新手学破解实战之4种方法让你快速入门(4)
2023-03-16 来源:你乐谷
004025DA.8D4D B4lea ecx,dword ptr ss:[ebp-0x4C]
004025DD.50push eax
004025DE.8D55 C4lea edx,dword ptr ss:[ebp-0x3C]
004025E1.51push ecx
004025E2.52push edx
004025E3.EB 56jmp XAfkayas_.0040263B
004025E568 C81B4000push Afkayas_.00401BC8;You Get Wrong
004025EA.68 9C1B4000push Afkayas_.00401B9C;
004025EF.FFD7call edi
004025F1.8BD0mov edx,eax
004025F3.8D4D E8lea ecx,dword ptr ss:[ebp-0x18]
004025F6.FFD3call ebx
004025F8.50push eax
004025F9.68 E81B4000push Afkayas_.00401BE8;Try Again
004025FE.FFD7call edi
00402600.8945 CCmov dword ptr ss:[ebp-0x34],eax
00402603.8D45 94lea eax,dword ptr ss:[ebp-0x6C]
00402606.8D4D A4lea ecx,dword ptr ss:[ebp-0x5C]
00402609.50push eax
0040260A.8D55 B4lea edx,dword ptr ss:[ebp-0x4C]
0040260D.51push ecx
0040260E.52push edx
0040260F.8D45 C4lea eax,dword ptr ss:[ebp-0x3C]
00402612.6A 00push 0x0
00402614.50push eax
00402615.C745 C4 08000mov dword ptr ss:[ebp-0x3C],0x8
0040261C.FF15 10414000 call dword ptr ds:[MSVBVM50.#595];MSVBVM50.rtcMsgBox
2、暂停法找关键位置
OD载入要破解的程序后,F9运行起来,点击按钮出现错误提示框,F12暂停后,ALT K显示调用,找到程序段地址的调用,双击进入也可来到关键位置
3、对消息函数下断
(MSVBVM50.rtcMsgBox)方法和F12法一样
4、查找字符串
004025DD.50push eax
004025DE.8D55 C4lea edx,dword ptr ss:[ebp-0x3C]
004025E1.51push ecx
004025E2.52push edx
004025E3.EB 56jmp XAfkayas_.0040263B
004025E568 C81B4000push Afkayas_.00401BC8;You Get Wrong
004025EA.68 9C1B4000push Afkayas_.00401B9C;
004025EF.FFD7call edi
004025F1.8BD0mov edx,eax
004025F3.8D4D E8lea ecx,dword ptr ss:[ebp-0x18]
004025F6.FFD3call ebx
004025F8.50push eax
004025F9.68 E81B4000push Afkayas_.00401BE8;Try Again
004025FE.FFD7call edi
00402600.8945 CCmov dword ptr ss:[ebp-0x34],eax
00402603.8D45 94lea eax,dword ptr ss:[ebp-0x6C]
00402606.8D4D A4lea ecx,dword ptr ss:[ebp-0x5C]
00402609.50push eax
0040260A.8D55 B4lea edx,dword ptr ss:[ebp-0x4C]
0040260D.51push ecx
0040260E.52push edx
0040260F.8D45 C4lea eax,dword ptr ss:[ebp-0x3C]
00402612.6A 00push 0x0
00402614.50push eax
00402615.C745 C4 08000mov dword ptr ss:[ebp-0x3C],0x8
0040261C.FF15 10414000 call dword ptr ds:[MSVBVM50.#595];MSVBVM50.rtcMsgBox
2、暂停法找关键位置
OD载入要破解的程序后,F9运行起来,点击按钮出现错误提示框,F12暂停后,ALT K显示调用,找到程序段地址的调用,双击进入也可来到关键位置
3、对消息函数下断
(MSVBVM50.rtcMsgBox)方法和F12法一样
4、查找字符串