µÚÒ»·¶ÎÄÍø - רҵÎÄÕ·¶ÀýÎĵµ×ÊÁÏ·ÖÏíÆ½Ì¨

ÊʺÏÈëÃŵÄÈí¼þÆÆ½â½Ì³Ì - ±ÉÊÓҪ̫¶à·ÖµÄ 

À´Ô´£ºÓû§·ÖÏí ʱ¼ä£º2025/11/4 4:17:45 ±¾ÎÄÓÉloading ·ÖÏí ÏÂÔØÕâÆªÎĵµÊÖ»ú°æ
˵Ã÷£ºÎÄÕÂÄÚÈݽö¹©Ô¤ÀÀ£¬²¿·ÖÄÚÈÝ¿ÉÄܲ»È«£¬ÐèÒªÍêÕûÎĵµ»òÕßÐèÒª¸´ÖÆÄÚÈÝ£¬ÇëÏÂÔØwordºóʹÓá£ÏÂÔØwordÓÐÎÊÌâÇëÌí¼Ó΢ÐźÅ:xxxxxxx»òQQ£ºxxxxxx ´¦Àí£¨¾¡¿ÉÄܸøÄúÌṩÍêÕûÎĵµ£©£¬¸ÐлÄúµÄÖ§³ÖÓëÁ½⡣

×¢²áÂë:25061473

ÓÃ×¢²á»ú±àдÆ÷keymake±àд¸ÃÈí¼þµÄ×¢²á»ú:

µãÆäËü-ÁíÀà×¢²á»ú(F8),Èí¼þÃû³ÆÊäÈëePaper.exe,×¢²áÂëÑ¡¼Ä´æÆ÷·½Ê½ EAX Ê®½øÖÆ¡£ Ìí¼Ó¶Ïµã£¬ÖжϵØÖ·:00488DE7,ÖжϴÎÊý:1,µÚÒ»×Ö½Ú:3B,Ö¸Á¶È:3¡£ Éú³É×¢²á»úºóÍ깤£¬ÍòÊÂOK!

ºÙºÙ£¬ÏÖÔÚÊDz»ÊǾõµÄÕÒÈí¼þµÄ×¢²áÂëÔ½À´Ô½ÏñСʱºòÍæµÄ¶ãèèÁË£¿ ¿ÉϧżСʱºòûÓÐÇà÷ÖñÂíÄÇÖÖÀàÐ͵Ļï°é...

ºÃµÄ£¬ÎÒÃÇÕâ´Î½²¸öÓеã¶ùÃûÆøµÄÈí¼þ£¬WinZIP8.1£¬Õâ¸öÈí¼þÏàÐÅ´ó¼Ò¶¼Óùý°É£¬·´ÕýżÊÇϲ»¶ÓÃRAR£¬²»¹ýÒ²¶àÉÙÓùý¼¸ÌìÕâÍæÒâ¶ù... Èç¹ûÄãûÌý˵¹ý£¬ÄÇ¿´½éÉܺÃÁË ¡¾Èí¼þÃû³Æ¡¿WinZIP ¡¾Èí¼þ°æ±¾¡¿8.1 Beta 2 ¡¾Îļþ´óС¡¿1757KB

¡¾ÊÊÓÃÆ½Ì¨¡¿Win9x/Me/NT/2000

¡¾Èí¼þ¼ò½é¡¿Ò»¸öÇ¿´ó²¢ÇÒÒ×ÓõÄѹËõʵÓóÌÐò£¬Ö§³ÖZIP¡¢CAB¡¢TAR¡¢GZIP¡¢MIME£¬ÒÔ¼°¸ü¶à¸ñʽµÄѹËõÎļþ¡£ÆäÌØµãÊǽôÃܵØÓëWindows×ÊÔ´¹ÜÀíÆ÷ÍϷż¯³É£¬²»ÓÃÀ뿪×ÊÔ´¹ÜÀíÆ÷¶ø½øÐÐѹËõ¡¢½âѹËõ¡£ ²»ÓÃÎÒ˵Á˰ɣ¬³ö´¦ÈÔ¾ÉÊǵçÄÔ±¨2001ÄêºÏ¶©±¾µÄÅäÌ×¹âÅÌ

