文章作者:混世魔王
信息来源:邪恶八进制信息安全团队(
www.eviloctal.com)
入口VC的伪装,仙剑 壳 0002 或者0003的版本
00750060 > 55 PUSH EBP //入口
00750061 8BEC MOV EBP,ESP
00750063 6A FF PUSH -1
00750065 68 3E1E4000 PUSH SearchW.00401E3E
0075006A 68 521E4000 PUSH SearchW.00401E52
0075006F 64:A1 00000000 MOV EAX,DWORD PTR FS:[0]
00750075 50 PUSH EAX
00750076 64:8925 0000000>MOV DWORD PTR FS:[0],ESP
0075007D 83EC 44 SUB ESP,44
00750080 53 PUSH EBX
00750081 56 PUSH ESI
00750082 57 PUSH EDI
00750083 66:9C PUSHFW
00750085 6A 10 PUSH 10
00750087 73 0B JNB SHORT SearchW.00750094
00750089 EB 02 JMP SHORT SearchW.0075008D
ALT+M 0066B000 (RSRC)
F2
F9
7C96437D 66:8B50 0C MOV DX,WORD PTR DS:[EAX+C]
7C964381 8955 B8 MOV DWORD PTR SS:[EBP-48],EDX
7C964384 8D70 10 LEA ESI,DWORD PTR DS:[EAX+10]
7C964387 8975 A0 MOV DWORD PTR SS:[EBP-60],ESI
7C96438A 66:F747 02 FFFF TEST WORD PTR DS:[EDI+2],0FFFF
7C964390 75 12 JNZ SHORT ntdll.7C9643A4
7C964392 0FB7D2 MOVZX EDX,DX
7C964395 8D34D6 LEA ESI,DWORD PTR DS:[ESI+EDX*8]
7C964398 8975 A0 MOV DWORD PTR SS:[EBP-60],ESI
7C96439B 33D2 XOR EDX,EDX
7C96439D 66:8B50 0E MOV DX,WORD PTR DS:[EAX+E]
7C9643A1 8955 B8 MOV DWORD PTR SS:[EBP-48],EDX
7C9643A4 33C0 XOR EAX,EAX
ALT+M 00401000 (CODE)
F2
F9
006333E8 55 PUSH EBP //OEP
006333E9 8BEC MOV EBP,ESP
006333EB 83C4 F0 ADD ESP,-10
006333EE 53 PUSH EBX
006333EF B8 802B6300 MOV EAX,SearchW.00632B80
006333F4 E8 FF3ADDFF CALL SearchW.00406EF8
006333F9 8B1D A4996300 MOV EBX,DWORD PTR DS:[6399A4] ; SearchW.0063ABC8
006333FF E8 9821F2FF CALL SearchW.0055559C
00633404 8B03 MOV EAX,DWORD PTR DS:[EBX]
00633406 E8 9952E6FF CALL SearchW.004986A4
0063340B 8B03 MOV EAX,DWORD PTR DS:[EBX]
0063340D BA B4346300 MOV EDX,SearchW.006334B4
ImportREC 等级一修复
这个程序破解 的暗桩太多了快20个暗桩,靠。还有自检测。AN-TI 一不小心OD就挂了。
靠,不就是破了他的2.5版,作者越搞越BT了。有时间破了2.9只发补丁,不发过程了。
最后要谢谢亚尔迪帮忙。by混世魔王. QQ:26836659