-14]
          call 004dcd9c
          push eax      ****
          ¡­¡­
          ¡­¡­
00406e92  call 004dcccc
          pop ecx
          test cl cl
          jz 00406e98
          mov byte [ebp-51] 01  ****
00406e98  dec dword [ebp-34]
          ¡­¡­
          ¡­¡­
00406eae  mov al [ebp-51] ***
          mov edx 02
          push eax  **
          leax eax [ebp-08]
          ¡­¡­
          ¡­¡­
00406ecd  call 004dcccc
          pop eax  *
          mov edx [ebp-50]
   ÏÖÔÚ¿ªÊ¼½éÉܳÌÐòÔÚÕâ¸öcallÖÐÈçºÎµÃµ½µÄeaxÖµµÄ£¬ÒòΪ³öÕâ¸öcallºóÎÒÃÇ×î¹ØÐĵľÍ
ÊÇeaxÖµ£¬ÄÇô¾ÍҪעÒâÕâ¸öÖµµÄ±ä»¯¡£ÎÒÏÈ´ÓºóÃæ¿´£¬Õâ¸öeax¾ÍÊdzÌÐò·µ»ØµÄÖµ£¬Ëü´ÓÕâ
ÀïµÃµ½µÄ¡£
          pop eax   *
   ÄÇôÔÚÉÏÃæ¾ÍÓнøÈë¶ÑÕ»µÄµØ·½
          push eax  **
    ËüÓÖÊÇmov al [ebp-51]´ÓÕâµÃµ½µÄ£¬ÔÙÏòÉϲéÕÒ³ÌÐòÔÚÕâÀïʹÓÃmov byte [ebp-51] 0
1£¬Õâ¸öÊǾö¶¨Äã×¢²á³É¹¦µÄ¹Ø¼ü£¬ÄÇôÉÏÃæÕýºÃÓÐÒ»¸öjz£¬Õâ¾ÍÓ¦µ±ÕÒµ½Á˹ؼüµØ·½ÁË¡£
µ«ÊÇÔÚÕâÀïÄã²»Òª½øÈë
00406e92  call 004dcccc
   ÖУ¬ÒòΪËü²»ÊÇ×îºóµÄÔËÐÐcall£¬ÎªÊ²Ã´£¿»¹ÊÇʹÓÃÇ°Ãæ½²µ½µÄµØ·½£¬ÒòΪ³ÌÐòʹÓõÄ
ÊÇpop ecxÀ´´«ÖµµÄ£¬ËùÒÔÉÏÃæ²ÅÊǹؼüµÄµØ·½¡£
          call 004dcd9c
          push eax  
  ÕâÀïÕ߹ؼüµÄµØ·½£¬ÄÇôÈç¹ûÄã½øÈëÕâÀïcallÖÐÄã»á·¢ÏÖÕâÀïÖ»ÊÇÒ»¸ö±È½Ï¹ý³Ì£¬ËüµÄÁ½
¸öÖµÒ»¸öÊÇÃ÷Â룬ÁíÒ»¸ö²»ÊÇ£¬ÆäÖÐÃûÂë¾ÍÊÇͨ¹ýÄãµÄname¼ÆËãµÃµ½µÄ£¬¶ø²»ÊÇÃ÷ÂëµÄ¾ÍÊÇ
ͨ¹ýÄãµÄ×¢²áÂë¼ÆËãµÃµ½µÄ¡£ÏÖÔڵĹؼüÊÇÕÒµ½ÈçºÎͨ¹ýÄãµÄ×¢²áÂë¼ÆËãµÃµ½Õâ¸ö±È½ÏÂëµÄ
¡£ÄÇôÔÚÉÏÃæããµÄ´úÂëÖÐÈçºÎÕÒÄØ£¿
   ÕâÀïÒ²ÓÐÒ»¸ö¼¼ÇÉ£¬ÒòΪÈç¹ûÄã½øÈëcall 00406bb0ÕâÀïºó£¬Äã»á·¢ÏÖ³ÌÐòÇ°ÃæµÄ¼ÆËãÈë
¿ÚÖµ¶¼ÊÇname£¬Ò²¾ÍÊÇÇ°ÃæµÄ¼ÆË㶼Õæ¶ÔnameµÄ£¬¶øÔÚÕâÀïÄã¿ÉÒÔ¿´µ½ËüµÄÈë¿ÚÖµÊÇÄãÊäÈë
µÄRN
00406e6b  mov edx [ebp-08]   <-RN    *******
          call notepro!@stratil@xordecord$qqrx17
          lea edx [ebp-2c]
          lea eax [ebp-14]
 ÄÇôÏÂÃæµÄÄǸöcall¾ÍÊÇÔËÐеĹؼüÁË£¬½øÈëºóÄã¾Í»á·¢ÏÖËüͬ¿´Ñ©½éÉܵÄÒ»Ñù£¬ÄãÊÖÖÐ
Ò»¶¨ÒªÓÐÒ»¸öXOR±í£¬Èç¹ûûÓл°£¬×Ô¼º×öÒ»¸ö¾ÍÐÐÁË¡£ÏÂÃæ¾ÍÊÇ¿´Ñ©ÆƽâµÄ¼ÆËã¹ý³Ì¡£
 
