EBPIG
6̽Ë÷ÔÓÖ¾6
MHJDQ
֪ʶ¹²ÏíJ×ÊÔ´¹²ÏíJ×ÊÁϹ²Ïí
¡¾·¢ÐÐʱ¼ä¡¿2001-02-19
¡¾ÆÚ¿¯ºÅÂë¡¿µÚ¶þÊ®°ËÆÚ
¡¾ÍøÕ¾µØÖ·¡¿http://programhunter.myetang.com
¡¾°æȨÉùÃ÷¡¿¡â¨z¨{¨|¨}¨~¨€³ÌʽÁÔÈ˨€¨~¨}¨|¨{¨z¡á
´ËÔÓÖ¾ÓɳÌʽÁÔÈ˱༭¡¢ÖÆ×÷¼°·¢ÐУ»ÔÓÖ¾¿ÉÒÔ×ÔÓÉתÔØ¡¢·Ö·¢ºÍ´«²¥£»ÈκθöÈË»òÍÅÌå²»µÃÔÚδ¾­±¾ÈËÊÚȨµÄÇé¿öÏÂÐÞ¸ÄÔÓÖ¾µÄÍâ¹Û¼°ÄÚÈÝ£»ÔÓÖ¾µÄ½âÊÍȨ¹é³ÌʽÁÔÈËËùÓС£

¡¾±à¼­¼ÄÓï¡¿

    
   {~._.~} 
    ( Y )  
   ()~*~() 
   (_)-(_) 

±¾ÈËÖÕÓÚ´Ó¿É°®µÄ¼ÒÏç»ØÀ´ÁË£¬ÕæÊDz»Í÷´ËÐУ¬²»½ö¿´µ½Á˸¸Ä¸£¬¶øÇÒÁ¬¡­¡­£¬²»ËµÁË£¬ÎÒ×Ô¼º¸ßÐ˾ͿÉÒÔÁË¡£ÎÒ»ØÀ´ºó¾ÍÏë¸Ã½«ÎÒÕâ¸öÔÓÖ¾°ìµÄ¸üºÃ£¬ÒòΪÎÒµÄÄǸöËýÈÃÎÒŬÁ¦Ñ§Ï°£¬ÎÒÏëÎÒҲϲ»¶Õâ¸ö¶«Î÷£¬ËùÒÔ»¹ÊDz»Ó¦µ±·ÅÆúÕâ¸ö°®ºÃ¡£

Õ⼸Ìì»ØÀ´ºóÊÕµ½ÁË·çƮѩºÍTAE!µÈÍøÓѵÄÎÄÕ£¬¸Ðµ½ÕæµÄºÃ¸ßÐË£¬ÒòΪÕâ¸öÔÓÖ¾ÖÕÓÚ¿ÉÒԵõ½ÍøÓѵijÐÈÏÁË¡£ËùÒÔÔÚÕâÀïÒªÏòËûÃDZíʾ¸Ðл¡£½ñÌìÔÚÕâÀï¾ÍÒªÏò´ó¼Ò½éÉÜ·çƮѩµÄÈýƪÆƽâÎÄÕ£¬ÏÂÆÚ½«½éÉÜTAE!µÄÎÄÕ¡£

 
¡¾Ä¿ ÿÿ ¼¡¿
ÿÿÿÿ&ÆƽâÐĵÃ
J¡­¡­ÆƽâÈðÐÇɱ¶¾Èí¼þ2001°æ£¬°ë×Ö½Ú£¬Ã»¸ã´í°É£¿£¿£¨ÆƽâÊּǣ© ·çƮѩ
K¡­¡­±©Á¦ÆƽâìûÁú×ÖÍõ V1.0 Beta2 £¨·þÎñÆ÷°æ£© ·çƮѩ
L¡­¡­°ë×Ö½ÚÆƽⳬ¼¶Ð¡¾«Áé ver1.0 ·çƮѩ
ÿÿÿÿ,ÔÓÖ¾ÐÅÏä
 
&¡¾ÆƽâÐĵá¿
 µÚһƪ
ÆƽâÈðÐÇɱ¶¾Èí¼þ2001°æ£¬°ë×Ö½Ú£¬Ã»¸ã´í°É£¿£¿£¨ÆƽâÊּǣ©


·Ç³£°ôµÄ¹ú²ú¾«Æ·É±¶¾Èí¼þ£¬´ÓÈðÐÇÍøÕ¾ÏÂÔØ×îа棬
ĿǰΪ2001°æ£¬°²×°Ê±ÐèÈðÐÇÃÜÔ¿ÅÌ¡£
ͼÐΰæravcpic.exe   ×Ö·û°æravcchar.exe
ÏÂÃæÒÔͼÐΰæΪÀý¡£
1¡£ÓÃwinzipµÈ½âѹËõÈí¼þ½«ravcpic.exe Õ¹µ½Ò»¸öĿ¼ÏÂ
2¡£½«ÆäÖеÄSETUP.DLLµÄUPX1.03¿Ç¸øÍÑÁË¡£ 
ÍÑ¿Ç¿ÉÓÃUPX1.06£¬²ÎÊý-D¼´¿É£¨UPX SETUP.DLL -D£© 
3¡£Óôò¿ªw32dasm»Æ½ð°æ´ò¿ªSETUP.DLL==¡·´®Ê½²Î¿¼
"Çë²åÈëÈðÐÇAºÅÅÌ£¬Èç¹û¸ÃÌáʾÈÔ³öÏÖÇëÓë¾­ÏúÉÌÁª?
¹²ËÄ´¦£¬ÎÒÃÇÖ»¿´×îÔçµÄÒ»´¦

