|
发表于 2009-6-10 13:47:09
|显示全部楼层
老样子 查壳 ASP2.001的。。。
ESP定律干掉。。。
00559CB4 C3 RETN
00559CB5 . 8BEC MOV EBP,ESP
00559CB7 . 83C4 DC ADD ESP,-24
00559CBA . 33C9 XOR ECX,ECX
00559CBC . 894D E4 MOV DWORD PTR SS:[EBP-1C],ECX
00559CBF . 894D F0 MOV DWORD PTR SS:[EBP-10],ECX
00559CC2 . 8955 E8 MOV DWORD PTR SS:[EBP-18],EDX
00559CC5 . 8945 FC MOV DWORD PTR SS:[EBP-4],EAX
00559CC8 . 33C0 XOR EAX,EAX
00559CCA 55 PUSH EBP
00559CCB . 68 049F5500 PUSH MIR2_u.00559F04
00559CD0 . 64:FF30 PUSH DWORD PTR FS:[EAX]
00559CD3 . 64:8920 MOV DWORD PTR FS:[EAX],ESP
00559CD6 . A1 30295700 MOV EAX,DWORD PTR DS:[572930]
00559CDB . 8338 00 CMP DWORD PTR DS:[EAX],0
00559CDE . 7E 07 JLE SHORT MIR2_u.00559CE7
00559CE0 . A1 30295700 MOV EAX,DWORD PTR DS:[572930]
00559CE5 . FF08 DEC DWORD PTR DS:[EAX]
00559CE7 > A1 40205700 MOV EAX,DWORD PTR DS:[572040]
00559CEC . 0FB640 40 MOVZX EAX,BYTE PTR DS:[EAX+40]
00559CF0 . BA 14000000 MOV EDX,14
00559CF5 . 2BD0 SUB EDX,EAX
00559CF7 . 6BC2 46 IMUL EAX,EDX,46
00559CFA . 8B15 FC285700 MOV EDX,DWORD PTR DS:[5728FC] ; MIR2_u.00571C58
00559D00 . 8902 MOV DWORD PTR DS:[EDX],EAX
00559D02 . A1 40205700 MOV EAX,DWORD PTR DS:[572040]
00559D07 . 0FB640 41 MOVZX EAX,BYTE PTR DS:[EAX+41]
00559D0B . BA 14000000 MOV EDX,14
00559D10 . 2BD0 SUB EDX,EAX
00559D12 . 6BC2 46 IMUL EAX,EDX,46
00559D15 . 8B15 2C205700 MOV EDX,DWORD PTR DS:[57202C] ; MIR2_u.00571C60
00559D1B . 8902 MOV DWORD PTR DS:[EDX],EAX
00559D1D . A1 10B15E00 MOV EAX,DWORD PTR DS:[5EB110]
00559D22 . 8B80 EC3B0C00 MOV EAX,DWORD PTR DS:[EAX+C3BEC]
00559D28 . 8B40 08 MOV EAX,DWORD PTR DS:[EAX+8]
00559D2B . 48 DEC EAX
00559D2C . 85C0 TEST EAX,EAX
00559D2E . 7C 6B JL SHORT MIR2_u.00559D9B
00559D30 . 40 INC EAX
00559D31 . 8945 EC MOV DWORD PTR SS:[EBP-14],EAX
00559D34 . C745 F8 00000>MOV DWORD PTR SS:[EBP-8],0
00559D3B > A1 10B15E00 MOV EAX,DWORD PTR DS:[5EB110]
00559D40 . 8B80 EC3B0C00 MOV EAX,DWORD PTR DS:[EAX+C3BEC]
00559D46 . 8B55 F8 MOV EDX,DWORD PTR SS:[EBP-8]
00559D49 . E8 2A2AECFF CALL MIR2_u.0041C778
00559D4E . 8B50 34 MOV EDX,DWORD PTR DS:[EAX+34]
00559D51 . 8B45 FC MOV EAX,DWORD PTR SS:[EBP-4]
00559D54 . E8 4B32FFFF CALL MIR2_u.0054CFA4
00559D59 . 84C0 TEST AL,AL
00559D5B . 74 1C JE SHORT MIR2_u.00559D79
00559D5D . A1 10B15E00 MOV EAX,DWORD PTR DS:[5EB110]
00559D62 . 8B80 EC3B0C00 MOV EAX,DWORD PTR DS:[EAX+C3BEC]
00559D68 . 8B55 F8 MOV EDX,DWORD PTR SS:[EBP-8]
00559D6B . E8 082AECFF CALL MIR2_u.0041C778
00559D70 . C680 00020000>MOV BYTE PTR DS:[EAX+200],1
00559D77 . EB 1A JMP SHORT MIR2_u.00559D93