  ´ó¼Ò¿´µ½ÉÏÃæµÄÀý×ÓÁË°É£¬Õâ¸öÈí¼þµÄÆƽâ¹ý³Ì²»ÊǺÜÄÑ£¬Ö»ÒªÄãÕÆÎÕËüÆƽâµÄ·½·¨¾Í¿É
ÒÔÁË¡£ÄÇôÉÏÃæµÄÀý×Ó¿ÉÒÔÇå³þµÄ±í´ïÁËÕâ¸ö±È½Ï¸ñʽ¡£³ÌÐò¹²Ê¹ÓÃÁËÁ½´ÎÕâÑùµÄ±È½Ï¹ý³Ì
£¬Èç¹ûÄã²»ÖªµÀÕâ¸ö±È½Ï¸ñʽµÄ»°£¬Äã»á»¨ºÜʱ¼äÀ´Ñо¿test eax eaxÉÏÃæµÄcall£¬¶øÕâ¸ö
call²»»áÈÃÄãÕÒµ½ÕýÈ·µÄÕýÈ·µÄ±È½ÏµØ·½µÄ¡£
  ºÃÁË£¬½ñÌìµÄ¿ÎOVER¡£×£´ó¼ÒÖÜδÓä¿ì¡£
·µ»Ø
O¡¾ÎÊÌâ´ðÒÉ¡¿
 
·µ»Ø
4¡¾ÍøÕ¾½éÉÜ¡¿
ÍѹìÆƽâÍøÕ¾ http://szycool.533.net

ÍѹìÆƽâÍøÕ¾ÊÇÒ»¸ö±È½ÏеÄÆƽâÍøÕ¾£¬Õâ¸öÍøÕ¾ÔÚÒ»¸öÌصãÊÇ¿ÉÒÔÏò¸ßÊÖÌṩÆƽâÈí¼þµÄ×ÊÁÏ£¬¶ø¶ÔÓÚÏëҪѧϰÆƽâµÄÈËÀ´Ëµ£¬Èç¹ûÓÐʲô×Ô¼ºÎÞ·¨ÆƽâµÄÈí¼þ¿ÉÒÔµ½ÕâÀォËüÌṩ¸ø°ßÖñ£¬ÕâÑù¾Í¿ÉÒÔʹ¸ßÊÖÄܹ»ÎªÄãÆƽâÈí¼þÁË¡£ÎÒ¾õµÃÕâ¸öÏë·¨ÊǷdz£ºÃ£¬Ò»¿ÉÒÔʹÓøßÊÖÓÃÓÐÏÞµÄʱ¼äÀ´Æƽâ±È½ÏÄѵÄÈí¼þ£¬ÁíÒ»¸ö·½ÃæÒ²¿ÉÒÔʹ³õѧÕ߸ü¿ìµÄÕÆÎÕÆƽâÕâÃż¼ÇÉ¡£´ó¼Ò¿ÉÒÔµ½Õâ¸öÍøÕ¾Ò»¿´¡£

·µ»Ø
,¡¾ÔÓÖ¾ÐÅÏä¡¿
Ͷ¸åÐÅÏ䣺discoveredit@china.com
´ðÒÉÐÅÏ䣺discoveranswer@china.com
°ßÖñÐÅÏ䣺programhunter@china.com
·µ»Ø