ÎÒÖ®ËùÒÔÏÈÔñËü£¬ÊÇÒòΪ¾õµÃËüµÄ¹Ø¼üCALLûÓÐǰ±ßÄÇÁ½¸öÄÇÑùºÃÕÒ(ÆäʵҲ¾ÍÄÇÑùÁË^_^)¼«¾ß´ú±íÐÔ£¬¶øÇÒͨ¹ýËü¿ÉÒÔÈÃÄã¸ÐÊÜÒ»ÏÂOllydbgÕâ¸ö÷ÈÁ¦±ÈÄã¼ÒµÄݱ¼¸»¹´óµÄµ÷ÊÔÆ÷

ÕâÀïÖ®ËùÒÔÌáµ½Ollydbg£¬ÊǾõµÄËüÕæÊÇÒ»¸ö·Ç³£·Ç³£°ôµÄµ÷ÊÔÆ÷...Ç¿ÁÒ½¨ÒéÄã¶àÍæ¼¸´Î...(MP3ºÃÌýÂ𣿠^_^)

ÎÒÃÇÀ´°É,Ê×Ïȵ±È»»¹ÊÇҪװÉÏËü(×óÉÁÊõ£¬ÓÒÉÁÊõ)£¬È»ºóÓÃOllydbgÀ´ÔØÈ룬´Ëʱ½çÃæ»á±»·Ö³ÉËĸö²¿·Ö,×óÉÏ·½ÊÇÈí¼þ·´»ã±àºóµÄ´úÂ룬ÓÒÉÏ·½ÊǼĴæÆ÷¿ª»áµÄµØ·½£¬×óÏ·½ÊÇÄÚ´æÇø£¬ÓÒÏ·½ÏÔʾµÄÔòÊǶÑÕ»µÄÐÅÏ¢¡£

ÎÒÃÇÀ´Ï¶ϵ㣬°´Alt+F4£¬Ö®ºóÑ¡USER32,È»ºóÔÙÊó±êÓÒ¼ü-->ËÑË÷-->µ±Ç°Ä£¿éÖеÄÃû³Æ£¬È»ºóÔÚÄÇÒ»´ó¶Ñº¯ÊýÖÐÕÒµ½ GetDlgItemTextA£¬°´F2À´Ï¶ϵ㣬Ëü»áÌáʾÄã´íÎ󣬲¢ËµÎÞ·¨ÉèÖÃÖжϵ㣬ÊDz»ÊǺܹýñ«£¿(ÎØÎØÎØ...´ó¸ç£¬ÎÒ´íÁË£¬ÔÙÒ²²»¸ÒÁË...)

ºÇºÇ£¬Õâ¸öÎÒÒ²²»ÖªµÀʲôԭÒò£¬Ã÷Ã÷ÊÇÓÃÁËÕâ¸öº¯ÊýÂ¾ÍÊDz»Èöϣ¬ÆäʵÎÒ¶ÔOllydbgÒ²²»ÊÇÌ«ÄǸö(¹Ø¼üÊÇÌÖÑáËüµÄ϶Ϸ½Ê½)¿´À´»¹ÊÇÓÃÎÒÃǵÄÍòÄܶϵã°É£¬ÊäÈë×¢²áÃûSuunb[CCG]£¬ÊäÈë×¢²áÂë 19870219£¬È»ºóÓÃTRW2000϶Ïbpx hmemcpy£¬¶Ïµ½Ö®ºó£¬pmodule·µ»ØÁì¿ÕºóÒ»´ÎF12¾Í»á³ö´í£¬¿´À´ËùÓеĶ«¶«¾ÍÔÚÕâÀïÁË...

