经过几天调试,终于弄懂了卸载精灵3.2的注册算法,下面就是破解过程请我要大侠多多指点!!谢谢! 载入卸载精灵3.2 在帮助菜单下选择我要注册 姓名:crackerboy 注册码:98765432 运行trw2000 CTRL+N呼出 下断点bpx hmemcpy g 点确定 被拦下来到这里: 我记住断点,用ollydbg1.09b调试:
0040C6BF . 3BC3 CMP EAX,EBX 0040C6C1 . DBE2 FCLEX 0040C6C3 . 7D 12 JGE SHORT CLEANER.0040C6D7 0040C6C5 . 68 A0000000 PUSH 0A0 0040C6CA . 68 004D4000 PUSH CLEANER.00404D00 0040C6CF . 56 PUSH ESI 0040C6D0 . 50 PUSH EAX 0040C6D1 . FF15 40104000 CALL DWORD PTR DS:[<&MSVBVM60.__vbaHresu>; MSVBVM60.__vbaHresultCheckObj 0040C6D7 > 8B55 DC MOV EDX,DWORD PTR SS:[EBP-24] 0040C6DA . 8D4D E0 LEA ECX,DWORD PTR SS:[EBP-20] 0040C6DD . 895D DC MOV DWORD PTR SS:[EBP-24],EBX 0040C6E0 . FF15 34114000 CALL DWORD PTR DS:[<&MSVBVM60.__vbaStrMo>; MSVBVM60.__vbaStrMove 0040C6E6 . 8D4D D4 LEA ECX,DWORD PTR SS:[EBP-2C] 0040C6E9 . FF15 44114000 CALL DWORD PTR DS:[<&MSVBVM60.__vbaFreeO>; MSVBVM60.__vbaFreeObj 0040C6EF . 8B07 MOV EAX,DWORD PTR DS:[EDI] 0040C6F1 . 57 PUSH EDI 0040C6F2 . FF90 08030000 CALL DWORD PTR DS:[EAX+308] 0040C6F8 . 8D4D D4 LEA ECX,DWORD PTR SS:[EBP-2C] 0040C6FB . 50 PUSH EAX 0040C6FC . 51 PUSH ECX 0040C6FD . FF15 54104000 CALL DWORD PTR DS:[<&MSVBVM60.__vbaObjSe>; MSVBVM60.__vbaObjSet 0040C703 . 8BF0 MOV ESI,EAX 0040C705 . 8D45 DC LEA EAX,DWORD PTR SS:[EBP-24] 0040C708 . 50 PUSH EAX 0040C709 . 56 PUSH ESI 0040C70A . 8B16 MOV EDX,DWORD PTR DS:[ESI] 0040C70C . FF92 A0000000 CALL DWORD PTR DS:[EDX+A0] 0040C712 . 3BC3 CMP EAX,EBX 0040C714 . DBE2 FCLEX 0040C716 . 7D 12 JGE SHORT CLEANER.0040C72A 0040C718 . 68 A0000000 PUSH 0A0 0040C71D . 68 004D4000 PUSH CLEANER.00404D00 0040C722 . 56 PUSH ESI 0040C723 . 50 PUSH EAX 0040C724 . FF15 40104000 CALL DWORD PTR DS:[<&MSVBVM60.__vbaHresu>; MSVBVM60.__vbaHresultCheckObj 0040C72A > 8B55 DC MOV EDX,DWORD PTR SS:[EBP-24] 0040C72D . 8D4D E4 LEA ECX,DWORD PTR SS:[EBP-1C] 0040C730 . 895D DC MOV DWORD PTR SS:[EBP-24],EBX 0040C733 . FF15 34114000 CALL DWORD PTR DS:[<&MSVBVM60.__vbaStrMo>; MSVBVM60.__vbaStrMove 0040C739 . 8D4D D4 LEA ECX,DWORD PTR SS:[EBP-2C] 0040C73C . FF15 44114000 CALL DWORD PTR DS:[<&MSVBVM60.__vbaFreeO>; MSVBVM60.__vbaFreeObj 0040C742 . 8D4D E4 LEA ECX,DWORD PTR SS:[EBP-1C] 0040C745 . 51 PUSH ECX 一路F10到这里 0040C746 . E8 75F2FFFF CALL CLEANER.0040B9C0 //关键Call,跟进去。 0040C74B . 66:85C0 TEST AX,AX
上一篇:亿维E书 V0.9算法
下一篇:空档接龙助手2.01注册码分析
|