:10001916 85C0                    test eax, eax
:10001918 7407                    je 10001921                    (74¸Ä75)
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10001947(C)
|
:1000191A B801000000              mov eax, 00000001
:1000191F 5E                      pop esi
:10001920 C3                      ret

* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:10001918(C)
| ^^^^^^^^^^^
:10001921 A180CD0010              mov eax, dword ptr [1000CD80]

* Reference To: USER32.MessageBoxA, Ord:0000h
                                  |
:10001926 8B356C910010            mov esi, dword ptr [1000916C]
:1000192C 6A31                    push 00000031

* Possible StringData Ref from Data Obj ->"Ìáʾ"
                                  |
:1000192E 6884B20010              push 1000B284

* Possible StringData Ref from Data Obj ->"Çë²åÈëÈðÐÇAºÅÅÌ£¬Èç¹û¸ÃÌáʾÈÔ³öÏÖÇëÓë¾­ÏúÉÌÁª?
                                        ->"µ¡?
                                  |
:10001933 6850B20010              push 1000B250
4¡£ÔËÐÐĿ¼Ïµİ²×°Ö÷³ÌÐòsetup.exe£¬ÍÛÈû£¬Ê¡µôÒ»°Ù¶à´óÑó£¬
ÇéÈ˽Úis coming,partyµÄÃÅƱǮ³öÀ´ÁË¡£
5¡£Çë±£´æÐ޸ĺóµÄsetup.dll£¬¿É½«ÈðÐÇ2001ͼÐΰæ±Ðµô£¨ÄѵÃÈðÐÇÈýÌìÁ½Í·µÄÉý¼¶£©
6¡£×Ö·û°æ¿É²Î¿¼1~5£¬Ô­Àíͬ¡£

µÚ¶þƪ
±©Á¦ÆƽâìûÁú×ÖÍõ V1.0 Beta2 £¨·þÎñÆ÷°æ£©


¹¤¾ß:w32dasm»Æ½ð°æ

ÏÂÔصØÖ·:http://www.mildragon.com/download/ws10b2.exe

ÏÈÓÃunaspackÍÑ¿Ç,w32dasm´®Ê½²Î¿¼

"лл£¬ÄúÒѾ­³É¹¦×¢²á£¬¿ÉÒÔÓÀ¾ÃʹÓÃÁË£¡"ÕÒµ½2´¦.

µÚ1´¦:

:004F2DE0 FF92D8000000 call dword ptr [edx+000000D8]

:004F2DE6 48 dec eax

:004F2DE7 7554 jne 004F2E3D

               ^^^^^^^^^^^ 75=>74

* Possible StringData Ref from Code Obj ->"×¢²á³É¹¦£¡"

:004F2DE9 B8542E4F00 mov eax, 004F2E54

:004F2DEE E8BD96F6FF call 0045C4B0

* Possible StringData Ref from Code Obj ->"лл£¬ÄúÒѾ­³É¹¦×¢²á£¬¿ÉÒÔÓÀ¾ÃʹÓÃÁË£¡"

:004F2DF3 BA682E4F00 mov edx, 004F2E68

.:µÚ2´¦:

:004F2EAD 803800 cmp byte ptr [eax], 00

:004F2EB0 744C je 004F2EFE

                ^^^^^^^^^^^ 74=>75 

* Possible StringData Ref from Code Obj ->"лл£¬ÄúÒѾ­³É¹¦×¢²á£¬¿ÉÒÔÓÀ¾ÃʹÓÃÁË£¡"

:004F2EB2 BA9C2F4F00 mov edx, 004F2F9C

ÖØÐÂÆô¶¯,"×¢²á"Ñ¡ÏîÕô·¢.





µÚÈýƪ
°ë×Ö½ÚÆƽⳬ¼¶Ð¡¾«Áé ver1.0 


³¬¼¶Ð¡¾«Áé ver1.0
ÏÂÔصØÖ·£ºhttp://www.soft999.com/download2/superspirit.exe 

w32dasm»Æ½ð°æ=¡·´®Ê½²Î¿¼" [×¢²á°æ±¾]"


:00408A0B 85C0                    test eax, eax
:00408A0D 7513                    jne 00408A22     ***£¨75=¡·74£©
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
:00408A0F 8D94248C000000          lea edx, dword ptr [esp+0000008C]
:00408A16 8D4C2440                lea ecx, dword ptr [esp+40]
:00408A1A 52                      push edx

* Reference To: MFC42.Ordinal:03AB, Ord:03ABh
                                  |
:00408A1B E8C0430000              Call 0040CDE0
:00408A20 EB0E                    jmp 00408A30

* Referenced by a (U)nconditional or (C)onditional Jump at Address:
|:00408A0D(C)
|^^^^^^^^^^^^^

* Possible StringData Ref from Data Obj ->" [×¢²á°æ±¾]"

ÔÙÆô¶¯£¬ÒÑΪע²á°æ±¾¡£

×÷Õߣº·çƮѩ
Ö÷Ò³http://duba.126.com
e-mail  gd1@yeah.net


,¡¾ÔÓÖ¾ÐÅÏä¡¿
Ͷ¸åÐÅÏ䣺discoveredit@china.com
´ðÒÉÐÅÏ䣺discoveranswer@china.com
°ßÖñÐÅÏ䣺programhunter@china.com