软件名是 EASY定时关机 下载地址
b7aK9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6h3c8G2N6$3&6^5K9h3q4Q4x3X3g2U0L8$3#2Q4x3V1k6V1L8%4N6F1K9h3&6X3L8#2)9J5c8U0p5&6x3K6c8Q4x3X3g2Z5N6r3#2D9
软件启动时会打开一个网页 代码如下:
00401A55 > \68 E8704000 PUSH EasyShut.004070E8 ;
0f2K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6h3!0F1L8r3W2F1k6h3c8G2N6$3&6Q4x3X3g2F1k6i4c8Q4x3V1k6K6L8$3k6@1i4K6u0r3x3e0V1%4z5o6S2Q4x3X3g2Z5N6r3@1`.
00401A5A . 8D4C24 08 LEA ECX,DWORD PTR SS:[ESP+8]
00401A5E . E8 55210000 CALL <JMP.&MFC42.#537_CString::CString>
00401A63 . 8B4424 04 MOV EAX,DWORD PTR SS:[ESP+4]
00401A67 . 6A 01 PUSH 1 ; /IsShown = 1
00401A69 . 6A 00 PUSH 0 ; |DefDir = NULL
00401A6B . 6A 00 PUSH 0 ; |Parameters = NULL
00401A6D . 50 PUSH EAX ; |FileName
00401A6E . 68 E0704000 PUSH EasyShut.004070E0 ; |open
00401A73 . 6A 00 PUSH 0 ; |hWnd = NULL
00401A75 . C78424 C00200>MOV DWORD PTR SS:[ESP+2C0],0 ; |
00401A80 . FF15 C4524000 CALL DWORD PTR DS:[<&SHELL32.ShellExecut>; \ShellExecuteA //只要把这行 NOP 掉 就可以不再让程序启动时打开这个网页
但是程序后面还有一个地方也是会打开网页
就是在设定好任务后 点确定时 它也会打开网页 代码如下
00402804 . E8 01130000 CALL <JMP.&MFC42.#4224_CWnd::MessageBoxA>
00402809 > 68 C0714000 PUSH EasyShut.004071C0 ;
7d9K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8Y4N6%4N6#2)9J5k6i4y4C8P5h3y4F1i4K6u0W2j5$3!0E0i4K6u0r3M7$3!0X3N6q4)9J5c8U0x3H3y4o6j5^5i4K6u0W2K9s2c8E0L8l9`.`.
0040280E . 8D4C24 14 LEA ECX,DWORD PTR SS:[ESP+14]
00402812 . E8 A1130000 CALL <JMP.&MFC42.#537_CString::CString>
00402817 . 8B4C24 10 MOV ECX,DWORD PTR SS:[ESP+10]
0040281B . 6A 01 PUSH 1 ; /IsShown = 1
0040281D . 55 PUSH EBP ; |DefDir
0040281E . 55 PUSH EBP ; |Parameters
0040281F . 51 PUSH ECX ; |FileName
00402820 . 68 E0704000 PUSH EasyShut.004070E0 ; |open
00402825 . 55 PUSH EBP ; |hWnd
00402826 . FF15 C4524000 CALL DWORD PTR DS:[<&SHELL32.ShellExecut>; \ShellExecuteA /// 可是现在如果NOP掉这行 它就程序错误了
求教各位大大 如何去掉后面的这个网页 又可以正常运行??
[注意]看雪招聘,专注安全领域的专业人才平台!