00559D79 > A1 10B15E00 MOV EAX,DWORD PTR DS:[5EB110]
00559D7E . 8B80 EC3B0C00 MOV EAX,DWORD PTR DS:[EAX+C3BEC]
00559D84 . 8B55 F8 MOV EDX,DWORD PTR SS:[EBP-8]
00559D87 . E8 EC29ECFF CALL MIR2_u.0041C778
00559D8C . C680 00020000>MOV BYTE PTR DS:[EAX+200],0
00559D93 > FF45 F8 INC DWORD PTR SS:[EBP-8]
00559D96 . FF4D EC DEC DWORD PTR SS:[EBP-14]
00559D99 .^ 75 A0 JNZ SHORT MIR2_u.00559D3B
00559D9B > A1 38255700 MOV EAX,DWORD PTR DS:[572538]
00559DA0 . 8B00 MOV EAX,DWORD PTR DS:[EAX]
00559DA2 . 8B40 08 MOV EAX,DWORD PTR DS:[EAX+8]
00559DA5 . 48 DEC EAX
00559DA6 . 83F8 00 CMP EAX,0
00559DA9 . 7C 53 JL SHORT MIR2_u.00559DFE
00559DAB . 8945 F8 MOV DWORD PTR SS:[EBP-8],EAX
00559DAE > A1 38255700 MOV EAX,DWORD PTR DS:[572538]
00559DB3 . 8B00 MOV EAX,DWORD PTR DS:[EAX]
00559DB5 . 8B55 F8 MOV EDX,DWORD PTR SS:[EBP-8]
00559DB8 . E8 BB29ECFF CALL MIR2_u.0041C778
00559DBD . FFB0 2C020000 PUSH DWORD PTR DS:[EAX+22C]
00559DC3 . E8 54F6F7FF CALL MIR2_u.004D941C
00559DC8 . 5A POP EDX
00559DC9 . 2BC2 SUB EAX,EDX
00559DCB . 3D 60EA0000 CMP EAX,0EA60
00559DD0 . 76 23 JBE SHORT MIR2_u.00559DF5
00559DD2 . A1 38255700 MOV EAX,DWORD PTR DS:[572538]
00559DD7 . 8B00 MOV EAX,DWORD PTR DS:[EAX]
00559DD9 . 8B55 F8 MOV EDX,DWORD PTR SS:[EBP-8]
00559DDC . E8 9729ECFF CALL MIR2_u.0041C778
00559DE1 . E8 C2A2EAFF CALL MIR2_u.004040A8
00559DE6 . A1 38255700 MOV EAX,DWORD PTR DS:[572538]
00559DEB . 8B00 MOV EAX,DWORD PTR DS:[EAX]
00559DED . 8B55 F8 MOV EDX,DWORD PTR SS:[EBP-8]
00559DF0 . E8 7328ECFF CALL MIR2_u.0041C668
00559DF5 > FF4D F8 DEC DWORD PTR SS:[EBP-8]
00559DF8 . 837D F8 FF CMP DWORD PTR SS:[EBP-8],-1
00559DFC .^ 75 B0 JNZ SHORT MIR2_u.00559DAE
00559DFE > E8 19F6F7FF CALL MIR2_u.004D941C
00559E03 . 8B15 EC285700 MOV EDX,DWORD PTR DS:[5728EC] ; MIR2_u.0057DFC0
00559E09 . 2B02 SUB EAX,DWORD PTR DS:[EDX]
00559E0B . 3D 88130000 CMP EAX,1388
00559E10 . 72 15 JB SHORT MIR2_u.00559E27
00559E12 . 8B45 FC MOV EAX,DWORD PTR SS:[EBP-4]
00559E15 . E8 F29A0000 CALL MIR2_u.0056390C
00559E1A . E8 FDF5F7FF CALL MIR2_u.004D941C
00559E1F . 8B15 EC285700 MOV EDX,DWORD PTR DS:[5728EC] ; MIR2_u.0057DFC0
00559E25 . 8902 MOV DWORD PTR DS:[EDX],EAX
00559E27 > E8 F0F5F7FF CALL MIR2_u.004D941C
00559E2C . 8B15 18205700 MOV EDX,DWORD PTR DS:[572018] ; MIR2_u.0058A2C4
00559E32 . 2B02 SUB EAX,DWORD PTR DS:[EDX]
00559E34 . 3D 10270000 CMP EAX,2710
00559E39 . E9 A8000000 JMP MIR2_u.00559EE6
00559E3E 90 NOP
00559E3F . E8 D8F5F7FF CALL MIR2_u.004D941C
00559E44 . 8B15 18205700 MOV EDX,DWORD PTR DS:[572018] ; MIR2_u.0058A2C4
00559E4A . 8902 MOV DWORD PTR DS:[EDX],EAX
00559E4C . 8D55 F0 LEA EDX,DWORD PTR SS:[EBP-10]
00559E4F . 8B45 FC MOV EAX,DWORD PTR SS:[EBP-4]
00559E52 . E8 DD800000 CALL MIR2_u.00561F34
00559E57 . 84C0 TEST AL,AL
00559E59 . E9 88000000 JMP MIR2_u.00559EE6
00559E5E . 50 PUSH EAX ; /Arg1
00559E5F . 8B45 F0 MOV EAX,DWORD PTR SS:[EBP-10] ; |
00559E62 . 8945 DC MOV DWORD PTR SS:[EBP-24],EAX ; |
00559E65 . C645 E0 0B MOV BYTE PTR SS:[EBP-20],0B ; |
00559E69 . 8D55 DC LEA EDX,DWORD PTR SS:[EBP-24] ; |
00559E6C . 33C9 XOR ECX,ECX ; |
00559E6E . B8 189F5500 MOV EAX,MIR2_u.00559F18 ; |特征字符:%s\
00559E73 . E8 202DEBFF CALL MIR2_u.0040CB98 ; \MIR2_u.0040CB98
00559E78 . 8D45 E4 LEA EAX,DWORD PTR SS:[EBP-1C]
00559E7B . BA 309F5500 MOV EDX,MIR2_u.00559F30 ; 系统检测到你正在使用非法程序,请关闭后在重新进入游戏.
00559E80 . E8 77B2EAFF CALL MIR2_u.004050FC
00559E85 . 8B55 E4 MOV EDX,DWORD PTR SS:[EBP-1C]
00559E88 . A1 7C2C5700 MOV EAX,DWORD PTR DS:[572C7C]
00559E8D . 8B00 MOV EAX,DWORD PTR DS:[EAX]
00559E8F . 66:8B0D 689F5>MOV CX,WORD PTR DS:[559F68]
00559E96 . E8 7966F9FF CALL MIR2_u.004F0514
00559E9B . A1 FCB05E00 MOV EAX,DWORD PTR DS:[5EB0FC]
00559EA0 . E8 932FF1FF CALL MIR2_u.0046CE38
00559EA5 . A1 1C295700 MOV EAX,DWORD PTR DS:[57291C]
00559EAA . 8038 00 CMP BYTE PTR DS:[EAX],0
00559EAD . EB 37 JMP SHORT MIR2_u.00559EE6
00559EAF . 6A 00 PUSH 0 ; /Title = NULL
00559EB1 . 68 6C9F5500 PUSH MIR2_u.00559F6C ; |Class = "TfrmJsyClient"
00559EB6 . E8 9DDBEAFF CALL <JMP.&user32.FindWindowA> ; \FindWindowA
00559EBB . 8945 F4 MOV DWORD PTR SS:[EBP-C],EAX
00559EBE . 837D F4 00 CMP DWORD PTR SS:[EBP-C],0
00559EC2 . EB 22 JMP SHORT MIR2_u.00559EE6
00559EC4 . A1 7C2C5700 MOV EAX,DWORD PTR DS:[572C7C]
00559EC9 . 8B00 MOV EAX,DWORD PTR DS:[EAX]
00559ECB . 66:8B0D 689F5>MOV CX,WORD PTR DS:[559F68]
00559ED2 . BA 309F5500 MOV EDX,MIR2_u.00559F30
00559ED7 . E8 3866F9FF CALL MIR2_u.004F0514
00559EDC . A1 FCB05E00 MOV EAX,DWORD PTR DS:[5EB0FC]
00559EE1 . E8 522FF1FF CALL MIR2_u.0046CE38
00559EE6 > 33C0 XOR EAX,EAX
00559EE8 . 5A POP EDX
00559EE9 . 59 POP ECX
00559EEA . 59 POP ECX
00559EEB . 64:8910 MOV DWORD PTR FS:[EAX],EDX
00559EEE . 68 0B9F5500 PUSH MIR2_u.00559F0B
00559EF3 > 8D45 E4 LEA EAX,DWORD PTR SS:[EBP-1C]
00559EF6 . E8 39AFEAFF CALL MIR2_u.00404E34
00559EFB . 8D45 F0 LEA EAX,DWORD PTR SS:[EBP-10]
00559EFE . E8 31AFEAFF CALL MIR2_u.00404E34
00559F03 . C3 RETN
00559F04 .^ E9 07A9EAFF JMP MIR2_u.00404810
00559F09 >^ EB E8 JMP SHORT MIR2_u.00559EF3
00559F0B . 8BE5 MOV ESP,EBP
00559F0D . 5D POP EBP
00559F0E . C3 RETN |
|