ÎÒÃÇÓÃTRW2000ÔÙ¶Ïһϣ¬·µ»ØÁì¿ÕÖ®ºó¼Ç×ŵÚÒ»ÌõÖ¸ÁîµÄµØÖ·0040bd5f£¬ÎØÎØÎØ...ÉÏÌõÖ¸ÁîÃ÷Ã÷Êǵ÷

ÓÃGetDlgItemTextA£¬ÎªÊ²Ã´ÔÚOllydbgÖв»ÈÃÏÂÄØ£¿

û¹ØÏµ£¬ÎÒÃǼÇÏÂÕâ¸öµØÖ·ºóÈÔ¾ÉÓÃOllydbgÀ´¼ÓÔØ³ÌÐò£¬Ö®ºóÔÚ·´»ã±à´°¿ÚÖÐÕÒµ½0040bd5f´¦£¬È»ºó°´ÏÂF2À´Ï¶Ï(»á±äΪºìÉ«)£¬Ï¶ÏÖ®ºó±ã°´ F9À´ÔËÐгÌÐò£¬½Ó×ÅÊäÈë×¢²áÃûSuunb[CCG]£¬×¢²áÂë19870219ºó°´È·¶¨£¬³ÌÐò»á±»Ollydbg¸ø¶Ïµ½: 0040BD5F |. 57 PUSH EDI

0040BD60 |. E8 F34A0500 CALL WINZIP32.00460858 0040BD65 |. 57 PUSH EDI ; /Arg1

0040BD66 |. E8 164B0500 CALL WINZIP32.00460881 ; \\WINZIP32.00460881 0040BD6B |. 59 POP ECX

0040BD6C |. BE 1CCA4C00 MOV ESI,WINZIP32.004CCA1C 0040BD71 |. 59 POP ECX

0040BD72 |. 6A 0B PUSH 0B ; /Count = B (11.)

0040BD74 |. 56 PUSH ESI ; |Buffer => WINZIP32.004CCA1C 0040BD75 |. 68 810C0000 PUSH 0C81 ; |ControlID = C81 (3201.) 0040BD7A |. 53 PUSH EBX ; |hWnd

0040BD7B |. FF15 F4C54A00 CALL DWORD PTR DS:[<&USER32.GetDlgItemTe>; \\GetDlgItemTextA

0040BD81 |. 56 PUSH ESI

0040BD82 |. E8 D14A0500 CALL WINZIP32.00460858 0040BD87 |. 56 PUSH ESI

0040BD88 |. E8 F44A0500 CALL WINZIP32.00460881 0040BD8D |. 803D F0C94C00 >CMP BYTE PTR DS:[4CC9F0],0 0040BD94 |. 59 POP ECX 0040BD95 |. 59 POP ECX

0040BD96 |. 74 5F JE SHORT WINZIP32.0040BDF7 0040BD98 |. 803D 1CCA4C00 >CMP BYTE PTR DS:[4CCA1C],0 0040BD9F |. 74 56 JE SHORT WINZIP32.0040BDF7

0040BDA1 |. E8 31F9FFFF CALL WINZIP32.0040B6D7 <--¹Ø¼üCALL£¬µÈ»á¶ù½øÈ¥ÍæÍæ 0040BDA6 |. 84C0 TEST AL,AL <--¸ù¾Ý¹Ø¼üCALLÖбȽϵĽá¹ûÀ´×öÏàÓ¦µÄ²âÊÔ

0040BDA8 |. 74 4D JE SHORT WINZIP32.0040BDF7 <--Ìø×ß¾ÍûϷ! 0040BDAA |. 57 PUSH EDI

0040BDAB |. 68 08DE4B00 PUSH WINZIP32.004BDE08 ; ASCII \

0040BDB0 |. FF35 1CC74A00 PUSH DWORD PTR DS:[4AC71C] ; WINZIP32.004BDDEC 0040BDB6 |. E8 8AFA0400 CALL WINZIP32.0045B845 0040BDBB |. 56 PUSH ESI

