这个软件的作者太搞笑了,加了vmp的标志,但是没用vmp处理。不知道是忘记了,还是吓唬人的?哈哈
你不加vm标志或许我找关键代码还需要花点时间,,加了vm标志又不vmp处理,不是等于告诉别人,这个call就是关键call吗?哈哈
空间:C:\Documents and Settings\Administrator\Local Settings\Temp\六点YY多开器831正式版.exe
00401267 |. C745 FC 00000000 mov dword ptr [ebp-4], 0
0040126E |. EB 10 jmp short 00401280
00401270 |. 56 4D 50 72 6F 74 65 63 74 20 62 65 67>ascii "VMProtect begin",0 //vm处理标识.开始
00401280 |> C705 20F65400 00000000 mov dword ptr [54F620], 0
0040128A |. B8 244B4E00 mov eax, 004E4B24
0040128F |. 50 push eax
00401290 |. 8B1D 24F65400 mov ebx, dword ptr [54F624] ; 六点YY多.004E4B24
00401296 |. 85DB test ebx, ebx
00401298 |. 74 09 je short 004012A3
....................................................
.....此处省略XX行
....................................................
004024AB |. /74 09 je short 004024B6
004024AD |. |53 push ebx
004024AE |. |E8 C3D00500 call 0045F576
004024B3 |. |83C4 04 add esp, 4
004024B6 |> \58 pop eax
004024B7 |. A3 80F65400 mov dword ptr [54F680], eax
004024BC |. EB 0E jmp short 004024CC
004024BE |. 56 4D 50 72 6F 74 65 63 74 20 65 6E 64>ascii "VMProtect end",0 //vm处理标识.结束
004024CC |> 8BE5 mov esp, ebp
004024CE |. 5D pop ebp
关键代码: