用PEID查了 Microsoft Visual C++ 6.0
确实没加密加壳
但是用OD查找关键字符,找不到:注册失败的字符
试试了用W32dsm也没找到
刚学 求大婶指导 是什么原因
或者指几条思路
7C92E4F9 54 push esp
7C92E4FA E8 29000000 call ntdll.RtlRaiseException
7C92E4FF 8B0424 mov eax,dword ptr ss:[esp]
7C92E502 8BE5 mov esp,ebp
7C92E504 5D pop ebp
7C92E505 C3 retn
7C92E506 8DA424 00000000 lea esp,dword ptr ss:[esp]
7C92E50D 8D49 00 lea ecx,dword ptr ds:[ecx]
7C92E510 > 8BD4 mov edx,esp
7C92E512 0F34 sysenter
7C92E514 > C3 retn
7C92E515 8DA424 00000000 lea esp,dword ptr ss:[esp]
7C92E51C 8D6424 00 lea esp,dword ptr ss:[esp]
7C92E520 > 8D5424 08 lea edx,dword ptr ss:[esp+8]
7C92E524 CD 2E int 2E
7C92E526 C3 retn
7C92E527 90 nop
7C92E528 > 55 push ebp
7C92E529 8BEC mov ebp,esp
7C92E52B 9C pushfd
7C92E52C 81EC D0020000 sub esp,2D0
7C92E532 8985 DCFDFFFF mov dword ptr ss:[ebp-224],eax
7C92E538 898D D8FDFFFF mov dword ptr ss:[ebp-228],ecx
这是用F12法 暂停以后的 问题是它没返回到程序领域
下面是堆栈情况
调用堆栈
地址 堆栈 函数例程 / 参数 调用来自 框架
000FD174 77D191BE 包含 ntdll.KiFastSystemCallRet USER32.77D191BC 000FD198
000FD178 77D2776B USER32.77D191B2 USER32.77D27766 000FD198
000FD19C 73D31203 USER32.GetMessageA MFC42.73D311FD 000FD198
000FD1A0 0052B38C pMsg = 【涵涵】.0052B38C
000FD1A4 00000000 hWnd = NULL
000FD1A8 00000000 MsgFilterMin = 0
000FD1AC 00000000 MsgFilterMax = 0
000FD1B8 73D455B1 包含 MFC42.73D31203 MFC42.73D455AE
000FD1DC 73D4544B MFC42.#5718 MFC42.73D45446
000FD218 0045D0F2 ? <jmp.&MFC42.#2514> 【涵涵】.0045D0ED
000FD29C 0045D082 【涵涵】.0045D0B0 【涵涵】.0045D07D 000FF3CC
000FD2B8 0041CD62 【涵涵】.0045D030 【涵涵】.0041CD5D 000FF3CC
000FF3D0 73D31FAE 包含 【涵涵】.0041CD62 MFC42.73D31FAC 000FF3CC
000FF450 73D31B07 包含 MFC42.73D31FAE MFC42.73D31B01 000FF44C
000FF470 73D31A78 包含 MFC42.73D31B07 MFC42.73D31A72 000FF46C
000FF4D0 73D319D0 MFC42.#1109 MFC42.73D319CB 000FF4CC
000FF4F0 73DBE47C MFC42.#1578 MFC42.73DBE477 000FF4EC
000FF4F4 005D07DE Arg1 = 005D07DE
000FF4F8 000005F4 Arg2 = 000005F4
000FF4FC FFFFFFFF Arg3 = FFFFFFFF
000FF500 00000001 Arg4 = 00000001
000FF51C 77D18734 包含 MFC42.73DBE47C USER32.77D18731 000FF518
000FF548 77D18816 ? USER32.77D1870C USER32.77D18811 000FF544
000FF5B0 77D189CD USER32.77D1875F USER32.77D189C8 000FF5AC
000FF5B4 00000000 Arg1 = 00000000
000FF5B8 73DBE443 Arg2 = 73DBE443
000FF5BC 005D07DE Arg3 = 005D07DE
000FF5C0 000005F4 Arg4 = 000005F4
000FF5C4 FFFFFFFF Arg5 = FFFFFFFF
000FF5C8 00000001 Arg6 = 00000001
000FF5CC 00C6E16C Arg7 = 00C6E16C
000FF5D0 00000001 Arg8 = 00000001
000FF610 77D196C7 ? USER32.77D188F1 USER32.77D196C2 000FF60C
000FF620 73D3122A ? USER32.DispatchMessageA MFC42.73D31224 000FF61C
000FF624 0052B38C pMsg = WM_HOTKEY hw = 5D07DE ("【涵涵】演义三国辅助svn90") ID = 8002
[注意]传递专业知识、拓宽行业人脉——看雪讲师团队等你加入!