0040BDBC |. 68 C8EB4B00 PUSH WINZIP32.004BEBC8 ; ASCII \

0040BDC1 |. FF35 1CC74A00 PUSH DWORD PTR DS:[4AC71C] ; WINZIP32.004BDDEC 0040BDC7 |. E8 79FA0400 CALL WINZIP32.0045B845

0040BDCC |. FF35 18C74A00 PUSH DWORD PTR DS:[4AC718] ; |Arg4 = 004BDDF4 ASCII \

0040BDD2 |. 6A 00 PUSH 0 ; |Arg3 = 00000000 0040BDD4 |. 6A 00 PUSH 0 ; |Arg2 = 00000000

0040BDD6 |. 68 14DE4B00 PUSH WINZIP32.004BDE14 ; |Arg1 = 004BDE14 ASCII \0040BDDB |. E8 4CFA0400 CALL WINZIP32.0045B82C ; \\WINZIP32.0045B82C 0040BDE0 |. A1 A8914C00 MOV EAX,DWORD PTR DS:[4C91A8] 0040BDE5 |. 83C4 28 ADD ESP,28 0040BDE8 |. 85C0 TEST EAX,EAX

0040BDEA |. 74 07 JE SHORT WINZIP32.0040BDF3

0040BDEC |. 50 PUSH EAX ; /hObject => 000013F4 (font)

0040BDED |. FF15 80C04A00 CALL DWORD PTR DS:[<&GDI32.DeleteObject>>; \\DeleteObject 0040BDF3 |> 6A 01 PUSH 1

0040BDF5 |. EB 30 JMP SHORT WINZIP32.0040BE27 0040BDF7 |> E8 C3020000 CALL WINZIP32.0040C0BF 0040BDFC |. 68 8E020000 PUSH 28E

0040BE01 |. E8 61470500 CALL WINZIP32.00460567 0040BE06 |. 50 PUSH EAX ; |Arg3 0040BE07 |. 53 PUSH EBX ; |Arg2

0040BE08 |. 6A 3D PUSH 3D ; |Arg1 = 0000003D

0040BE0A |. E8 C8050400 CALL WINZIP32.0044C3D7 ; \\WINZIP32.0044C3D7 ÎÒÃÇÓÃOllydbg¶Ïµ½Ö®ºó£¬¿ÉÒÔÏñÔÚTRW2000ÖÐÒ»Ñùͨ¹ýF8(Õâ¸öµ÷ÊÔÆ÷¸úÎÒÒ»Ñù£¬Ò²²»Ï²»¶F4^_^)À´µ¥²½Ö´ÐгÌÐò£¬ÎÒÃǰ´32ÏÂF8ºó³ÌÐò¾Í»á³ö´í£¬ÄÇÎÒÃÇÔÚµÚ¶þ±éÔØÈëʱ°´F8°´µ½20¶àÏÂʱ¾Í×Ðϸ¿´¿´ÓÐûÓпÉÒɵĵط½£¬ÄãÒ»Ñ۾ͿÉÒÔ¿´µ½0040BDA1´¦µÄÕâ¸ö¹Ø¼üCALL£¬ÎÒÃÇֻҪ׷µ½ÕâÀïʱ׷½øÈ¥¾ÍÓÐ

¿ÉÄÜ¿´µ½Èí¼þÕýÈ·µÄ×¢²áÂë ÄÇ»¹µÈÊ²Ã´ÄØ£¿ÎÒÃǾͽøÈ¥°É...

