[QUOTE=fosom;1191133][ATTACH]
[/ATTACH]
修改几个跳转就可以搞定了。
楼主既然知道bp Messageboxa,那么就继续琢磨一下吧。
在messageboxa的返回地址,细细推敲一下,难度不大的。
做破解,不要依赖性太强。[/QUOTE]
0048ED10 . 83EC 64 sub esp,64
0048ED13 . 56 push esi ; Dumped_.004613AC
0048ED14 . 8B7424 74 mov esi,dword ptr ss:[esp+74] ; Dumped_.00580070
0048ED18 . 57 push edi
0048ED19 . 8B7E 08 mov edi,dword ptr ds:[esi+8]
0048ED1C . 57 push edi
0048ED1D . E8 0E410100 call Dumped_.004A2E30
0048ED22 . 83C4 04 add esp,4
0048ED25 . 85C0 test eax,eax
0048ED27 . 74 10 je short Dumped_.0048ED39
0048ED29 . 8D4424 08 lea eax,dword ptr ss:[esp+8]
0048ED2D . 50 push eax
0048ED2E . 56 push esi ; Dumped_.004613AC
0048ED2F . E8 FCE2FFFF call Dumped_.0048D030
0048ED34 . 83C4 08 add esp,8
0048ED37 . EB 42 jmp short Dumped_.0048ED7B
0048ED39 > 81FF 04000080 cmp edi,80000004 ; Switch (cases 80000002..80000004)
0048ED3F 75 04 jnz short Dumped_.0048ED45
0048ED41 . 8B0E mov ecx,dword ptr ds:[esi] ; Case 80000004 (SINGLE STEP) of switch 0048ED39
0048ED43 . EB 3A jmp short Dumped_.0048ED7F
0048ED45 > 81FF 02000080 cmp edi,80000002
0048ED4B 75 12 jnz short Dumped_.0048ED5F
0048ED4D . 8B16 mov edx,dword ptr ds:[esi] ; Case 80000002 (DATATYPE MISALIGNMENT) of switch 0048ED39
0048ED4F . 8D4C24 08 lea ecx,dword ptr ss:[esp+8]
0048ED53 . 51 push ecx
0048ED54 . 52 push edx
是这一段吧?