etModuleHandleA`
016F:3257DBEB
PUSH EAX 016F:3257DBEC
CALL NEAR [
ESI+18] <<---关键! ! !
016F:3257DBEF
ADD ESP,
BYTE +10
016F:3257DBF2
PUSH EAX 016F:3257DBF3
CALL `CC3250MT!_exit`
016F:3257DBF8
POP ECX 016F:3257DBF9
JMP SHORT 3257DC1C
016F:3257DBFB
MOV EDX,[325AD400]
016F:3257DC01
PUSH EDX 016F:3257DC02
MOV ECX,[325AD3FC]
016F:3257DC08
PUSH ECX ......................
当走到016F:3257DBEC
CALL NEAR [
ESI+18]时,按F10带过此处时,
软件弹出“未检测到本
软件使用的
软件狗,本
软件将工作试验版状态”对话框。估计在016F:3257DBEC
CALL NEAR [
ESI+18]此处有重大嫌疑,重新在此处下中断点。按F8进入此CAll。来到了SD3000的领空,就真正进入的
软件检查加密的核心。
.................
016F:004017F4 55
PUSH EBP 016F:004017F5 8BEC
MOV EBP,
ESP 016F:004017F7 83C4C0
ADD ESP,
BYTE -40
016F:004017FA 53
PUSH EBX 016F:004017FB 56
PUSH ESI 016F:004017FC 57
PUSH EDI 016F:004017FD B8D8C97500
MOV EAX,0075C9D8
016F:00401802 E8AD782800
CALL 006890B4
016F:00401807 6A00
PUSH BYTE +00
016F:00401809 680EC97500
PUSH DWORD 0075C90E
016F:0040180E E853933500
CALL `USER32!FindWindowA`
016F:00401813 8945C0
MOV [
EBP-40],
EAX 016F:00401816 837DC000
CMP DWORD [
EBP-40],
BYTE +00
016F:0040181A 7622
JNA 0040183E
016F:0040181C 6A00
PUSH BYTE +00
016F:0040181E 6A00
PUSH BYTE +00
016F:00401820 68B9080000
PUSH DWORD 08B9
016F:00401825 FF75C0
PUSH DWORD [
EBP-40]
016F:00401828 E841943500
CALL `USER32!PostMessageA`
016F:0040182D 33C0
XOR EAX,
EAX 016F:0040182F 8B55C4
MOV EDX,[
EBP-3C]
016F:00401832 64891500000000
MOV `DOSMGR_BackFill_Allowed`,
EDX 016F:00401839 E9F0030000
JMP 00401C2E
016F:0040183E C6050056890000
MOV BYTE [00895600],00
016F:00401845 803D0056890000
CMP BYTE [00895600],00
016F:0040184C 0F852B010000
JNZ NEAR 0040197D
016F:00401852 C6050056890001
MOV BYTE [00895600],01
016F:00401859 66C745D41400
MOV WORD [
EBP-2C],14
016F:0040185F 8D45F8
LEA EAX,[
EBP-08]
016F:00401862 E8D1030000
CALL 00401C38
016F:00401867 FF45E0
INC DWORD [
EBP-20]
016F:0040186A E86D353500
CALL `SD3000!@Dogtestpro@_ManCheckDlgDan$qqrv`
016F:0040186F 66C745D40800
MOV WORD [
EBP-2C],08
016F:00401875 66C745D42000
MOV WORD [
EBP-2C],20
016F:0040187B BA1FC97500
MOV EDX,0075C91F
016F:00401880 8D45F4
LEA EAX,[
EBP-0C]
016F:00401883 E8EC3D3500
CALL 00755674
016F:00401888 FF45E0
INC DWORD [
EBP-20]
016F:0040188B 8D55F4
LEA EDX,[
EBP-0C]
016F:0040188E 8D45F8
LEA EAX,[
EBP-08]
016F:00401891 E856413500
CALL 007559EC
016F:00401896 50
PUSH EAX 016F:00401897 FF4DE0
DEC DWORD [
EBP-20]
016F:0040189A 8D45F4
LEA EAX,[
EBP-0C]
016F:0040189D BA02000000
MOV EDX,02
016F:004018A2 E861403500
CALL 00755908
016F:0