°´F7 ¸ú½øºóÄã»á¿´µÄÑÛ»¨ÑÛ»¨çÔÂÒ£¬µ½´¦¶¼ÊÇPUSH¸úPOP£¬µ½µ×Äĸö²ÅÊÇÄØ£¿ÏÖÔÚÖªµÀÎÒΪʲôÈÃÄãÓÃOllydbgÁ˰É(żÆð³õÒ²ÊÇÒªÓÃTRW2000µÄ£¬µ«ÁÙʱ¸Ä±äÖ÷Òâ ^_^)ÓÃOllydbgµÄÒ»¸ö×î´óºÃ´¦¾ÍÊÇ¿ÉÒÔÕæ½Ó¿´µ½¼Ä´æÆ÷ÖеÄÖµ£¬ÌرðÊÇÄãͨ¹ýF8À´µ¥²½Ö´ÐеÄʱºò£¬ÔÚ·´»ã±à´úÂëµÄϱߣ¬»áÓÐÒ»¸öС´°Ì壬ÔÚÄÇÀï¿ÉÒÔÏÔʾÏà¹ØÖ¸ÁîÖÐËùʹÓõļĴæÆ÷µÄÖµ£¬Ë¬°É£¡

ÎÒÃǰ´76ÏÂF8Ö®ºó£¬ÔÚ0040B803´¦¾Í¿ÉÒÔµÚÒ»´Î¿´µ½ÕýÈ·µÄ×¢²áÂëÁË£¬ºÇºÇ£¬ÎÒÕâ±ß¶ùÊÇ71C20EDC£¬È»ºóÄ㻹»áÔÙÂ½Ðø¿´µ½¼¸´Î£¬Ë¬£¿

ÁíÍâÎÒ»¹·¢ÏÖÒ»¸öÓÐȤµÄÊÂÇ飬ÔÚWinZIP8.1ÖУ¬Ò»¸ö×¢²áÃû¿ÉÒÔÓÐÁ½¸ö×¢²áÂ룬ºÇºÇ£¬²»ÖªµÀÊDz»ÊÇ»¹ÓÐÎªÌØ±ðÓû§×¼±¸µÄÌØ±ð×¢²áÂëÒÔÓÃÀ´ºÍÆÕͨµÄ×öÇø±ð µ±³ÌÐòͨ¹ý±È½Ï£¬·¢ÏÖÄãÊäÈëµÄ×¢²áÂë²»ÕýÈ·ºó¾¹È»»áÔÙ´ÎËã³öÁíÒ»¸ö×¢²áÂëÀ´ÔٱȽÏÒ»´Î£¬ºÙºÙ£¬Îҵĵڶþ¸ö×¢²áÂëÊÇ25170288 ×·Èë¹Ø¼üCALLÀïµÄ´úÂë:

0040B6D7 /$ 55 PUSH EBP 0040B6D8 |. 8BEC MOV EBP,ESP 0040B6DA |. 81EC 0C020000 SUB ESP,20C

0040B6E0 |. 8065 FF 00 AND BYTE PTR SS:[EBP-1],0 0040B6E4 |. 803D F0C94C00 >CMP BYTE PTR DS:[4CC9F0],0 0040B6EB |. 53 PUSH EBX 0040B6EC |. 56 PUSH ESI 0040B6ED |. 57 PUSH EDI

0040B6EE |. 0F84 FB000000 JE WINZIP32.0040B7EF 0040B6F4 |. 8D45 E8 LEA EAX,DWORD PTR SS:[EBP-18] 0040B6F7 |. 50 PUSH EAX

0040B6F8 |. 68 C0E84B00 PUSH WINZIP32.004BE8C0 0040B6FD |. E8 DE61FFFF CALL WINZIP32.004018E0 0040B702 |. 8D45 E8 LEA EAX,DWORD PTR SS:[EBP-18] 0040B705 |. 50 PUSH EAX

0040B706 |. E8 F57C0800 CALL WINZIP32.00493400 0040B70B |. 83C4 0C ADD ESP,0C 0040B70E |. 83F8 14 CMP EAX,14

0040B711 |. 72 11 JB SHORT WINZIP32.0040B724

0040B713 |. BF 20C74A00 MOV EDI,WINZIP32.004AC720 ; ASCII \

0040B718 |. 6A 21 PUSH 21 0040B71A |. 57 PUSH EDI

0040B71B |. E8 86F60000 CALL WINZIP32.0041ADA6 0040B720 |. 59 POP ECX 0040B721 |. 59 POP ECX

0040B722 |. EB 05 JMP SHORT WINZIP32.0040B729

0040B724 |> BF 20C74A00 MOV EDI,WINZIP32.004AC720 ; ASCII \0040B729 |> 8D85 F4FDFFFF LEA EAX,DWORD PTR SS:[EBP-20C]

0040B72F |. BB F0C94C00 MOV EBX,WINZIP32.004CC9F0 ; ASCII \0040B734 |. 50 PUSH EAX 0040B735 |. 53 PUSH EBX

0040B736 |. E8 50030000 CALL WINZIP32.0040BA8B

0040B73B |. 8D85 F4FDFFFF LEA EAX,DWORD PTR SS:[EBP-20C] 0040B741 |. 50 PUSH EAX

0040B742 |. E8 B97C0800 CALL WINZIP32.00493400 0040B747 |. BE C8000000 MOV ESI,0C8 0040B74C |. 83C4 0C ADD ESP,0C 0040B74F |. 3BC6 CMP EAX,ESI

0040B751 |. 72 0A JB SHORT WINZIP32.0040B75D 0040B753 |. 6A 23 PUSH 23 0040B755 |. 57 PUSH EDI

0040B756 |. E8 4BF60000 CALL WINZIP32.0041ADA6 0040B75B |. 59 POP ECX 0040B75C |. 59 POP ECX

0040B75D |> 8D85 F4FDFFFF LEA EAX,DWORD PTR SS:[EBP-20C] 0040B763 |. 50 PUSH EAX

0040B764 |. 8D45 E8 LEA EAX,DWORD PTR SS:[EBP-18] 0040B767 |. 50 PUSH EAX

0040B768 |. E8 03300900 CALL WINZIP32.0049E770 0040B76D |. 59 POP ECX 0040B76E |. 85C0 TEST EAX,EAX 0040B770 |. 59 POP ECX

ÊʺÏÈëÃŵÄÈí¼þÆÆ½â½Ì³Ì - ±ÉÊÓҪ̫¶à·ÖµÄ .doc ½«±¾ÎĵÄWordÎĵµÏÂÔØµ½µçÄÔ£¬·½±ã¸´ÖÆ¡¢±à¼­¡¢ÊղغʹòÓ¡
±¾ÎÄÁ´½Ó£ºhttps://www.diyifanwen.net/c7w6882x74s2b61z989ic_8.html£¨×ªÔØÇë×¢Ã÷ÎÄÕÂÀ´Ô´£©
ÈÈÃÅÍÆ¼ö
Copyright © 2012-2023 µÚÒ»·¶ÎÄÍø °æÈ¨ËùÓÐ ÃâÔðÉùÃ÷ | ÁªÏµÎÒÃÇ
ÉùÃ÷ :±¾ÍøÕ¾×ðÖØ²¢±£»¤ÖªÊ¶²úȨ£¬¸ù¾Ý¡¶ÐÅÏ¢ÍøÂç´«²¥È¨±£»¤ÌõÀý¡·£¬Èç¹ûÎÒÃÇ×ªÔØµÄ×÷Æ·ÇÖ·¸ÁËÄúµÄȨÀû,ÇëÔÚÒ»¸öÔÂÄÚ֪ͨÎÒÃÇ£¬ÎÒÃǻἰʱɾ³ý¡£
¿Í·þQQ£ºxxxxxx ÓÊÏ䣺xxxxxx@qq.com
ÓåICP±¸2023013149ºÅ
Top